SPP allows you to restore the data on your appliance with data from a selected backup. SPP does not restore the appliance IP address, NTP settings, or the DNS settings.

To verify that the settings are correct after a restore, go to:

  • web client: Navigate to Appliance > Appliance Information.

There are special considerations for restoring a clustered appliance. For more information, see Using a backup to restore a clustered appliance.

Caution: If you restore a backup that is older than the Maximum Password Age set in the Local Login Control settings, all user accounts (including the bootstrap administrator) will be disabled and you will have to reset all of the user account passwords or SSH keys. If your bootstrap administrator's password is locked out, you can reset it from the Recovery Kiosk. For more information, see Admin password reset.

CAUTION: When restoring a backup that was created with a Hardware Security Module integration in place, the encryption key used at the time of the backup creation needs to still be present and accessible by the SPP appliance. If not, the appliance will not be able to verify the Hardware Security Module configuration used to encrypt the data in the backup. You will be allowed to continue with the restore, however the SPP appliance will most likely Quarantine in the process, so this is not recommended.

Version considerations when restoring a backup

An Appliance Administrator can restore backups as far back as SPP version 6.0.0.12276. Only the data is restored; the running version is not changed.

You cannot restore a backup from a version newer than the one running on the appliance. The restore will fail and a message like the following displays: Restore failed because backup version [version] is newer then the one currently running [version].

The backup version and the running version display in the Activity Center logs that are generated when Safeguard starts, completes, or fails a restore.

To restore the SPP appliance from a backup

  1. Go to Backup and Restore:
    • web client: Navigate to Backup and Retention > Backup and Restore.
  2. Select a backup. If the backup file is not listed, you can  Upload the .sgb backup file. For more information, see Upload a backup.
  3. Click Restore.
    If a problematic condition is detected, Warning for Restore of Backup displays along with details in the Restore Warnings, Warning X of X message. Click Cancel to stop the restore process and address the warning or click Continue to move to the next warning (if any) or complete the process.
  4. If the backup is protected by a password, the Protected Backup Password dialog displays. Type the password in the Enter Backup Password text box. If the password entered is not correct, the OK button is disabled and you cannot proceed. For more information, see Backup protection settings.
  5. When the Restore dialog displays, enter the word Restore in the box and click OK.

    SPP automatically restarts the appliance, if necessary.

  6. After restoring from backup verify that the following are set correctly.

    • Check the archive server in the automated backup schedule. If necessary, set the correct archive server. For more information, see Archive backup.
    • Check the archive server in the session archive settings. If necessary, set the correct archive server. If you used the embedded sessions module and had an archive server configured, the archive server must be configured to play back the archived sessions.

    • If you restored a backup to a different appliance, managed networks will no longer have any assigned appliances. Password and SSH key management and discovery tasks will fail. For more information, see Managed Networks.
  7. Once the appliance is fully operational, it asks you to restart the client. All modifications to Safeguard for Privileged Passwords objects since the backup was created will be lost.

Caution: After a restore, requesters, approvers, and reviewers will not have access to any access request workflow events that were in process at the time of the backup. The Activity Center displays those workflow events as incomplete.