Skip to main content

Acronis Backup 12.5 client has too much permissions

Thread solved

I don't know if I missed something, but, after installing backup server into a machine, then I added a client through internet with the public ip. Everything was right, until I realized that client, through internet, can access to the server console and see every backup, delete it, restore it, download backups that don't belong to that client, and more, as client was the admin.

When I open the web console on agent, I use their windows account (machineName\username), not the server win account

Is there a way to solve this? Agent just had to see their own backups only.

 

0 Users found this helpful
frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 0
Comments: 2016

Hello Ricard,

welcome to Acronis forums!

I recommend that you read the respective chapter regarding user administration in Acronis Cyber Backup 12.5: https://www.acronis.com/en-us/support/documentation/AcronisBackup_12.5/index.html#39307.html

In your situation, you should delete that remote Agent, then follow Settings -> Administrators on the Backup Console UI and create a separate Unit for remote Agents with respective rights to restrict their access to other units. Then deploy these Agents to the remote PCs.

Oh ok, thanks I see how it works now, but after installing the agent remotely, I can see the agent machine name on devices but can't add it to administrators from their Unit, I search for the machine name or windows account and there is nothing to find.

Should the windows account be added automatically to the server console?

Because after deploying the agent to a specific Unit, when I try to access to the console from the new Agent using Agent's windows credentials, it says the user or password are incorrect.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 0
Comments: 2016

Hello Ricard.

You do not need to create a separate Windows account for each Agent. Please create Windows account for a dedicated Unit on the Management Server (Unit Administrator). When you switch to this Unit in the Organization tree, please Add Devices (remote Agents) to this Unit. These Agents will connect to the backup console under the Unit Administrator Windows account.

Ok, thanks Maria.

So, a windows account is only necessary if you want to split data, I mean, prevent a unit to see what data have another unit.

Thanks.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 0
Comments: 2016

Hello Ricard.

Yes, all Agents that are added to a Unit under a specific Windows account will have access rights of this account on your management server. Despite the right granted by this Windows account, an Agent of a Unit could not switch outside of its Unit.