Install some system components (Custom option)
The Custom option installs the management server, but you can select which other server and client components you want to install on the current computer. Depending on your selections, you can install the rest of the system components on other computers afterward, through the management server's Download Manager/download web page.
I. The installation file
II. Language, end-user agreement and privacy settings
III. Components to install
On the Select an installation type page, select Customto select the components to install on this computer. Apart from the management server, all components in the list are optional.
Important
For your system to function properly, you must install at least one instance of XProtect API Gateway.
Depending on the components you selected to install some of the steps below might to be applicable for your case. In the steps below, all system components are installed. If you cannot recognize an installation step, it is likely because you have not selected to install the system component that this page belongs to.
IV. Internet Information Services (IIS)
The Select a website on the IIS to use with your XProtect system page is shown only if you have more than one IIS website available on the computer.
You must select which website you will use with your XProtect system. Select a website with HTTPS binding.
V. Database setup
On the Database setup page, select one of the options:
Let the installer create or recreate a database
Milestone XProtect cannot be installed or upgraded using an MS-SQL database enrolled in a database mirroring session or an availability group because some operations cannot run on this kind of database. Remove the database from the availability group or mirroring session during the installation or upgrade. After the installation or upgrade is complete, the database can be enrolled in a mirroring session or an availability group again.
When you select this option, the Select Microsoft SQL Server page opens. Select one of the following options:
Install Microsoft® SQL Server® Express on this computer: This option is shown only if you do not have SQL Server installed on the computer
Use the SQL Server on this computer: This option is shown only if SQL Server is already installed on the computer
Select a SQL Server on your network through search: Enables you to search for all SQL Server installations that are discoverable on your network subnet
Select a SQL Server on your network: Enables you to enter the address (host name or IP address) of SQL Server that you might not be able to find through search
On the Select database page (only shown if you have selected existing SQL Server), select or create a SQL Server database for storing your system configuration.
If you choose an existing SQL Server database, decide on what you want to do with your existing data:
Keep is used when upgrading to a newer version.
Overwrite
Use a pre-created database
When you select this option, the Advanced database setup page opens.
Select the authentication type. The account to be used for the installation must be created in Microsoft Entra ID or Windows AD depending on the authentication type you want to use. Multi-factor authentication (MFA) is not supported for the accounts.
Windows Authentication, do not trust server certificate (recommended)
Windows Authentication, trust server certificate
Microsoft Entra Integrated, do not trust server certificate (recommended)
Microsoft Entra Managed Identity, do not trust server certificate.
The (do not trust server certificate) option is recommended for Windows Authentication and mandatory for Microsoft Entra Integrated. This is to ensure that server certificates are validated and verified before installation. More information about invalid server certificates is available in the installation log file. With the Windows Authentication, trust server certificate option, you skip the validation of server certificates.
Enter the server and the database name for the XProtect components.
Click the icon to verify the connection. By clicking the icon, you also validate server certificates.
VI. Password protection
VII. Service accounts
On the Select service account, select either This predefined account or This account to select the service account for the recording server. If needed, enter a password.
Note
The user name for the account must be a single word. It must not have a space.
VIII. Recording server settings
IX. Encryption
X. Server logs
On the Server logs setup page, specify the following parameters:
Open Telemetry Protocol (OTLP) endpoint
Log language - the display language for the logs
Log level - select between Standard (uses less storage) or Extended (collects more data)
Retention period - how long the database should keep the log entries
Enable or disable to use Open Telemetry Protocol for server logs.