Why backup servers should never be part of the same domain

Backups are often seen as the last resort after a cyber attack, a hardware defect or human error. Nevertheless, a central security error is still ignored in many companies today: The backup server is located within the same Active Directory domain as the productive systems.

In an emergency, this can lead to the backups being compromised or deleted.

The basic problem: The domain admin controls everything

In a classic Windows environment, a domain administrator has far-reaching rights. If this account is compromised - for example through phishing, malware or ransomware - the attacker often gains access to all systems within the domain.

If the backup server is also located in this domain, the consequences are serious:

  • Backups can be deleted
  • Backup jobs can be manipulated
  • Restore points disappear
  • Backup software can be deactivated
  • Encryption Trojans also reach the backups


This means that the backup loses its actual purpose: independent recovery in the event of a disaster.

The most important principle: separate backup infrastructure

A secure backup strategy is based on isolation. The backup server should therefore never be completely dependent on the same domain whose systems it is supposed to protect.

Proven approaches are:

  • own separate domain
  • Workgroup instead of domain membership
  • Dedicated management networks
  • Separate administrator accounts
  • restricted firewall rules
  • Immutable storage or offline backups


The goal is clear: even if the production domain is compromised, the backup environment must continue to function independently.

Service user instead of domain administrator

Another common error is the use of a domain administrator account for backup jobs.

Although many backup solutions require access to servers, databases or virtual machines, they do not require full domain admin rights.

Dedicated service accounts should be used instead:

  • with minimum necessary authorisations
  • only for defined systems
  • without interactive login
  • with strong password and rotation
  • separately per backup service or system area


This significantly reduces the attack surface.

Principle of minimum rights

The so-called «Least Privilege Principle» is one of the most important security principles of modern IT infrastructures.

For example, a backup service requires:

  • Access to certain shares
  • Snapshot rights on hypervisors
  • Database read rights
  • Rights to secure certain systems


However, it does not usually require complete control over the entire domain.

The fewer rights a compromised account has, the lower the potential damage.

Today, ransomware thinks of backups first

Modern attacks no longer only target productive data. Professional ransomware groups are actively looking for:

  • backup servers
  • Backup software
  • NAS systems
  • Veeam instances
  • Hypervisor accesses
  • Storage systems


Because attackers know that: Without functioning backups, the probability of a ransom payment increases massively.

It is therefore no longer enough to have a backup «somewhere». The backup environment itself must be specially protected.

Best practices for secure backup environments

The following measures have proved their worth:

1. isolate the backup server
No direct membership in the productive domain or clear separation via separate positions of trust.

2. use your own service accounts
No use of domain admin accounts for backup software.

3. use immutable backups
Backups must not be deletable or modifiable for defined periods of time.

4. test backup restore
A backup is only valuable if the restoration works reliably.

5. create offline or air-gap copies
At least one backup copy should be physically or logically separated.

A backup within the same security zone as the productive systems often only offers deceptive security. If the domain is compromised, the backups are often also affected.

Backup servers should therefore be operated outside the domain to be protected wherever possible - combined with separate service accounts and minimal authorisations.

After all, a backup only provides real protection if it remains unassailable in an emergency.

Your partner for servers and backups - Flying Supporter

Do you have any questions?
We will be happy to help you.

Leave a Reply

Your email address will not be published. Required fields are marked *