This website is originally written in the Czech language. Most content is machine (AI) translated into English. The translation may not be exact and may contain errors.
Statistics
Page has been view by 12 229 464 visitors. During today 181. Right now is here 66 guests.
Veeam ONE - Upgrade to Version 13.1
A brief description of the in-place upgrade of Veeam ONE 13.0.1.6168 to version 13.1.0.7233 (including Patch 0, which is required to support VBR 13.0.3). The article also mentions upgrading the Veeam ONE Client on the administrator's workstation, where a minor problem occurred. The upgrade of Veeam ONE on the server is very simple using the wizard and went through without any issues. Veeam ONE 13.1 supports Veeam Backup & Replication 12 and newer.
Creating and Configuring a Microsoft Entra App Registration and Enterprise Application
This article provides a practical description of registering applications in Microsoft Entra ID. The goal is to connect an internal or external application to authentication and authorization using Entra ID accounts and/or to access data (resources) and APIs. It covers creating and configuring an App Registration (Application object) and an Enterprise application (Service Principal) for applications that use the OAuth 2.0 / OpenID Connect (OIDC) protocol or SAML 2.0.
App Registrations and Enterprise Applications in Microsoft Entra ID
In this article we'll look at registering applications in Microsoft Entra ID, which enables connecting various internal and external applications to authentication and authorization using Entra ID accounts. It may also involve access to data (resources) and APIs. The OAuth and OpenID Connect (OIDC) protocols are primarily used, with SAML being the other option. The whole area is quite extensive, with many properties and interconnections. This article simplifies and condenses various things. It presents basic terminology, a description and comparison of App Registration vs Enterprise Application, and covers various OAuth Flows and related topics (permissions, scopes, consents). Security implications should always be considered as well.
Modern SAML, OAuth, and OpenID Connect Protocols for Authentication and Authorization
This article generally describes the protocols used on the internet (and, for instance, also in Microsoft Entra ID applications) for secure federated identity verification (authentication) and control of access to data (authorization, permission verification, delegated access). They are used for single sign-on (SSO), where one central account (such as Entra ID, Google, Apple) serves for logging into multiple applications (independent, in different domains). We will look at the open standards SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC). They are most commonly used with web applications, but their use is broader (from mobile applications to communication between services).
Veeam Backup & Replication - VM migration using replication
The previous article described the basic options for using replication in Veeam Backup & Replication. Today we will build on that and look at a less typical situation, where we use replication to migrate a Hyper-V VM between two different Hyper-V clusters.
Veeam Backup & Replication - Replication Job
Veeam Backup & Replication is a well-known solution for data protection and disaster recovery. Many people think of it as just backup. But the name itself also contains a second function, which is replication. In this article we will look at the basic options for using replication.
Object First Storage in Veeam Backup & Replication
Object First Ootbi is an on-premises hardware appliance specifically designed as a secure backup object storage (S3-compatible) for Veeam. It is built on simplicity, security, and performance. The previous article covered basic information and described the cabling and configuration. Today we will look at actual usage together with Veeam Backup & Replication (VBR). Specifically creating an access key and a bucket, and adding it as a Backup Repository in VBR.
Object First Ootbi Appliance Basic Setup
Object First is an American company that primarily manufactures on-premises backup storage called Ootbi (Out-of-the-Box Immutability). This object storage is specifically designed for Veeam Backup & Replication. It is built on simplicity, security, and sufficient performance. Support for Immutability to protect backups against ransomware and access via S3 API are standard features.
Guest Processing and Group Managed Service Accounts (gMSA) in Veeam Backup & Replication
gMSA is a special type of account in Active Directory used for service accounts. It can be used on Windows for services, applications (that support it), or scripts (scheduled tasks). The administrator does not know its strong password, which is changed automatically. We will describe the options for using gMSA within Veeam Backup & Replication (VBR), where it is supported for Application-Aware Processing. We will also look more closely at Guest Processing on Windows and what accounts we need for certain situations.
Veeam ONE Reporting Service failed to start due to a missing certificate
One day, the Veeam ONE Reporting Service stopped starting without any warning. As a result, most Veeam ONE features stopped working. The cause turned out to be straightforward, a self-signed certificate for the Web API had disappeared from the system certificate store. How this happened could not be determined, but the fix was quick and simple.
Most viewed acrticles
TCP/IP - addresses, masks, subnets and calculations
The seventh part of the series on computer networks is more interesting and provides practical information. At the beginning there is a description of the basic terms for networks and subnets, IP addresses and masks. Next, the various network classes and how to write subnets are discussed. The second part deals with practical calculations of network ranges, network masks, number of hosts and subnets.
Windows commands for command line
My plan was to write down various useful commands for Windows in one place, along with a very brief description and example of common usage. I got some basics together but wanted to expand and fix it, but months go by and nothing, so I'm posting it in a not-so-finished state. Here you will find commands for use within the domain, but also for local matters. These are mostly commands used from the command line that are included with Windows. However, some are from Support Tools or Windows Resource Kits. I welcome your comments and additions in the comments.
