The Veritas Enterprise Vault (EV) Compliance Accelerator (CA) product introduced a new feature in the 12.2.0 release called Prevent Self-Review. This feature prevents a CA Reviewer from being able to review messages they have sent or received.
The normal configuration of this feature expects the CA Reviewer's Active Directory (AD) account to be in the same AD Domain as their Exchange mailbox. When a multi-domain environment is present with the mailbox domain being different from the login domain, additional steps are required to configure the CA environment for proper operation of the Prevent Self-Review feature.
To configure the CA environment to use the Prevent Self-Review feature in an AD multi-domain environment where the CA Reviewer logs into a logon domain and their Exchange mailbox is located in a resource domain, complete the following steps:
Upon completion of the above actions, any new emails to or from the CA Reviewer will be restricted from review by that CA Reviewer.
The following conditions will still allow a CA Reviewer to review their own messages:
Initial Configuration Example:
1. Resource domain name: mail.mydomain.com
NetBIIOS name: mail
SMTP Address Domains applied to all accounts: mail.mydomain.com
mydomain.com
CA Reviewer account Display Name: John Smith
CA Reviewer account ID: john.smith
CA Reviewer email addresses: john.smith@mail.mydomain.com
john.smith@mydomain.com
CA Reviewer login: mail\john.smith
Journaled user account Display Name: Jane Doe
Journaled user account ID: jane.doe
Journaled user email addresses: jane.doe@mail.mydomain.com
jane.doe@mydomain.com
Journaled user login: mail\jane.doe
2. Login domain name: users.mydomain.com
NetBIOS name: users
SMTP Address Domains applied to all accounts: users.mydomain.com
CA Reviewer account Display Name: John Smith
CA Reviewer account ID: john.smith
CA Reviewer email addresses: john.smith@users.mydomain.com
CA Reviewer login: users\john.smith
3. Compliance Accelerator:
Employee Tab -
Employee: John Smith
Account: mail\john.smith
Addresses: john.smith@mail.mydomain.com
john.smith@mydomain.com
Synchronize with AD: Yes
Enabled: Yes
Employee: John Smith
Account: users\john.smith
Addresses: john.smith@users.mydomain.com
Synchronize with AD: Yes
Enabled: Yes
Employee: Jane Doe
Account: mail\jane.doe
Addresses: jane.doe@mail.mydomain.com
jane.doe@mydomain.com
Synchronize with AD: Yes
Enabled: Yes
Employee: Jane Doe
Account: users\jane.doe
Addresses: jane.doe@users.mydomain.com
Synchronize with AD: Yes
Enabled: Yes
Department Tab -
Department Name: Test Department
Department Monitored Employees: Jane Doe (mail\jane.doe)
John Smith (mail\john.smith)
John Smith (users\john.smith)
Department Reviewer: John Smith (users\john.smith)
Corrected Configuration Example (changes in bold italics):
1. Resource domain name: mail.mydomain.com
NetBIIOS name: mail
SMTP Address Domains applied to all accounts: mail.mydomain.com
mydomain.com
CA Reviewer account Display Name: John Smith
CA Reviewer account ID: john.smith
CA Reviewer email addresses: john.smith@mail.mydomain.com
john.smith@mydomain.com
CA Reviewer login: mail\john.smith
Journaled user account Display Name: Jane Doe
Journaled user account ID: jane.doe
Journaled user email addresses: jane.doe@mail.mydomain.com
jane.doe@mydomain.com
Journaled user login: mail\jane.doe
2. Login domain name: users.mydomain.com
NetBIOS name: users
SMTP Address Domains applied to all accounts: users.mydomain.com
CA Reviewer account Display Name: John Smith
CA Reviewer account ID: john.smith
CA Reviewer email addresses: john.smith@users.mydomain.com
CA Reviewer login: users\john.smith
3. Compliance Accelerator:
Employee Tab -
Monitored Employee: John Smith
Account: mail\john.smith
Addresses: john.smith@mail.mydomain.com
john.smith@mydomain.com
Synchronize with AD: No
Enabled: No
Monitored Employee: John Smith
Account: users\john.smith
Addresses: john.smith@users.mydomain.com
john.smith@mail.mydomain.com
john.smith@mydomain.com
Synchronize with AD: Yes
Enabled: Yes
Monitored Employee: Jane Doe
Account: mail\jane.doe
Addresses: jane.doe@mail.mydomain.com
jane.doe@mydomain.com
Synchronize with AD: Yes
Enabled: Yes
Monitored Employee: Jane Doe
Account: users\jane.doe
Addresses: jane.doe@users.mydomain.com
Synchronize with AD: Yes
Enabled: Yes
Department Tab -
Department Name: Test Department
Department Monitored Employees: Jane Doe (mail\jane.doe)
John Smith (users\john.smith) made into an Exception Employee
Department Reviewer: John Smith (users\john.smith)
Exception Employee Reviewer (who will review John Smith's emails): Jane Doe (users\jane.doe)