This is an archive version of the document. To get the most up-to-date information, see the current version.

Permissions and Security Groups

Do not mix permissions on virtual infrastructure inventory objects with the Veeam ONE security model that is based on security groups.

Users in Security Groups

Security groups define what actions users can perform in Veeam ONE. That is, what part of Veeam ONE functionality is available to users.

  • Veeam ONE Administrators have access to all functions in Veeam ONE. They can perform all types of actions that Veeam ONE supports, including configuration actions.
  • Veeam ONE Read-Only Users have limited access to Veeam ONE functions: they can access data in the read-only mode but cannot perform configuration tasks.

Users included in either Veeam ONE security group (Administrators or Read-Only Users) have access to:

  • All Veeam ONE consoles (Veeam ONE Monitor, Veeam ONE Reporter, Veeam ONE Business View)
  • All objects of the infrastructure inventory (including VMware vSphere, vCloud Director, Microsoft Hyper-V and Veeam Backup & Replication)

Users with Restricted Permissions on Virtual Infrastructure Inventory

Permissions define what part of the virtual infrastructure is visible to a Veeam ONE user. To monitor and report on a restricted subset of the virtual infrastructure in Veeam ONE, a user must have permissions assigned on objects of the VMware vSphere or vCloud Director inventory hierarchy. In this case, the user can utilize Veeam ONE monitoring and reporting capabilities for available objects of the VMware vSphere or vCloud Director infrastructure. Microsoft Hyper-V and Veeam Backup & Replication inventory objects will be unavailable for the user.

Note that for users of this type some Veeam ONE functionality is disabled.  For details on limitations, see section Functional Restrictions.

Permissions and Security Groups Important!

Do not include a user with restricted permissions into Veeam ONE security groups. Members of security groups always have access to the whole infrastructure inventory in Veeam ONE, regardless of their permissions on the VMware vSphere or vCloud Director inventory hierarchy.