0% found this document useful (0 votes)
2 views154 pages

End Point Admin Guide

The Carbonite Endpoint Administrator Guide provides instructions for IT administrators on configuring and deploying Carbonite Endpoint for data backup on desktop and laptop devices. It covers topics such as policy management, user and device management, and the dashboard interface for monitoring backups. The document is subject to change and includes legal notices regarding proprietary information and trademarks.

Uploaded by

donato.brea
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views154 pages

End Point Admin Guide

The Carbonite Endpoint Administrator Guide provides instructions for IT administrators on configuring and deploying Carbonite Endpoint for data backup on desktop and laptop devices. It covers topics such as policy management, user and device management, and the dashboard interface for monitoring backups. The document is subject to change and includes legal notices regarding proprietary information and trademarks.

Uploaded by

donato.brea
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Notices

Carbonite Endpoint Administrator Guide, version 10.7, Tuesday, November 24, 2020
If you need technical assistance, you can contact CustomerCare. All basic configurations outlined in the
online documentation will be supported through CustomerCare. Assistance and support for advanced
configurations may be referred to a Pre-Sales Systems Engineer or to Professional Services.
This documentation is subject to the following: (1) Change without notice; (2) Furnished pursuant to a
license agreement; (3) Proprietary to the respective owner; (4) Not to be copied or reproduced unless
authorized pursuant to the license agreement; (5) Provided without any expressed or implied warranties, (6)
Does not entitle Licensee, End User or any other party to the source code or source code documentation of
anything within the documentation or otherwise provided that is proprietary to Carbonite, Inc.; and (7) All
Open Source and Third-Party Components (“OSTPC”) are provided “AS IS” pursuant to that OSTPC’s
license agreement and disclaimers of warranties and liability.
Carbonite, Inc. and/or its affiliates and subsidiaries in the United States and/or other countries own/hold
rights to certain trademarks, registered trademarks, and logos. Windows is a registered trademark of
Microsoft. Mac is a registered trademark of Apple. All other trademarks are the property of their respective
companies. For a complete list of trademarks registered to other companies, please visit that company’s
website.
© 2020 Carbonite, Inc. All rights reserved.
Contents
Chapter 1 Overview 6
Chapter 2 Get started 7
Chapter 3 Dashboard 9
Chapter 4 Company 12
Chapter 5 Policies 14
View available polices 15
Add a new policy 16
Edit an existing policy 17
Delete a policy 18
Policy settings 19
Manage backup rules for centrally managed policies 28
Default exclusions 31
Policy inheritance 33
Set the policy for a company 34
Set the policy for a group 35
Set the policy for a user 36
Set the policy for a device 37
Chapter 6 Deployment 38
Activation codes 39
View available activation codes 40
Add an activation code 42
Edit an activation code 44
Delete an activation code 45
Installation 46
Install on Windows or MacOS using the installation wizard 47
Install on Windows using Msiexec 50
Install on Windows using group policy 53
Install on MacOS using the installer app 54
Examples for [Link] 56
Activate on MacOS 57
Chapter 7 Groups 60
View available groups 61
Add a group 62
View group details 63
Edit an existing group 65
Delete a group 66
Chapter 8 Users 67
View available users 68
Add users 70
Add a single user 71
Import multiple users 74
View user details 76
Edit user settings 77

Contents 3
View devices for a user 78
Manage user permissions 79
Reset a user password 83
Delete a user 84
Manage users with LDAP 85
LDAP requirements 86
Sample configurations 87
Install LDAP agent 89
Configure LDAP synchronization 92
Monitor and troubleshoot LDAP synchronization 96
Chapter 9 Devices 98
View available devices 100
Add devices 102
Add a single device 103
Import multiple devices 105
View device details 107
Edit device settings 109
Manage a device 110
View device activity 112
View device issues 114
View device events 115
View device messages 116
Restore files from a device 117
Locate a device 120
Delete a device 121
Chapter 10 Manage alerts 122
Chapter 11 Admin restores 124
Chapter 12 Reports 126
View a list of available reports 127
Add a report 128
View a report 130
Delete a report 132
Chapter 13 QuickCache 133
View available QuickCaches 135
Add a QuickCache 136
View QuickCache activity 138
View QuickCache details 139
Edit QuickCache server settings 140
Manage the QuickCache bandwidth schedule 141
Manage a QuickCache 143
Assign a device to a QuickCache 145
Delete a QuickCache 146
Chapter 14 Single sign-on 147
View single sign-on details 148
Enable single sign-on for the first time 149
Edit single sign-on configuration 151

Contents 4
Disable single sign-on for one user 153
Disable single sign-on 154

Contents 5
Chapter 1 Overview
Carbonite Endpoint provides backup protection for desktop and laptop data. Desktops and laptops are
known as devices or endpoints. All endpoints are backed up to a single location known as the vault. After
the initial backup, subsequent backups are smaller and faster because only changes are backed up. An
optional QuickCache can be used for faster backups in local environments. Backed up data can be
restored from the vault to any device, any time, anywhere.

To configure protection, an administrator or user selects the files to be backed up and how often the files
are checked for changes (default every 15 minutes). Once protection is configured, the files are backed
up and protected, as long as the computer is running. Protection occurs locally if the computer is not
connected to the local network or Internet. The changes are sent to the vault (or optional QuickCache)
when the computer is back online. You do not need to take any additional action unless you want to
change the protection configuration or restore files. If you want to restore files, they are downloaded
from the vault to the original location or a new location. In the event your computer crashes or is stolen,
you can restore all of your protected files to your replacement computer.
This document is for IT administrators whose responsibilities include configuring Carbonite Endpoint for
their company. It includes tasks like configuring Carbonite Endpoint policies and deploying Carbonite
Endpoint within your company. This document does not include topics for using the end-user client
running on each device or topics for partners managing multiple companies.

Chapter 1 Overview 6
Chapter 2 Get started
Before you get started with Carbonite Endpoint, you need to make several key decisions, including
configuring policies, adding users to Carbonite Endpoint, and deploying the end-user client software on
the endpoint devices.

Policies
A policy configures the behavior of the end-user client, for example determining what content is backed
up, backup frequency, bandwidth management, and so on.
l Centrally-managed policy—With a centrally-managed policy, the Carbonite Endpoint
administrator configures the policy definitions.
l Self-managed policy—With a self-managed policy, end-users configure the policy definitions.
You can implement multiple policy types to meet the needs of different users or groups of users in your
organization. A starter policy is included (with common default settings) for you to use or customize as
needed.
See Policies on page 14 for more details and tasks available for policies.

Adding users to Carbonite Endpoint


In order to protect an endpoint device, a user must be associated with the device. You can think of a user
as an organizational tool for devices. You need to decide what organizational user account strategy you
want to implement.
l Multiple user accounts—With this strategy, you will add multiple user accounts, and each
account will have one or more devices associated with that particular user. Use this strategy when
devices are used by only one person.
l Single user account—With this strategy, you add a single user account, and many devices are
assigned to that account. Use this strategy when devices are shared by many people.
You can implement a combination strategy to meet the needs of individually used devices and shared
devices. You have multiple methods for adding user accounts from manual entry to bulk uploads to
automation using LDAP. In some cases, you can add the user at the same time you are deploying the
end-user software on the devices.
See Users on page 67 for more details and tasks available for manually adding user accounts and bulk
uploads to add user accounts. For automated methods, see end-user client deployment below.

End-user client deployment


Deployment is the process of getting an activation code and installing the end-user software on the
endpoint devices. In some cases, the deployment process also includes adding a user account.

Chapter 2 Get started 7


l Activation codes—The activation code option you select depends on what you want to happen
when the client software is installed.
l Add devices and add user accounts—If you want to add both a device and user in
Carbonite Endpoint when the client software is installed and activated, you will want to use
the Enable full directory integration option. (If the user already exists, only the device
will be added.) This method requires the user to log in on the device when connected to the
corporate network to capture the user information, and it requires a valid email address for
the user in LDAP for the mail attribute.
l Add devices for existing, individual user accounts—If you want to add a device in

Carbonite Endpoint for a user account that already exists, you will want to use the Enable
directory user integration option. This method requires you to add individual user
accounts in Carbonite Endpoint before the client software is installed.
l Add devices for existing, single user account—If you want to add a device in

Carbonite Endpoint for a single user account that already exists, you will want to use the
Enable directory device integration option. This method requires you to add a single
user account in Carbonite Endpoint before the client software is installed. All devices will be
associated with this single user account.
l Do not add devices—If you do not want to add any devices in Carbonite Endpoint when

the client software is installed, do not select any option (or use the Disable automatic
creation option if you selected another option and want to go back to no selection). This
method requires you to add individual user accounts and devices in Carbonite Endpoint
before the client software is installed.
l Installation—You have choices in the type of installation you perform.
l Remote deployment—With this strategy, you can push the end-user client software to
each device.
l Local installation—With this strategy, the software is installed manually on each device.

Regardless of the method you choose, you should initially work with a small subset of devices
until you are confident your deployment strategy is working. Once you are sure, you can
implement the strategy for larger numbers of devices.

See Deployment on page 38 for more details and tasks for activation and installation.

Chapter 2 Get started 8


Chapter 3 Dashboard
The Carbonite Endpoint administration console is called the vault dashboard. You can access it in a web
browser by going to [Link] Your <regioncode> will depend
on your location.

Location Region Code URL

Asia-Pacific APAC [Link]


Australia AU [Link]
Canada CA [Link]
Europe, the Middle East, and Africa EMEA [Link]
France FR [Link]
United Kingdom UK [Link]
US [Link]
United States
US2 [Link]

If you grant users the ability to log in to the web retrieval page of the portal (which allows users to
download their own data without using their device), the URL is the portal URL /access. For
example, if you are using [Link] a user would access the web
retrieval page by going to [Link]

The dashboard is divided into three main sections.


l Header—At the top of the window are a search tool and a link to your user account. You can limit
your search term by device, user, or company. If you select your name under the down arrow in
the far right corner, you will automatically go to your user account. This down arrow is also where
you log out of the dashboard.
l Navigation tabs on the left—On the left side are navigation tabs to take you to the main areas
of the dashboard. You can click the toggle above the tabs to expand to the full tab names or
collapse to the tab icon only.
l Home—This page is the highest level view of protected data and devices, where you can

see data and device usage.

Chapter 3 Dashboard 9
l Uploaded data—This chart shows the amount of data that was backed up each
day.
l Devices successfully backed up—This chart shows which percentage of your

devices were backed up during the specified time period.


l Activity summary—This chart shows the devices added and activated as well as

the total number of restores for each day.


l Protected data—This chart shows the total number of devices being protected and

the total amount of data being protected.


l Company—This page is where you perform administrative tasks for your company. See

Company on page 12 for details.


l Users—This page is a list of users and where you can manage your users. See Users on

page 67 for details.


l Devices—This page is a list of devices and where you can manage your devices. See

Devices on page 98 for details.


l QuickCache—This page is a list of QuickCaches and where you can manage your

QuickCaches. See QuickCache on page 133 for links where you can find details about
installing and using a QuickCache.
l Reports—This page is a list of reports and where you can manage your reports. See

Reports on page 126 for details.


l Pages on the right—The remaining part of the dashboard display is the various pages you
interact with. These pages may have additional tabs within them, at the top of the page.
Some of the right side pages in the dashboard will show different lists of data depending on how
you got to the page. For example, if you click on the Devices navigation tab on the left, you will be
taken to the Devices page and all devices will be displayed. However, if you are on the Users
page and you click on the hyperlink in the Number of devices column, you will be taken to the
Devices page but only those devices assigned to the user you were viewing will be displayed.

Chapter 3 Dashboard 10
In addition to this dashboard, there is also the backup client software including an end-user interface,
installed on each device, which may or may not be hidden to end-users. The end-user interface is not
covered in this document.

Chapter 3 Dashboard 11
Chapter 4 Company
This page is where you perform administrative tasks for your company. The page is divided into multiple
tabs for different functions.
l Company details—This tab shows the details for your company.

l Manage keys—A key server, or reset server, is an advanced function that allows you to
store and control access to keys for device resets. You will only use this button if you are
using your own key server and need to manage your keys.
l Edit company—Click this button to modify your company settings.
l Default policy set—Click this hyperlink to edit the policy details. See Edit an existing
policy on page 17 for details.
l Users—There are several access points you can select related to users.
l Hyperlink or number—Click the hyperlink or the number to go to the Users page.

See View available users on page 68 for details.


l Add user—Click this button to add a new user. See Add a single user on page 71

for details.
l Export users—Click this button to export a complete user list to your local

computer. You can select to download a Microsoft Excel (.xlsx) file or a comma-
delimited file (.csv). If you download the Excel format, you must enable editing for any
hyperlinks to the portal to be active.
l Import users—Click this button to import multiple users. See Import multiple users

on page 74 for details.

Chapter 4 Company 12
l Devices—There are several access points you can select related to devices.
l Hyperlink or number—Click the hyperlink or the number to go to the Devices

page. See View available devices on page 100 for details.


l Add device—Click this button to add a new device. See Add a single device on

page 103 for details.


l Export devices—Click this button to export a complete device list to your local

computer. You can select to download a Microsoft Excel (.xlsx) file or a comma-
delimited file (.csv). If you download the Excel format, you must enable editing for any
hyperlinks to the portal to be active.
l Import devices—Click this button to import multiple devices. See Import multiple

devices on page 105 for details.


l QuickCaches—There are several access points you can select related to users. See

QuickCache on page 133 for links where you can find details about installing and using a
QuickCache.
l Hyperlink or number—Click the hyperlink or the number to go to the

QuickCaches page.
l Add QuickCache—Click this button to add a new QuickCache.

l Export QuickCache—Click this button to export a complete QuickCache list to your

local computer. You can select to download a Microsoft Excel (.xlsx) file or a comma-
delimited file (.csv). If you download the Excel format, you must enable editing for any
hyperlinks to the portal to be active.
l Policies—A policy configures the behavior of the end-user client, for example determining what
content is backed up, backup frequency, bandwidth management, and so on. See Policies on
page 14 for details.
l Groups—Groups provide a way to associate multiple users. This provides the ability to perform
tasks for the users in a group. For example, you can define a policy for a group and all users in the
group will use that policy. See Groups on page 60 for details.
l Deployment (AD/LDAP)—Deployment is the process of getting an activation code and installing
the end-user software on the devices. In some cases, the deployment process also includes
adding a user account. See Deployment on page 38 for details on activation codes and
installation.
l LDAP synchronization—If you are using Lightweight Directory Access Protocol (LDAP ), you
can manage Carbonite Endpoint users by synchronizing Carbonite Endpoint and LDAP. This will
add and disable users based on their status in your LDAP company directory. See Manage users
with LDAP on page 85 for details.
l Alerts—You can enable daily alerts (email notifications) to notify you when specific device and
QuickCache criteria have been met. See Manage alerts on page 122 for details.
l Single sign-on—You will only see this tab if you have worked with Carbonite Professional
Services to configure it. See Single sign-on on page 147 for details.
l Admin restores—You can view the restores performed by an administrator. See Admin
restores on page 124 for details.

