Install all system components (Single computer option)
The Single computer option installs the server and client components on the current computer.
Important
With XProtect 2025 R3, XProtect Smart Client is not included in the VMS installation package and must be downloaded separately. To download the latest version of XProtect Smart Client, go to the https://www.milestonesys.com/download/ site.
Note
Milestone recommends that you read the following section carefully before you install: Before you start installation.
Note
For FIPS installations, you cannot upgrade XProtect VMS when FIPS is enabled on the Windows operating system. Before you install, disable the Windows FIPS security policy on all of the computers that are part of the VMS, including the computer that hosts SQL Server. But, if you are upgrading from XProtect VMS version 2020 R3 and after, you do not need to disable FIPS. For detailed information on how to configure your XProtect VMS to run in FIPS 140-2 compliant mode, see the FIPS 140-2 compliance section in the hardening guide.FIPS 140-2 compliance
After initial installation, you can continue with the configuration wizard. Depending on your hardware and configuration, the recording server scans your network for hardware. You can then select which hardware devices to add to your system. Cameras are preconfigured in views, and you have the option to enable other devices such as microphones and speakers. You also have the option of adding users to the system with either an operator role or an administrator role. After installation, XProtect Smart Client opens, and you are ready to use the system.
Otherwise, if you close the installation wizard, XProtect Management Client opens, where you can make manual configurations such as add hardware devices and users to the system.
Note
If you upgrade from a previous version of the product, the system does not scan for hardware or create new views and user profiles.
I. The installation file
Download the .iso file with the software from the internet (https://www.milestonesys.com/download/). When you download the .iso file, it will be loaded as a DVD drive called XProtect VMS Installer.
Run the
Milestone XProtect VMS Products [Release_Version] System Installer.exefile. The installation files unpack. Depending on the security settings, one or more Windows® security warnings appear. Accept these and the unpacking continues.When done, the Milestone XProtect VMS installation wizard appears.
II. Language, end-user agreement and privacy settings
Select the Language to use during the installation (this is not the language that your system uses once installed; this is selected later).
Read the Milestone End-user License Agreement. Select the I accept the terms in the license agreement check box.
On the Privacy settings page, select whether you want to share usage data. You can always change your privacy setting later.
Note
You must not enable data collection if you want the system to have an EU GDPR-compliant installation. For more information about data protection and the usage data collection, see the GDPR privacy guide.GDPR privacy guide
III. Components to install
On the Select an installation type page, select Single computerto install the all components on this computer.
IV. Password protection
On the Assign a system configuration password page, enter a password that protects your system configuration. You will need this password in case of system recovery or when expanding your system, for example when adding clusters.
Note
It is important that you save this password and keep it safe. If you lose this password, you may compromise your ability to recover your system configuration.
If you do not want your system configuration to be password protected, select I choose not to use a system configuration password and understand that the system configuration will not be encrypted.
On the Assign a mobile server data protection password page, enter a password to encrypt your investigations. As a system administrator, you will need to enter this password to access the mobile server data in case of system recovery or when expanding your system with additional mobile servers.
Important
You must save this password and keep it safe. Failure to do so may compromise your ability to recover mobile server data.
If you do not want your investigations to be password-protected, select I choose not to use a mobile server data protection password, and I understand that investigations will not be encrypted.
V. Recording server settings
On the Specify recording server settings page, specify the different recording server settings:
In the Recording server name field, enter the name of the recording server. The default is the name of the computer.
The Management server address field shows the address and port number of the management server: localhost:80.
In the Select your media database location field, select the location where you want to save your video recording. Milestone recommends that you save your video recordings in a separate location from where you install the software and not on the system drive. The default location is the drive with the most space available.
In Retention time for video recordings field, define for how long you want to save the recordings. You can enter from between 1 and 365,000 days, where 7 days is the default retention time.
VI. Encryption
On the Select encryption page, you can secure the communication flows:
Between the recording servers, data collectors, and the management server
To enable encryption for internal communication flows, in the Server certificate section, select a certificate.
Important
If you encrypt the connection from the recording server to the management server, the system requires that you also encrypt the connection from the management server to the recording server.
Between the recording servers and clients
To enable encryption between recording servers and client components that retrieve data streams from the recording server, in the Streaming media certificate section, select a certificate.
Between the mobile server and clients
To enable encryption between client components that retrieve data streams from the mobile server, in the Mobile streaming media certificate section, select a certificate.
Between the event server and components that communicate with the event server
To enable encryption between the event server and components that communicate with the event server, including the LPR server, in the Event server and extensions section, select a certificate.
You can use the same certificate file for all system components or use different certificate files depending on the system components.
You can also enable encryption after installation from the Server Configurator in the Management Server Manager tray icon in the notification area.
VII. Server logs
On the Server logs setup page, specify the following parameters:
Open Telemetry Protocol (OTLP) endpoint
Log language - the display language for the logs
Log level - select between Standard (uses less storage) or Extended (collects more data)
Retention period - how long the database should keep the log entries
Enable or disable to use Open Telemetry Protocol for server logs.
VIII. Location and language
On the Select file location and product language page, do the following:
In the File location field, select the location where you want to install the software.
Note
If any Milestone XProtect VMS product is already installed on the computer, this field is disabled. The field displays the location where the component will be installed.
In Product language, select the language in which to install your XProtect product.
Click Install.
The software now installs. If not already installed on the computer, Microsoft® SQL Server® Express and Microsoft IIS are automatically installed during the installation.
You may be prompted to restart the computer. After restarting your computer, depending on the security settings, one or more Windows security warnings may appear. Accept these and the installation completes.
IX. Add hardware and users
When the installation completes, a list shows the components that are installed on the computer.
Click Continue to add hardware and users to the system.
Note
If you click Close now, you bypass the configuration wizard and XProtect Management Client opens. You can configure the system, for example add hardware and users to the system, in Management Client.
On the Enter user names and passwords for hardware page, enter the user names and passwords for hardware that you have changed from the manufacturer defaults.
The installer scans the network for this hardware as well as hardware with manufacturer default credentials.
Click Continue and wait while the system scans for hardware.
On the Select the hardware to add to the system page, select the hardware that you want to add to the system. Click Continue and wait while the system adds the hardware.
On the Configure the devices page, you can give the hardware descriptive names by clicking the edit icon next to the hardware name. This name is then prefixed to the hardware devices.
Expand the hardware node to enable or disable the hardware devices, such as cameras, speakers, and microphones.
Note
Cameras are enabled by default, and speakers and microphones are disabled by default.
Click Continue and wait while the system configures the hardware.
On the Add users page, you can add users to the system as Windows users or basic users. The users can have either the Administrators role or the Operators role.
Define the user and click Add.
When you are done adding users, click Continue.
When the installation and initial configuration are done, the Configuration is complete page appears, where you see:
A list of hardware devices that are added to the system
A list of users who are added to the system
Addresses to the XProtect Web Client and XProtect Mobile client, which you can share with your users
When you click Close, XProtect Smart Client opens and is ready to use.