maxrebo Posted January 20, 2022 Posted January 20, 2022 Hi, We have been advised to de-attach our Veeam backup service from our Active directory, to prevent attackers from gaining access to this in the event of a Ransomware attack. Our current setup is a domain joined Virtual Machine with the latest Veeam version, we (and the backups) connect to this using our domain admin credentials. Is the best way of doing this by having the VM non domain joined and backups connecting to this using the local admin account of the VM?
Aprice Posted January 20, 2022 Posted January 20, 2022 Yes, kick the Veeam server off the domain, so you only login to it with a local windows user. The backup jobs can use a domain account, or local one to connect to the VM being backed up. I don't think it would matter either way so long as the Veeam server is off the domain. Also worth making sure that the storage is secure, not using domain authentication either. Alex 2
maxrebo Posted January 20, 2022 Author Posted January 20, 2022 Yes, kick the Veeam server off the domain, so you only login to it with a local windows user. The backup jobs can use a domain account, or local one to connect to the VM being backed up. I don't think it would matter either way so long as the Veeam server is off the domain. Also worth making sure that the storage is secure, not using domain authentication either. Alex That`s great, Thank you. 1
supportman Posted January 20, 2022 Posted January 20, 2022 Yep its a good idea, and of course Veeam can hold credentials securly for the domain.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now