Installation and Operation
The accounts used for installing and using Veeam Backup & Replication must have the following permissions (detailed list is provided in the User Guide):
Account | Required Permissions |
---|---|
Setup Account | Local Administrator permissions on the Veeam Backup & Replication console to install Veeam Backup & Replication. |
Target/Source Host Configuration | Linux host: root or equivalent permissions Hyper-V server: Local Administrator permissions Target folder and share: write permissions ESXi server: root permissions vCenter: administrative or granular* permissions * The required granular permissions depend on the operations that you are planning to carry out. For the possible operations, see other sections in this guide. For example, permissions required for backup operations are described in the Backup section. |
SQL Server | The account used to run Veeam Backup Service requires db-datareader and db_datawriter roles, as well as permissions to execute stored procedures for the VeeamBackup database (or another one used as Veeam Backup database) on the SQL Server instance. Alternatively, you can assign db_owner role for that database to service account. The account used to run Veeam Backup Enterprise Manager service requires db-datareader and db_datawriter roles, as well as permissions to execute stored procedures for the VeeamBackupReporting database (or another one used as Veeam Backup Enterprise Manager database) on the SQL Server instance. Alternatively, you can assign db_owner role for that database to service account. |
Veeam Backup Enterprise Manager | Local Administrator permissions on the destination server to install Veeam Backup Enterprise Manager. To be able to work with Veeam Backup Enterprise Manager, users must be assigned the Portal Administrator, Restore Operator or Portal User role. For more information on permissions required for Enterprise Manager operation, see the Required Permissions section in the Enterprise Manager User Guide. |
Veeam Explorer for Microsoft Active Directory | The account used for connection with target domain controller where objects/containers will be restored needs the following:
|
Veeam Explorer for Microsoft SQL Server |
|
Veeam Explorer for Microsoft Exchange | Full access to Microsoft Exchange database and its log files for item recovery. You need both Read and Write permissions to all files in the folder with the database. Access rights for item recovery can be provided through impersonation, as described in the Configuring Exchange Impersonation article, or by providing user account with Full Access to mailbox. For more information, see the Required Permissions section in the Veeam Explorers User Guide. |
Veeam Explorer for Microsoft SharePoint | For more information on accounts used for Veeam Explorer operations and corresponding permissions, see the Required Permissions section in the Veeam Explorers User Guide. |
Veeam Explorer for Oracle | For more information on accounts used for Veeam Explorer operations, and corresponding permissions see the Required Permissions section in the Veeam Explorers User Guide. |