Considerations and Limitations
General
-
A custom role can access only the operations and resources explicitly included in its scope. Operations not covered by any scope, such as replication or tape management, are unavailable to that role.
- Enhanced Role-Based Access Control (RBAC) feature is only available with a certain license edition. For more information, see Veeam Data Platform Feature Comparison.
-
Assigning both custom and built-in roles to the same user or group is not supported. A user who belongs to multiple groups can end up with a combination of custom and built-in roles, even though assigning both role types to the same user or group directly is not supported.
- Empty nodes may be displayed in the inventory tree if their objects are inaccessible to a custom role.
- If an administrator moves or copies a backup, the backup ACL will be reset, which may result in custom roles losing access to the backup.
- The software appliance backup server remains available for use even if only the Original location option is selected.
Job Editing
-
If a job contains a source, repository, credential, or encryption password that is unavailable to a role, that role cannot edit or clone the job. The user receives a warning. This also applies to the Administrator role for credentials and encryption passwords created by a custom role, since these objects are accessible only to that role. This applies to the Veeam Backup & Replication console, web UI, and REST API.
Backup
- If a user does not have permission to view certain credentials, those credentials do not appear in the backup wizard when editing a job. However, the credentials remain configured in the job.
- If a custom backup operator is not restricted to a specific repository, backups can be created in Snapshot Repositories.
Recovery
- The Encrypted backups node is not available to restore operators, unless the backups have been decrypted.
- Backups imported as VBK are not visible in the backup scope selection in the role wizard.
- A role with restrictions on the restore target cannot select a different location for the Copy to option in Linux file-level restore.
VMware vSphere
- In the Tag view, all vCenter Servers are always visible but cannot be added or expanded. VMware tags can only be used if they have been explicitly added to a role.
- vApps may be visible but cannot be selected for restore/backup operations.
- VMware objects associated with those added to a role may be visible but cannot be used.
- Unavailable original hosts may remain visible in certain restore wizards.
Unstructured Data Backup
- Role-based access control does not support instant file share recovery.
- If the original location is included in the target restore scope, the Copy to option in specific file and folder restore is unavailable.
- The Copy to option may be used to restore to more locations than those defined in the target restore scope.