Arctera™ Insight Management Console Help
- Getting started
- Archive Overview
- Working with Dashboard
- Managing Configurations
- About Provisioning
- About Managed Tags
- About Account Management
- Managing Archive Collectors
- About Exchange Online Archiving
- About Google Chat Archiving
- About Google Workspace Archiving
- About SCIM Archiving
- About Import Collector
- About Insight Capture Services Archiving
- About Audio-Video Archiving
- About Audio-Video Archiving using NTR-X Collectors
- About Dubber Speik SMS Archiving
- About Dubber Speik Recordings Archiving
- About Text-Delimited Archiving
- About XSLT-XML Archiving
- About JSON Archiving
- About iMessage Archiving
- About LinkedIn Archiving
- About Signal Archiving
- About Verint Archiving
- About WeChat Archiving
- About WhatsApp Archiving
- Managing Roles and Permissions
- Managing Policies
- Managing Authentication
- Managing Retention Policies
- Managing Email Continuity Services
- Managing Reports and Notifications
- Classification
- Managing Data Import
- AD FS Configuration Guide
Configuring the MYOK feature
Configuring the MYOK feature for customers is a multi-stage process that requires collaboration between the Arctera Insight Management Console administrator and the customer administrator. The stages involved in the MYOK feature configuration are described below.
During the initial provisioning of a new customer, the Arctera Insight Management Console administrator can access the MYOK option on the
page. However, after the customer has been created, this option becomes unavailable.Note:
The customer for whom the MYOK feature is not enabled can contact Arctera support to access this option; however, the process incurs additional time and cost.
To enable a customer for the MYOK feature
- In the left navigation pane, select Customer Service > Customers.
- On the Company Details tab, specify or ensure all the required customer details.
- [Mandatory] Select the Manage Your Own Encryption Keys check box.
- Click Save.
After saving the customer profile, the application sends the Service Alert notification to the customer.
To install the Azure App and assign a role to it
- Log in to the Arctera Insight Management Console with the customer administrator credentials.
- Ensure that the Service Alert notification is received and displayed immediately after login.
- Click Install Azure App to begin the app installation. The application redirects you to the Azure Sign-in page.
Enter your administrator credentials to log in to Azure. If permission to install Management Console is denied, click Retry Install Azure App. Accept the requested permissions to initiate the installation. This app gets installed on the customer's Azure subscription.
- On the Microsoft Azure portal, select Access Control > Check Access tab, and then click Add Role Assignment. Assign the Key Vault Crypto Officer role to the installed Azure app.
- Select the Arctera app that is installed on customer Azure portal, and assign the selected role to it.
To generate a Key Vault Encryption Key Identifier URI
- On the Microsoft Azure portal, navigate to Storage Accounts, and select your account.
- In the left pane of your storage account page, select Encryption as shown in the sample image below.
- On the Encryption page, select the Encryption Type as Customer-managed keys.
Enabling Customer-managed keys grants your storage account access to the selected key vault. Additionally, enabling this feature activates soft delete and purge protection on the key vault, which cannot be disabled.
- On your Microsoft Azure portal, select Home > Key Vault.
- On the Key Vaults page, in the left navigation pane, under Objects, select Keys, and click Generate/Import.
- On the Create a key page, specify the required details, and click Create to generate a key. Select the key name to view the key.
- Click the key as shown in the above-mentioned sample image to view its details.
- Copy the key from the Key Identifier field.
To acknowledge a successful configuration
- Paste the key path into the Key Vault Encryption Key Identifier URI field on the Service Alert notification window. Then, click Save Storage Uri.
- Ensure that the Service Alert window displays all the steps are completed, as shown in the sample image below.
The application initiates the storage provisioning process and transitions the MYOK configuration steps from storage provisioning started to storage provisioning completed.
- After storage provisioning is completed, click Acknowledge to confirm successful provisioning and prevent further display of this service alert. Else, click Skip.
- To confirm if the MYOK feature is enabled, on the Arctera Insight Management Console, select Policy Management > Archive Options.
- Ensure that the status under the Manage Your Own Keys section is set to Enabled.