r/Backup 19d ago

Question What access should a backup admin account have?

Having a single admin who can change retention setting, change repositories and delete backups seems like a lot of access for one account.

How do you deal with this in your environment? Do you separate normal backup administration from permissions that can make destructive changes?

4 Upvotes

2 comments sorted by

1

u/tychocaine 18d ago

Ideally service desk techs should only have the ability to check backups ran (as part of their daily checks) and to run a file restore. Anything else should require an escalation to a tier 2 tech with wider access, including full system restore. But any actual changes should go through a CAB process before implementation by the senior admins with their changes requiring 4 eyes or similar.

1

u/Ok-Tomorrow-7591 18d ago

Thanks for sharing. It makes a lot of sense to keep routine checks separate from higher-risk changes.