Important Update: Cohesity Products Documentation
All Cohesity product documentation are now managed via the Cohesity Docs Portal: https://docs.cohesity.com/HomePage/Content/home.htm. Some documentation available here may not reflect the latest information or may no longer be accessible.
System Health Insights User Guide
- Introduction
- Getting Started
- Registering an Appliance
- Associating the Team, Site, and Contacts with appliances
- Managing the Sites, Contacts, and Teams
- Searching within System Health Insights
- Actions on the Appliance List search results
- Globally accessible menus
- Activity History
- My Query Dashboard
- Account Dashboard
- Appliance Dashboard
- Appliance Update Management
- Security Insights
- Managing alerts
- Frequently Asked Questions
Automate Security Admin Onboarding
System Health Insights supports Multi-Person Authorization (MPA) for sensitive operations such as Access Key generation through the Secure Quorum dashboard. To use MPA, your team must assign Security Admins who can authorize users and manage Secure Quorum permissions.
This release adds an automated onboarding workflow. Team Admins can request Security Admin onboarding directly in the portal instead of sending a manual email request to Support.
This topic explains eligibility indicators, informational banners, and how to submit an onboarding request.
Previously, customers requested onboarding by emailing Support with the team ID and the names and email addresses of at least two team members to be designated as Security Admins. Support reviewed the request and enabled the Security Admin role for the team.
With automated onboarding, Team Admins submit the request from the Team Details page. The portal enforces eligibility rules automatically (for example, you must select exactly two eligible team members, and read-only members are excluded).
If no one approves or rejects the request within 72 hours of submission, the request is automatically approved.
The Secure Quorum status indicates your team's readiness for MPA. You can view this status in the Secure Quorum column on the Team Management (Team List) page and on the Team Details page. Statues:
Eligible for onboarding: Your team's appliances qualify for MPA. A Team Admin must submit an onboarding request.
Onboarding in progress: An onboarding request has been submitted and is awaiting review.
Configured: Security Admins are set up and MPA is active.
Partially configured: Secure Quorum setup is incomplete. Contact your Team Admin.
Ineligible: our team's appliances does not qualify for Secure Quorum based on Access Key Generation Status of its appliances
When one or more teams are eligible for Security Admin onboarding, the portal displays informational banners on relevant pages. Each banner includes a More info button that links documentation
If one or more of your teams are associated with eligible appliances, a banner appears at the top of the Team List.
One or more teams below are associated with appliances that are eligible for leveraging Multi-Person authorization (MPA) for secure operations like Access Key generation via Secure Quorum Dashboard. Please navigate to the eligible team details page for further setup of the onboarding process.
If you are a Team Admin for an eligible team, the banner provides a direct link to start onboarding.
One or more appliances in the team are eligible for leveraging Multi-Person authorization (MPA) for secure operations enabled via Secure Quorum Dashboard. This requires assignment of a new role 'Security Admin' who can authorize users and permissions.
If you are a Team Admin for an eligible team, the banner provides a direct link to start onboarding.
One or more appliances in the team are eligible for leveraging Multi-Person authorization (MPA) for secure operations enabled via Secure Quorum Dashboard. This requires assignment of a new role 'Security Admin' who can authorize users and permissions.
If you are not a Team Admin, the banner advises you to contact your Team Admin.
One or more appliances in the team are eligible for leveraging Multi-Person authorization (MPA) for secure operations enabled via Secure Quorum Dashboard. This requires assignment of a new role 'Security Admin' who can authorize users and permissions.
Request a team admin to onboard Security Admins
Note:
Only Team Admins can submit onboarding requests. If you are not a Team Admin, contact your Team Admin.
Go to Team Management and select a team with Secure Quorum status Eligible for onboarding.
On the Team Details page, select the onboarding link in the banner to open the Request Security Admin Onboarding dialog.
In Select members, choose eligible team members.
Note:
Read-only members are not eligible and appear disabled.
Select exactly two members. When two members are selected, Add becomes enable.
Select Add to submit the request. A success message appears and the team status changes to Onboarding in progress.
After you submit the request:
The portal sets the team status to Onboarding in progress.
Email notifications are sent to the recipients configured for your tenant (see Email notifications).
An internal reviewer may approve or reject the request.
If no one approves or rejects the request within 72 hours of submission, the request is automatically approved.
After approval, the selected members are assigned the Security Admin role and the team status changes to Configured.
If the request is rejected, a cancellation email is sent and the Team Admin can submit a new request with different members.
Note:
If a request was submitted in error, contact Support before the 72-hour auto-approval window expires
The system sends email notifications at key stages:
Request submitted
Subject: Security Admin Onboarding Request Hello, We have received your request to enable the Secure Quorum feature and grant Security Admin privileges to the following users: Team Name (Team ID) - user1@example.com - user2@example.com The feature will be enabled in 72 hours. The nature of the Security Admin role is sensitive and will allow users to grant access for important actions. Ensure the following: A) The person requesting the role is someone that you are well acquainted with. B) The person is someone who is expected to be responsible for the security of the Appliances. If you have any concerns about this request or if the request was incorrectly created, contact DL-COH-SHI-HELP@cohesity.com. Thank you, System Health Insights teamRequest approved (manual approval or auto-approval after 72 hours)
Subject: Security Admin Onboarding Approval Hello, The Secure Quorum Feature is enabled for the team Team Name (Team ID) and the following users are granted the Security Admin privileges: - user1@example.com - user2@example.com You can verify the changes from: [link to team details page] Reminder: You must configure requesters and approvers before you can view the Support tab > Access Key tab in System Health Insights. The following documentation is available about how to configure users and the Secure Quorum feature: https://help.veritas.com/vxhelp6/#/content?id=142015400-165936081-0%2Fv163830773-165936081 If you have any questions, contact DL-COH-SHI-HELP@cohesity.com. Thank you System Health Insights teamRequest rejected
Subject: Security Admin Onboarding Request Cancellation Hello, Your request to enable the Secure Quorum feature and grant Security Admin privileges to the following users of the team Team Name (Team ID) is cancelled. - user1@example.com - user2@example.com If you have any concerns about this request or if the request was incorrectly created, contact DL-COH-SHI-HELP@cohesity.com. Thank you System Health Insights team
For each template, ensure the subject line, sender address, and contact instructions match your production configuration.
If customers must complete additional Secure Quorum configuration after approval (for example, configuring requesters and approvers), document the steps here and link to the relevant help topic.
If you have concerns or you want expedited approval, contact DL-COH-SHI-HELP@cohesity.com