Veeam Backup 11 0 Permissions
Veeam Backup 11 0 Permissions
Veeam Backup 11 0 Permissions
Version 11
Required Permissions for VMware vSphere
July, 2021
© 2021 Veeam Software.
All rights reserved. All trademarks are the property of their respective owners.
No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or
translated into any language in any form by any means, without written permission from Veeam Software
(Veeam). The information contained in this document represents the current view of Veeam on the issue
discussed as of the date of publication and is subject to change without notice. Veeam shall not be liable for
technical or editorial errors or omissions contained herein. Veeam makes no warranties, express or implied, in
this document. Veeam may have patents, patent applications, trademark, copyright, or other intelle ctual
property rights covering the subject matter of this document. All other trademarks mentioned herein are the
property of their respective owners. Except as expressly provided in any written license agreement from Veeam,
the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other
intellectual property.
NOTE :
Read the End User Software License Agreement before using the accompanying software programs. Using
any part of the software indicates that you accept the terms of the End User Software License Agreement.
Customer Support
Should you have a technical concern, suggestion or question, visit the Veeam Customer Support Portal to open a
case, search our knowledge base, reference documentation, manage your license or obtain the latest product
release.
Company Contacts
For the most up-to-date information about company contacts and office locations, visit the Veeam Contacts
Webpage.
Online Support
If you have any questions about Veeam products, you can use the following resources:
Setup Account Local Administrator permissions on the Veeam Backup & Replication console to install
Veeam Backup & Replication.
SQL Server The account used to run Veeam Backup Service requires db-datareader and
db_datawriter roles, as well as permissions to execute stored procedures for the
VeeamBackup database (or another one used as Veeam Backup database) on the SQL
Server instance. Alternatively, you can assign db_owner role for that database to
service account.
The account used to run Veeam Backup Enterprise Manager service requires db-
datareader and db_datawriter roles, as well as permissions to execute stored
procedures for the VeeamBackupReporting database (or another one used as Veeam
Backup Enterprise Manager database) on the SQL Server instance. Alternatively, you
can assign db_owner role for that database to service account.
Veeam Backup Local Administrator permissions on the destination server to install Veeam Backup
E nterprise Manager Enterprise Manager.
To be able to work with Veeam Backup Enterprise Manager, users must be assigned
the Portal Administrator, Restore Operator or Portal User role.
For more information on permissions required for Enterprise Manager operation, see
the Required Permissions section in the Enterprise Manager User Guide.
Veeam Explorer for The account used for connection with target domain controller where
Microsoft Active objects/containers will be restored needs the following:
Directory
• Administrative rights for target Active Directory
• Membership in the Exchange Organization Management group — to provide for
automatic mailbox re-connect for recovered user or group account
• The user account that you specify for guest processing of the Microsoft SQL
Veeam Explorer for
Microsoft SQL Server VM in the backup job should have the sysadmin fixed role assigne d on
Server that SQL Server, or the set of garnular roles described here.
• The account you will use to access the target Microsoft SQL server where
database will be restored needs the sysadmin fixed role on that server.
• The account you plan to use for connection to the Windows machine (where
database log backup files will be copied for further log replay) will need
sufficient permissions to access the administrative share on that machine: Read
and Write are minimal required. For restore scenarios that involve log r eplay,
that machine is your target SQL Server. For export, this is your staging system.
For more information, see the Required Permissions section in the Veeam
Explorers User Guide.
• The account used to run Veeam Explorer for Microsoft SQL Server should have
sufficient permissions for the folder where you plan to export the database files:
Read and Write are minimal recommended.
Veeam Explorer for Full access to Microsoft Exchange database and its log files for item recovery. You
Microsoft Exchange need both Read and Write permissions to all files in the folder with the database.
Access rights for item recovery can be provided through impersonation, as described
in the Configuring Exchange Impersonation article, or by providing user account with
Full Access to mailbox.
For more information, see the Required Permissions section in the Veeam Explorers
User Guide.
