You use information security and access control configurations to prevent unauthorized access and accidental or malicious damage to the backup data.
Because the image-level backups use vCenter Server, provision a service account for your VADP-compatible solution that has only the correct level of access.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
SDDC-BC-BR-040 |
Configure an Active Directory backed service account in vCenter Server for application-to-application communication from your VADP-compatible backup solution to vSphere. |
Provides the following access control features:
|
You must maintain the service account's life cycle outside of the SDDC stack to ensure its availability. |
SDDC-BC-BR-041 |
Use global permissions when you create the service account in vCenter Server. |
|
All vCenter Server instances must be in the same vSphere domain. |