[ Applies to ] StorageGuard / Everpure FlashArray / Block & SAN Storage
This article lists the recommended baseline checks for Everpure FlashArray. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Everpure (formerly Pure Storage) FlashArray is an all-flash enterprise storage platform for block and file workloads, designed for consistent low latency and simple, API-driven management.
Why hardening Everpure FlashArray matters
FlashArray commonly hosts databases, virtual infrastructure and business applications. Hardening administrative access, API tokens, encryption, SafeMode snapshots and remote-support settings reduces the risk of data exposure and ransomware impact.
Recommended baseline checks
The baseline below contains 132 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-M6174T199V01 | Account Lockout duration |
| SG-C0393T199V01 | Account lockout threshold |
| SG-M7227T199V01 | Anonymous user SMB access is enabled |
| SG-M2996T199V01 | API token_ttl settings |
| SG-M1777T199V01 | API used with SSL verification |
| SG-M2877T199V01 | Approved admin users / AD groups |
| SG-M3126T199V01 | Approved API Clients |
| SG-M2653T199V01 | Approved cloud offload targets |
| SG-C0449T199V01 | Approved DNS servers |
| SG-C0435T199V01 | Approved LDAP servers |
| SG-C0013T199V01 | Approved NTP servers |
| SG-M9163T199V01 | Approved pure1 users |
| SG-F5425T199V01 | Approved SMTP relay hosts |
| SG-M6719T199V01 | Approved snapshot offload targets |
| SG-C0015T199V01 | Approved Syslog servers |
| SG-M4510T199V01 | Atime synchronization |
| SG-M3234T199V01 | Audit logging status |
| SG-M6466T199V01 | Authentication server configuration |
| SG-M6590T199V01 | Authentication server redundancy |
| SG-M8378T199V01 | Automatic PHONE HOME Enabled |
| SG-M8326T199V01 | Banner configuration |
| SG-M7108T199V01 | CC-compliance mode |
| SG-M2603T199V01 | Central Certificate Authority (CA) status |
| SG-C0029T199V01 | Centralized log server |
| SG-C0233T199V01 | Centralized log server redundancy |
| SG-M7545T199V01 | Certificate Algorithm |
| SG-M8721T199V01 | Certificate expiry date |
| SG-C0235T199V01 | Certificate key size |
| SG-C0411T199V01 | CHAP authentication mode |
| SG-C0128T199V01 | CIFS SMB anonymous user access restriction |
| SG-C0343T199V01 | CIFS SMB encryption (policy) |
| SG-M2981T199V01 | Cloud offload enabled |
| SG-C0329T199V01 | Console lock status |
| SG-C0065T199V01 | Data at-rest encryption |
| SG-M8367T199V01 | Data encryption algorithm strength |
| SG-C0098T199V01 | Data retention period |
| SG-C0056T199V01 | Default passwords |
| SG-C0243T199V01 | DNS server configuration |
| SG-C0060T199V01 | DNS server redundancy |
| SG-C0245T199V01 | Domain name configuration |
| SG-M6879T199V01 | Domain name settings |
| SG-M1768T199V01 | DS server authenticity enforcement |
| SG-M1312T199V01 | Enabled applications |
| SG-C0600T199V01 | End of support |
| SG-C0372T199V01 | Eradication delay (secure data erasure) |
| SG-F6664T199V01 | Event types enabled for audit logging |
| SG-M9141T199V01 | External logging server |
| SG-C0600T199V02 | Future end of support |
| SG-C0209T199V01 | Idle session timeout |
| SG-M7094T199V01 | Inactive users |
| SG-M1864T199V01 | iSCSI CHAP enabled |
| SG-M1370T199V01 | Kerberos settings |
| SG-M9306T199V01 | KMIP/KMS server configuration |
| SG-F5384T199V01 | KMS server configuration |
| SG-M9639T199V01 | LDAP redundancy |
| SG-C0039T199V01 | LDAP server configuration |
| SG-C0025T199V01 | LDAP server redundancy |
| SG-M3512T199V01 | LDAP settings |
| SG-C0427T199V01 | Login banner message |
| SG-C0426T199V01 | Login banner status |