Veeam Explorer for For more information on accounts used for Veeam Explorer operations and
Microsoft corresponding permissions, see the Required Permissions section in the Veeam
Sha rePoint Explorers User Guide.
Veeam Explorer for For more information on accounts used for Veeam Explorer operations, and
Ora cle corresponding permissions see the Required Permissions section in the Veeam
Explorers User Guide.
IMP ORTANT!
To back up and restore virtual machines in VMware vSphere 5.x environment, make sure the following
permissions are set for the corresponding account at the vCenter Server level: Disable methods, Enable
methods, Licenses.
For more information, see the VMware Knowledge Base KB 2063054 article.
IMP ORTANT!
To back up and restore virtual machines in VMware vSphere 5.x environment, make sure the following
permissions are set for the corresponding account at the vCenter Server level: Disable Methods, Enable
Methods, Licenses.
For more information, refer to the VMware Knowledge Base KB 2063054 article.
NOTE :
The permissions to create and edit tag categories can only be granted at the root level.
E d it Inventory Create
Register
Remove
Unregister
* required if machines have Virtual Compatibility RDM disks and Virtual appliance mode is used for a backup p roxy
** required for template restore
Virtual Cha nge Acquire disk lease Acquire disk lease Acquire disk lease
Ma chine Configuration Advanced Add existing disk Advanced
configuration Add or remove device configuration
Set Annotation Advanced configuration Set annotation
Toggle disk change Configure RAW device (if Toggle disk change
tracking machines have Virtual tracking
Compatibility RDM disks)
Remove disk
Set annotation
Toggle disk change tracking
P rovisioning Allow read-only disk Allow read-only disk access Allow read-only disk
access Allow virtual machine access
Allow virtual machine download Allow virtual machine
download download
Resource Assign virtual machine Assign virtual machine Assign virtual machine
to resource pool to resource pool to resource pool
vAp p Add virtual machine Add virtual machine Add virtual machine
Assign resource pool Assign resource pool Assign resource pool
Unregister Unregister Unregister
Virtual Cha nge Acquire disk lease Acquire disk lease Acquire disk lease
Ma chine Configuration Add new disk Add existing disk Add new disk
Advanced configuration Add new disk Advanced configuration
Extend virtual disk Advanced configuration Extend virtual disk
Toggle disk change Change resource Toggle disk change
tracking Extend virtual disk tracking
Remove disk
Toggle disk change
tracking
P rovisioning Allow disk access Allow disk access Allow disk access
Allow read-only disk Allow read-only disk Allow read-only disk
access access access
Allow virtual machine Allow virtual machine Allow virtual machine
download download download
E d it Inventory Register
E d it Inventory Register
Remove
E d it Inventory Register
E d it Inventory Register
Unregister
E d it Inventory Register
Remove
Unregister
Global Licenses
Log event
E d it Inventory Register
Remove
Unregister
vAp p Add virtual machine Add virtual machine Add virtual machine
Assign resource pool Assign resource pool Assign resource pool
Unregister Unregister Unregister
Virtual Cha nge Acquire disk lease Add existing disk Add existing disk
Ma chine Configuration Add existing disk Add new disk Add new disk
Add new disk Advanced configuration Advanced configuration
Advanced Change Settings Change Settings
configuration Modify device settings Modify device settings
Change Settings Remove disk Remove disk
Modify device Toggle disk change Toggle disk change
settings tracking tracking
Remove disk
Toggle disk change
tracking
P rovisioning Allow disk access Allow disk access Allow disk access
Allow read-only disk Allow read-only disk Allow read-only disk
access access access
Allow virtual Allow virtual machine Allow virtual machine
machine download download download
Allow virtual Allow virtual machine Allow virtual machine
machine files upload files upload files upload
Mark as template* Mark as template* Mark as template*
Mark as virtual Mark as virtual machine* Mark as virtual machine*
machine*
E d it Inventory Register
Unregister