HP IAP Version 2.0 Administrator Guide (July 2008)

Granting “Delet
e Administration privilege
All IAP Admin use
rs, with the exception of root” users, can grant or revoke Delete Administration
privilege. Only a rem o te user (a user existing in the Active Directory and imported by DAS) c an be
granted Delete Administra tion privilege.
To grant a user w
ith this privilege:
1. Log in to PCC as root.
2. Open the PCC Account Managem ent page and grant “IAP Admin” privilege to a user.
3. Log in to PCC as
this IAP Admin user and open the PCC Account Management page.
4. Select the user who needs to execute Administrative Delete a nd edit this user by checking the
Delete Admin check box. (The domain that this user belongs to should have Administrative
Delete enable
d; otherwise, the Delete Admin check box will not appear.)
5. Save the change.
To revoke a user with this privilege:
1. Log in to PCC a
s the remote IAP Admin user.
2. Open the PCC Account Management page and select the user who has the Delete Adm in
privilege and edit this user by unchecking the Delete Admin check box.
3. Save the cha
nge.
Executing Administrative Deletion
After o btaining Delete Admin privilege, a user is allowed to delete any messages stored in IAP. To
delete messages:
1. Log in to the Web UI as the user with D elete Admin privilege.
2. Search for and select the message to be deleted.
3. Click the More Options button.
4. Click the Delete Chec ked Items button.
5. To conrm the deletion, click the Conrm Delete button.
6. After conrming deletion, you will see a status page whic h will report on the success or failure
of the deletion sub mittal.
After the message is submitted to delete, it will take up to two hours for the message to be
removed from the index. During that time, the message contents will be still searchable, but
not retrievable.
When a message is deleted by Administrative Delete:
The deletion physically removes the message and a ll references of the message from IAP.
The d eletion also deletes a quarantined message.
The deletion is done on both primary and secondary smart cells. If the IAP is running in a
replication environment, the message is also deleted on the replica smart cells.
If the IAP is running in a replication environment, Administrative Delete can only be executed to
delete a message which is stored on the primary IAP the deletion is triggered on the re plica
IAP by replication process. Administrative Delete can n ot delete any message stored on the
replica IAP directly.
Logging in Auditlog
Activities in Administrative Delete are logged in the Auditlog. Auditlog messages are stored in the
Audit
log repository.
When a user obtains or loses D elete Admin privilege, the change is logged in the Auditlog.
When a message is deleted by Administrative Delete, the operation is logged in Auditlog.
Administrator Guide
53