VLAN - Virtual Local Area Network
The eighth part of the series on computer networks. VLAN, or Virtual Local Area Network, is a common technology these days that brings a number of advantages. I think that all medium-sized and larger companies use VLAN technology, and it can be interesting for small companies as well. VLANs are used to logically divide the network without being tied to physical division. In the article, I try to describe everything necessary to understand what VLAN is, what are the advantages and methods of deployment.
TCP/IP - Routing
In the eleventh part of the series on computer networks, I deal with routing, i.e. routing in networks. There is a brief description, explanation of terms, and then some more common routing methods (RIP, IGRP, EIGRP and OSPF) are described very briefly, including the division of these methods. For the methods, there is a sample of the basic configuration on Cisco. The article is far from exhaustive and the description is often to the point. Finally, rooting on Windows is mentioned.
Azure AD / Entra ID identity and authentication
Articles related to user and device identity (not only) in Microsoft Entra ID. Different login and authentication options. Areas such as modern authentication, multi-factor authentication, password-less login, etc. Often involving the use of FIDO Authentication, for example using the FIDO2 security key or Windows Hello for Business.
(articles in the series: 21)
Basics of computer networks
I wrote this series for Connect magazine. It contains most of the same information as my older series Computer networks, but it is written in a slightly different way. Computer network technologies are first briefly summarized and then discussed in a little more detail from the lowest layers up.
(articles in the series: 4)
Cisco IOS
A large series about the operating system of Cisco's active elements. It contains some of the most read articles on this site. The articles describe the configuration of switches and routers, primarily with Cisco IOS. Things about ports, VLANs, STP, ACLs, QoS, etc.
(articles in the series: 45)
Computer networks
This series covers the basics of computer networking. Important practical aspects that everyone interested in networking should know are briefly described. It contains some of the most widely read articles on this site. It is used for teaching in schools.
(articles in the series: 26)
Computer Storage
Data storage is a vast and complex issue in the computer world. Here you will find articles dedicated to Storage Area Networks (SAN), iSCSI technologies, Fiber Channel, disk arrays (Storage System, Disk Srray) and data storage and storage in general.
(articles in the series: 22)
Fortinet FortiGate and more
Fortinet security solutions. Mostly focused on the Next Generation Firewall (NGFW) FortiGate. Configuration of FW, policies, NAT, but also VPN and authentication options. Marginally working with logs using FortiAnalyzer and with clients using FortiClient EMS.
(articles in the series: 28)
Kerberos protocol with focus on SSO in AD DS
A new series that deals in detail with the Kerberos V5 protocol, mainly in the Microsoft Active Directory environment. It also describes a number of related things that are needed to understand how Kerberos Single Sign-On (SSO) works.
(articles in the series: 14)
Microsoft Exchange
Almost since the beginning of my practice, I have been involved in the administration of the Microsoft mail server, i.e. Exchange Server. I started with the 2003 version and worked my way up to Exchange Online. The articles cover many areas of management. Most since the migration to Exchange Server 2016 and its complete configuration. But also Exchange Hybrid and e-mail security.
(articles in the series: 47)
Veeam Backup & Replication
Articles that focus on Veeam Software's backup solution. It is a platform for Backup, Replication and Restore. In other words, a Data Protection and Disaster Recovery solution.
(articles in the series: 40)
Most recent comments
[em][/em]
[98] dir *nazev* /s prohleda cely strom od aktualniho adresare dolu.
Za mě je tu nedostatečně vysvětlený princip. Jak funguje autorizace krok po kroku. Není tu "marketingová" zmínka o tom proč to dělat místo klasického domain účtu kterému jednou za čas změním heslo.
Je mi jasné že přínos je v tom, že se heslo jednou za měsíc "změní samo". Ale opravdu je to jasné každému kdo tu příjde a čte si to?
Bez pořádného vysvětlení co se vlastně stane na pozadí nelze posoudit jestli je to vůbec bezpečný způsob a zda si zavedením této praxe do infrastruktury nepustím nějakou bezpečnostní díru, kterou pak cracker zneužije. Tzn pustí powershell skript pod servisním účtem - a nebude k tomu potřebovat znát heslo (viz níže)?
Taky se mi nezdá to, že se zde uvádí - účet nemůže mít interaktivní přihlášení, ale pak se dá občůrat pomocí powershell něco jako runas, takže vlastně může mít interaktivní přihlášení?
Jinak super článek, který ve mě vzbudil ještě pár otázek k zamyšlení :-).
V případě MS Exchange 2019 CU15 jsem setkal s tím, že ani auditování schránky nezapisuje událost jako je přesun nebo smazání adresáře. Máte stejnou zkušenost zkoušel jste tento scénář někdy?
Thanks for the post! The part about Application Aware Processing definitely helped.
I didn't want to use one gMSA that is Domainadmin for everything so knowing the specific permissions was useful.
Im doing this exact conversion right now, but with some extras like ipsec/sslvpn currently, great guide, thanks!
In year 2026 there is an useful documentation about the details you can see in debug log: docs.fortinet.com/document/fortigate/7.4.4/administration-guide/32970/configuring-os-and-host-check