Step 3. Specify Account Settings
At the Account step of the wizard, choose whether you want to use an IAM role, an AWS account or one-time access keys of an IAM user to allow Veeam Backup & Replication to perform the restore operation. For information on the permissions that the IAM role or IAM user must have to perform the restore operation, see EFS Restore IAM Permissions.
By default, Veeam Backup & Replication will do either of the following, depending on the AWS account to which the restored EFS file system belongs:
- If you restore the file system that belong to an AWS account within an AWS Organization, Veeam Backup for AWS automatically chooses the AWS account to which the source EFS file system belongs and the organization identity that contains the account.
- If you restore the file system that belong to a separate AWS account, Veeam Backup for AWS automatically chooses an IAM role from the same AWS account to which the source EFS file system belongs.
Specifying IAM Role
To specify an IAM role to be used for the restore operation, select the IAM role option and choose the necessary IAM role from the list. Keep in mind that the selected role must belong to an AWS account to which you plan to restore EFS file systems. For an IAM role to be displayed in the list of available roles, it must be added to the backup appliance as described in section Adding IAM Roles.
Specifying AWS Account
To specify an AWS account to be used for the restore operation, select the Organization account option. Since Veeam Backup for AWS does not support cross-account recovery of EFS file systems, Veeam Backup for AWS automatically chooses the AWS account to which the source EFS file systems belong and the organization identity (either an entire AWS Organization or a limited scope of organizational units) that includes the account.
For an organization identity to be displayed in the list of available identities, it must be added to the backup appliance as described in section Adding AWS Organizations. For an AWS account to be displayed in the list of available accounts, it must be included in the the selected organization identity.
Specifying One-Time Access Keys
To specify one-time access keys to be used for the restore operation, select the Temporary access keys option and use the Access key and Secret key fields to provide the access keys of an IAM user. Note that the IAM user must belong to an AWS account where the source file systems reside.
Note |
Veeam Backup for AWS does not store one-time access keys in the configuration database. |