---
title: "Sysadmin Settings - Quorum Policy"
slug: "fortanix-data-security-manager-sysadmin-settings-guide-quorum-approval"
updated: 2026-06-26T11:56:04Z
published: 2026-06-26T11:56:04Z
canonical: "support.fortanix.com/fortanix-data-security-manager-sysadmin-settings-guide-quorum-approval"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sysadmin Settings - Quorum Policy

## 1.0 Introduction

This article describes the Quorum approval policy settings available in the System Administration account and how they are configured by a Fortanix-Data-Security-Manager (DSM) system administrator.

The Quorum approval policy adds an additional layer of control and protection to sensitive operations performed within the System Administration account. When configured, a defined minimum number of quorum approvers must approve a sensitive operation before it can be executed.

A Quorum approver is a system administrator designated to review and approve Quorum requests.

## 2.0 System Administration Quorum Policy

This policy defines the Quorum approvers and the minimum number of approvals required before a Secure Node Join request can be approved.

In the DSM user interface (UI), navigate to **System Administration** → **Settings** → **QUORUM POLICY** tab.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (4106).png)

**Figure 1: Account level quorum policy**

The **Quorum approval policy** page displays the current configuration for the System Administration account. It contains the following sections:

- **System Administration Quorum Policy**: Defines the Quorum approvers and the minimum number of approvals required for Secure Node Join requests.
- **Operations that require Quorum approval**: Specifies which operations within the System Administration account require Quorum approval.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (4109).png)

**Figure 2: Detailed form**

## 3.0 Create a System Administration Quorum Policy

Perform the following steps to create a System Administration Quorum approval policy:

1. In the **Sensitive operations within the account require approval from** section, enter the minimum number of approvals required in the **#** field.
2. In the **choose people** field, search for and select the system administrator users who will serve as Quorum approvers. Selected users appear as removable tags.

> [!NOTE]
> NOTE
> 
> Only active system administrator users are available for selection.
3. Click **ADVANCED** to define multiple quorum approval rules using **AND** or **OR** logic (optional):
  - **AND**: All rules must be satisfied for the operation to be approved.
  - **OR**: Any one rule, if satisfied, is sufficient for quorum approval.
4. Additionally, there are two optional check boxes:
  - **Using second factor security key is required to approve requests**: Select this option to require Quorum approvers to authenticate using a second-factor security key when approving requests.
  - **Profile password re-entry is required to approve request**: Select this option to require Quorum approvers to re-enter their password when approving requests.
5. In the **Operations that require Quorum approval** section, select the operations that should generate a quorum approval request:

If you enabled **ADVANCED** settings, select either **any** or **all** to determine whether any rule or all rules must be satisfied to achieve quorum.
  - **Update cluster**: Automatically enabled when **Secure node join** is selected and cannot be enabled or disabled independently. This ensures that any updates to the Quorum approval policy configuration, such as creating, modifying, or deleting the policy also require quorum approval before taking effect.
  - **Secure node join**: When selected, requires quorum approval before a new node is permitted to join the cluster. Selecting this option automatically enables **Update cluster**. *For more information, refer to* [*Secure Node Join (on-prem only)*](/v1/docs/fortanix-dsm-secure-node-join)*.*
6. Click **SAVE POLICY**.

> [!NOTE]
> NOTE
> 
> - After saving any changes to the **Quorum Policy** settings, a rolling restart of the backend containers must be performed for the configuration to take effect. Until the restart is complete, a warning indicator (⚠) appears next to the tab name in the **Settings** menu, indicating that there are pending changes.
> - Alternatively, you can revert the configuration change before the cluster restart begins, click **CANCEL CHANGE** in the Pending changes banner. In the **Cancel changes** dialog box, click **DELETE** to confirm and restore the previous configuration, or click **CANCEL** to return without making any changes.
7. The **Quorum policy** dialog box displays the policy summary. Review the configuration and click **SAVE** to apply the policy.

> [!NOTE]
> NOTE
> 
> This setting is applicable only to clusters where Secure Node Join is enabled with DCAP attestation.

## 4.0 Update System Administration Quorum Policy

Perform the following steps to update the System Administration Quorum approval policy:

1. On the **Quorum approval policy** page, click **EDIT POLICY**.
2. Update the policy settings as required.
3. Click **SAVE POLICY** to apply the changes.
4. The **Quorum policy** dialog box displays the policy summary. Review the configuration and click **SAVE** to apply the policy.

> [!NOTE]
> NOTE
> 
> - Any changes to this configuration, such as adding or removing Quorum approvers or modifying the minimum approval count, require quorum approval before taking effect.
> - After saving any changes to the **Quorum Policy** settings, a rolling restart of the backend containers must be performed for the configuration to take effect. Until the restart is complete, a warning indicator (⚠) appears next to the tab name in the **Settings** menu, indicating that there are pending changes.
> - Alternatively, you can revert the configuration change before the cluster restart begins, click **CANCEL CHANGE** in the Pending changes banner. In the **Cancel changes** dialog box, click **DELETE** to confirm and restore the previous configuration, or click **CANCEL** to return without making any changes.

## 5.0 Delete System Administration Quorum Policy

Perform the following steps to delete the System Administration Quorum approval policy:

1. On the **Quorum approval policy** page, click **EDIT POLICY**.
2. Scroll to the bottom of the page and click **DELETE POLICY**.
3. In the **Delete Policy** confirmation dialog box, click **DELETE**.

> [!NOTE]
> NOTE
> 
> - Deleting a Quorum approval policy is a sensitive operation and will automatically generate a quorum approval request that must be approved before the policy is removed.
> - After saving any changes to the **Quorum Policy** settings, a rolling restart of the backend containers must be performed for the configuration to take effect. Until the restart is complete, a warning indicator (⚠) appears next to the tab name in the **Settings** menu, indicating that there are pending changes.
> - Alternatively, you can revert the configuration change before the cluster restart begins, click **CANCEL CHANGE** in the Pending changes banner. In the **Cancel changes** dialog box, click **DELETE** to confirm and restore the previous configuration, or click **CANCEL** to return without making any changes.

## 6.0 Quorum Approval Requests

When an operation that requires quorum approval is performed, an approval request is automatically generated and sent to all configured Quorum approvers.

Quorum approvers can view and act on pending requests under **System Administration** → **Tasks** → **PENDING** tab.

- **PENDING**: Requests awaiting the required number of approvals
- **COMPLETED**: Requests for which quorum was achieved and the operation was completed.
- **FAILED**: Requests that were declined or expired before quorum was achieved.

The approval request expiration period is configured under **System Administration** → **Settings** → **POLICIES** → **Quorum approval**. By default, approval requests expire after 90 days.

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.
