About multi-person authorization
NetBackup Security Administrator can configure multi-person authorization. It proactively protects NetBackup primary servers from an undesirable or a malicious act by ensuring that a second authorized user approves that action before it is allowed to take place. If you configure multi-person authorization for a certain operation, you can perform the associated operation only using the NetBackup web UI or REST APIs. You cannot perform the operation using the NetBackup Administration Console.
To bypass multi-person authorization, you can add the associated users as exempted users who do not require approval for performing the required operations.
To configure multi-person authorization in NetBackup, you need to have two users: one is the requester and other is the approver.
A requester cannot be an approver of his or her own tickets.
Ticket - Ticket is a multi-person authorization request to perform a critical operation.
Requester - Requester is an end user who wants to perform a critical operation that requires multi-person authorization.
Approver - Approver is an individual who reviews and allows an operation that requires multi-person authorization by approving a ticket.
Exempted user - An exempted user is not required to go through the multi-person authorization process, and must be used only when an automation user wants to perform critical operations.
For enhanced security, it is suggested that there should not be any exempted users.