Skip to main content

We want to use encryption for our backup to ensure that our backup data is secure, and when we restore the backup, the decryption key must be required.

 

To enforce restore-level access on encrypted backups, enable Passkey for Restore — a feature that requires a password even if encryption is already in place.

Quick setup:

  1. Enable Passkey

    • Go to CommCell Console > Client > Properties > Security

    • Set a strong passkey under Passkey for Restore

    • Store it securely (e.g., password manager)

  2. Verify Encryption

    • Check Storage Policy > Copy Properties > Advanced

    • Ensure Encrypt Data is selected (AES-256 recommended)

  3. Understand Key Dependency

    • Commvault auto-generates encryption keys (DEK → KEK → Master Key)

    • Restore requires the passkey to decrypt data — without it, recovery isn't possible

  4. Test and Audit

    • Regularly test restores using the passkey

    • Monitor encryption activity and key rotations via audit logs


Reply