Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell ObjectScale 1.3 Administration Guide

Account Protection Mode

Account Protection Mode protects S3 data from unauthorized activity. It offers an extra layer of protection on data with object locks in governance mode.

Account Protection Mode is a configuration setting on an IAM account. It is applied individually to each account, making it possible to set the protection on some accounts and leave it disabled on others. When Account Protection Mode is enabled, certain actions on buckets in the account must get approval from a second user. The Privileged Actions Approval System (PAAS) is used to gain approval.

For a list of actions that require approval when account protection mode is enabled, see Table 3.

Workflow to perform protected actions

The following steps describe the workflow for performing protected actions when Account Protection Mode is enabled.

  1. A Management User submits the request to PAAS. For S3 protected actions that IAM users perform, the IAM user is identified in the payload of the request. For information about various ways that Management Users can submit a request to PAAS, see Create requests.
  2. An Approver User approves the request.
  3. Depending on the type of request, users complete the actions as follows:

Account Protection Mode and ObjectScale federation

When Account Protection Mode is set on an account in a federated ObjectScale system, the setting is automatically replicated to other ObjectScale systems in the federation.

Each ObjectScale performs an account protection check according to data in the local ObjectScale. It is possible that an IAM account with Account Protection Mode enabled is replicated to an ObjectScale that does not have PAAS enabled. In that case, the following actions are required for S3 protected actions:
  1. The IAM User must contact an Admin in the primary ObjectScale for the IAM account. The primary ObjectScale is the ObjectScale in which Account Protection Mode was set on the account.
  2. The IAM User must ask the admin to create the PAA request in the primary ObjectScale for the protected action.
  3. When the request is approved, the IAM User must get the temporary federated PAA token from the primary ObjectScale.
  4. The IAM User can use the temporary PAA token in any ObjectScale in the federation.

Account Protection Mode and object locks in GOVERNANCE mode

Object lock GOVERNANCE mode lets users with the correct permissions bypass an object lock and proceed with actions on data, such as overwrites and deletes.

When Account Protection Mode is set on the bucket account, GOVERNANCE mode does not work as stated above. In Account Protection Mode, the IAM user must first gain approval through the PAAS before they can bypass the object lock. Because only Management Users can submit approval requests to PAAS, the IAM user must ask a Management User to submit the request.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\