| SG-M3121T199V01 | Lossless logging server protocol |
| SG-C0394T199V01 | Mail (SMTP) settings |
| SG-C0392T199V01 | Minimum account lockout duration |
| SG-C0264T199V01 | Minimum password length |
| SG-C0239T199V01 | Multi-factor authentication - RSA |
| SG-M4252T199V01 | Multifactor authentication |
| SG-C0153T199V01 | NFS enabled |
| SG-C0377T199V01 | NFS root squash status |
| SG-M8309T199V01 | NFS/SMB permission |
| SG-C0230T199V01 | Non-default local admin |
| SG-M8116T199V01 | Non-default local users |
| SG-C0171T199V01 | NTP server configuration |
| SG-C0432T199V01 | NTP server redundancy |
| SG-M1400T199V01 | Off-Site Replication Configuration |
| SG-M7357T199V01 | Phonehome HTTPS proxy |
| SG-C0373T199V01 | Pure SafeMode |
| SG-M6087T199V01 | Pure SafeMode configuration |
| SG-M2091T199V01 | Pure Storage FA SSMS Extension version |
| SG-M3932T199V01 | Pure Storage FlashArray PowerShell SDK version |
| SG-M4662T199V01 | Pure1 Enabled |
| SG-M5762T199V01 | Pure1 mutual TLS authentication |
| SG-M6742T199V01 | Pure1 TLS level |
| SG-M8785T199V01 | PureStorage Unified Add-on for Splunk version |
| SG-M8942T199V01 | Puresupport account configuration |
| SG-M1627T199V01 | Purity version |
| SG-C0374T199V01 | Rapid Data Locking (RDL) status |
| SG-M1642T199V01 | Rapid Data Locking configuration |
| SG-M1846T199V01 | Remote support auto termination timeout |
| SG-C0138T199V01 | Remote support status |
| SG-C0398T199V01 | Remote support via proxy |
| SG-M3108T199V01 | RemoteAssist state |
| SG-C0450T199V01 | Required DNS servers |
| SG-C0164T199V01 | Required domain name |
| SG-C0439T199V01 | Required LDAP servers |
| SG-C0014T199V01 | Required NTP servers |
| SG-C0349T199V01 | Required SNMP trap hosts |
| SG-C0016T199V01 | Required Syslog servers |
| SG-M4462T199V01 | REST API authentication |
| SG-M4159T199V01 | Restricted shell |
| SG-M5938T199V01 | Root Squash disabled |
| SG-M9512T199V01 | Secure erase holdout period |
| SG-M9168T199V01 | Security email notification |
| SG-C0447T199V01 | Self-signed certificate |
| SG-C0147T199V01 | Service location protocol (SLP) status |
| SG-M2731T199V01 | SMB digital signing |
| SG-C0145T199V01 | SMI-S service status |
| SG-M7079T199V01 | SMIS status |
| SG-C0395T199V01 | SMTP server configuration |
| SG-M5092T199V01 | SMTP with TLS (supported?) |
| SG-M6486T199V01 | Snapshot offload enabled |
| SG-M1896T199V01 | SNMP authentication |
| SG-M6297T199V01 | SNMP Authentication Protocol |
| SG-M3787T199V01 | SNMP Community string |
| SG-M3346T199V01 | SNMP message privacy |
| SG-M5673T199V01 | SNMP status |
| SG-C0347T199V01 | SNMP trap host configuration |
| SG-M4511T199V01 | SNMP user authentication |
| SG-M4508T199V01 | SNMP versions allowed |
| SG-C0123T199V01 | SNMP versions enabled |
| SG-C0346T199V01 | SNMPv3 user security |
| SG-M6373T199V01 | SSH cipher strength |
| SG-M3640T199V01 | SSH MAC strength |
| SG-M7479T199V01 | SSL certificate private key configuration |
| SG-M7075T199V01 | SSO status |
| SG-C0306T199V01 | Syslog communication protocol |
| SG-C0019T199V01 | Target OS version |
| SG-M7955T199V01 | Tenant replication allowed |
| SG-C0005T199V01 | TLS audit logging |
| SG-M9038T199V01 | TLS Level |
| SG-C0116T199V01 | Unapproved admin users |
| SG-C0213T199V01 | Use of secure LDAP |
| SG-M7875T199V01 | User role configuration |
Related components
A complete baseline also covers the components that manage, connect to or protect Everpure FlashArray. Review the configuration of:
- Pure1
- FlashBlade
- Pure PowerShell SDK and other automation tools
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.