After Enabling MFA, Veeam Backup Server Is Listed as Inaccessible in Veeam Service Provider Console
Challenge
After enabling multi-factor authentication (MFA) in Veeam Backup & Replication or Veeam Cloud Connect, that server may become listed as "inaccessible" within Veeam Service Provider Console yet the Veeam Management Agent for VSPC continues to display a "healthy" status.
Cause
When MFA is enabled, the Local System account cannot access the Veeam Backup & Replication/Veeam Cloud Connect application. By default, the Veeam Service Provider Console management agents associated service on the Veeam Backup & Replication/Veeam Cloud Connect server runs under the Local System account.
Solution
To resolve this issue, review the options below:
Option 1: Have the Veeam Management Agent Use a Dedicated Service Account
The recommended solution is to configure the Veeam Management Agent service to use a dedicated service account (either Domain or Windows local) for which MFA is explicitly disabled. For more information, see Disabling MFA for Service Accounts.
- In Windows Services ( services.msc ), check if Veeam Management Agent is still running under the Local System account.
- Edit the Veeam Management Agent service and change the "Log on as" account from Local System account to any user that is a member of the Local Administrators group or any Domain account with Local Administrators group permissions on that machine.
- Add the Service account to Veeam Backup & Replication/Veeam Cloud Connect:
- Add the service account specified for the service to the Users and Roles section.
- Assign the role: Veeam Backup Administrator.
- Select the "This a service account" checkbox to disable MFA.
- Restart the Veeam Management Agent service.
In about 10 minutes, the inaccessible status in VSPC will change to normal.
Option 2: Add the Local System Account as Service Account with MFA Disabled
An alternative option is to configure Local System as a service account within the Users and Roles Security settings.
- In Windows Services ( services.msc ), confirm that the Veeam Management Agent service is configured to Log on as the Local System account.
- Add the account "NT AUTHORITY\SYSTEM" to Veeam Backup & Replication/Veeam Cloud Connect:
- Add the account "NT AUTHORITY\SYSTEM" to the Users and Roles section.
Note: You must enter NT AUTHORITY\SYSTEM manually, as it is impossible to search for it using the Select User or Group tool. - Assign the role: Veeam Backup Administrator.
- Select the "This a service account" checkbox to disable MFA.
- Add the account "NT AUTHORITY\SYSTEM" to the Users and Roles section.
- Restart the Veeam Management Agent service.
In about 10 minutes, the inaccessible status in VSPC will change to normal.
More Information
If the presented options are unsuitable for your situation for any reason, it may be advisable to consider disabling MFA entirely.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.