Chapter 4 Company 13
Chapter 5 Policies
A policy configures the behavior of the end-user client, for example determining what content is backed
up, backup frequency, bandwidth management, and so on.
l Centrally-managed policy—With a centrally-managed policy, the Carbonite Endpoint
administrator configures the policy definitions.
l Self-managed policy—With a self-managed policy, end-users configure the policy definitions.
You can implement multiple policy types to meet the needs of different users or groups of users in your
organization. A starter policy is included (with common default settings) for you to use or customize as
needed.
Think about the following key questions and situations when determining what type of policy to use.
l What is the size of your user-base? If you have a smaller number of end-users, you may want to
use self-managed policies. If you have many end-users, you may be better off using centrally-
managed policies.
l Where are your users located? If your users are geographically dispersed, each with their own
bandwidth, you may not have bandwidth concerns for backing up files. If your users are all in the
same location, you may need to have bandwidth policies in place to protect the available
bandwidth.
l Who needs to define what should be backed up? If you are comfortable with users deciding what
files to back up, you can use self-managed policies. If you must retain control over the files that are
backed up, you will need to use centrally-managed policies.
l Does it matter if users know the software is there? If you want to hide the software, you must use
centrally-managed policies (and remote deployment).
l Do you have separate groups that have different backup needs? For example, if one office
location or department needs to have different protected files than another office location or
department, you may want to have different centrally-managed policies for the different groups or
a combination of centrally-managed and self-managed policies. You should also consider if you
have different groups of employees, such as executives, that have different legal needs. In that
case, you may need different centrally-managed policies or a combination of centrally-managed
and self-managed policies.
l Do you have a dedicated IT staff to administer the centrally-managed policies? If not, you may
want to use self-managed policies.
The following tasks are available for policies.
l View available polices on page 15
l Add a new policy on page 16
l Edit an existing policy on page 17
l Delete a policy on page 18
In addition to those tasks, see Policy settings on page 19 for details on each of the individual settings,
Default exclusions on page 31 for details on which files, folders, and files without an extension are
excluded from the backup, and Policy inheritance on page 33 to understand how policies are assigned
and inherited.

Chapter 5 Policies 14
View available polices
To view your available policies, go to the Company page and then the Policies tab. All companies start
with the Base Policy which is a starter policy that you can use to add your own customized policies.

The following controls are available on the Polices tab.


l Show Entries—Specify the number of rows to be shown in the table on each page. Additional
rows over the number you select are shown on additional pages and can be viewed by using the
paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—Click a policy name or the policy description to manage that policy. See Edit
an existing policy on page 17 for details.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 5 Policies 15
Add a new policy
To add a new policy, you start by making a copy of an existing policy.
1. Go to the Company page and then the Policies tab.
2. Locate in the table an existing policy you want to copy. See View available polices on page 15 for
details on searching the table.
3. Once you have located the policy you want to copy, click on the policy's name.
4. Make changes to the policy, if desired. See Policy settings on page 19 for details on each of the
individual settings.
5. Select one of following, depending on if you made policy setting changes.
l Done—Click this button if you have not made any changes to the policy settings. No new

policy will be added.


l Save as—Click this button if you have specified a different, unique policy name. One new

policy will be added using the name you specified. If you have not changed the policy name,
one new policy will be added by appending a number to the existing policy name.
l Save policy—You will not be able to click this button unless you have made a policy setting

change. If you have specified a different, unique policy name, one new policy will be added
using the name you specified. If you have not changed the policy name, one new policy will
be added by appending a number to the existing policy name.
If you selected either save option, click Done to return to the Policies tab, or click Continue
editing to remain on the Edit policy details page.

Chapter 5 Policies 16
Edit an existing policy
Use these instructions to edit an existing policy.
1. Go to the Company page and then the Policies tab.
2. On the Policies tab, locate in the table the policy you want to edit. See View available polices on
page 15 for details on searching the table.
3. Once you have located the policy you want to edit, click on the policy's name.
4. On the Edit policy details page, modify any of the policy settings. See Policy settings on page 19
for details on each of the individual settings.

5. If you have changed the policy name to a unique name, you can click Save as or Save policy. If
you have not changed the policy name, Save as will create a new policy by appending a number
to the existing policy name, and Save policy replaces the existing policy reusing the existing
policy name.

You cannot change the policy name to a name that already exists.

Changes to policies will be applied to devices using the policy as soon as the changes are
saved and the device is connected.

6. Click Done to return to the Policies tab, or click Continue editing to remain on the Edit policy
details page.

Chapter 5 Policies 17
Delete a policy
If you no longer need a policy, you can delete it.
1. Go to the Company page and then the Policies tab.
2. On the Policies tab, locate in the table the policy you want to delete. See View available polices
on page 15 for details on searching the table.
3. Once you have located the policy you want to delete, click on the policy's name.
4. On the Edit policy details page, click Delete policy.

5. Click Delete policy on the confirmation box.

Chapter 5 Policies 18
Policy settings
Below is a description of all possible policy settings. Review the key questions and situations in Policies
on page 14 when determining what settings to use for a policy.

You may not have all of these settings if Carbonite has restricted your access.

Use the following steps to get to the policy settings.

1. Go to the Company page and then the Policies tab.


2. On the Policies tab, locate in the table the policy that contains the settings you want to view or
modify. See View available polices on page 15 for details on searching the table.
3. Once you have located the policy that contains the settings you want to view or modify, click
on the policy's name.

l General

l Policy name—Provide a name for the policy. If the name already exists and you select
Save as, Carbonite Endpoint will append a number to the policy name. The name cannot
contain any of the following reserved characters.
l less than <
l greater than >

l colon :

l quotation marks or double quote "

l forward slash /

l backslash \

l vertical bar or pipe |

l question mark ?

l asterisk *

l Policy description—Provide a description of the policy. The description cannot contain


any of the reserved characters identified under policy name.
l Policy status—Specify if you want to enable or disable this policy.

Chapter 5 Policies 19
l Protected Files

l File Selection Management—This setting identifies who defines the files that will be
backed up.
l Self managed by end users—Users define their own backup rules.

l Centrally managed by administrator—Administrators define the backup rules.

When this option is selected, you must define the rules the policy will use to identify
which files to include or exclude in the backup. See Manage backup rules for
centrally managed policies on page 28 for details.

Regardless of self managed or centrally managed, some files and folders (including
files without an extension) are excluded, by default, from backups. See Default
exclusions on page 31 for details.

l Backup frequency—Specify the amount of time between backups. Carbonite Endpoint


will scan for changes on this interval and back up any changes, additions, or deletions.
The lock icon is a toggle you can turn on and off. It indicates if users can modify this policy
setting in the client interface. When the icon displays locked, users cannot modify the
setting. When the icon displays unlocked, user can modify the setting.
l Only back up during Backup Schedule—When enabled, a defined backup schedule
controls when files are backed up. Within the defined scheduled, files will be backed up.
Outside of the defined scheduled, files will not be backed up. When disabled, files are
backed up any time.

Chapter 5 Policies 20
The lock icon is a toggle you can turn on and off. It indicates if users can modify this policy
setting in the client interface. When the icon displays locked, users cannot modify the
setting. When the icon displays unlocked, user can modify the setting.
l Backup schedule—When Only back up during Backup Schedule is enabled, you can
configure the schedule when you want files to be backed up. This option is not used when
Only back up during Backup Schedule is disabled. The toggle circle will be on the right
and blue when enabled and on the left and gray when disabled.
l Start time—Specify when you want the backup schedule to start. Files will be

backed up between this time and the End time.


l End time—Specify when you want the backup schedule to end. Files will be backed

up between the Start time and this time.


The time is configured using your local machine time.
The lock icon is a toggle you can turn on and off. It indicates if users can modify this policy
setting in the client interface. When the icon displays locked, users cannot modify the
setting. When the icon displays unlocked, user can modify the setting.
l Device Settings

l Track device location—When enabled, Carbonite Endpoint tracks the location of the
device, and the location can be viewed on a map. When disabled, the location of the device
is not tracked. This setting can be useful for locating lost or stolen devices. The toggle circle
will be on the right and blue when enabled and on the left and gray when disabled.
l Remote Wipe—Select which files can be deleted from the device (but not the backup) by
the administrator.
l None—No files can be deleted from the device.

l Quick Delete—Files configured for backup can be deleted from the device. (Files

are not retained in the trash or recycle bin.)


l Delete and Overwrite—Files configured for backup can be deleted from the device.

After they are deleted, the file location is overwritten multiple times. This option is
more secure and makes recovery of the original files more difficult, however, the
deletion process takes longer.

Chapter 5 Policies 21
l Quick Delete with remove EFS keys—For Windows devices, files configured for
backup are deleted from the device. Also, the folder on the device containing the
EFS encryption keys is deleted. Once the encryption keys are deleted, all files
encrypted with EFS will be inaccessible, even those that were not backed up with
Carbonite Endpoint.
l Delete and Overwrite with remove EFS keys—For Windows devices, files

configured for backup are deleted from the device. After they are deleted, the file
location is overwritten multiple times. Also, the folder on the device containing the
EFS encryption keys is deleted. This option has the same benefits and caveats as
above, in addition to making EFS files inaccessible.
l Timed Remote Wipe—The toggle circle will be on the right and blue when enabled and on
the left and gray when disabled. When disabled, files will never be automatically deleted
from a device. When enabled, files will be automatically deleted from a device (but not the
backup) when the device has failed to connect to the vault or QuickCache within the time
period specified. If you enable this option, you must confirm you want to use this setting
because it can lead to unintended data loss. Select Devices will be wiped based on time
configuration, click Enable Remote Wipe, and specify the number of days. For example,
if you set this option to 30 days, at the beginning of the 31st day, data on the device will be
deleted as configured in Remote Wipe. Each time the device connects, the countdown will
be rest for the time remote wipe.
l End user self restore—When enabled, users can perform file restores from the vault or
QuickCache. When disabled, only administrators can restore files. The toggle circle will be
on the right and blue when enabled and on the left and gray when disabled.
l Advanced settings—Click the link to show or hide advanced settings.
l Advanced File Deletion

l End users can erase their data from vault—When enabled, users can

erase (delete) their backed up files from the vault and QuickCache. When
disabled, users cannot erase their backed up files and the backed up files will
be maintained until a retention or storage policy overwrites the file or the
device is deleted from the vault. The toggle circle will be on the right and blue
when enabled and on the left and gray when disabled.
l User State Migration Tool—Carbonite Endpoint uses Microsoft User State

Migration Tool (USMT) to provide a process for replacing or refreshing Windows


computers. The utility captures operating system settings, application settings, user
accounts, and user files and migrates them to a new Windows installation. You must
be familiar with using and configuring USMT. See [Link]
us/windows/deployment/usmt/usmt-topics for details on this utility.
l Scheduled user scan backup—When enabled, Carbonite Endpoint will

scan a Windows device for the latest settings, accounts, and files. The
frequency of the scan is defined by the number of days specified. When
disabled, scans must be run manually. The toggle circle will be on the right and
blue when enabled and on the left and gray when disabled.

You can also perform manual scans as needed. See Manage a device
on page 110 for details.

Chapter 5 Policies 22
l Location of the 32-bit USMT executable—Specify where the 32-bit
version of the utility is located. This file will be used on 32-bit Windows
computers. The location must be accessible by the Windows devices. You do
not need to specify the file name, just the location.
l Location of the 64-bit USMT executable—Specify where the 64-bit
version of the utility is located. This file will be used on 64-bit Windows
computers. The location must be accessible by the Windows devices. You do
not need to specify the file name, just the location.
l Parameters for ScanState executable—Specify the options you want to
use with ScanState . Generally, this is /config:[Link], however you
should review [Link]
us/windows/deployment/usmt/usmt-scanstate-syntax for details on the
command syntax.
l Abort ScanState execution—Specify how long you want to let ScanState
run before it is terminated automatically. The minimum is one minute.
l Location for custom configuration files—Specify the location of your XML
files for custom configurations. See [Link]
us/windows/deployment/usmt/usmt-include-files-and-settings and
[Link]
files-and-settings for details on custom files to include and how to exclude files
and settings. You do not need to specify the file names, just the location.
l After a restart, start USMT ScanState—Specify the amount of time to wait
after a Windows computer has been restarted to initiate a scan. The minimum
is one minute.
l Parameters for LoadState executable—Specify the options you want to
use with LoadState . See [Link]
us/windows/deployment/usmt/usmt-loadstate-syntax for details on the
command syntax.
l Abort LoadState execution—Specify how long you want to let LoadState
run before it is terminated automatically. The minimum is one minute.

Chapter 5 Policies 23
l Retention & Storage

l Versions—Select how many versions of an individual file to keep.


l Unlimited—Select this option to keep all file versions. If you have specified a length

of time for Keep older versions, that time will be disregarded because all versions
are being kept.
l Specified number of versions—Select this option to keep at least the number of

versions specified. Versions outside of this minimum number will be deleted at the
specified length of time for Keep older versions.
l Keep older versions—Select how many days of version history to keep.
l Forever—Select this option to keep all days of version history. If you have specified

a number of versions for Versions, that number will be disregarded because all days
of version history are being kept.
l Specified length of time—Select this option to keep at least the number of days of

version history specified. Versions outside of this minimum date will be removed at
the specified number of versions for Versions.
l Retain deleted files—Select how many days to keep files that have been deleted from a
device or files that were once backed up but are no longer being backed up because of a
change to file selection rules.
l Forever—Select this option to keep all deleted files within the backup even if they

are deleted from the device or no longer included in the backup policy.

Chapter 5 Policies 24
Keep in mind your consumed capacity will always grow and will not be
subject to any retain policy, even if you delete users and their devices.

l Specified length of time—Specify the number of days to keep all deleted (or no
longer backed up) files. After the specified number of days, the files will be deleted.
The maximum number of days is 180. If you need more than that, you must select
Forever.

The default value for retaining deleted files changed in Carbonite Endpoint version
10.6. If you were using the default value previously (forever or 180 days depending
on your version), your new default value will be 90 days. Files beyond the 90 day
value will be deleted from the backup. If you customized the value, your setting will
be retained.

l Advanced settings—Click the link to show or hide advanced settings.


l Unlimited storage quota—When enabled, there is no size limit to how much data

can be backed up. When disabled, the size specified will be used as a quota. The
toggle circle will be on the right and blue when enabled and on the left and gray when
disabled. The minimum storage quota is 5 GB. You can use the quota for reporting
and to monitor usage to avoid overage fees.
l Prevent backups when storage quota is reached—When enabled,

backups will stop when the specified quota limit has been reached. When
disabled, devices can exceed the specified quota limit.
l Largest file size to include in backups—Specify the maximum file size, in GB,

that will be backed up. Files larger than this size will not be backed up.

Chapter 5 Policies 25
l Bandwidth Management

l Device bandwidth configuration—Select how much bandwidth a device will use to back
up files.
l Reduced Bandwidth—Select this option to limit the amount of bandwidth used for
backing up files to the amount specified in Maximum upload rate when reduced.
l Use all available bandwidth—Select this option to have unlimited bandwidth for

backing up files.
The lock icon is a toggle you can turn on and off. It indicates if users can modify this policy
setting in the client interface. When the icon displays locked, users cannot modify the
setting. When the icon displays unlocked, user can modify the setting.
l Maximum upload rate when reduced—Specify the amount of bandwidth a device will
use to back up file when Device bandwidth configuration is set to Reduced
Bandwidth.
l Maximum download rate—Specify the bandwidth limit a device will use when
downloading during restores and when using the User State Migration Tool.
l Proxy settings—Select this option if you need to specify proxy server settings.
l No Proxy—Select this option if you want remove an existing proxy server or prevent

users from using a proxy server.


l Automatically detect settings—Select this option to have the system

automatically detect the proxy server.


l Specify the server and port—Select this option to specify the proxy server to use.

