Enterprise Vault™ Setting up File System Archiving (FSA)
- About this guide
- About File System Archiving
- About File System Archiving
- About using FSA with clustered file servers
- About setting up File System Archiving
- About FSA policies
- About target volumes, folders, and archive points
- About client access to FSA-archived items
- About archived file permissions
- About FSA shortcut files
- About the FSA Agent
- About retention folders
- About FSA Reporting
- About FSAUtility
- Steps to configure File System Archiving
- Adding a Windows file server to File System Archiving
- Adding a Windows file server to File System Archiving
- Using FSA with the Windows Encrypting File System (EFS)
- About archiving from Windows Server 2012 or later file servers
- Account requirements for managing FSA with Windows file servers
- Permissions and privileges required by the Vault Service account on Windows file servers
- Configuring a file server's firewall for FSA
- Adding a Windows file server as an archiving target
- Adding a NetApp filer to File System Archiving
- Adding a NetApp C-Mode Vserver to File System Archiving
- Adding a NetApp C-Mode Vserver to File System Archiving
- Permissions and privileges required by the Vault Service account on NetApp C-mode Vservers
- Granting the required permission on each Vserver
- Configuring the FPolicy server details
- Adding a NetApp C-Mode Vserver as an archiving target
- Points to note about File System Archiving on NetApp C-Mode file servers
- Adding a Celerra/VNX device to File System Archiving
- Adding a Dell EMC Unity device to File System Archiving
- Configuring FSA with clustered file servers
- About configuring FSA with clustered file servers
- Steps to configure FSA with clustered file servers
- Preparing to set up FSA services in a cluster
- Adding the Vault Service account to the non-secure VCS cluster for FSA high availability
- Adding the virtual file server as an FSA target
- Configuring or reconfiguring the FSA resource
- Removing the FSA resource from all cluster groups
- Troubleshooting the configuration of FSA with clustered file servers
- Installing the FSA Agent
- Defining volume and folder policies
- About defining FSA volume and folder policies
- Creating FSA volume policies and folder policies
- About FSA volume policy and folder policy properties
- About selecting the shortcut type for an FSA policy
- About FSA policy archiving rules
- About options for archiving files that have explicit permissions, and files under DAC
- Configuring the deletion of archived files on placeholder deletion
- Configuring target volumes, target folders, and archive points
- About adding target volumes, target folders, and archive points for FSA
- Adding a target volume for FSA
- Adding a target folder and archive points for FSA
- About managing archive points
- Archive point properties
- Effects of modifying, moving, or deleting folders
- About deleting target folders, volumes, and file servers
- Configuring pass-through recall for placeholder shortcuts
- Configuring and managing retention folders
- Configuring and running FSA tasks
- About configuring and running FSA tasks
- Adding a File System Archiving task
- Scheduling a File System Archiving task
- Setting the FSA folder permissions synchronization schedule
- Scheduling the deletion of archived files on placeholder deletion for Dell EMC Celerra/VNX
- Configuring FSA version pruning
- Using Run Now to process FSA targets manually
- About File System Archiving task reports
- About scheduling storage expiry for FSA
- Configuring file system filtering
- Managing the file servers
- PowerShell cmdlets for File System Archiving
- Appendix A. Permissions and privileges required for the Vault Service account on Windows file servers
- About the permissions and privileges required for the Vault Service account on Windows file servers
- Group membership requirements for the Vault Service account
- DCOM permissions required by the Vault Service account
- WMI control permissions required by the Vault Service account
- Local security user rights required by the Vault Service account
- Permissions required by the Vault Service account for the FSA Agent
- Permissions required by the Vault Service account to support the FSA resource on clustered file servers
- FSA target share and folder permissions required by the Vault Service account
About options for archiving files that have explicit permissions, and files under DAC
FSA volume policies and folder policies let you specify whether to archive the following:
Files that have explicit permissions. That is, files with permissions applied directly to them. Note that when evaluating a file for explicit permissions, Enterprise Vault ignores Dynamic Access Control (DAC) permissions.
Files that are under DAC. That is, files whose access is controlled completely or partially through a DAC central access policy, user claim, or device claim.
The default policy setting is not to archive these files.
Before you choose to archive files that have explicit permissions or files that are under Dynamic Access Control, note the following:
In the archive no explicit file permissions apply, and no DAC permissions apply. The result is that an archived file has the permissions of its parent folder, less any DAC permissions.
If Enterprise Vault leaves a placeholder shortcut, the placeholder has all the permissions of the original file.
The absence of explicit file permissions and all DAC permissions in the archive has the following consequences:
A user who has conventional (non-DAC) permission to access a folder can find and access any file in the associated archive folder. However, if the user did not have permission to access the original file, the user cannot access the archived file from its placeholder.
A user who has conventional (non-DAC) permission to delete items from a folder can delete the archived version of any file from the associated archive folder. However, if the user did not have permission to delete the original file, the user cannot delete its placeholder.
A user who has access to a file through DAC alone cannot access the file in the archive.
Note that to allow access to files in the archive, you can set permissions manually on an archive from the Enterprise Vault Administration Console. If you set permissions on an archive they are applied to every folder in the archive.
If a file is restored from the archive, the restored file has the original parent folder permissions, less any DAC-related permissions that were applied directly to the file.
If a file is recalled from a placeholder, the placeholder's permissions are retained in the recalled file. The recalled file has all the permissions of the original file, unless the permissions of placeholder or the inherited permissions of any of its parent folders were changed.