Solved

Login to Veeam with Domain users when the server is a workgroup

  • 24 January 2024
  • 6 comments
  • 180 views

Userlevel 4

I removed the veeam B&R server and Enterprise manager from the domain due to security issues, and now I want to know if it is possible to log in to these servers, which are workgroups, with domain users ?

Is there a best practice?
 

icon

Best answer by coolsport00 24 January 2024, 20:06

View original

6 comments

Userlevel 7
Badge +17

You can only log in with domain users if a domain user has already logged in. Their credentials are cached (i.e. user profiles). But, if/when passwords change for the domain users, the domain users’ credentials wouldn’t reflect the pwd change on the servers. You would need to have local admin users created to be able to use Veeam components.

Veeam actually recommends to put its components in a “management domain”, separate from your regular production environment. It does cause a little complexity obviously, however. But, so does having the components in a workgroup. You just have to decide what route you’re most comfortable with. Veeam discusses your setup in their Best Practice Guide. You can review their recommendations, pros/cons, here.

 

Userlevel 7
Badge +6

Hello, @Jenes hooshangi. The procedure is exactly informed by @coolsport00! In the best practices chapter regarding Hardeninfg, there is a reference architecture about domains and components that is very complete. Follow the link:

Segmentation - Veeam Backup & Replication Security Best Practice Guide

 

 

 

 

Userlevel 7
Badge +20

If you will keep the servers in a Workgroup, then create local accounts with Administrative rights on each server to be able to log in to the VBR/VEM consoles.  That is best practice when working with a Workgroup setup, otherwise follow the best practices for a backup domain as noted by others.

Userlevel 7
Badge +20

Hi,

 

This is the case due to a few core constraints that are all overcome with a management domain.

Firstly, trust. We don’t trust the domain on our server, so why would the server trust users of the domain that we don’t trust? Without being part of the security ecosystem of an AD domain, we can’t trust identities.

Secondly, authentication methods. Veeam utilises windows authentication of a user account to validate who the user says they are, if windows can’t validate they’re part of the domain, we can’t use windows authentication.

 

If you deploy a dedicated management domain instead you’ll enjoy your logical separation of production and management, whilst achieving this centralised identity requirement you have

Userlevel 2
Badge

Anyone have insight into using Workgroup and having to restore files to a domain share? Not exactly this topic but close in ways that maybe someone here has insight or can point us in the right direction.

Userlevel 7
Badge +20

Anyone have insight into using Workgroup and having to restore files to a domain share? Not exactly this topic but close in ways that maybe someone here has insight or can point us in the right direction.

You would need login credentials for the domain but should be able to restore.  The other option is restore locally then copy over to the domain.

Comment