Enterprise Vault™ Using SQL Database Roles in Enterprise Vault, Compliance Accelerator, and Discovery Accelerator
- About this guide
- Using Enterprise Vault database roles
- About Enterprise Vault database roles
- Configuring the Vault Service account for normal operations
- Preparing to configure the Vault Service account
- Configuring the Vault Service account's SQL login
- Changing ownership of Enterprise Vault databases
- Assigning the Vault Service account to EVRuntimeRole
- Mapping the Vault Service account to the msdb system database
- Creating EVMonitoringOperator in the msdb system database and assigning Vault Service account
- Restarting Enterprise Vault services
- Configuring the Vault Service account for operations that require elevated privileges
- Using Compliance Accelerator and Discovery Accelerator roles
- About Compliance Accelerator and Discovery Accelerator database roles
- Configuring the Vault Service account for normal operations
- Preparing to configure the Vault Service account
- Configuring the Vault Service account's SQL login
- Changing ownership of Compliance Accelerator and Discovery Accelerator databases
- Assigning the Vault Service account to EVRuntimeRole
- Mapping the Vault Service account to the msdb system database
- Creating EVScheduledSearchOperator in the msdb system database and assigning the Vault Service account
- Creating EVAnalyticsOperator in the msdb system database and assigning the Vault Service account
- Restarting Compliance Accelerator and Discovery Accelerator services
- Configuring the Vault Service account for operations that require elevated privileges
About Enterprise Vault database roles
The Enterprise Vault databases contain roles which you can use to increase the database security in your environment.
Standard Enterprise Vault installation and upgrade procedures do not use these roles. When you have completed the installation or upgrade of Enterprise Vault, the Vault Service account is the owner of all Enterprise Vault databases and has a high level of privilege on the SQL server.
Use the procedures in this chapter to do the following:
Configure the Vault Service account with only the SQL privileges that are required for normal daily operations.
See Configuring the Vault Service account for normal operations.
Grant temporary additional SQL privileges to the Vault Service account for other tasks that require higher privileges.
See Configuring the Vault Service account for operations that require elevated privileges.
Note:
Before you use the procedures in this chapter, you must have completed the installation or upgrade of Enterprise Vault, and its configuration.
Table: Enterprise Vault database roles lists the Enterprise Vault database roles and describes the purpose of each.
Table: Enterprise Vault database roles
Role | Used in these databases | For these operations |
|---|---|---|
EVAdminRole | Directory Vault store Vault store group (fingerprint) | Assign the Vault Service account to EVAdminRole for all administrative operations, such as the creation of vault store partitions, and all EVSVR operations. Revoke the Vault Service account's membership of EVAdminRole when you have completed the administrative operations. |
EVMonitoringOperator | msdb system database | Assign the Vault Service account to EVMonitoringOperator for all normal operations. |
EVReportingRole | Audit Directory Monitoring Reporting Vault store Vault store group (fingerprint) | Assign the Vault Service account or the reporting user to EVReportingRole for all reporting operations. This allows the collection of the data required in Enterprise Vault reports. |
EVRuntimeRole | Audit Directory Monitoring Reporting Vault store Vault store group (fingerprint) | Assign the Vault Service account to EVRuntimeRole for all normal operations. |
EVUpgradeRole | Audit Directory Monitoring Vault store Vault store group (fingerprint) | Assign the Vault Service account to EVUpgradeRole before upgrading Enterprise Vault. Revoke the Vault Service account's membership of EVUpgradeRole when you have completed the upgrade. |
The installation or upgrade of Enterprise Vault automatically creates these roles in the databases where they are required, except for the msdb system database.
The procedures in this chapter include the steps required to create the database roles in the msdb system database.