Veritas Alta™ Archiving : Customer Administration Guide
- About customer administration
- Using the Customer Service tool
- My Config
- Provisioning customers
- Creating Google G Suite Gmail archive accounts in bulk from a downloaded Google user list
- Managing customers
- Reseller portal
- Distributor portal
- Customer Service administration roles
- Reporting
Configuring the MYOK feature
Configuring the MYOK feature is a multi-stage process that involves actions from both, the Veritas Alta View Compliance and Governance Management Console administrator and the customer administrator.
Firstly, the Veritas Alta View Compliance and Governance Management Console administrator enables the customer administrator to configure MYOK feature independently.
Later, the customer administrator logs in to the Veritas Alta View Compliance and Governance Management Console and completes the configuration process solely.
When the customer administrator logs in to the Veritas Alta View Compliance and Governance Management Console, the
window appears and instructs the customer administrator to complete the MYOK configuration on the Microsoft Azure portal. To understand the configuration process, the customer administrator can access the link provided on the same window. Until the MYOK configuration is completed, the Veritas Alta View Compliance and Governance Management Console restricts the customer administrator from using any other features.
Note:
For detail information, refer to Veritas Alta Archiving Key Management.
The entire MYOK feature configuration process involves the following stages:
: Enabling the MYOK feature for a customer
: Installing the Azure App and assigning role to it
: Creating a storage account with customer's managed key
During the initial provisioning of a new customer, the Veritas Alta View Compliance and Governance Management Console administrator can access the MYOK feature on the
page. After the customer has been created, this option becomes unavailable.Note:
The non-MYOK enabled customers can contact Veritas support to avail this option, however, the process incurs additional time and cost.
To enable the MYOK feature for a customer
- In the left navigation pane, select Customer Service > Customers.
- On the Company Details tab, while specifying the required customer details, select the Manage Your Own Encryption Keys check box as shown in the sample image below.
- Click Save.
The application enables the customer to use the MYOK feature.
The customer administrator must log in using Azure Org User credentials to install the Azure app and create the encryption keys. The Microsoft user on the tenant cannot perform these activities.
The customer administrator requires both, the Application Administrator role to install the Azure app and the Subscription Owner role to create encryption keys.
The customer administrator needs to create a Key Vault in the Azure subscription, prior to the Azure app installation.
To install the Azure App and assigning role to it
- Ensure that the Service Alert window appears after you log in to your Veritas Alta View Compliance and Governance Management Console.
- Click Install Azure App to initiate installation on your Microsoft Azure subscription. The application redirects you to log in to your Microsoft Azure subscription.
- After login, select Home > Key Vault to access your key vault.
- In the left navigation pane of the Key Vault page, select Objects > Keys, and click Generate/Import.
- On the Create a key page, select the required key configuration, and click Create.
The application generates the encryption key. Click the key value to view its details.
- On the key details page, select Access Control > Check Access tab, and click Add Role Assignment.
- On the Role tab, assign the Key Vault Crypto Officer role to the installed Azure app.
- On the Members tab, click Select Members and select the Azure app as a member. Then, click Review + assign.
- From the key vault, copy the key from the Key Identifier field.
To create a storage account with customer's managed key
- Paste the key Identifier URI into the Key Vault Encryption Key Identifier URI field on the Service Alert window, and click Save Storage Uri.
The storage account creation process with your managed encryption key initiates in the background.
- After successfully creating the storage account, verify that the Service Alert window displays completion of all steps, and click Acknowledge to confirm successful configuration of the MYOK feature.
If you skip to acknowledge, the window reappears again.
- To confirm if the MYOK feature is enabled, in the left navigation pane of the Veritas Alta View Compliance and Governance Management Console, do any of the following: