Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Web UI Administrator's Guide
  3. Section IX. Managing security
  4. Configuring multiperson authorization
  5. multiperson authorization process with respect to roles
NetBackup™ Web UI Administrator's Guide

multiperson authorization process with respect to roles

Users can be requesters and approvers at the same time, however they cannot approve their own tickets.

The multiperson authorization process flow with respect to roles is as follows:

Table:

Component

Description

multiperson authorization ticket

When a requester performs a critical NetBackup operation that is protected by multiperson authorization, a ticket is generated that requires an approval from the approver before a specific action can be executed.

This ticket is used within NetBackup to ensure that critical actions undergo thorough review process by multiple people before they are executed.

The following sample flow is for the image expiry operation that requires multiperson authorization:

  1. A requester expires an image using the NetBackup web UI.

  2. A ticket is created.

  3. The ticket is pending for approval.

  4. Approvers review the ticket.

  5. Approvers either approve or reject the ticket.

  6. After the approval, the ticket is scheduled by NetBackup and finally marked Done after the execution.

  7. The ticket activity log, request, and response details can be viewed by the approver or the requester using the web UI, on the Ticket details page.

  8. A ticket is expired after it ages beyond the expiration period. Such tickets cannot be approved unless they are renewed by the Requester.

  9. Tickets in the Done, Rejected, Expired, and Canceled states are purged when no action is performed on them for the specified purge period in days.

Requester role

  1. A requester is a user who initiates an operation that requires multiperson authorization.

  2. A ticket is created for the operation if the user is not in the exempted users' list.

  3. The ticket requires an approval from an approver before the operation is performed.

  4. A requester is not allowed to self approve even if the requester is also an approver, an Administrator, or a Security Administrator.

  5. Once the ticket is created it is in the Pending state.

  6. The requester can cancel a ticket only if it is in the Pending state.

  7. If the ticket ages beyond the expiry period, the ticket is moved to the Expired state.

  8. Only the requester can renew such tickets. A new expiry period is calculated for the renewed ticket based on the configuration settings multiperson authorization.

Approver role

  1. An approver is an authorized individual who reviews and provides approval for tickets.

  2. The approver evaluates the details of the ticket and either approves or rejects the ticket based on the assessment.

  3. After the approval, the ticket is scheduled for execution.

  4. To be an approver, the user should have RBAC permissions like Update Ticket, View Ticket or the user should have the Default Multiperson Authorization Approver role.

  5. When a ticket is in the Pending State, it can be approved or rejected.

Exempted users

  1. An exempted user is an individual who does not need multiperson authorization for operations except the following:

    • To modify multiperson authorization configuration

    • To modify security properties

  2. User groups cannot be exempted.

  3. This eliminates the necessity for any approvals, however it must be used with caution.

  4. If the exempted user account is hacked, the multiperson authorization process can be of no use as it is bypassed for this user.

  5. For example, if user1 is an exempted user and she attempts to expire an image (an operation that needs multiperson authorization), the image expires without ticket generation and additional approvals.

Feedback

Was this page helpful?
Previous

RBAC roles and permissions for multiperson authorization

Next

NetBackup operations that need multiperson authorization

Feedback

Was this page helpful?