Performing Security Officer Tasks
Users with Security Officer permissions can perform the following tasks in the Veeam Host Management web UI:
- Approve or decline authorization requests
- View authorization request events
- Reset own password
- Reset MFA
- Reset password recovery token
- Approve or decline remote password reset
- Use password recovery token to resolve authentication issues
- View and export Veeam appliance events
- Manage configuration backup passphrases
Note |
|
If you have multi-factor authentication enabled, you must enter a one-time password before you can complete the following operations:
Authentication remains valid for 15 minutes. |
Managing Authorization Requests
You can approve or decline the following requests from Host Administrators:
- Enable SSH
- Stop a Veeam service
- Grant temporary root access
- Reset password for the locked user
- Import configuration files
- Change a domain membership
- Add a Security Officer account
- Allow remote connections for Veeam Agents
- Allow a backup server to be added to a High Availability cluster
- Disable backup infrastructure lockdown
- Change the host management certificate
- Add a trusted certificate
To manage authorization requests, perform the following steps:
- Log in to the Veeam Host Management web UI as a Security Officer
- In the management pane, click Overview.
- Select the request and click Approve or Decline.
Viewing Authorization Request Events
Events related to Security Officer authorization requests include information about:
- Approved and rejected requests
- Locked and unlocked Host Administrator accounts
As a Security Officer, you can view these events in the Veeam Host Management web UI. For more information, see Viewing Appliance Events.
Local Veeam appliance users that have access to the Veeam Backup & Replication console as Backup Administrators, can view these events in the Veeam Backup & Replication web UI and desktop application.
To view authorization request events in the Veeam Backup & Replication web UI, perform the following steps:
- Log in to the Veeam Backup & Replication web UI as a Backup Administrator.
- In the management pane, click Logs and Events. Then, click the Authorization Events tab.
To view authorization request events in the Veeam Backup & Replication desktop application, perform the following steps:
- Log in to the Veeam Backup & Replication console as a Backup Administrator.
- Open the History view and select the Authorization Events node.
To view detailed information related to a specific authorization request event, select the event and click Details on the ribbon. Alternatively, right-click the event and select Details.
To receive email notifications with authorization request events, enable this setting in the Veeam Backup & Replication console. For more information, see Configuring Global Email Notification Settings.
As a Security Officer, you can reset your password in the Veeam Host Management web UI. To do this, perform the following steps:
- Log in to the Veeam Host Management web UI as a Security Officer.
- In the management pane, click Overview.
- Click Change password.
- Specify the current password and a new password and click Apply.
Note |
If you forgot or lost the password, or your Security Officer account locked after three failed login attempts, you can use a recovery token to restore access to your account. For more information, see Using Recovery Token. |
If you have multi-factor authentication issues, lose or change a mobile device with the mobile authentication application, you can use a recovery token to restore access to your account. For more information, see Using Recovery Token.
Resetting Password Recovery Token
You can reset your current password recovery token. To do this, perform the following steps:
- Log in to the Veeam Host Management web UI as a Security Officer.
- In the management pane, click Overview.
- Click Create password recovery token and confirm the operation.
- Enter a 6-digit confirmation code generated in the mobile authenticator application.
- Copy new recovery token and save it in a secure place.
Note |
|
When you reset a password recovery token, consider the following:
|
Approving or Declining Remote Password Reset
If remote password resets are enabled and a Host Administrator forgets their password or cannot log in to the Veeam Host Management web UI, they can request a password reset.
To approve or decline a password reset request, perform the following steps:
- Log in to the Veeam Host Management web UI as a Security Officer.
- In the management pane, click Overview.
- In the list of pending requests, select the password reset request and click Approve or Decline.
- If you approve the request, in the Password Reset window, specify a new password in the New password and Repeat password fields and click Apply.
- Provide the new password to the Host Administrator. They will be prompted to specify a new password the next time they log in.
If you forgot or lost the password, your Security Officer account locked after three failed login attempts, or you have multi-factor authentication issues, you can restore access through the recovery token generated during the initial Security Officer logon. To do this, perform the following steps:
- In the Veeam Host Management web UI sign-in page, click Forgot password?.
- Click I have a password recovery token.
- Specify your recovery token and click Sign in.
- Complete the Security Officer Initialization wizard to enter new password, set up multi-factor authentication and get new recovery token.
- Click Finish.
Note |
If multi-factor authentication was disabled in the Initial Configuration wizard, the MFA setup step of the Security Officer Initialization wizard is skipped. |
You can monitor system, security, configuration and other types of events occurred on the Veeam appliance. To view the list of events, log in to the Veeam Host Management web UI as a Security Officer and click Events in the management pane.
To export all events in the CSV format, click Export.
Managing Configuration Backup Passphrases
You can change the configuration backup passphrase that you configured during the initial Security Officer login. To do this, perform the following steps:
- Log in to the Veeam Host Management web UI as a Security Officer.
- In the management pane, click Configuration.
- In the Configuration Backup section, click Change passphrase.
- Specify new passphrase and hint.
- Click OK.
If you have a configuration backup passphrase from the previous backup server, you can add it to restore configuration. To do this, perform the following steps:
- Log in to the Veeam Host Management web UI as a Security Officer.
- In the management pane, click Configuration.
- In the Configuration Restore section, click Add.
- Specify a passphrase and a hint.
- Click OK.








