Active Directory Planning for Lockout
How the Everyone group and multi-domain Active Directory trust relationships affect SMB lockout scope, and what to review before enabling enforcement.
How the Everyone group and multi-domain Active Directory trust relationships affect SMB lockout scope, and what to review before enabling enforcement.
How to safely onboard a new application or workflow onto a monitored cluster that is already running in Enforcement or Critical mode with lockout enabled.
Configuration
Placing honeypot bait files (PowerScale) and bait objects (ECS) as tripwires to accelerate ransomware detection, and changing the default honeypot naming pattern.
Forward raw PowerScale audit events from the ECA to an external syslog server, or archive them to an S3 bucket via Data Orchestration, independent of Data Auditing's own query database
How user lockout works across SMB, NFS, and ECS when a security event reaches Major or Critical severity, and how to restore access afterward.
Deep-reference material for Recovery Manager -- snapshot-selection logic, quarantine forensics, and ECS-specific behavior. Covers both PowerScale and ECS.
How the Suspicious Extensions master list is maintained and updated, and the CLI commands to control update mode and roll back a version.
How Data Security responds to a security event -- user lockout across SMB, NFS, and ECS, and the protective snapshots taken alongside it.