You need to specify credentials, the server, and the port number.
l Use automatic configuration script—Select this option to use a configuration

script on your proxy server to automatically configure the device. You need to specify
credentials and the IP address of the proxy server.

Chapter 5 Policies 26
l Advanced settings—Click the link to show or hide advanced settings.
l Do not upload when device is attached to a mobile broadband network—

When enabled, Windows devices attached to a mobile network will not back up files.
When disabled, Windows devices attached to a mobile network will back up files.
The toggle circle will be on the right and blue when enabled and on the left and gray
when disabled.
l Mobile Network Names—This setting allows you to identify specific WiFi networks

as a mobile network, which can be used to identify tethering or hotspot scenarios.


WiFi networks identified as mobile networks will be limited by the Do not upload
when device is attached to a mobile broadband network setting. Enter each
network name on a separate line.

Chapter 5 Policies 27
Manage backup rules for centrally managed policies
If you want administrator control over which files do and do not get backed up (a centrally-managed
policy), you will need to define rules in the policy to identify the files to include or exclude in the backup.
l Rules can be specified for volumes, folders, files, and file types.
l Wildcards can be used.
l All rules are recursive, which means the rule is automatically applied to the subfolders of the
specified path.
l A rule for a file type will take precedence over a rule for All Files.
l In the case of multiple rules, files use the rule that is closest in the folder structure to them. In the
following example, all files and folders under C:\Users will be backed up (the first rule). However,
video files will be excluded from C:\Users and its subfolders (the second rule), except the videos
located in C:\Users\*\marketing and its subfolders will be included (the third rule).

l Some files and folders (including files without an extension) are excluded, by default, from
backups. See Default exclusions on page 31 for details.

You have the following toolbar and table controls available for the File selection rules section on the
Edit policy details page.

Use the following steps to get to the File selection rules.

1. Go to the Company page and then the Policies tab.


2. On the Policies tab, locate in the table the policy that contains the backup rules you want to
view or modify. See View available polices on page 15 for details on searching the table.
3. Once you have located the policy that contains the backup rules you want to view or modify,
click on the policy's name.
4. Make sure File Selection Management is set to Centrally Managed by administrator
and you will see the File selection rules section.

Chapter 5 Policies 28
l Filter by—Text entered in the box will narrow the list displayed to only those rows that contain the
filter text.
l Manage custom file types—Click this button to see a list of custom file types. These are specific
files you want to include or exclude from the backup.
l Add custom file type—Click this button to add a new custom file type.

l File type name—Specify a name to identify this type of file.

l Copy from—If desired, you can select an existing file type to pre-populate the File

type extensions field.


l File type extensions—Specify the file extensions for the files you want to include or

exclude from the backup. Separate multiple extensions by a space.


Click Save once you have defined the new custom file type.
lEdit—Click this button to edit the file type definition. Use the same guidelines as outlined
above when adding a custom file type. Click Save to save the changes.
l Table row overflow menu—Click Delete in the overflow menu of a table row to delete the

file type definition. Confirm the deletion by clicking Delete.


l Close—Click this button to close the Manage custom file type dialog box.

l Add rule—Click this button to add a new rule.


l Define type of rule—Select the type of rule you want to add.

l Backup—Select this option if you want the file types defined by this rule to be

backed up.

Chapter 5 Policies 29
lDo not backup—Select this option if you do not want the file types defined by this
rule to be backed up.
l Select a file type—Select the type of file to be included in the rule.
l Pre-defined file type—Click on one of the pre-defined tiles to select that specific file

type.
l Custom file type—If you have added custom file types, select a custom file type

definition from the drop-down list. If you only have one custom file type, it is a single
tile, not a drop-down list. Click Edit to modify the selected custom file type, or click
Create custom file type if you need to add a new custom file type.
l Define the file location—Select where to look for files that should be backed up
l Commonly used file locations—If desired, select a common location on the

devices to look for files that should be backed up. You can select all drives for both
Windows and MacOS devices, or for Windows devices only, you can select the
system drive, desktop, documents folders, or user folders.
If you do not select anything, then the specified File location will be used.
l File location—If you selected a commonly used location, this field will be
automatically populated. You can specify a folder, file, or wildcard that exists under
the common location if desired. For example, if you selected the %Users% common
Windows location, you could modify that to %Users%\*\Documents. However, do
not modify the syntax of the common location (%AllDrives%, %SystemDrive%,
%Desktop%, %Documents%, or %Users%) or enter any other shortcuts or macros.
Only the pre-defined shortcuts or macros listed in Commonly used file locations
can be used. Any other shortcut or macro will not work.
If you did not select a commonly used location, enter the file location on the devices to
look for files that should be backed up. Make sure you use the proper syntax for the
operating system. For example, use C:\folder\subfolder for Windows and
/folder/subfolder for MacOS. Each device will use the rules formatted for its operating
system syntax.
l Save & add another—Click this button to save the rule and refresh the Add a rule dialog
box so you can add another rule.
l Save—Click this button to save the rule and close the dialog box.

l Sort—You can sort the table by clicking on any column heading.


l Table row overflow menu—In the overflow menu on the right of a table row, you can select the
following actions.
l Edit rule—Click this option to edit the rule. Use the same guidelines as outlined above
when adding a rule. Click Save to save the changes.
l Delete rule—Click this option to delete the rule. Confirm the deletion by clicking Delete
rule.

Chapter 5 Policies 30
Default exclusions
Some files and folders (including files without an extension) are excluded, by default, from backups.
l Windows—The following apply to all Windows devices.
l Any file or folder with the system, device, temporary, or offline attribute applied to it are

excluded.
l Any file or folder that starts with ~ and has the hidden attribute is excluded. Both criteria

must be met to be excluded. If only one criteria is met, the file or folder will be included if it
meets a backup rule.
l Any folder with the reparse point attribute is excluded.

l MacOS—For all MacOS devices, any file or folder with the following DirectoryEntry (as
determined by the readdir_r system method) is excluded.
l DT_BLK—block device

l DT_CHR—character device

l DT_FIFO—named pipe (FIFO)

l DT_LNK—symbolic link

l DT_SOCK—UNIX domain socket

l DT_UNKNOWN—unknown file type

l File extensions—The following file extensions are excluded.


l DT_Store

l gfs

l hiberfil*.sys

l log

l log*

l ost

l pagefile*.sys

l thumbs*.db

l tmp

l db-wal

l db-shm

l db-journal

l sqlite-wal

l sqlite-shm

l sqlitedb-wal

l sqlitedb-shm

l sqlite3-wal

l sqlite3-shm

l Files without an extension—Files without an extension are excluded unless it is in a folder


included in an All Files backup rule. Other categories are looking at specific file extensions, so
files without an extension will be excluded from those rules.
l Temp, cache, and runtime data folders—Folders that contain temp or cache files or runtime

Chapter 5 Policies 31
data are excluded. This list depends on the applications you are running. For example, on
Windows, this might include folders located in %Users%\*\AppData\Local, such as folders under
%Users%\*\AppData\Local\Google\Chrome\User Data\Default or
%Users%\*\AppData\Local\Mozilla\Firefox\Profiles. On MacOS, this might include folders located
in /users/*/Library, such as folders under /users/*/Library/Application
Support/Google/Chrome/Default or /users/*/Library/Application Support/Slack.
If you need to back up a folder in one of these locations, for example for browser bookmarks, you
need to create an include rule for the specific folder.
l Files and folders using reserved characters—Files and folders containing reserved
operating system characters may appear to be protected, but they cannot be restored. Do not use
any of the following reserved operating system characters in any files or folders.
l less than <
l greater than >
l colon :
l quotation marks or double quote "
l forward slash /
l backslash \
l vertical bar or pipe |
l question mark ?
l asterisk *

Chapter 5 Policies 32
Policy inheritance
By default, a policy is set at the company level and users, groups, and devices in that company inherit the
policy assigned to the company. If desired, you can set a policy at the user, group, or device level as well.
Policies set at those lower levels will override the inheritance from higher levels.
Once you have policies defined, you can set them at a specific level.
l Set the policy for a company on page 34—Setting a policy for a company establishes inheritance.
All groups, users, and device assigned to the company use the company policy by default.
l Set the policy for a group on page 35—By default, a group's policy is set to inherit from the
company the group is assigned to. If desired, you can override the inheritance and set a policy so
that all users and devices assigned to the group use the policy assigned to the group.
l Set the policy for a user on page 36—By default, a user's policy is set to inherit from the company
the user is assigned to. If desired, you can override the inheritance and set a policy so that all
devices assigned to that user use the policy assigned to the user.
l Set the policy for a device on page 37—By default, a device's policy is set to inherit from the
company the device is assigned to. If desired, you can override the inheritance and set a policy so
that the device uses its own policy.

Chapter 5 Policies 33
Set the policy for a company
Setting a policy for a company establishes inheritance. All groups, users, and device assigned to the
company use the company policy by default.
1. Go to the Company page and then the Company details tab.
2. Click Edit company.
3. Change the Default policy set to the policy you want to use for the company.

4. Click Save changes.

Chapter 5 Policies 34
Set the policy for a group
By default, a group's policy is set to inherit from the company the group is assigned to. If desired, you can
override the inheritance and set a policy so that all users and devices assigned to the group use the
policy assigned to the group.
1. Go to the Company page and then the Groups tab.
2. On the Groups tab, locate in the table the group you want to set the policy for. See Groups on
page 60 for details on searching the table.
3. Once you have located the group you want to set the policy for, click on the group's name.
4. Click Edit group.
5. Change the Default policy set to the policy you want to use for the group, or if you want to go
back to an inherited policy, select Inherit policy from.

6. Click Save changes.

Chapter 5 Policies 35
Set the policy for a user
By default, a user's policy is set to inherit from the company the user is assigned to. If desired, you can
override the inheritance and set a policy so that all devices assigned to that user use the policy assigned
to the user.
1. On the Users page, locate in the table the user you want to set the policy for. See View available
users on page 68 for details on searching the table.
2. Once you have located the user you want to set the policy for, click on the user's name.
3. On the User page, on the User details tab, click Edit user details.
4. Change the Default policy set to the policy you want to use for the user, or if you want to go back
to an inherited policy, select Inherit policy from.

5. Click Save changes.

Chapter 5 Policies 36
Set the policy for a device
By default, a device's policy is set to inherit from the company the device is assigned to. If desired, you
can override the inheritance and set a policy so that the device uses its own policy.
1. On the Devices page, locate in the table the device you want to set the policy for. See Devices on
page 98 for details on searching the table.
2. Once you have located the device you want to set the policy for, click on the device's name.
3. On the Device page, on the Device details tab, click Edit device.
4. Change the Select default policy set to the policy you want to use for the device, or if you want
to go back to an inherited policy, select Inherit policy from.

5. Click Save changes.

Chapter 5 Policies 37
Chapter 6 Deployment
Deployment is the process of getting an activation code and installing the end-user software on the
endpoint devices. In some cases, the deployment process also includes adding a user account.
l Activation codes—The activation code option you select depends on what you want to happen
when the client software is installed.
l Add devices and add user accounts—If you want to add both a device and user in
Carbonite Endpoint when the client software is installed and activated, you will want to use
the Enable full directory integration option. (If the user already exists, only the device
will be added.) This method requires the user to log in on the device when connected to the
corporate network to capture the user information, and it requires a valid email address for
the user in LDAP for the mail attribute.
l Add devices for existing, individual user accounts—If you want to add a device in

Carbonite Endpoint for a user account that already exists, you will want to use the Enable
directory user integration option. This method requires you to add individual user
accounts in Carbonite Endpoint before the client software is installed.
l Add devices for existing, single user account—If you want to add a device in

Carbonite Endpoint for a single user account that already exists, you will want to use the
Enable directory device integration option. This method requires you to add a single
user account in Carbonite Endpoint before the client software is installed. All devices will be
associated with this single user account.
l Do not add devices—If you do not want to add any devices in Carbonite Endpoint when

the client software is installed, do not select any option (or use the Disable automatic
creation option if you selected another option and want to go back to no selection). This
method requires you to add individual user accounts and devices in Carbonite Endpoint
before the client software is installed.
l Installation—You have choices in the type of installation you perform.
l Remote deployment—With this strategy, you can push the end-user client software to
each device.
l Local installation—With this strategy, the software is installed manually on each device.

Regardless of the method you choose, you should initially work with a small subset of devices
until you are confident your deployment strategy is working. Once you are sure, you can
implement the strategy for larger numbers of devices.

See Activation codes on page 39 and Installation on page 46 for details.

You can also use WCF or REST APIs to add users, assign devices, trigger email notifications,
and so on. Documentation of these APIs is not included here. Contact your Professional
Services representative if you want to use an API to automate any deployment tasks.

Chapter 6 Deployment 38
Activation codes
The activation code option you select depends on what you want to happen when the client software is
installed.
l Add devices and add user accounts—If you want to add both a device and user in Carbonite
Endpoint when the client software is installed and activated, you will want to use the Enable full
directory integration option. (If the user already exists, only the device will be added.) This
method requires the user to log in on the device when connected to the corporate network to
capture the user information, and it requires a valid email address for the user in LDAP for the mail
attribute.
l Add devices for existing, individual user accounts—If you want to add a device in Carbonite
Endpoint for a user account that already exists, you will want to use the Enable directory user
integration option. This method requires you to add individual user accounts in Carbonite
Endpoint before the client software is installed.
l Add devices for existing, single user account—If you want to add a device in Carbonite
Endpoint for a single user account that already exists, you will want to use the Enable directory
device integration option. This method requires you to add a single user account in Carbonite
Endpoint before the client software is installed. All devices will be associated with this single user
account.
l Do not add devices—If you do not want to add any devices in Carbonite Endpoint when the
client software is installed, do not select any option (or use the Disable automatic creation
option if you selected another option and want to go back to no selection). This method requires
you to add individual user accounts and devices in Carbonite Endpoint before the client software
is installed.

Regardless of the method you choose, you should initially work with a small subset of devices
until you are confident your deployment strategy is working. Once you are sure, you can
implement the strategy for larger numbers of devices.

See the following sections for activation code details.


l View available activation codes on page 40
l Add an activation code on page 42
l Edit an activation code on page 44
l Delete an activation code on page 45

Chapter 6 Deployment 39
View available activation codes
To view your available activation codes, go to the Company page and then the Deployment
(AD/LDAP) tab.

The following controls are available on the Deployment (AD/LDAP) tab.


l Add activation code-Click this button to add a new activation code. See Add an activation code
on page 42 for details.
l Installation download buttons—You may or may not see these buttons, depending on your
vault configuration.
l MSI—If this button is available, click it to download a Windows Msiexec file.

l EXE—If this button is available, click it to download a Windows executable file.

l PKG—If this button is available, click it to download a MacOS package file.

See Installation on page 46 for choices and details on remote deployment and local
installation using .msi, .exe., and .pkg files.

l Show Entries—Specify the number of rows to be shown in the table on each page. Additional
rows over the number you select are shown on additional pages and can be viewed by using the
paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—Click an activation code to manage that activation code. From the
Activation code details page, you can do any of the following.

