Veeam Backup & Replication Version 7.0 January, 2014
2014 Veeam Software. All rights reserved. All trademarks are the property of their respective owners. No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form by any means, without written permission from Veeam Software Inc (Veeam). The information contained in this document represents the current view of Veeam on the issue discussed as of the date of publication and is subject to change without notice. Veeam shall not be liable for technical or editorial errors or omissions contained herein. Veeam makes no warranties, express or implied, in this document. Veeam may have patents, patent applications, trademark, copyright, or other intellectual property rights covering the subject matter of this document. All other trademarks mentioned herein are the property of their respective owners. Except as expressly provided in any written license agreement from Veeam, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. Important! Please read the End User Software License Agreement before using the accompanying software program(s). Using any part of the software indicates that you accept the terms of the End User Software License Agreement. 2 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
CONTENTS ABOUT THIS DOCUMENT... 4 INSTALLATION AND OPERATION... 4 BACKUP... 5 REPLICATION... 6 INSTANT VM RECOVERY... 6 QUICK MIGRATION... 7 SUREBACKUP... 8 FULL VM RESTORE... 9 REPLICA FAILOVER... 9 REPLICA FAILBACK... 10 FILE-LEVEL RESTORE (OTHER GUEST)... 10 CUMULATIVE PERMISSIONS... 11 3 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
ABOUT THIS DOCUMENT This document provides information about accounts and permissions required for Veeam Backup & Replication installation and operation, and also about granular vcenter Server permissions required for the certain Veeam Backup & Replication functions. INSTALLATION AND OPERATION The accounts used for installing and using Veeam Backup & Replication should have the following permissions: Account Setup Account Local Administrator permissions on the Veeam Backup & Replication console to install Veeam Backup & Replication Root permissions on the source ESX/ESXi server Target/Source Host SQL Server Local Administrator permissions on the source Hyper-V server. Root (or equivalent) permissions on the target Linux host. Write permission on the target folder and share. If vcenter is used, administrator credentials are required. The account used to run Veeam Backup service must have database owner role for the VeeamBackup database (or another one used as Veeam Backup database) on the SQL Server instance. The account used to run Veeam Backup Enterprise Manager service must have database owner role for the VeeamBackupReporting database (or another one used as Veeam Backup Enterprise Manager database)on the SQL Server instance. Full access to Microsoft Exchange database and its log files for item recovery. You need both Read and Write permissions to all files in the folder with the database. Veeam Explorer for Exchange Access rights for item recovery can be provided through impersonation, as described in the Configuring Exchange Impersonation article, or by providing user account with Full Access to mailbox. For more details, please refer to http://helpcenter.veeam.com/backup/70/vsphere/index.html?vee_required_permissions.html 4 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
Account The account used for working with Veeam Explorer for SharePoint requires membership in the sysadmin fixed server role on the staging Microsoft SQL Server. Veeam Explorer for SharePoint The account used for connection with target SharePoint server where document item(s)/list will be restored needs the following: If permissions of the item being restored are inherited from the parent item (list) - Full Control for that list is required. If permissions are not inherited, and restored item will replace an existing item - then Contribute for the item and Full Control for its parent list are required. Important! To backup and restore virtual machines in VMware vsphere 5.x environment, make sure the following permissions are set for the corresponding account at the vcenter Server level: Disable Methods,, Licenses. To read more, refer to the VMware KB article at http://kb.vmware.com/selfservice/microsites/search.do?language=en_us&cmd=displaykc&extern alid=2063054. BACKUP Below are vcenter Server granular permissions required for backup: Direct SAN Access Mode Virtual Appliance Mode Network Mode Licenses* Virtual Machine Guest operating system management by VIX API Disk lease * Required for template backups Guest operating system management by VIX API Change resource Add existing disk Remove disk Guest operating system management by VIX API 5 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
REPLICATION Below are vcenter Server granular permissions required for replication: Direct SAN Access Mode Virtual Appliance Mode Network Mode Guest operating system management by VIX API Device connection Guest operating system management by VIX API Device connection Guest operating system management by VIX API Device connection Virtual Machine Disk lease Change resource Add existing disk Remove disk Remove Remove Remove Assign VM to resource pool Assign VM to resource pool Assign VM to resource pool vapp * required for templates replication INSTANT VM RECOVERY Below are vcenter Server granular permissions required for Instant VM Recovery: Host Storage partition configuration Power Off 6 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
vapp s Assign VM to resource pool QUICK MIGRATION Below are vcenter Server granular permissions required for Quick Migration: vapp Disable methods Enable methods Licenses Log Event Settings s Suspend Device connection Power off Power on Add existing disk Change resource Remove disk Rename Remove Allow virtual machine download Assign virtual machine to resource pool Migrate powered off virtual machine Migrate powered on virtual machine 7 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
SUREBACKUP Below are vcenter Server granular permissions required for SureBackup: Licenses Host Network configuration Storage partition configuration Network Assign network Power Off Add or remove device Remove Assign VM to resource pool Create resource pool Remove resource pool Folder dvport Group Create folder Delete folder Create Delete 8 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
FULL VM RESTORE Below are vcenter Server granular permissions required for full VM restore: Folder vapp Disable methods Enable methods Allow VM files upload Remove disk Assign VM to resource pool Create folder dvport Group REPLICA FAILOVER Create Delete Below are vcenter Server granular permissions required for replica failover: Power Off Rename 9 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
REPLICA FAILBACK Below are vcenter Server granular permissions required for replica failback: Power Off Allow virtual machine download Rename Disk lease Add existing disk Remove disk Assign VM to resource pool FILE-LEVEL RESTORE (OTHER GUEST) Below are vcenter Server granular permissions required for FLR (other guest OS): Network Assign network Configure Modify device settings Power Off Assign VM to resource pool Host Storage partition configuration 10 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
CUMULATIVE PERMISSIONS This section lists cumulative vcenter permissions required for Veeam Backup & Replication operations. Important! To backup and restore virtual machines in VMware vsphere 5.x environment, make sure the following permissions are set for the corresponding account at the vcenter Server level: Disable Methods,, Licenses. To read more, refer to the VMware KB article at http://kb.vmware.com/selfservice/microsites/search.do?language=en_us&cmd=displaykc&extern alid=2063054. Cumulative Permissions Network Licenses Settings Assign network Configure Add existing disk Add or remove device Change resource Disk lease Modify device settings Remove disk Rename Device connection Guest operating system management by VIX API Power Off Suspend Remove Allow VM files upload 11 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS
Cumulative Permissions Host Folder vapp dvport Group Assign VM to resource pool Create resource pool Remove resource pool Migrate powered off virtual machine Migrate powered on virtual machine Network configuration Storage partition configuration Create folder Delete folder Create Delete 12 Veeam Backup & Replication 7.0 REQUIRED PERMISSIONS