User privileges on a storage node
The scope of a user’s privileges on Acronis Backup & Recovery 10 Storage Node depends on the user’s rights on the machine where the storage node is installed.
A regular user, such as a member of the Users group on the storage node, can:
A user who is a member of the Administrators group on the storage node can additionally:
Users with these additional privileges are also called storage node administrators.
Recommendations on user accounts
To allow users to access the centralized vaults managed by a storage node, you must ensure that those users have a right to access the storage node from the network.
If both the users’ machines and the machine with the storage node are in one Active Directory domain, you probably do not need to perform any further steps: all users are typically members of the Domain Users group and so can access the storage node.
Otherwise, you need to create user accounts on the machine where the storage node is installed. We recommend creating a separate user account for each user who will access the storage node, so that the users are able to access only the archives they own.
When creating the accounts, follow these guidelines:
Additional right of machine administrators
A user who is a member of the Administrators group on a machine can view and manage any archives created from that machine in a managed vault—regardless of the type of that user’s account on the storage node.
Suppose that two users on a machine, UserA and UserB, perform backups from this machine to a centralized vault managed by a storage node. On the storage node, let these users have regular (non-administrative) accounts UserA_SN and UserB_SN, respectively.
Normally, UserA can access only the archives created by UserA (and owned by UserA_SN), and UserB can access only the archives created by UserB (and owned by UserB_SN).
However, if UserA is a member of the Administrators group on the machine, this user can additionally access the archives created from this machine by UserB—even though UserA’s account on the storage node is a regular one.