Chapter 6 Deployment 40
l View the details of the activation code—You can view the code and its details.
l Delete activation code—If you no longer need the activation code, click the Delete

activation code button to delete the code. Click Yes on the confirmation box.
l Edit details—You can modify the type of activation code or its settings. See Edit an

activation code on page 44 for details.


l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 6 Deployment 41
Add an activation code
When you install Carbonite Endpoint, regardless of the installation method you select, you need an
activation code.
1. Go to the Company page and then the Deployment (AD/LDAP) tab.
2. Click Add activation code.
3. Determine what type of activation code you want to add based on what you want to happen when
the client software is installed.

l Add devices and add user accounts—If you want to add both a device and user in
Carbonite Endpoint when the client software is installed and activated, you will want to use
the Enable full directory integration option. (If the user already exists, only the device
will be added.) This method requires the user to log in on the device when connected to the
corporate network to capture the user information, and it requires a valid email address for
the user in LDAP for the mail attribute.
l Add devices for existing, individual user accounts—If you want to add a device in
Carbonite Endpoint for a user account that already exists, you will want to use the Enable
directory user integration option. This method requires you to add individual user
accounts in Carbonite Endpoint before the client software is installed.
l Add devices for existing, single user account—If you want to add a device in
Carbonite Endpoint for a single user account that already exists, you will want to use the
Enable directory device integration option. This method requires you to add a single
user account in Carbonite Endpoint before the client software is installed. All devices will be
associated with this single user account.
l Do not add devices—If you do not want to add any devices in Carbonite Endpoint when
the client software is installed, do not select any option (or use the Disable automatic
creation option if you selected another option and want to go back to no selection). This
method requires you to add individual user accounts and devices in Carbonite Endpoint
before the client software is installed.

Chapter 6 Deployment 42
4. Select your activation code type.
l Enable full director integration—Click this button to add an activation code to add

device and add user accounts. Select the User group you want the activation code to
apply to. If desired, select Enable web retrieval, which allows users to log into the
dashboard and access their files online. This allows them to download individual files from
their browser. Click Save changes.
l Enable directory user integration—Click this button to add an activation code to add

devices for existing, individual user accounts. No additional options are needed.
l Enable directory device integration—Click this button to add an activation code to add

devices for an existing, single user account. Select the user account you want the activation
code to be associated with. Then click Select user.
l Disable automatic creation—Click this button if you have selected one of the other

activation code types but want to go back to the option to not add any devices. No additional
options are needed.
5. Once your activation code type has been selected, click Add activation code.
6. You will be taken to the Activation code details section automatically. The activation code that
is listed is the activation code you will use in the installation.

Chapter 6 Deployment 43
Edit an activation code
Use these instructions to edit an existing activation code. The changes will impact new devices
attempting to activate. There will be no changes for existing devices.
1. Go to the Company page and then the Deployment (AD/LDAP) tab.
2. On the Deployment (AD/LDAP) tab, locate in the table the activation code you want to edit.
See View available activation codes on page 40 for details on searching the table.
3. Once you have located the activation code you want to edit, click on the activation code.
4. On the Edit activation code page, you can change the user or user creation settings,
depending on your activation code type. You can also change activation codes types, if
desired. See Add an activation code on page 42 for details on each of the activation types.

5. Click Save changes.

Chapter 6 Deployment 44
Delete an activation code
If you no longer need an activation code, you can delete it. This will have no impact on devices already
using the code. It only prohibits new devices from using it.
1. Go to the Company page and then the Deployment (AD/LDAP) tab.
2. On the Deployment (AD/LDAP) tab, locate in the table the activation code you want to
delete. See View available activation codes on page 40 for details on searching the table.
3. Once you have located the activation code you want to delete, click on the activation code.
4. On the Activation code details page, click Delete activation code.

5. Click Yes on the confirmation box.

Chapter 6 Deployment 45
Installation
You have choices in the type of installation you perform.
l Remote deployment—With this strategy, you can push the end-user client software to each
device.
l Local installation—With this strategy, the software is installed manually on each device.

Regardless of the method you choose, you should initially work with a small subset of devices
until you are confident your deployment strategy is working. Once you are sure, you can
implement the strategy for larger numbers of devices.

See the following sections for installation details.


l Install on Windows or MacOS using the installation wizard on page 47
l Install on Windows using Msiexec on page 50
l Install on MacOS using the installer app on page 54

Chapter 6 Deployment 46
Install on Windows or MacOS using the installation wizard
These instructions to install Carbonite Endpoint follow the Windows interactive installation wizard. At a
high-level, the same process is used on MacOS devices, except for a few differences outlined below and
a different style interface, such as Next buttons being labeled as Continue on MacOS devices.
1. Launch the installation file.
2. At the Welcome page, click Next to continue.
3. Review the Terms of Service. You must accept the terms in order to continue with the
installation program. Click Next to continue.
4. On Windows, modify the installation location, if desired. This option is not available on MacOS
devices. Carbonite Endpoint will be installed on Macintosh HD.
5. Click Next to continue.
6. On Windows, select an internal, local disk that will be used for the local data cache. The drive you
select should have at least 1 GB free space. This option is not available for MacOS devices. The
local data cache will be installed on Macintosh HD.

7. Click Next to continue.


8. If desired, deselect the options for the desktop shortcut and running the client after the installation.
These option are not shown on MacOS devices and will automatically be enabled.

Chapter 6 Deployment 47
9. When you are ready to begin the installation, click Install.
10. When the installation is completed, click Finish.
11. In the Thank you window that opens after the installation is complete, enter your activation
information.

Chapter 6 Deployment 48
l Activation Server URL—This is the URL where files will be backed up.
l Activation Code—This is the activation code for the device.

12. If you need to specify a proxy server for Internet access, click Proxy settings and complete the
proxy information.
13. Click Next to continue.
14. If you are reactivating a previously used device, you will be prompted to enter a Passphrase.
Enter it and then click Next to continue. You will not see this page if you are not reactivating.
15. Once the activation is complete and the account is activated, click Close.

Chapter 6 Deployment 49
Install on Windows using Msiexec
Msiexec is a Windows command-line based program that interprets and installs software installation
packages. You can use Misexec to install Carbonite Endpoint on any version of Windows 7 through
Windows 10, except RT, Itanium, and Home versions. In most cases, you will use this method of
installation when you are pushing the software using a remote deployment tool.
The following is the syntax for using Msiexec with Carbonite Endpoint.
msiexec /i PackageLocationAndName /qn PublicProperty1=Value
PublicProperty2=Value ... PublicPropertyN=Value
The following tables explains the parameters used with the command.

Parameter Description

Identifies the location and name of the .msi installation


/i PackageLocationAndName
package
/qn Installs silently, hiding the installation user interface

Chapter 6 Deployment 50
PublicProperty1=Value One or more of the following arguments used when installing
the Carbonite Endpoint package. Do not use a slash / before
PublicProperty2=Value any of these parameters.
. l ActivationCode—If you have generated a
. deployment activation code ahead of time, use this
. option to enter the code. If you do not use this option or
PublicPropertyN=Value this option is blank, the user will have to provide an
activation code before being able to use Carbonite
Endpoint. The default value is blank.
l ActivationUrl—This option is the URL of the vault. If
you do not use this option or this option is blank, the
user will have to provide a URL before being able to
use Carbonite Endpoint. The default value is blank.
l CompanyId—Use this option as an alternative to
ActivationCode when you are using directory user
integration (adding devices for existing, individual user
accounts). This is not a commonly used option, and you
may be directed to Professional Services for assistance
with this option. The default value is blank.
l Drive—This option specifies an internal, local disk that
will be used for the local data cache. If you do not use
this option, the default value is C:\.
l InstallDesktopShortcut—This option indicates if a
Carbonite Endpoint shortcut will appear on the
desktop, letting you decide if Carbonite Endpoint is
visible to users. If you do not use this option, the default
value is 1.
l 0—A shortcut will not appear on the desktop.

l 1—A shortcut will appear on the desktop.

l PassphraseRequired—This option indicates if the


end-user must enter a passphrase to decrypt the
device key if the machine has been reset. If you do not
use this option, no passphrase is needed.
l 0—The user does not need to enter a

passphrase.
l 1—The user needs to enter a passphrase.

l RunServiceAsLocalSystem—This option indicates


what account will be used to run Carbonite Endpoint. If
you do not use this option, the default value is 1.
l 0—The new DCProtectService admin user will

be used to run Carbonite Endpoint.


l 1—The Local System account will be used to run

Carbonite Endpoint.
l Silent—This option indicates if the interactive
activation workflow appears after the installation. If you

Chapter 6 Deployment 51
do not use this option, the default value is 0.
l 0—The silent workflow is not enabled, so the

activation workflow will appear after the


installation.
l 1—The silent workflow is enabled, so the

activation workflow will not appear after the


installation.
l StartClientPostActivate—This option indicates if the
client will be started after the activation. If you do not
use this option, the default value is 1.
l 0—The client will not start after activation.

l 1—The client will start after activation.

Use the following examples as a guideline, and modify them as needed for your environment and needs.
l Unattended installation, unattended activation, client software available to users—In
this example, the client software is deployed and activated without any interaction from the end-
user. The end-user can access the software.
msiexec /i "C:/temp/[Link]" /qn ActivationCode=1ab2-cdef-
3g45-h67i-j890 ActivationUrl=[Link] Silent=1
l Unattended installation, unattended activation, client software hidden from users—This
example is like the previous one, however, the end-user cannot access the software from a
desktop shortcut.
msiexec /i "C:/temp/[Link]" /qn ActivationCode=1ab2-cdef-
3g45-h67i-j890 ActivationUrl=[Link] Silent=1
InstallDesktopShortcut=0

Chapter 6 Deployment 52
Install on Windows using group policy
Group policy can be used a software deployment tool with the .msi installer, however it does not support
command-line arguments. You have a few alternatives.
l Edit .msi—You can edit the .msi using the Carbonite Endpoint MSI editor or another MSI editor.
This method will break the MSI signature, so any future updates must also be installed using this
method.
l Transform file—You can use a generic editor to create an MSI transform file. This method will
not break the MSI signature, so future updates can be performed using another method if desired.
l Script—Create a script that runs Msiexec and run that script using the group policy. This method
will avoid editing the .msi or creating a transform file. You could also perform a check at the
beginning of the script to make sure the installer is not downloaded every time the device is
rebooted. The example script below would determine if Carbonite Endpoint is installed. If it is, the
script exits. If it is not, the software would be installed.

IF EXIST
“c:\dcprotectdata\service\[Link]” (
ECHO “Carbonite Endpoint already installed”
EXIT
) ELSE (
Net use x: \\update_server\software
msiexec /i x:\[Link] /qn ActivationCode=1ab2-cdef-3g45-h67i-j890
ActivationUrl=[Link] Silent=1
)

For details on using group policies, see your Windows documentation.

Chapter 6 Deployment 53
Install on MacOS using the installer app
You can install Carbonite Endpoint on MacOS using installer and a [Link] file.
1. Create a file called [Link] in the root Library folder (/Library). The file name is case-
sensitive.

MacOS 10.15 (Catalina) requires the [Link] file to be located in the root
/Library folder. However, any previously supported version of MacOS will work with the
[Link] file in the root folder. To work with all versions, using /Library. If you
have any existing scripts that had the [Link] file in the root rather than
/Library, you need to update your scripts to /Library if you will be installing on MacOS
10.15.

Once Carbonite Endpoint is activated, the [Link] file will automatically be


moved to the DCProtect folder.

2. Edit the [Link] file.


3. Add the opening <AutoConfig> and closing </AutoConfig> tags.

<AutoConfig>
</AutoConfig>

4. Specify one or more of the properties listed in the following table by specifying them between
opening and closing tags. Make sure the property tags are between the <AutoConfig> tags. See
the examples after the table.

Parameter Description

If you have generated a deployment activation code


ahead of time, use this option to enter the code. If you
do not use this option or this option is blank, the user
ActivationCode
will have to provide an activation code before being
able to use Carbonite Endpoint. The default value is
blank.

ActivationUrl This option is the URL of the vault. If you do not use this
option or this option is blank, the user will have to
provide a URL before being able to use Carbonite
Endpoint. The default value is blank.
Use this option as an alternative to ActivationCode
when you are using directory user integration (adding
devices for existing, individual user accounts). This is
CompanyId
not a commonly used option, and you may be directed
to Professional Services for assistance with this option.
The default value is blank.

Chapter 6 Deployment 54
This option indicates if a Carbonite Endpoint shortcut
will appear on the desktop, letting you decide if
Carbonite Endpoint is visible to users. If you do not use
InstallDesktopShortcut this option, the default value is 1.
l 0—A shortcut will not appear on the desktop.
l 1—A shortcut will appear on the desktop
This option indicates if the end-user must enter a
passphrase to decrypt the device key if the machine
has been reset. If you do not use this option, no
PassphraseRequired passphrase is needed.
l 0—The user does not need to enter a
passphrase.
l 1—The user needs to enter a passphrase.

ProxyAutoDetect If you need to use a proxy server, use this option to


specify if the proxy server specified in
System Preferences should be used. The default value
is no proxy server.
l 0—Use the proxy server specified in System
Preferences
l 1—Do not use the proxy server specified in
System Preferences

ProxyScript This option is the path and file name to the proxy script.

ProxyServer This option is the proxy server IP address and port


number. For example, you might use
[Link]
This option indicates if the interactive activation
workflow appears after the installation. If you do not
use this option, the default value is 0.
l 0—The silent workflow is not enabled, so the
Silent activation workflow will appear after the
installation.
l 1—The silent workflow is enabled, so the
activation workflow will not appear after the
installation.
This option indicates if the client will be started after the
activation. If you do not use this option, the default
StartClientPostActivate value is 1.
l 0—The client will not start after activation.
l 1—The client will start after activation.

Chapter 6 Deployment 55
Examples for [Link]

l Unattended installation, unattended activation, client software available to


users—In this example, the client software is deployed and activated without any
interaction from the end-user. The end-user can access the software.

<AutoConfig>
<ActivationCode>1ab2-cdef-3g45-h67i-j890</ActivationCode>
<ActivationUrl>[Link]
<Silent>1</Silent>
</AutoConfig>

l Unattended installation, unattended activation, client software hidden from


users—This example is like the previous one, however, the end-user cannot access the
software from a desktop shortcut.

<AutoConfig>
<ActivationCode>1ab2-cdef-3g45-h67i-j890</ActivationCode>
<ActivationUrl>[Link]
<Silent>1</Silent>
<InstallDesktopShortcut>0</InstallDesktopShortcut>
</AutoConfig>

5. Save the changes to the [Link] file.


6. Run the installer using the following command.
sudo installer -pkg /path/to/[Link] -target /
Substitute the path and file name for the [Link] for /path/to/[Link]. For
example, you might use sudo installer -pkg /[Link] -target /.

Chapter 6 Deployment 56
Activate on MacOS
If you disabled activation (RunActivatePostInstall is 0), then you can activate later. The following is the
syntax for activating.
/Library/ApplicationSupport/DCProtect/[Link]/Contents
/MacOS/DCProtect -autoactivation -argument1=Value -
argument2=Value ... -argumentN=Value
You must use the -email argument. The other arguments are optional

Argument Description

-email This argument is required.


