Skip to main content

XProtect Hardening guide

Cyber Assurance of Physical Security Systems (CAPSS)

Last Updated: 3 minute read
Versionver24
LanguageEnglish

The hardening guide explicitly covers servers, clients, devices, and network components together as part of a secure system architecture.

A CAPSS-compliant XProtect deployment requires hardened devices (no default credentials, reduced services, secure access) combined with a controlled and segmented network (firewalls, encryption, and monitored access) where all layers are hardened together.

For CAPSS environments, Milestone recommends using HTTPS/TLS with certificates for all supported components and devices.

Further guidance and details can be found in the following sections, as well as throughout the extended sections in the present Hardening Guide:

1. Identity, authentication, and account control

  • Remove all default credentials (devices + systems)

  • Enforce strong password policy

  • Use dedicated service accounts for system components

  • Implement role-based access control (RBAC)

  • Ensure unique identities per user/system.

2. Device hardening

  • Replace default credentials

  • Disable unused services (Telnet, FTP, etc.)

  • Use secure authentication (HTTPS, certificates, SSH keys)

  • Create dedicated device accounts

  • Maintain device inventory and ownership

  • Apply firmware updates and patching

  • Ensure device logs are enabled and retained

  • Enforce secure onboarding of devices (controlled addition to VMS).

3. Network security and segmentation

Core controls

  • Use secure communication by default (HTTPS / VPN / TLS)

  • Use TLS (latest supported version) with valid certificates

  • Configure network to support secure sessions only

Access control

  • Use firewalls to restrict IP access and ports

  • Open only required ports for XProtect components

  • Separate inbound (server) vs outbound (client) traffic flows

  • Network segmentation (VMS isolated from IT network)

  • Device whitelisting / trusted endpoints

  • Strict access allow-listing

  • No direct internet exposure of core servers

  • Use DMZ for external access services (Mobile/Web)

  • Restrict management interfaces to trusted admin zones.

4. Secure communication and encryption

  • Encrypt communication:

    • Server ↔ Server

    • Server ↔ Client

    • Recording server ↔ devices

  • Use TLS encryption and secure protocols

  • Disable weak protocols

  • Enforce minimum TLS versions (e.g., TLS 1.2+)

  • Use certificates issued by trusted authority

  • Ensure encryption is applied to:

    • Video streams

    • Authentication

    • API traffic

5. Server and platform hardening

  • Harden OS (Windows):

    • Remove unnecessary roles/services

    • Apply security updates

  • Harden IIS / services:

    • Disable insecure headers/methods

  • Secure database connectivity (SQL hardening)

  • Disable legacy protocols/remoting

  • Implement centralized patching process.

6. Access control to system (clients and users)

  • Restrict user access by role

  • Use secure authentication methods

  • Ensure only authorized clients can connect

  • Multi-factor authentication (where supported). MFA is not configured within XProtect. Instead, it is enforced through the organization's identity provider (IdP) or other authentication mechanism. MFA must be enabled for all administrative accounts.

  • Limit admin access to dedicated workstations

  • Restrict management tools to internal networks

  • Implement lockout sessions after a defined period of inactivity, requiring the user to re-authenticate. The inactivity period must be no longer than 15 minutes for admin roles and up to 120 minutes for operator roles or other roles used in a secure area for passive data review.

  • Password policy: Check the section Users and Security in the Milestone XProtect Administrator Guide to learn more about XProtect password policy and user authentication.

    Password protection of configuration backups and configuration data is mandatory in CAPSS deployments.

  • Remote access (RDP): Remote Desktop Protocol must be disabled on all XProtect hosts. Physical console access is the preferred administrative method.

7. Logging, audit and monitoring

  • Enable logging across:

    • Devices

    • Servers

    • Network access

  • Use logs to track:

    • Access

    • Changes

    • Events

  • Central log collection (SIEM)

  • Define log retention policy

  • Monitor:

    • Failed logins

    • Configuration changes

    • Network anomalies.

  • Synchronized event timestamps: XProtect requires accurate time synchronization to maintain consistent event timestamps. In disconnected CAPSS deployments, synchronize systems with an approved local NTP source or trusted standalone time appliance if external time synchronization is unavailable.

8. Change management and configuration control

CAPSS-critical (not optional)

  • Establish baseline hardened configuration

  • Ensure all changes:

    • Are approved

    • Are documented

Practical controls:

  • Change approval workflow

  • Configuration backup

  • Drift detection

9. Operational security

Define:

  • Maintenance procedures

  • Update processes

  • Incident response

Examples:

  • Regular patching for VMS and devices

  • Monitoring system health and activity

  • Controlled remote access policy

Restrictions on physical media

  • Disable USB storage via Group Policy

  • Disable AutoRun

  • Restrict removable media through endpoint security controls

  • Permit only authorized encrypted media