Quantcast
Channel: Veeam Support Knowledge Base
Viewing all articles
Browse latest Browse all 4362

How to upgrade Service Role to match new requirements

$
0
0

Challenge

After upgrading Veeam Backup for AWS you can receive the following notifications:
  • “Role for account Default Backup Restore has insufficient permissions for workers management. You need to grant them first”
  • “Role for account Default Backup Restore has insufficient permissions to use change-tracking in policies. You need to grant them first”

Solution

Within Veeam Backup for AWS, this happens when several new features and improvements are introduced. As a result, it requires new permissions for Service Role to operate normally. You will see these notifications if any role on the accounts page is missing some permissions.

Usual cause is the Worker Role missing required permissions from the list below.
To resolve this issue manually, you should add following permissions to your Worker Role:
"ebs:ListChangedBlocks"
"ebs:ListSnapshotBlocks"
"ec2:DescribeVolumeAttribute"
"ec2:GetEbsDefaultKmsKeyId"
"kms:CreateGrant"
"kms:GetKeyPolicy"
"kms:ReEncryptFrom"
"kms:ReEncryptTo"
"sqs:SetQueueAttributes"
"iam:GetContextKeysForPrincipalPolicy"
"iam:SimulatePrincipalPolicy"
Alternatively, you can use the Check Permissions button on the Accounts page within the Configuration section to see the list of missing permissions.

Viewing all articles
Browse latest Browse all 4362

Trending Articles