It is the email address that the device will be assigned to. You
must specify this option. If you do not have an easy method of
getting this address, you may want to fetch the user’s USER
variable and prepend the variable as part of the email
address. Even though this may not be the user’s actual email
address, it allows the user to be identifiable by a login ID.
If you have generated a deployment activation code ahead of
time, use this option to enter the code. If you do not specify
this option or this option is blank, the user will have to provide
-activationCode an activation code before being able to use Carbonite
Endpoint. The default value is blank.
You do not need to use this option if you specified it in the
[Link].
This option is the URL of the vault. If you do not specify this
option or this option is blank, the user will have to provide a
URL before being able to use Carbonite Endpoint. The
-activationUrl default value is blank.
You do not need to use this option if you specified it in the
[Link].

-deviceName This option is the name of the device to be activated. If you do


not specify this option, the value from the hostname utility will
be used.

-displayName This is the first and last name assigned to the user using the
device. If you do not specify this option, the -firstName and -
lastName fields will be used.

-firstName This is the first name assigned to the user using the device. If
you do not specify this option, the local-part of the email
address (the text before @) will be used.

Chapter 6 Deployment 57
-lastName This is the last name assigned to the user using the device. If
you do not specify this option, the last name will be blank.

-timeoutMs This is the amount of time to wait. If you do not specify this
option, 120,000 will be used.

-timezoneId This is the time zone assigned to the device. If you do not
specify this option, the time zone of the device at installation
time will be used.

-verbose This option provides additional output details while running


the activation.

Use the following examples as a guideline, and modify them as needed for your environment and needs.
l Activate with code, URL, and email address—In this example, the software is activated using
an activation code, activation URL, and an email address.
/Library/ApplicationSupport/DCProtect/[Link]/Contents/MacOS/
DCProtect -autoactivation -activationCode=1ab2-cdef-3g45-h67i-j890
-activationUrl=[Link] -email=name@[Link]
l Activate with code, URL, and email address created from USER variable—In this
example, the software is activated using an activation code, activation URL, and an email address
created from the USER environment variable.
/Library/ApplicationSupport/DCProtect/[Link]/Contents/MacOS/
DCProtect -autoactivation -activationCode=1ab2-cdef-3g45-h67i-j890
-activationUrl=[Link] -
email=$USER@[Link]
l Activate with code, URL, email address created from USER variable, and display name
created from login name—In this example, the software is activated using an activation code,
activation URL, an email address created from the USER environment variable, and a display
name created from the login name.
FULLNAME="$ (id -F)"
/Library/ApplicationSupport/DCProtect/[Link]/Contents/MacOS/
DCProtect -autoactivation -activationCode=1ab2-cdef-3g45-h67i-j890
-activationUrl=[Link] -
email=$USER@[Link] -displayName="$FULLNAME"

Once you have activated the software, you can determine the activation status by using the -
getClientStatus argument with DTProtect.
/Library/ApplicationSupport/DCProtect/[Link]/Contents
/MacOS/DCProtect -getClientStatus
You will get one of the following return codes.

Chapter 6 Deployment 58
Return Code Status

-2 Timed out
-1 Unknown
0 Created but not activated
1 Activated
2 Reset
3 DataDelete
4 Suspended
5 PersistentAuthFailure
6 Canceled

You can optionally add -verbose to return additional status information.

Chapter 6 Deployment 59
Chapter 7 Groups
Groups provided a way to associate multiple users. This provides the ability to perform tasks for the
users in a group. For example, you can define a policy for a group and all users in the group will use that
policy.
The following tasks are available for groups.
l View available groups on page 61
l Add a group on page 62
l View group details on page 63
l Edit an existing group on page 65
l Delete a group on page 66

You may not have access to groups if your partner has disabled this feature.

Chapter 7 Groups 60
View available groups
To view your available groups, go to the Company page and then the Groups tab.

The following controls are available on the Groups tab.


l Add group—Click this button to add a new group. See Add a group on page 62 for details.
l Show Entries—Specify the number of rows to be shown in the table on each page. Additional
rows over the number you select are shown on additional pages and can be viewed by using the
paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Table hyperlinks—Click a group name to see details for that group. See View group details on
page 63 for details.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 7 Groups 61
Add a group
Use the following instructions to add a group.
1. Go to the Company page and then the Groups tab.
2. Click Add group.
3. Specify the group information.

User group—Specify a unique name for the group.


l

l Custom—If desired, enter any custom information in the three provided fields. These fields

allow you to use your own internal information. This field is limited to 500 characters.
4. When the group definition is complete, click Add group.

Chapter 7 Groups 62
View group details
Use the following instructions to view the details and properties of a group.
1. Go to the Company page and then the Groups tab.
2. Locate in the table the group that you want to view. See View available groups on page 61 for
details on searching the table.
3. Once you have located the group you want to view, click on the group name.
4. In the Group properties section, you can view and manage the group properties.

l Delete user group—Click this button to delete the group. Everything under the group
(users, devices, and backed up data) will be deleted. You must confirm that you want to
delete the group and then click OK.
l Edit group—Click this button to edit the group. See Edit an existing group on page 65 for

details.
l Table hyperlinks—There are hyperlinks in the table that will take you directly to a page in

the dashboard.
l Company—This hyperlink will take you to the Company page. See Company on

page 12.
l Default policy set—This hyperlink will take you to the policy details for the policy the

group is using. See Edit an existing policy on page 17 for details.


5. In the Users in group section, you can see and add users to the group.

Chapter 7 Groups 63
l Add user—Click this button to add a new user to this group. See Add a single user on
page 71 for details. (If you need to move an existing user into this group, edit the user. See
View user details on page 76 for details.)
l Show Entries—This table is limited to 100 rows. Specify the number of rows to be shown
in the table on each page. Additional rows over the number you select are shown on
additional pages and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—Click an email address to see details for that user. See View user
details on page 76 for details.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

Chapter 7 Groups 64
Edit an existing group
Use the following instructions to edit an existing group.
1. Go to the Company page and then the Groups tab.
2. Locate in the table the group that you want to edit. See View available groups on page 61 for
details on searching the table.
3. Once you have located the group you want to edit, click on the group name.
4. In the Group properties section, click Edit group.

5. Edit the group settings as desired. In addition to the settings available when you added the group,
(see Add a group on page 62 for details), you can also set the default policy for the group. By
default, a group's policy is set to inherit from the company the group is assigned to. If desired, you
can override the inheritance and set a policy so that all users and devices assigned to the group
use the policy assigned to the group.
6. After you have modified the group settings, click Save changes.

Chapter 7 Groups 65
Delete a group
Use the following instructions to delete a group. Everything under the group (users, devices, and backed
up data) will be deleted.
1. Go to Company page and then the Groups tab.
2. Locate in the table the group that you want to delete. See View available groups on page 61 for
details on searching the table.
3. Once you have located the group you want to delete, click on the group name.
4. In the Group Properties section, click Delete user group.

5. Confirm that you want to delete the group and click OK.

Chapter 7 Groups 66
Chapter 8 Users
In order to protect an endpoint device, a user must be associated with the device. You can think of a user
as an organizational tool for devices. You need to decide what organizational user account strategy you
want to implement.
l Multiple user accounts—With this strategy, you will add multiple user accounts, and each
account will have one or more devices associated with that particular user. Use this strategy when
devices are used by only one person.
l Single user account—With this strategy, you add a single user account, and many devices are
assigned to that account. Use this strategy when devices are shared by many people.
You can implement a combination strategy to meet the needs of individually used devices and shared
devices. You have multiple methods for adding user accounts from manual entry to bulk uploads to
automation using LDAP. In some cases, you can add the user at the same time you are deploying the
end-user software on the devices.

Think about the following key questions and situations when determining how you want to add user
accounts.
l How many user accounts do you need to add? If you have only a few user accounts to add, it may
be quicker and easier to add them manually. If you have many accounts to add, you may want to
use a bulk upload or automated method.
l Do you need to add groups of users? Grouping user accounts allows you to assign policies to
groups to meet your requirements. If you are going to use groups, you may want to start with
group creation before you add users. See Groups on page 60 for details.
l Have you considered how you are going to deploy the software to the endpoint devices?
Deployment strategies can impact the user account creation strategy. For example, if you use
LDAP, users can automatically be added in Carbonite Endpoint. See Deployment on page 38 and
Manage users with LDAP on page 85 for details.

The following tasks are available for users.


l View available users on page 68
l Add users on page 70
l View user details on page 76
l Edit user settings on page 77
l View devices for a user on page 78
l Manage user permissions on page 79
l Reset a user password on page 83
l Delete a user on page 84
If you want to manage users using Lightweight Directory Access Protocol (LDAP), see Manage users
with LDAP on page 85. If you want to automate user creation, see Deployment on page 38.

Chapter 8 Users 67
View available users
To view your available users, go to the Users page, where you will find high-level information for your
users.

You have the following toolbar and table controls available on the Users page.
l Add user-Click this button to add a single, new user. See Add a single user on page 71 for
details.
l Download list—Click this button to download a complete user list to your local computer. You
can select to download a Microsoft Excel (.xlsx) file or a comma-delimited file (.csv). If you
download the Excel format, you must enable editing for any hyperlinks to the portal to be active.
l Show Entries—Specify the number of rows to be shown in the table on each page. Additional
rows over the number you select are shown on additional pages and can be viewed by using the
paging buttons at the bottom of the table.

This table is limited to 100 rows. If you need to see a list of all entries, use Download list.

l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—There are hyperlinks in the table that will take you directly to a page in the
dashboard.
l First name, Last name, and Email—Each of these hyperlinks will take you to the User

details tab on the User page. See View user details on page 76 for details.

Chapter 8 Users 68
l Number of devices—This hyperlink will take you to the Devices page for that user. See
View device details on page 107 for details.
l Company—This hyperlink will take you to the Company page. See Company on page 12

for details.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 8 Users 69
Add users
You can manually add individual user accounts or you can import names to bulk add user accounts.
l Add a single user on page 71—You can manually add a single user. Use this method when you
only have a few users to add.
l Import multiple users on page 74—You can bulk import multiple users. Use this method when you
have many users to add, but you are not using an automated method.
If you want to manage users using Lightweight Directory Access Protocol (LDAP), see Manage users
with LDAP on page 85. If you want to automate user creation, see Deployment on page 38.

Chapter 8 Users 70
Add a single user
Use the following instructions to add a single, new user.
1. Click Add user from the Company or Users page.
2. On the User page, in the Add user section, define the details for the new user.

l Email—Enter a valid email address for the user.


l First name—Enter the user's first name.

l Last name—Enter the user's last name.

l Custom—If desired, enter any custom information in the three provided fields. These fields

allow you to use your own internal information. This field is limited to 500 characters.
l Company—This field is display only and shows the company the user will be assigned to.

l User group—Select the group the user should be a member of.

l Time zone—Select the time zone the user is located in. This is the time zone the user will

see in the dashboard. All times, like last backup or restore times, will use the logged in
user's time zone.
3. In the Permissions section, define the settings for the new user.

Chapter 8 Users 71
l Login to Dashboard—Enable this option if you want to grant the user the ability to log in
to the portal. Without this permission, the user cannot log in to the portal.
l Send New User Email—If you are granting the user access to the portal, enable this
option to send a welcome email to the specified email address after the user is added. The
email will contain a login link for the user.
l Login to Access—Enable this option if you want to grant the user the ability to log in to the
web retrieval page of the portal. It is referred to as the Access page because the URL is
the portal URL /access. For example, if you are using [Link]
[Link], a user would access the web retrieval page by going to
[Link] This web retrieval page allows users to
download their own data without using their device. Without this permission, users can only
restore data from their own device, if they have access to the end-user client software on
their device. (An administrator can still restore data from the portal, regardless of this
setting.)
l Personal permission—These permissions determine if and how users can access their
data and devices. The permissions available and what those permissions grant access to
depend on the logins you have enabled for the user.

If only Login to If both Login to


If only Login to
Dashboard is Dashboard and Login
Access is enabled
enabled to Access are enabled
l Full access to the
l Full access to
user's data and
the user's data
devices in the
and devices in
portal
Administrator the portal Not applicable
l Full access to the
l No access to
user's data
the web
through the web
retrieval page
retrieval page
l Read-only l Read-only
access to the access to the
user's data and user's data and
devices in the devices in the
Read Only portal Not applicable portal
l No access to l No access to
the web web retrieval
retrieval page page
l No access to
l No access to the
the portal
portal
Retrieve l Full access to
Not applicable l Full access to the
Only the user's data
user's data
through the
through the web
web retrieval
retrieval page
page

Chapter 8 Users 72
If neither login is enabled, the user will not have access to the portal or to the web retrieval
page.
l Company permission—These permissions determine what access the user has to the
company, including policies and other users and devices.
l Administrator—This permission provides full access to all of the portal. You should
limit this role to as few people as possible because each user who has this access
has full control over everything.
l Backup Administrator—This permission provides full access to all users and
devices, but only partial access to other areas of the portal. This role might be
appropriate for a service desk team member who can assist other users with
retrieving data.
l Legal Administrator—This permission provides full access to legal holds and
admin restores, but read-only access to other areas of the portal. This role is
appropriate for those responsible for retrieving data that is on legal hold.
l Support—This permission provides the ability to reset devices. Read-only access is
granted to the rest of the portal.
l Read Only—This permissions provides read-only access to all parts of the portal,
except legal holds.
l None—This permission hides company level information from a user that has
access to log in to the portal.

Backup Legal
Administrator Support Read Only
Administrator Administrator

No add, edit, or
Company Full access Read only Read only Read only
delete

Read only plus


Users Full access Full access Read only Read only
password resets

Read only plus


Read only plus
Devices Full access Full access reset device and Read only
admin restore
admin restore

Legal Hold Full access No access Full access No access No access

Full access except


QuickCache Full access No access Read only Read only
cannot delete

Reports Full access Full access Read only Read only Read only

To view this comparison table within the console, click Compare Roles. From
there, you can click More details to see detailed tables of permissions.

4. When the user definition is complete, click Add user.

Chapter 8 Users 73
Import multiple users
Use the following instructions to import multiple, new users.
1. Go to the Company page and then the Company details tab.
2. Click Import users.
3. If you have not already done so, prepare your import file.
a. Download the template which is used for the import user process by clicking Download
template.
b. Save and open the Excel (.xlsx) file.
c. Enable editing of the file.
d. For each user you want to add, enter the user's information in one row of the spreadsheet
in the First Name, Last Name, and Email columns. Do not enter any data in the remaining
pre-defined columns, and do not modify the Row ID entries.
e. You can optionally create additional columns for additional, optional information. You can
skip this step if you only want to enter the name and email for each user.
i. In the Excel spreadsheet, right-click the Users sheet name and click Unhide.
ii. Select the sheet named Dictionary and click OK. The Dictionary sheet defines
how the template is used when importing both users and devices.
iii. For each additional, optional field defined that want to include in your import, enter
the Name, exactly as defined in the Dictionary, in a new column on the Users
sheet.
iv. Populate the new columns with data as desired. Cells in the new columns that are
not populated will use the default value, if any.
f. Repeat adding a row for each additional user.
g. After you have added all of the users you want to import, save the file.
4. Select the file to import by clicking Choose file.
5. Browse to and select your file and click Open.
6. You will see the imported file in the table at the bottom of the page. By default, all rows will be
imported. If you only want to import specific users, select the specific users from the table by
clicking the checkbox in that user's table row.

The following table controls are available for the import users table.

l Show Entries—Specify the number of rows to be shown in the table on each page.
Additional rows over the number you select are shown on additional pages and can be
viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

Chapter 8 Users 74
7. You have three choices after you have opened an import file.
l Start over—Click this button to abort the import of the selected file or to import another file

after completing an import.


l Perform import—Click this button to import all rows or the selected rows.

l Validate import—Click this button to validate all rows or the selected rows, without

actually importing the users.


