Hey all,
Got some questions around tightening up security in our Commvault setup, especially by reducing reliance on AD. A customer of ours wants to limit exposure, so looking for some practical advice if anyone’s tackled this before. Here’s what we’re thinking:
-
Separating from AD-Connected vCenter: If we pull Commvault away from an AD-connected vCenter, any gotchas or issues we should watch out for? Trying to keep everything functional while reducing risk.
-
Dropping AD for Authentication: They want Commvault running on local creds instead of AD. If anyone’s switched from AD to local auth, were there any surprises or smooth enough?
-
Taking Media Agents Off AD: If we decide to remove the Media Agents from AD, what kind of trouble (if any) are we walking into?
-
Making Backups Immutable: They’re keen on having backups that can’t be deleted or messed with until a set expiry. Any tips for setting up immutability in Commvault that actually works?
-
Locking Down Admin Access: Finally, only a few specific accounts should have full access in Commvault. Any straightforward way to set this up so only the right folks have those permissions?
Appreciate any advice or real-world experiences—thanks in advance!