About role elevation
Role elevation allows authorized users in NetBackup to temporarily elevate their privileges so they can perform administrative or security‑sensitive actions that are normally restricted.
This feature supports the principle of least privilege by eliminating the need to permanently grant powerful roles to users. During an elevation session, the user operates with the privileges of an assigned elevated role. Once the role elevation session expires, either automatically or manually, the users return to their base roles.
Users who have role elevation mappings defined can request role elevation.
Actions performed with elevated roles are audited with the reason specified during role elevation request..
The following NetBackup operations may need role elevation configured:
Configuration updates of high‑risk administrative actions (for example, device and media operations)
Security‑sensitive operations that require enhanced rights
Infrastructure‑level actions such as restarting NetBackup services
Any workflow that your organization classifies as sensitive data should avoid assigning permanent privileges. Use temporary roles when required.