Configure StorageGRID multi-admin verification
Configuring a StorageGRID multi-admin verification (MAV) system involves creating and managing MAV administrator groups and users, enabling the MAV function, and selecting or configuring protected operations.
MAV administrators have approval and veto authority for protected operations.
-
You have the Root access permission.
-
You're signed in to the Grid Manager from the primary Admin Node.
Step 1: Create MAV administrator groups and users
You can add existing administrators to a MAV group or create new administrators.
You can configure Active Directory (AD) users as MAV administrators. The AD user must be configured as a StorageGRID administrator.
-
To create a MAV administrator group, follow the steps to create a local or federated group.
-
For Group permissions, select Root access or Multi-admin verification requests.
-
Add local or federated users to the group, or create new local users and add them to the group by following the steps to create a local user.
Step 2: Enable or disable MAV
You must enable multi-admin verification (MAV) explicitly. If MAV is enabled and you decide to disable it when there are pending MAV requests, a notification states that pending requests will be deleted.
-
Select Configuration > Access control > Multi-admin verification > MAV settings.
-
Select the Enable MAV checkbox to enable multi-admin verification.
-
The Approver groups section lists the MAV admin groups and approvers.
-
In the Operations section, select the checkboxes for the operations you want to protect with MAV.
-
(Optional) If you want to use email notifications to alert MAV administrators of pending approval requests:
-
If you haven't configured an email server, follow the steps to configure an email server.
-
Enter the email address of the sender.
-
Enter one or more recipients for the email notifications.
-
-
Select Save to save your changes.
If you decide not to configure email notifications, MAV administrators can view the Grid Manager dashboard or check the approval queue for pending approval requests. To check the approval queue, select Other requests on the Multi-admin verification page.
Step 3: Manage protected operations
After you enable multi-admin verification, you can manage the protected operations by selecting or clearing the checkboxes for the operations you want to protect with MAV.
|
|
For StorageGRID 12.1, the only protected operation is ILM policy activation. You must select the checkbox for ILM policy activation if you want to enable MAV. |
A MAV request can have one of the following statuses:
-
Pending. Request has been initiated.
-
Expired. Request wasn't addressed within 30 days. Or a user with Root access permission disabled MAV, which means all pending requests are expired.
-
Withdrawn. A user withdrew their request.
-
Approved. A MAV administrator approved the pending request.
-
Rejected. A MAV administrator rejected the pending request.
Troubleshoot MAV email notifications
If MAV administrators do not receive email notifications for pending requests, follow these steps to resolve the issue.
-
You are signed in to the Grid Manager using a supported web browser.
-
You have the Manage alerts or Root access permission.
-
Verify your settings.
-
Select Configuration > Monitoring > Email server.
-
Verify that the Email (SMTP) Server settings are correct.
-
Verify that you have specified valid email addresses for the recipients.
-
-
Check your spam filter, and make sure that the email was not sent to a junk folder.
-
Ask your email administrator to confirm that emails from the sender address aren't being blocked.
-
Collect a log file for the Admin Node, and then contact technical support.
Technical support can use the information in the logs to help determine what went wrong. For example, the prometheus.log file might show an error when connecting to the server you specified.