Install some system components (Custom option)

The Custom option installs the management server, but you can select which other server and client components you want to install on the current computer. Depending on your selections, you can install the rest of the system components on other computers afterwards. through the management server's download web page named Download ManagerDownload Manager/download web page.

Milestone recommends that you read the following section carefully before you install: Before you start installation.

For FIPS installations, you cannot upgrade XProtect VMS when FIPS is enabled on the Windows operating system. Before you install, disable the Windows FIPS security policy on all of the computers that are part of the VMS, including the computer that hosts SQL Server. But, if you are upgrading from XProtect VMS version 2020 R3 and after, you do not need to disable FIPS. For detailed information on how to configure your XProtect VMS to run in FIPS 140-2 compliant mode, see the FIPS 140-2 compliance section in the hardening guide.

I. The installation file

  1. Download the .iso file with the software from the internet (https://www.milestonesys.com/download/). When you download the .iso file, it will be loaded as a DVD drive called XProtect VMS Installer.

  2. Run the Milestone XProtect VMS Products 2026 R1 System Installer.exe file.The installation files unpack. Depending on the security settings, one or more Windows® security warnings appear. Accept these and the unpacking continues.

    When done, the Milestone XProtect VMS installation wizard appears.

II. Language, end-user agreement and privacy settings

  1. Select the Language to use during the installation (this is not the language that your system uses once installed; this is selected later).

  2. Read the Milestone End-user License Agreement. Select the I accept the terms in the license agreement check box.

  3. On the Privacy settings page, select whether you want to share usage data. You can always change your privacy setting later.

    You must not enable data collection if you want the system to have an EU GDPR-compliant installation. For more information about data protection and the usage data collection, see the GDPR privacy guide.

III. Components to install

On the Select an installation type page, select Customto select the components to install on this computer. Apart from the management server, all components in the list are optional.

With XProtect 2025 R3, XProtect Smart Client is not included in the VMS installation package and must be downloaded separately. To download the latest version of XProtect Smart Client, go to the https://www.milestonesys.com/download/ site.

For your system to function properly, you must install at least one instance of XProtect API Gateway.

Depending on the components you selected to install some of the steps below might to be applicable for your case. In the steps below, all system components are installed. If you cannot recognize an installation step, it is likely because you have not selected to install the system component that this page belongs to.

IV. Internet Information Services (IIS)

  • The Select a website on the IIS to use with your XProtect system page is shown only if you have more than one IIS website available on the computer.
  • You must select which website you will use with your XProtect system. Select a website with HTTPS binding.
  • V. Database setup

    On the Database setup page, select one of the options:

    Let the installer create or recreate a database

    Milestone XProtect cannot be installed or upgraded using an MS-SQL database enrolled in a database mirroring session or an availability group because some operations cannot run on this kind of database. Remove the database from the availability group or mirroring session during the installation or upgrade. After the installation or upgrade is complete, the database can be enrolled in a mirroring session or an availability group again.

    1. When you select this option, the Select Microsoft SQL Server page opens. Select one of the following options:

      • Install Microsoft® SQL Server® Express on this computer: This option is shown only if you do not have SQL Server installed on the computer
      • Use the SQL Server on this computer: This option is shown only if SQL Server is already installed on the computer

      • Select a SQL Server on your network through search: Enables you to search for all SQL Server installations that are discoverable on your network subnet
      • Select a SQL Server on your network: Enables you to enter the address (host name or IP address) of SQL Server that you might not be able to find through search
    2. On the Select database page (only shown if you have selected existing SQL Server), select or create a SQL Server database for storing your system configuration.

      If you choose an existing SQL Server database, decide on what you want to do with your existing data:

      • Keep is used when upgrading to a newer version.

      • Overwrite

    Use a pre-created database

    When you select this option, the Advanced database setup page opens.

    1. Select the authentication type. The account to be used for the installation must be created in Microsoft Entra ID or Windows AD depending on the authentication type you want to use. Multi-factor authentication (MFA) is not supported for the accounts.

      • Windows Authentication, do not trust server certificate (recommended)

      • Windows Authentication, trust server certificate

      • Microsoft Entra Integrated, do not trust server certificate (recommended)

      • Microsoft Entra Managed Identity, do not trust server certificate.

      The (do not trust server certificate) option is recommended for Windows Authentication and mandatory for Microsoft Entra Integrated. This is to ensure that server certificates are validated and verified before installation. More information about invalid server certificates is available in the installation log file. With the Windows Authentication, trust server certificate option, you skip the validation of server certificates.

    2. Enter the server and the database name for the XProtect components.
    3. Click the icon to verify the connection. By clicking the icon, you also validate server certificates.

    VI. Password protection

    1. On the Assign a system configuration password page, enter a password that protects your system configuration. You will need this password in case of system recovery or when expanding your system, for example when adding clusters.

      It is important that you save this password and keep it safe. If you lose this password, you may compromise your ability to recover your system configuration.

      If you do not want your system configuration to be password protected, select I choose not to use a system configuration password and understand that the system configuration will not be encrypted.

    2. On the Assign a mobile server data protection password page, enter a password to encrypt your investigations. As a system administrator, you will need to enter this password to access the mobile server data in case of system recovery or when expanding your system with additional mobile servers.

      You must save this password and keep it safe. Failure to do so may compromise your ability to recover mobile server data.

      If you do not want your investigations to be password-protected, select I choose not to use a mobile server data protection password, and I understand that investigations will not be encrypted.

    VII. Service accounts

    1. On the Select service account, select either This predefined account or This account to select the service account for the recording server. If needed, enter a password.

      The user name for the account must be a single word. It must not have a space.

    2. On the Select service account for recording server, select either This predefined account or This account to select the service account for the recording server.

      If needed, enter a password.

      The user name for the account must be a single word. It must not have a space.

    VIII. Recording server settings

    On the Specify recording server settings page, specify the different recording server settings:
    1. In the Recording server name field, enter the name of the recording server. The default is the name of the computer.
    2. The Management server address field shows the address and port number of the management server: localhost:80.
    3. In the Select your media database location field, select the location where you want to save your video recording. Milestone recommends that you save your video recordings in a separate location from where you install the software and not on the system drive. The default location is the drive with the most space available.
    4. In Retention time for video recordings field, define for how long you want to save the recordings. You can enter from between 1 and 365,000 days, where 7 days is the default retention time.

    IX. Encryption

    On the Select encryption page, you can secure the communication flows:

    You can use the same certificate file for all system components or use different certificate files depending on the system components.

    You can also enable encryption after installation from the Server Configurator in the Management Server Manager tray icon in the notification area.

    X. Server logs

    On the Server logs setup page, specify the following parameters:

    XI. Location and language

    1. On the Select file location and product language page, select the File location for the program files. If any Milestone XProtect VMS product is already installed on the computer, this field is disabled. The field displays the location where the component will be installed.

    2. In the Product language field, select the language in which to install your XProtect product. Click Install.

    The software now installs. When the installation completes, you see a list of successfully installed system components. Click Close.

    You may be prompted to restart the computer. After restarting your computer, depending on the security settings, one or more Windows security warnings may appear. Accept these and the installation completes.