Right now Veeam is installed and running using the domain account administrator (yes I know, bad IT guy). In efforts to become more secure I was going to do what I thought was the correct thing and create a backup domain account. Put that account in the backup operator group on the VM’s being backed up and then do what ever else was needed to backup things with a less privileged approach.<\/p>\n
Looking at Veeam’s documentations in order to back up anything in a vsphere environment you need to give the account root access to VMware, local admin to the server running Veeam, local admin on the VM’s you are backing up and domain admin access to do AD. So is there a benefit to changing Veeam over to this back up account that I am not seeing? Since I want to back AD the account will have domain Admin access. Is there a link that maybe describes least privileged access that I am not finding?<\/p>\n
I do have an immutable repository so I have some protection<\/p>","upvoteCount":14,"answerCount":9,"datePublished":"2021-10-11T15:45:10.000Z","author":{"@type":"Person","name":"davidglazewwski","url":"https://community.spiceworks.com/u/davidglazewwski"},"suggestedAnswer":[{"@type":"Answer","text":"
Right now Veeam is installed and running using the domain account administrator (yes I know, bad IT guy). In efforts to become more secure I was going to do what I thought was the correct thing and create a backup domain account. Put that account in the backup operator group on the VM’s being backed up and then do what ever else was needed to backup things with a less privileged approach.<\/p>\n
Looking at Veeam’s documentations in order to back up anything in a vsphere environment you need to give the account root access to VMware, local admin to the server running Veeam, local admin on the VM’s you are backing up and domain admin access to do AD. So is there a benefit to changing Veeam over to this back up account that I am not seeing? Since I want to back AD the account will have domain Admin access. Is there a link that maybe describes least privileged access that I am not finding?<\/p>\n
I do have an immutable repository so I have some protection<\/p>","upvoteCount":14,"datePublished":"2021-10-11T15:45:11.000Z","url":"https://community.spiceworks.com/t/question-for-veeam-experts-out-there/813680/1","author":{"@type":"Person","name":"davidglazewwski","url":"https://community.spiceworks.com/u/davidglazewwski"}},{"@type":"Answer","text":"
I guess I’m not 100% sure what you’re asking, but I can explain how I do it on my, and my clients, smaller networks. (Mind you my largest client is about 20 people, same with my office). We backup just the 3 servers in my office. All windows, 2 servers to 1 repository, and the financial server to its own repository.<\/p>\n
I have two accounts for myself. One is an admin account, the other is my normal user account. My admin account is used for things like you explain (backups, giving approval to individuals who want to install things locally, the sonicwall AD account, etc.), and my user account is what I use for everything else. They use two separate passwords and are configured completely different.<\/p>\n
Like I said, not sure if this helps, it’s just the way that I do it. I feel it’s a bit more secure since I use the admin account extremely rarely.<\/p>","upvoteCount":0,"datePublished":"2021-10-11T18:02:57.000Z","url":"https://community.spiceworks.com/t/question-for-veeam-experts-out-there/813680/2","author":{"@type":"Person","name":"anonimoose","url":"https://community.spiceworks.com/u/anonimoose"}},{"@type":"Answer","text":"
Run Veeam on a non-domain-joined computer with a local account. It will connect to domain guests just fine with credentials, and isn’t flapping in the breeze for ransomware or whatever else might go stomping through your network.<\/p>","upvoteCount":1,"datePublished":"2021-10-11T18:37:43.000Z","url":"https://community.spiceworks.com/t/question-for-veeam-experts-out-there/813680/3","author":{"@type":"Person","name":"johnmeredith3839","url":"https://community.spiceworks.com/u/johnmeredith3839"}},{"@type":"Answer","text":"
You would just create another user on VMware to backup the VMs and use the backup account to do in OS Snapshot and make sure the location where you back up to is not tied to a domain.<\/p>\n
These are the requirements<\/p>