UNSOLVED

bleblancUL

updated

12 years ago

B

bleblancUL

1 Rookie

20 Posts

0

865

March 26th, 2014 11:00

Protecting data from a rogue admin?

Hello,

Does anyone know if there is a way to protect data on a DD from a potential rogue admin?

I'm looking into Retention Lock and from what I can tell I would be looking at Compliancebecause apparently it's the only thing that prevents a filesys destroy.

e.g.

When filesys destroy is run on a system with a DD Retention Lock Governance enabled MTree:

  • All data is destroyed, including retention-locked data.
  • All filesys options are returned to their defaults. This means that retention locking is disabled and the minimum and maximum retention periods are set back to their default values on the newly created file system.

Note

  This command is not allowed if DD Retention Lock Compliance is enabled on the system.

Does anyone have any experience with such an issue and have an advise?

-Brian