Creating a privileged NetBackup user account for EWS access
This procedure provides an example of how to create a privileged account for NetBackup Exchange operations for EWS access. This account is used for the in the Exchange client host properties, enabling NetBackup to perform operations with Granular Recovery Technology (GRT).
Note the following:
Configure each Exchange mailbox server.
Configure each client that performs granular operations. To determine which clients to configure, see the following topic:
In a cluster environment, perform the steps on each database node in the cluster. For an Exchange DAG, perform the steps on each database node in the DAG.
To create a privileged NetBackup user account for EWS access
- In the Exchange Management Console, create a new Exchange mailbox for NetBackup.
This process creates a new user that is automatically a domain user.
- Double-click on the user account you created.
- Select the Member Of tab.
- Click Add and add this user to the Organization Management group.
- Provide the credentials for this account in the Exchange client host properties.
See About the Exchange credentials in the client host properties.
Cohesity recommends that you configure the Exchange credentials in the Exchange client host properties. However, existing NetBackup customers can continue to configure the logon account for the NetBackup Client Service.
- Configure this account with the right to "Replace a process level token."
If you configure the NetBackup Client Service with a logon account and configure the Exchange credentials in the Exchange client host properties, you must configure the "Replace a process level token" for both users.