[ Applies to ] StorageGuard / Dell PowerProtect Data Manager / Data Protection (Backup)
This article lists the recommended baseline checks for Dell PowerProtect Data Manager. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Dell PowerProtect Data Manager (PPDM) is an enterprise data protection solution that provides backup, recovery and disaster recovery across on-premises, virtual and cloud environments.
Why hardening Dell PowerProtect Data Manager matters
PPDM controls the policies, protection engines, agents and protection storage behind your recovery copies. Hardening authentication, roles, encryption, certificates and retention settings prevents unauthorized changes and keeps backup data trustworthy.
Recommended baseline checks
The baseline below contains 73 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0393T227V01 | Account lockout threshold |
| SG-F6771T227V01 | Agent port |
| SG-F2136T227V01 | Agent script execution |
| SG-F6066T227V01 | Agent trusted addresses |
| SG-C0163T227V01 | Approved AD domain |
| SG-F2820T227V01 | Approved application agents |
| SG-C0449T227V01 | Approved DNS servers |
| SG-C0437T227V01 | Approved identity provider servers |
| SG-F2279T227V01 | Approved MTree (PowerProtect DD) |
| SG-C0013T227V01 | Approved NTP servers |
| SG-F2778T227V01 | Approved protection engines |
| SG-F1593T227V01 | Approved protection policies |
| SG-C0400T227V01 | Approved SMTP recipients |
| SG-C0406T227V01 | Approved SMTP server |
| SG-C0015T227V01 | Approved Syslog servers |
| SG-F2404T227V01 | Asset protection status |
| SG-F3383T227V01 | Automatic software package management |
| SG-F3383T227V02 | Automatic software package management - Proxy |
| SG-C0475T227V01 | Backup restore encryption |
| SG-F6559T227V01 | CA certificate check bypass |
| SG-C0029T227V01 | Centralized log server |
| SG-F7036T227V01 | Certificate key strength |
| SG-F1603T227V01 | Certificate signature algorithm |
| SG-F4871T227V01 | Cloud disaster recovery encryption |
| SG-C0464T227V01 | Disaster recovery backups |
| SG-C0243T227V01 | DNS server configuration |
| SG-C0060T227V01 | DNS server redundancy |
| SG-F9487T227V01 | Encryption over wire (PowerMax) |
| SG-C0600T227V01 | End of support |
| SG-C0162T227V01 | Expired SSL certificate |
| SG-C0600T227V02 | Future end of support |
| SG-F3095T227V01 | Hyper-V onboarding protocol |
| SG-F9887T227V01 | Inventory source HTTPS links |
| SG-F4947T227V01 | Inventory source multi-factor authentication |
| SG-C0234T227V01 | Maximum password age |
| SG-C0392T227V01 | Minimum account lockout duration |
| SG-F3130T227V01 | Minimum password age |
| SG-C0264T227V01 | Minimum password length |
| SG-F9368T227V01 | MTree indefinite retention |
| SG-F1483T227V01 | MTree maximum retention |
| SG-F6494T227V01 | MTree minimum retention |
| SG-F6017T227V01 | MTree retention lock mode |
| SG-C0230T227V01 | Non-default local admin |
| SG-C0231T227V01 | Non-default local users |
| SG-C0171T227V01 | NTP server configuration |
| SG-C0432T227V01 | NTP server redundancy |
| SG-F6504T227V01 | Password complexity |
| SG-F5896T227V01 | Password history |
| SG-F8061T227V01 | Protection engine - DHCP disabled |
| SG-F9891T227V01 | Protection engine - Health check interval |
| SG-F8725T227V01 | Protection engine - IPv6 status |
| SG-F2104T227V01 | Protection engine - Required DNS domain name |
| SG-F6639T227V01 | Protection engine - Required DNS search domain |
| SG-F7120T227V01 | Protection engine - Required proxy port |
| SG-F5027T227V01 | Protection engine - SSL enabled |
| SG-F7190T227V01 | Protection engine - Transport session mode |
| SG-F9047T227V01 | Protection policy status |
| SG-F7207T227V01 | Replication encryption |
| SG-C0450T227V01 | Required DNS servers |
| SG-C0014T227V01 | Required NTP servers |
| SG-C0407T227V01 | Required SMTP servers |
| SG-F6119T227V01 | Search cluster index retention |
| SG-F8952T227V01 | Search cluster status |
| SG-C0447T227V01 | Self-signed certificate |
| SG-C0395T227V01 | SMTP server configuration |
| SG-F9773T227V01 | Strict certificate validation |
| SG-C0306T227V01 | Syslog communication protocol |
| SG-F7220T227V01 | Syslog facility |
| SG-F2060T227V01 | Syslog minimum severity |
| SG-F6043T227V01 | Target OS version |
| SG-C0448T227V01 | Trusted certificate-authority (CA) |
| SG-C0119T227V01 | Unapproved user groups |
| SG-F6581T227V01 | Unapproved users |
Related components
A complete baseline also covers the components that manage, connect to or protect Dell PowerProtect Data Manager. Review the configuration of:
- PowerProtect DD protection storage
- Protection engines (VM Direct)
- Application agents and search clusters
- Inventory sources such as vCenter, Hyper-V and PowerMax, and the protected hosts
- SMTP, syslog, NTP and DNS servers used by PPDM
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.