8. When the import or validation is complete, you will see the overall status at the top of the page.
Click Download results spreadsheet and open the Excel file to see individual status for each
user. You can edit and use this generated spreadsheet as the basis of another import, if desired.

Chapter 8 Users 75
View user details
To view user details, go to the Users page and click the name of the user you want to view. See View
available users on page 68 for details on searching the user table. On the User details tab on the User
page, you will see details about the user.

l Move user—Click this button to move the user to a different group. Select the new group where
you want the user and click OK.
l Delete user—If you have permissions, you will see this button. Click it to delete the user.
Everything associated with the user (devices and backed up data) will be deleted. You must
confirm that you want to delete the user and then click OK.
l Edit user details—Click this button to edit the user. You will not be able to change the company
or user group, but you can change any other settings associated with the user. See Add a single
user on page 71 for details on the user settings.
l Table hyperlinks—There are hyperlinks in the table that will take you directly to a page in the
dashboard.
l Company—This hyperlink will take you to the Company page. See Company on page 12

for details.
l User group—This hyperlink will take you to the group details for a company. This is the

same as going to the Company page, then to the Groups tab, and then clicking a group
name hyperlink in the groups table. See View group details on page 63 for details.
l Default policy set—This hyperlink will take you to Edit policy [Link] is the same as

going to the Company page, then to the Polices tab, and then clicking a policy name
hyperlink in the policies table. See Edit an existing policy on page 17 for details.
l Reset password—Click this button to send a new passcode to the user's email address. The
user will be prompted to update the password after logging in with the temporary passcode.

Chapter 8 Users 76
Edit user settings
1. To edit user settings, go to the Users page and click the name of the user you want to edit. See
View available users on page 68 for details on searching the user table.
2. On the User details tab on the User page, click Edit user details.
3. You will not be able to change the company or user group, but you can change any other setting
associated with the user. See Add a single user on page 71 for details on the user settings.

If you need to change the group a user belongs to, go back to the User details and click
Move user.

4. After you have modified the user settings, click Save changes.

Chapter 8 Users 77
View devices for a user
To view the devices for a user, go to the Users page and click the name of the user you want to view.
See View available users on page 68 for details on searching the user table. On the Devices tab on the
User page, you will see details about each device associated with that user.

l Add device—Click this button to add a device for this user. See Add a single device on page 103
for details.
l Show Entries—This table is limited to 100 rows. Specify the number of rows to be shown in the
table on each page. Additional rows over the number you select are shown on additional pages
and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—The Device name hyperlink will take you to the Device details tab on the
Device page. SeeView device details on page 107 for details.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

The statistics on this page will not be populated until the first backup has been completed. You
can see detailed processing information for the device, including a pending files statistic that is
useful before and after the first backup has been completed, on the device Activity page. See
View device activity on page 112 for details.

Chapter 8 Users 78
Manage user permissions
To view user permissions, go to the Users page and click the name of the user you want to view. See
View available users on page 68 for details on searching the user table. On the Permissions tab on the
User page, you will see details about the user's permissions.

l Login to Dashboard—Enable this option if you want to grant the user the ability to log in to the
portal. Without this permission, the user cannot log in to the portal.
l Login to Access—Enable this option if you want to grant the user the ability to log in to the web
retrieval page of the portal. It is referred to as the Access page because the URL is the portal
URL /access. For example, if you are using [Link] a user would
access the web retrieval page by going to [Link] This
web retrieval page allows users to download their own data without using their device. Without
this permission, users can only restore data from their own device, if they have access to the end-
user client software on their device. (An administrator can still restore data from the portal,
regardless of this setting.)
l Personal permission—These permissions determine if and how users can access their data
and devices. The permissions available and what those permissions grant access to depend on
the logins you have enabled for the user.

If both Login to
If only Login to If only Login to
Dashboard and Login
Dashboard is enabled Access is enabled
to Access are enabled

Chapter 8 Users 79
l Full access to the
l Full access to the
user's data and
user's data and
devices in the
devices in the
portal
Administrator portal Not applicable
l Full access to the
l No access to the
user's data through
web retrieval
the web retrieval
page
page
l Read-only access
l Read-only access
to the user's data
to the user's data
and devices in the
and devices in the
Read Only portal Not applicable portal
l No access to the
l No access to web
web retrieval
retrieval page
page
l No access to the l No access to the
portal portal
Retrieve l Full access to the l Full access to the
Not applicable
Only user's data user's data through
through the web the web retrieval
retrieval page page

If neither login is enabled, the user will not have access to the portal or to the web retrieval page.
l Admin role(s)—If a user has been granted Login to Dashboard access, there will be an
additional section at the bottom of the Permissions tab for Admin role(s). This table shows you
the permissions, if any, assigned to the user for company and group access.
l Add role—Click this button to add a new role to the user's permissions.

l Organization—Select the company or group this user should be assigned to.

l Role—Select the role the user should have assigned.

l Administrator—This permission provides full access to all of the portal. You


should limit this role to as few people as possible because each user who has
this access has full control over everything.
l Backup Administrator—This permission provides full access to all users
and devices, but only partial access to other areas of the portal. This role might
be appropriate for a service desk team member who can assist other users
with retrieving data.
l Legal Administrator—This permission provides full access to legal holds
and admin restores, but read-only access to other areas of the portal. This role
is appropriate for those responsible for retrieving data that is on legal hold.
l Support—This permission provides the ability to reset devices. Read-only
access is granted to the rest of the portal.
l Read Only—This permissions provides read-only access to all parts of the
portal, except legal holds.

Chapter 8 Users 80
l None—This permission hides company level information from a user that has
access to log in to the portal.

Backup Legal
Administrator Support Read Only
Administrator Administrator

No add, edit, or
Company Full access Read only Read only Read only
delete

Read only plus


Users Full access Full access Read only password Read only
resets

Read only plus


Read only plus reset device
Devices Full access Full access Read only
admin restore and admin
restore

Legal Hold Full access No access Full access No access No access

Full access
QuickCache Full access except cannot No access Read only Read only
delete

Reports Full access Full access Read only Read only Read only

To view this comparison table within the console, click Compare Roles.
From there, you can click More details to see detailed tables of permissions.

Click OK to apply the role.


l Show Entries—Specify the number of rows to be shown in the table on each page.
Additional rows over the number you select are shown on additional pages and can be
viewed by using the paging buttons at the bottom of the table.

This table is limited to 100 rows. If you need to see a list of all entries, use
Download list.

l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—Click an action hyperlink to delete or edit an assigned role.
l Remove rule—Click this link to remove the role from the user's permissions.

l Change role—Click this link to change the role for the specified company or group .

l Table paging buttons—At the bottom of the table are paging buttons allowing you to

Chapter 8 Users 81
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

Chapter 8 Users 82
Reset a user password
Use the following instructions to reset a user password. This process will send a temporary passcode to
the user's email address. The user will be prompted to update the password after logging in with the
temporary passcode.
1. Go to the Users page and click the name of the user. See View available users on page 68 for
details on searching the user table.
2. On the User details tab on the User page, click Reset password.

3. Click OK to email the temporary passcode to the user.

Chapter 8 Users 83
Delete a user
When you delete a user, everything associated with the user (devices and backed up data) will be
deleted.
1. Go to the Users page and click the name of the user. See View available users on page 68 for
details on searching the user table.
2. On the User details tab on the User page, click Delete user. If you do not see this button, you do
not have permissions to delete users.
3. Confirm that you want to delete the user and click OK.

Chapter 8 Users 84
Manage users with LDAP
If you are using Lightweight Directory Access Protocol (LDAP), you can manage Carbonite Endpoint
users by synchronizing Carbonite Endpoint and LDAP. This will add and disable users based on their
status in your LDAP company directory. You will be able to move users into Carbonite Endpoint groups
based on LDAP queries, allowing you to apply unique Carbonite Endpoint backup policies to the
different groups of users.
See the following sections for LDAP synchronization tasks.
l LDAP requirements on page 86
l Install LDAP agent on page 89
l Configure LDAP synchronization on page 92
l Monitor and troubleshoot LDAP synchronization on page 96

Chapter 8 Users 85
LDAP requirements
In order to use the LDAP feature, you must meet the following requirements and caveats.
l Provisioning server—You must have a physical or virtual server for the provisioning server.
l Operating system—The provisioning server must be running Windows 2016 or later.

l Microsoft .NET—The provisioning server must be running Microsoft .NET version 4.7.2 or

later.
l Availability—The provisioning server does not need to be a high availability server.

Carbonite Endpoint backups will function if the provisioning server is offline. However, user
updates (add, move, disable) will be deferred until the provisioning sever is online.
l Colocation—Your provisioning server and domain controller can be the same server or

separate servers. See the sample configurations below.


l Network routes—The provisioning server must have network routes between the server

and the Carbonite Endpoint dashboard and between the server and a domain controller, a
read-only domain controller, or another queryable LDAP server. See the sample
configurations below.
l Ports—Use the following ports for communication. See the sample configurations below.

l Use LDAP on port 389 or LDAPS on port 636 for communication from the

provisioning server to the domain controller.


l Use TLS port 443 for communication from the provisioning server to the Carbonite

Endpoint dashboard.
l Account—You must have an LDAP service account that has query rights in the search root you
intended to use.
l Single sign-on—If you are using single sign-on (SSO) and have removed a user, the user will
not be able to log in to Carbonite Endpoint even if the LDAP query to modify Carbonite Endpoint
has not be executed yet, because the user will not be able to authenticate through SSO.
However, if you add a user to SSO, you must run the LDAP query to add the user to Carbonite
Endpoint before the user can log in, because SSO does not automatically add an account for the
user in Carbonite Endpoint.
l Multiple domains—Keep in mind the following if you have multiple domains.
l You should query domain controllers on a per-domain basis rather than a single global

catalog across domains.


l You should add a Carbonite Endpoint company for each domain and have a provisioning

server for each company/domain. If that is not possible, you may have to reassign users to
the correct company after they are added.
l You may need to modify the search root for a per-user query.

Chapter 8 Users 86
Sample configurations

These diagrams represent the three most common LDAP configurations.


l Provisioning server installed on the domain controller,
l Provisioning server separate from the domain controller
l Multiple provisioning servers and domain controllers.
Complex scenarios, like multiple domains, may be referred to Professional Services for further
assistance.

Chapter 8 Users 87
Component to Component Communication and Port Arrow Color

Provisioning Server to Domain Controller LDAP port 389 or LDAPS port


Domain Controller to Provisioning Server 636

Provisioning Server to Carbonite Endpoint


TLS port 443
dashboard

Chapter 8 Users 88
Install LDAP agent
Use the following instructions to install the LDAP agent on your provisioning server. See LDAP
requirements on page 86 for sample configurations.
1. On the Company page, go to the LDAP synchronization tab.
2. The next step will depend on if you have previously configured LDAP synchronization.
l No previous configuration—Use the following steps if you have not previously

configured LDAP synchronization.


a. Review the overview information and the requirements and click Get Started.
b. Review the Getting Started process outlined at the top of the Synchronization
status section.
c. Click Install and Activate the LDAP Synchronization Agent which will jump you
to the Synchronization agents section. You can also scroll down to that section.
l Previous configuration—If you have previously configured LDAP synchronization, scroll

down to the Synchronization agents section.


3. Click Download installer and then click the For Windows .msi link to save a copy of the
installation file for the LDAP synchronization agent. Close the dialog box after the download is
complete.
4. Copy an Activation Code with an Available status from the table and copy the
LDAP Activation URL from under the table. You will need this information when you install the
LDAP synchronization agent.

5. On your provisioning server, install the LDAP synchronization agent using the file that you
downloaded.

If your LDAP agent needs to use a proxy server for communication, use the alternate
instructions at the end of this section to install the agent.

a. Review and accept the Terms of Service and click Next to continue
b. If desired, change the destination folder and click Next to continue.
c. Enter the LDAP Activation URL and Activation Code that you copied earlier and click
Next to continue.

Chapter 8 Users 89
d. Click Install.
e. When the installation is complete, click Close.
6. Verify the Status of the agent has changed to Activated. Review the following if it is not.
l Make sure the provisioning server can access the Carbonite Endpoint dashboard. Try

opening the dashboard URL in a browser on the provisioning server.


l Make sure the LDAP Synchronization Service is running.

l Make sure the user running the LDAP Synchronization Service has rights on the network to

reach the Carbonite Endpoint dashboard.


l Make sure the firewall or other security settings are not blocking communication.

l If your LDAP agent needs to use a proxy server for communication, you will need to

manually specify the proxy server information. See the alternate agent instructions for
details.

If you need to install on another provisioning server, click Add Agent to obtain another
Activation Code and then repeat the installation steps on the next server.

If you need to delete or suspend a provisioning server from queries, click Edit for that agent in
the table in the Synchronization agents section and click the appropriate button. You can also
edit the assigned name, if needed.

Alternate instructions for LDAP agent installation with a proxy server


1. On your provisioning server, open a command prompt.
2. Run the following command to launch the installation without requiring activation during the
installation process.
msiexec /i C:\DownloadLocation\[Link]
SKIPLDAPACTIVATION=1

Substitute your download location for C:\DownloadLocation.


3. When the installation begins, review and accept the Terms of Service and click Next to continue
4. If desired, change the destination folder and click Next to continue.
5. When prompted for activation information, leave the fields blank and click Next to continue.
6. Click Install.
7. When the installation is complete, click Close.
8. Using a text editor, open C:\Program Files
(x86)\Carbonite\LdapSyncService\[Link].
9. Add a new section before the closing </LdapSynchronizationConfiguration> tag. The section you
add will depend on the proxy server configuration.

The section you add is case-sensitive. Make sure you enter it exactly as shown.

Chapter 8 Users 90
l Auto-detect—If your proxy server is automatically detecting, add the following section.

<Proxy>
<Type>Autodetect</Type>
</Proxy>

l Server—If your proxy server uses a specific IP and port, add the following section.

<Proxy>
<Type>Server</Type>
<Server>ServerIpAddress:Port</Server>
</Proxy>

l Auto-config script—If your proxy server is using a proxy auto-config (PAC) script, add
the following section.

<Proxy>
<Type>Script</Type>
<Server>PacFilePath/[Link]</Server>
</Proxy>

10. Save the file changes.


11. Restart the LDAP service by running the following commands at a command prompt.
net stop LDAPSynchronizationService
net start LDAPSynchronizationService
12. Open a browser and go to [Link]
13. Provide the activation information, keeping in mind that the activation URL must be in the
following format.
[Link]

For example, if you are using the red-US vault, you would use [Link]
[Link]/[Link].

