Compliance+ mode in HPE StoreOnce requires dual authorization for critical operations.
In HPE StoreOnce, Compliance mode (Compliance+) is designed to protect immutable backup data from ransomware and insider threats by enforcing strict, non-overridable retention locks. To reinforce this protection, StoreOnce pairs Compliance mode with the Dual Authorization feature, which mandates that a second user holding the Security Officer role must approve critical operations — such as deleting a Catalyst store, modifying or deleting system storage, changing the system clock, or enabling/disabling Dual Authorization itself — before they can be executed. This role-based, two-person control prevents any single administrator, even one with full admin privileges, from unilaterally altering or deleting protected data, satisfying regulatory compliance requirements for separation of duties.
Community Discussion