Chapter 8 Users 91
Configure LDAP synchronization
Make sure you have installed the LDAP agent on the provisioning server. See Install LDAP agent on
page 89 for details. Then use the following instructions to configure LDAP synchronization.
1. On the Company page, go to the LDAP synchronization tab.
2. In the Synchronization settings section, click Change connection. (If the Getting Started
section is still visible at the top of the page, you can click Configure the Synchronization
settings to automatically open the LDAP connection settings dialog box.)
3. Configure your LDAP server settings.

l Server—Specify the LDAP server name. Use the IP address or fully qualified domain
name (FQDN) of the LDAP server. This must be resolvable by the provisioning server
where you installed the LDAP agent.
l Port—Specify the port to use to communicate with the server. Use port 636 if you are using
TLS. Use port 389 if you are not using TLS.
l TLS—Enable this option if you are using Transport Layer Security (secure communication)
between the provisioning server and the LDAP server.
l User name—Specify a user that is an LDAP service account that has query rights in the
search root you intended to use. Enter the account using the format domain\username,
l Password—Specify the password associated with the user. Make sure that the password
does not use any of the following reserved operating system characters.
l less than <
l greater than >
l colon :
l quotation marks or double quote "
l forward slash /

Chapter 8 Users 92
lbackslash \
l vertical bar or pipe |

l question mark ?

l asterisk *

After you have configured your LDAP connection settings, click Save changes. Use the Change
connection button again if you need to edit the connection settings later.
4. Click Change mapping to modify the mapping of Carbonite Endpoint attributes to LDAP
attributes.

l Mapping configuration—Select the mapping configuration you want to use.


l Unique identifier—Select the unique identifier for each attribute. Generally, you will not
need to change the objectGUID default. However, in some cases where objectGUID is not
implemented properly, you may need to use an alternate attribute, such as EmployeeID.
l Email—This is the attribute Carbonite Endpoint uses to determine a user name. This
attribute must be a mail address format. Mail and userPrincipalName are the most
commonly used attributes. If you are also implementing single sign-on (SSO), the attribute
used here must also be used for Name-ID.
l First name—This is the attribute Carbonite Endpoint uses for the user's first name.
Generally, you will not need to change the givenName default. However, in some cases

Chapter 8 Users 93
you may need to use another attribute, for example when the preferred name is identified
using a different attribute or when non-Latin characters are used.
l Last name—This is the attribute Carbonite Endpoint uses for the user's last name, or

surname. Generally, you will not need to change the sn default. However, in some cases
you may need to use another attribute.
l Custom—If desired, enter any custom information in the three provided fields. These fields

allow you to use your own internal information. This field is limited to 500 characters. These
fields will only be available if the LDAP synchronization agent you are using is from vault
version 10.6 or later. Check with Carbonite if you do not know your vault version.
After you have configured your mappings, click Save changes. Use the Change mapping
button again if you need to edit the mappings later.
5. Click Add user query to specify the LDAP query to use. You can add multiple queries.

l Name—Specify a name for this query. Make it descriptive for the type of users you are
querying.
l Search root—Specify the search root you want to use in the query. Parentheses are not
required. For example, if [Link] is using the default Active Directory structure, the
search root will be similar to CN=Users, DC=domain, DC=com. Keep in mind that you can
define your search roots on a per-query basis for compatibility with global catalogs.

If your domain has more than 1000 users, narrow your search to a specific OU,
otherwise, not all of your users will be synchronized.

l Filter—Specify an RFC4515 compatible string filter. See the IETF specification or the
Microsoft TechNet article Active Directory: LDAP Syntax Filters for details. This is a query

Chapter 8 Users 94
that is more or less the same as dsquery or other similar Active Directory tools. For
example, you might use one of the following queries.
l All users—(objectCategory=Person)

l All users with a valid email address—(&(objectCategory=Person)(mail=*))

l All users that are a member of a group—(&

(memberof=CN=GroupName,OU=Users,DC=domain,DC=com)
(objectCategory=Person))

Click the help icon (the question mark icon) to see more example queries.

Make sure you have validated your query before using it in Carbonite Endpoint.

l User group—Select the Carbonite Endpoint user group you want the users captured in
the query to be applied to.
l Enable web retrieval—Select this option to allow users to log into the dashboard and

access their files online. This allows them to download individual files from their browser.
After you have configured your query, click Save changes. Use the Edit link if you need to edit
the query later or the Delete link if you no longer want to use the query.
6. Manage your queries by using the links in the Action column of the table. If users are found in
multiple queries, the first query they are found in will take precedence.
l Move down—Click this link to move the query down in the order of precedence.

l Move up—Click this link to move the query up in the order of precedence.

l Edit—Click this link to edit the query.

l Delete—Click this link to delete the query.

7. If you have not already enabled production mode, you can go to the top of the LDAP
synchronization tab and click Test synchronization. Look for the results in the Synchronization
history table.

Chapter 8 Users 95
Monitor and troubleshoot LDAP synchronization
After you have configured LDAP synchronization, you can monitor it through the LDAP
synchronization tab. You can also go to [Link] on the provisioning server to see a log of the
synchronization process.
l Synchronization status—Initially, this section contains a Getting Started overview which
outlines basically how to use the LDAP synchronization feature. Once you have clicked Enable
production mode, the overview section is no longer displayed.

l Status—This read-only field indicates the latest status of the synchronization.


l Schedule— This read-only field indicates the synchronization schedule or manual if there
is not a set schedule.
l Test synchronization—Click this button to test your settings. This button is only available
before you have enabled production mode.
l Synchronize now—Click this button to synchronize Carbonite Endpoint with your LDAP
server based on your defined queries. This manual synchronization can be used even if a
schedule is set.
l Edit schedule—Click this button to add or modify a synchronization schedule. Select the
Synchronization frequency and the Approximate time. The schedule applies to all
provisioning servers.
l Refresh—Click this button to update the Status.
l Synchronization history—This table show each synchronization and the changes or
issues that happened during the update. Use the Previous and Next buttons at the bottom
of the table to move between pages of the table.

To see further information on issues identified in the table, go to [Link]


on the provisioning server to see a log of the synchronization process. Common
issues include the following.

l The LDAP server name cannot be resolved by the provisioning server. Try using an
IP address if name resolution is an issue.
l The LDAP binding failed. Make sure the user specified to connect to the LDAP
server has a valid password, is active in LDAP, and has not been locked out due to
failed login attempts. Also, make sure the search root has no parentheses and is
typed correctly.
l No users are provisioned. Test a more simple query, such as a single mail address.
Make sure it succeeds before adding and running more advanced queries. Make

Chapter 8 Users 96
sure the email address is unique and has not already been provisioned in another
account. Check Active Directory for duplicate objects. You may need to consider
using a UPN-based query.
l Attributes are blank. Validate using PowerShell or another tool that the attributes are
populated in Active Directory.

l Synchronization agents—This section is where you can download the agent to install on your
provisioning servers. This section also has the activation codes that need to be used on the
provisioning server during the installation. See Install LDAP agent on page 89 for details.
l Synchronization settings—This section is where you configure the LDAP connection settings,
the mappings to Active Directory objects, and manage the queries. See Configure LDAP
synchronization on page 92 for details.

Chapter 8 Users 97
Chapter 9 Devices
Devices are the endpoints (desktops, laptops, and tablets) that contain the files you are protecting. Like
Users on page 67, you can add devices manually in Carbonite Endpoint, use bulk uploads, or add the
device at the same time you are deploying the end-user software on the device.
The following tasks are available for devices.
l View available devices on page 100
l Add devices on page 102
l View device details on page 107
l Edit device settings on page 109
l Manage a device on page 110
l View device activity on page 112
l View device issues on page 114
l View device events on page 115
l View device messages on page 116
l Restore files from a device on page 117
l Locate a device on page 120
l Delete a device on page 121
If you want to automate device creation, see Deployment on page 38.

Starting with MacOS 10.14 Mojave, the operating system includes a security feature called Full
Disk Access (FDA) which blocks applications from accessing specific locations. This may
prevent Carbonite Endpoint from backing up and restoring files, such as Apple Mail, Photos,
Calendar, and so on. In order to back up and restore these files, you must grant Carbonite
Endpoint access within Full Disk Access. You can resolve this issue at each MacOS 10.14 or
later device individually or you can use Jamf to push the change out to groups of devices.

Enable Full Disk Access at each device individually

1. Under the Apple icon, click System Preferences, Security & Privacy, and on the Privacy
tab, select Full Disk Access.
2. If the padlock icon is locked, click the icon and enter your MacOS credentials. Do not use your
Apple ID or Carbonite Endpoint credentials.
3. Click Add an application (the plus icon), highlight Applications on the left, select Carbonite
Endpoint from the list, and click Open.
4. If desired, click the padlock icon again to lock Full Disk Access.
5. Restart the device.
Enable Full Disk Access for groups of devices using Jamf

1. If you do not already have it, download the Privacy Preferences Policy Control (PPPC) Utility
from [Link]

Chapter 9 Devices 98
2. Create a configuration file and add Carbonite Endpoint by clicking Add (plus sign in the
bottom left corner) and locating and selecting Carbonite Endpoint.
3. Set the permissions for All Files to Allow.
4. Save the changes.
5. Upload the configuration file to your Jamf server.
6. Go to Configuration Profiles and select the configuration file and settings. Be sure to select
Install Automatically and Computer Level.
7. Save the changes.
8. Deploy the configuration using Jamf.
See the PPPC and Jamf documentation for additional details.

Chapter 9 Devices 99
View available devices
To view your available devices, go to the Devices page, where you will find high-level information for
your devices.

You have the following toolbar and table controls available on the Devices page.
l Add device-Click this button to add a new device. See Add a single device on page 103 for
details.
l Download list—Click this button to download a complete device list to your local computer. You
can select to download a Microsoft Excel (.xlsx) file or a comma-delimited file (.csv). If you
download the Excel format, you must enable editing for any hyperlinks to the portal to be active.
l Show Entries—Specify the number of rows to be shown in the table on each page. Additional
rows over the number you select are shown on additional pages and can be viewed by using the
paging buttons at the bottom of the table.

This table is limited to 100 rows. If you need to see a list of all entries, use Download list.

l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—There are hyperlinks in the table that will take you directly to a page in the
dashboard.
l Device name—This hyperlink will take you to the Device details tab on the Device page.

See View device details on page 107 for details.

Chapter 9 Devices 100


l Email—This hyperlink will take you to the User details tab on the User page. See View
user details on page 76 for details.
l Company—This hyperlink will take you to the Company page. See Company on page 12

for details.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 9 Devices 101


Add devices
You can manually add individual devices or you can import to bulk add devices.
l Add a single device on page 103—You can manually add a single device. Use this method when
you only have a few devices to add.
l Import multiple devices on page 105—You can bulk import multiple devices. Use this method
when you have many devices to add, but you are not using an automated method.
If you want to automate device creation, see Deployment on page 38.

Chapter 9 Devices 102


Add a single device
Use the following instructions to add a single, new device.
1. Click Add device from the Company or Devices page.
2. Enter search criteria to look for the user you want to associate the device to, select one of the
search fields from the drop-down list, and click Search.

If the user you want does not exist, click Add user and after you finish adding the user,
you will come back to this page and you can search for the user you just added. See Add a
single user on page 71 for details on adding a new user.

3. In the search results, select the user you want to associate the device to. Use the standard page
and table functionality if the search return is a long list.
l Show Entries—This table is limited to 100 rows. Specify the number of rows to be shown

in the table on each page. Additional rows over the number you select are shown on
additional pages and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.
4. Once you have selected the user you want to associate the device to, click Select user.
5. On the Device page, in the Add device section, define the details for the new device.

Chapter 9 Devices 103


Current context—The account that the device will be associated to is displayed in the
l

context area. Make sure you have selected the correct user. If you have not, click Cancel
and search again for the correct user.
l Device name—If desired, you can enter a name to identify the device. This name is

optional. If you do not enter a device name, it will be displayed as Device x, where x is an
incremental number, for example Device 1, then Device 2, and so on.
l Select device policy set—Select the policy you want applied to the device. See Policies

on page 14 for details.


l Select storage quota—Select the amount of space this device can use for backing up

files. If you select Unlimited, the device will not have any space restrictions. If you select
Custom, enter the size, in GB, that the device will be limited to.
6. Once you have configured the device details, click Create device.
The user will receive an email to download the end-user software. The email will have the necessary
activation URL and activation code.

Chapter 9 Devices 104


Import multiple devices
Use the following instructions to import multiple, new devices. (Existing devices will not be overwritten.)
1. Go to the Company page and then the Company details tab.
2. Click Import devices.
3. If you have not already done so, prepare your import file.
a. Download the template which is used for the import device process by clicking Download
template.
b. Save and open the Excel (.xlsx) file.
c. Enable editing of the file.
d. For each device you want to add, enter the device's information in one row of the
spreadsheet in the First Name, Last Name, and Email columns. You can optionally enter
data for the columns listed below, however, do not enter any data in the remaining pre-
defined columns, and do not modify the Row ID entries.
l GB—Set the amount of disk space, in GB, that the that the device will be limited to

when backing up files. If you leave this blank, the policy setting will be used.
l Policy Set—Specify the policy you want the device to use. If you leave this blank,

the policy will be inherited.


l Device Name—Specify a name to identify the device. This name is optional.

l QuickCache Name—Specify the name of the QuickCache to use.

e. You can optionally create additional columns for additional, optional information. You can
skip this step if you only want to enter the information above for each device.
i. In the Excel spreadsheet, right-click the Devices sheet name and click Unhide.
ii. Select the sheet named Dictionary and click OK. The Dictionary sheet defines
how the template is used when importing both users and devices.
iii. For each additional, optional field defined that want to include in your import, enter
the Name, exactly as defined in the Dictionary, in a new column on the Devices
sheet.
iv. Populate the new columns with data as desired. Cells in the new columns that are
not populated will use the default value, if any.
f. Repeat adding a row for each additional device.
g. After you have added all of the devices you want to import, save the file.
4. Select the file to import by clicking Choose file.
5. Browse to and select your file and click Open.
6. You will see the imported file in the table at the bottom of the page. By default, all rows will be
imported. If you only want to import specific devices, select the specific devices from the table by
clicking the checkbox in that device's table row.

The following table controls are available for the import devices table.

l Show Entries—Specify the number of rows to be shown in the table on each page.
Additional rows over the number you select are shown on additional pages and can be
viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that

Chapter 9 Devices 105


contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

7. You have three choices after you have opened an import file.
l Start over—Click this button to abort the import of the selected file or to import another file

after completing an import.


l Perform import—Click this button to import all rows or the selected rows.

l Validate import—Click this button to validate all rows or the selected rows, without

actually importing the devices.


8. When the import or validation is complete, you will see the overall status at the top of the page.
Click Download results spreadsheet and open the Excel file to see individual status for each
device. You can edit and use this generated spreadsheet as the basis of another import, if
desired.

Chapter 9 Devices 106


View device details
To view device details, go to the Devices page and click the name of the device you want to view. See
View available devices on page 100 for details on searching the device table. On the Device details tab
on the Device page, you will see details about the device.

l Move device—Click this button to move the device to a different user. Select the user from the
table by clicking the circle in that user's table row and click Select user. The following table
controls are available when selecting a new user.
l Show Entries—This table is limited to 100 rows. Specify the number of rows to be shown

in the table on each page. Additional rows over the number you select are shown on
additional pages and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.
l Edit device—Click this button to modify the device settings. See Edit device settings on page 109
for details.
l Table hyperlinks—There are hyperlinks in the table that will take you directly to a page in the
dashboard.

Chapter 9 Devices 107


l Policy set—This hyperlink will take you to Edit policy [Link] is the same as going to
the Company page, then to the Polices tab, and then clicking a policy name hyperlink in
the policies table. See Edit an existing policy on page 17 for details.
l QuickCache—This hyperlink will take you to QuickCache activity tab on the the

QuickCache page. See View QuickCache activity on page 138 for details.
l Retrieve protected file—This hyperlink will open another tab or window to allow you to

search for a file to retrieve.


l Email and User name—Both of these hyperlinks will take you to the User details tab on

the User page. See View user details on page 76 for details.
l User group—This hyperlink will take you to the group details for a company. This is the

same as going to the Company page, then to the Groups tab, and then clicking a group
name hyperlink in the groups table. See View group details on page 63 for details.
l Company—This hyperlink will take you to the Company page. See Company on page 12

for details.
l Help activating device—Click this hyperlink to see useful information for activating this device.
You will see links to the installation file and the activation URL. If you need to reinstall Carbonite
Endpoint on this device, you need to reset the device and then reinstall. See Manage a device on
page 110 for details.

Chapter 9 Devices 108


Edit device settings
1. To edit device settings, go to the Devices page and click the name of the device you want to edit.
See View available devices on page 100 for details on searching the device table.
2. On the Device details tab on the Device page, click Edit device.
3. Modify the device settings as needed. See Add a single device on page 103 for details on the
device settings.

4. After you have modified the device settings, click Save changes.

Chapter 9 Devices 109


Manage a device
To manage or administer a device, go to the Devices page and click the name of the device you want to
manage. See View available devices on page 100 for details on searching the device table. On the
Manage device tab on the Device page, you will see the tasks available.

The available tasks will depend on the state of the device.

l Put on legal hold—Click this button to disable the retention and erase options. This keeps data
from being deleted from the vault, and it keeps the device from being deleted. You might use this
feature when you are legally required to preserve data, for example because of a lawsuit or a user
investigation. The data can be made available upon request, and it prevents someone from trying
to delete files or entire backups. When prompted, specify any notes you need and then click Put
on legal hold.
l Remove from legal hold—Click this button when the legal hold is no longer needed.

Confirm that the device can be removed from legal hold and click OK.
l Suspend device—Click this button to stop protecting this device. You might use this feature
when you do not want additional data backed up from a device, but you want to preserve the data
that has already been backed up. When prompted, confirm the suspension by clicking OK.
l Reactivate device—Click this button when the suspension is no longer needed. Confirm

that the device can be reactivated and click OK.


l Delete data from device—Click this button to delete all of the protected data from the device.
Unprotected data on the device will not be deleted. The protected data will not be deleted from the
vault, only from the device. You might use this feature if a laptop is lost or stolen, and there is
concern that someone malicious will access the laptop and the files on it. This option also resets
the license so you can reuse it again later, on the same or a different device. After deleting data
from a device, you will have to generate a new license by using Reset device. When prompted,
confirm the data deletion and click OK.
l Delete device—Click this button to delete the device from Carbonite Endpoint. All of the
protected data will be deleted from the vault. You will not be able to restore any data. The device
will not longer be protected. You might use this feature when you want to remove the data from

Chapter 9 Devices 110


the vault or no longer need the backup. It allows you to stop using the license. This action is not
reversible. Once the device is deleted, the data that was backed up cannot be accessed. When
prompted, confirm you want to delete the device and click OK.
l Reset device—Click this button to reset a device. Once the device is reset, it will not be protected
until you install and activate (if using a new device) or reinstall and reactivate (if reusing a device).
You might use this feature when you need to reinstall on the same device or when a user is getting
a new device. It keeps you from having to use two licenses. When prompted, enter and confirm a
passphrase that will be used to activate or reactivate the device, then click Reset device. Copy
the activation code that is presented. The same code will also be displayed on the Device details
tab on the Device page. You will need the activation code for the device.

The passphrase expires after 14 days. You will need to reset the device again to generate
a new passphrase.

If you are using MacOS 10.14 Mojave or later and you are uninstalling and reinstalling on
a device, you may need to reboot the machine after the uninstall or at least wait a few
minutes before attempting to reinstall. This is due to MacOS Full Disk Access impacting
the uninstall process, making uninstall process take longer to fully finish. If you do not wait
long enough or reboot, the reinstall will not be clean and the client will be in the same state
it was in before the uninstall was started.

l Scan user state—Click this button to start a manual scan of the user state. Carbonite Endpoint
uses Microsoft User State Migration Tool (USMT) to provide a process for replacing or refreshing
Windows computers. The utility captures operating system settings, application settings, user
accounts, and user files and migrates them to a new Windows installation. You must be familiar
with using and configuring USMT. See [Link]
us/windows/deployment/usmt/usmt-topics for details on this utility. Once a scan is completed, you
can restore the user state.

You can schedule periodic user state scans using a policy setting. See Policy settings on
page 19 for details.

Chapter 9 Devices 111


View device activity
To view device activity, go to the Devices page and click the name of the device you want to view. See
View available devices on page 100 for details on searching the device table. On the Activity tab on the
Device page, you will see the device activity.

l Status—The top section identifies when the last status information was captured. The activity at
the time the status information was captured is listed.
l Recent activity—The bottom section shows the protection and restore activity on the device.
The most recent 50 activities are shown. Using the Type filter drop-down, you can filter the table
to see only specific types of activity. The following table controls are available when viewing the
recent activity.
l Show Entries—This table is limited to 50 rows. Specify the number of rows to be shown in

the table on each page. Additional rows over the number you select are shown on
additional pages and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.

Chapter 9 Devices 112


l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

Chapter 9 Devices 113


View device issues
Issues are problems with files on a device that are being backed up. These issues may need manual
intervention to be resolved, depending on the issue.
1. To view device issues, go to the Devices page and click the name of the device you want to view.
See View available devices on page 100 for details on searching the device table.
2. On the Issues tab on the Device page, you will see the device issues, if any. For example, if a file
is too large to backup, it will be flagged as an issue.

l Show Entries—This table is limited to 50 rows. Specify the number of rows to be shown in
the table on each page. Additional rows over the number you select are shown on
additional pages and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

Chapter 9 Devices 114


View device events
Events are problems or alerts with the environment or due to a policy violation. These events generally
do not need manual intervention and will resolve on their own.
1. To view device events, go to the Devices page and click the name of the device you want to view.
See View available devices on page 100 for details on searching the device table.
2. On the Events tab on the Device page, you will see the device events, if any. For example, if a file
is too large to backup, it will be flagged as an issue.

l Show Entries—This table is limited to 50 rows. Specify the number of rows to be shown in
the table on each page. Additional rows over the number you select are shown on
additional pages and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that
contain the search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

Chapter 9 Devices 115


View device messages
Messages contain information about the device and its backup. The messages may lead to events or
issues that may or may not need manual intervention to be resolved, depending on the message. To
view device messages, go to the Devices page and click the name of the device you want to view. See
View available devices on page 100 for details on searching the device table. On the Messages tab on
the Device page, you will see the device messages, if any. By default, the newest message will be at the
top of the table.

To delete all of the messages, click Delete messages. Additionally, the following table controls are
available when viewing the recent activity.
l Show Entries—This table is limited to 20 rows. Specify the number of rows to be shown in the
table on each page. Additional rows over the number you select are shown on additional pages
and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 9 Devices 116


Restore files from a device
If you have permissions to complete admin restores, use the following steps. If you do not have
permissions to complete admin restores, you will not see this tab.
1. To restore files from a device, go to the Devices page and click the name of the device you want
to restore. See View available devices on page 100 for details on searching the device table.
2. Go to the Restore tab on the Device page.
3. If desired, select a File category to narrow what you are searching for.
4. If desired, modify the Sort order of the results that will be returned.
5. If desired, enter in the Search field a specific file name or a wildcard pattern.
6. Click Search. The following table controls are available when viewing the search results.

l Show Entries—This table is limited to 100 rows. Specify the number of rows to be shown
in the table on each page. Additional rows over the number you select are shown on
additional pages and can be viewed by using the paging buttons at the bottom of the table.
l Table hyperlinks—Volume and folders are hyperlinks that you can click on to drill down
into that volume or folder. The path you are in will be displayed above the table. If you need
to navigate up in the path, click the arrow button to the left of the displayed path.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to
move more quickly between pages of the table. Each button will jump to that respective
page of the table.

Chapter 9 Devices 117


7. If you only want to restore specific files, select the specific files from the table by clicking the
checkbox in that file's table row and clicking Restore selection. If you do not select any rows in
the table, clicking the button Restore all matches will restore everything listed in the table.
8. Select the restore options you want to use.

l Restore time—By default, the most recent version of the file will be restored. If you want to
restore an older version, click Change and select the date and time that you want to restore
and click Save changes. If you change your mind, click Reset to most recent to restore
the most recent version of the file.
l Include deleted files—Select this option if you want to restore files that were deleted.
l Restore location—Select where you want to restore the file to. Click Original location to
restore to the original location, which is the location the file existed when it was backed up. If
you want to restore to a new location, click Change. Specify the volume and path where
you want to restore the file. UNC paths are supported. You can click any combination of the
Add tokens to path buttons to include that information in the path name. Click Save
changes after specifying the path.
l Overwrite behavior—Specify how you want to handle the case where a file with the same
name already exists.
l Overwrite—Overwrite any existing files.

l Rename—The file that is being restored will be renamed and have .restored

appended to the file name.


l Skip restoring—If the file already exists, do not restore the file.

l Overwrite with newer files and skip matching files—If the existing file is older,

overwrite it. If the existing file has the same or a newer date, do not restore the file.
l Restoring device—By default, the file will be restored to the original device. If you want to
restore to a different device, click Change and select the device you want to restore to and

Chapter 9 Devices 118


click Select device. An alternate device must have Carbonite Endpoint installed and
activated. If you change your mind, click Reset to original device to restore back to the
same device.

The following table controls are available when selecting the device to restore to.

l Show Entries—Specify the number of rows to be shown in the table on each


page. Additional rows over the number you select are shown on additional pages
and can be viewed by using the paging buttons at the bottom of the table.

This table is limited to 100 rows. If you need to see a list of all entries, use
Download list.

l Search—Text entered in the box will narrow the list displayed to only those rows
that contain the search text. The search checks the entire table, not just the
visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table paging buttons—At the bottom of the table are paging buttons allowing
you to move more quickly between pages of the table. Each button will jump to
that respective page of the table.

l Include user state load—Select this option if you want to restore the user state data. You
must have backed up the user state using the User State Migration Tool for this functionality
to work.
9. Click Submit to start the restore. You will be redirected to the Company page Admin restores
tab where you can monitor and control the progress of the restore. See Admin restores on page
124 for details.

Chapter 9 Devices 119


Locate a device
You can determine the physical location of a device if the device is using a policy that has Track device
location enabled.
1. Go to the Devices page and click the name of the device you want to delete. See View available
devices on page 100 for details on searching the device table.
2. Go to the Location tab on the Device page and wait for the map to appear. You can zoom in or
out on the map and change the view of the map between Road, Aerial (which is like a satellite
view), and Streetside (which is a street level view).
3. If you want to delete the history of captured locations for this device, click Erase location. The
device will start reporting location the next time it connects.

There are different methods, for example WiFi or IP address based on network traffic, for
reporting location. Some devices may not support all methods.

Chapter 9 Devices 120


Delete a device
When you delete a device from Carbonite Endpoint, all of the protected data will be deleted from the
vault. You will not be able to restore any data. The device will no longer be protected.
1. Go to the Devices page and click the name of the device you want to delete. See View available
devices on page 100 for details on searching the device table.
2. On the Manage device tab on the Device page, click Delete device.

3. Confirm that you want to delete the device and click OK.

Chapter 9 Devices 121


Chapter 10 Manage alerts
You can enable alerts (email notifications) to notify you when specific device and QuickCache criteria
have been met. The alerts can be configured to be emailed daily or weekly.
l Device alerts—This alert is for devices that have not been backed up in the past seven days,
devices that have never been backed up, and for devices that are approaching or have exceeded
their storage quota. Devices will be excluded from the device alert in the following cases.
l The device is a phone. Device alerts are for all non-mobile devices.

l The device is not actively contacting the vault. If the device was on the report but goes

offline for more than 3 days, it will no longer be on the report regardless of the conditions
that placed it on the report originally.
l The device is experiencing quota issues and either of these conditions are met.

l The date and time the device was approaching the quota limit is more than 14 days

ago.
l The device is over quota, quota is not enforced, and the date and time the device

reached the quota limit is more than 14 days ago.


l The device is experiencing backup issues, but the last time the device finished a backup

was less than 7 days before the device last checked in.
l The device has never completed a backup, but the last time the device checked in was less

than 14 days after the device was activated.


l QuickCache alerts—This alert is for QuickCaches that have been offline for a specified number
of days, when the QuickCache is approaching or has exceeded the storage quota for more than
14 days, and when the oldest block is older than a specified number of days.
1. To view or modify your alerts, go to the Company page and then the Alerts tab.
2. For the device alert, click Enable alert or Edit alert settings, depending on if you have an alert
configured already.

l Enabled—Select this option to enable the alert. Clear this checkbox to disable the alert.
l Recipients—Specify a comma-separated list of email addresses. This is where the alerts
will be sent.

Chapter 10 Manage alerts 122


l Schedule—Select an hour of the day, using a 24-hour clock, and the day of the week to
indicate when you want the alert emailed. Select Daily if you want the alert emailed every
day.
3. Click Save changes.
4. For the QuickCache alert, click Enable alert or Edit alert settings, depending on if you have an
alert configured already.

l Enabled—Select this option to enable the alert. Clear this checkbox to disable the alert.
l Recipients—Specify a comma-separated list of email addresses. This is where the alerts
will be sent.
l Schedule—Select an hour of the day, using a 24-hour clock, and the day of the week to

indicate when you want the alert emailed. Select Daily if you want the alert emailed every
day.
l Offline for more than—Select the number of days a QuickCache has to be offline to

trigger the alert.


l Free space is less than—Specify the amount of free space left to trigger the alert.

l Oldest block is older than—Select the number of days the oldest block must be older

than to trigger the alert.


5. Click Save changes.

Chapter 10 Manage alerts 123


Chapter 11 Admin restores
To view the restores performed by an administrator, go to the Company page and select the Admin
restores tab.

See Restore files from a device on page 117 for details on initiating the restore.

You have the following toolbar and table controls available on the Admin restores tab.
l Show Entries—This table is limited to 100 rows. Specify the number of rows to be shown in the
table on each page. Additional rows over the number you select are shown on additional pages
and can be viewed by using the paging buttons at the bottom of the table.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—There are hyperlinks in the table that will take you directly to a page in the
dashboard or take an action on a specific restore process.
l Device name—This hyperlink will take you to the Device details tab on the Devices

page. See View device details on page 107 for details.


l Email—This hyperlink will take you to the User details tab on the User page for the user

whose device is being restored. See View user details on page 76 for details.
l Restoring device—This hyperlink will take you to the Activity tab on the Devices page.

See View device activity on page 112 for details.


l Submitted by—This hyperlink will take you to the User details tab on the User page for

the user who initiated the restore. See View user details on page 76 for details.
l Actions—This hyperlink will cancel the current process.

l Table paging buttons—At the bottom of the table are paging buttons allowing you to move

Chapter 11 Admin restores 124


more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 11 Admin restores 125


Chapter 12 Reports
You can add and view reports that detail your Carbonite Endpoint activity. The following tasks are
available for reports.
l View a list of available reports on page 127
l Add a report on page 128
l View a report on page 130
l Delete a report on page 132

Chapter 12 Reports 126


View a list of available reports
To view your available reports, go to the Reports page, where you will find high-level information for
your reports.

You have the following toolbar and table controls available on the Users page.
l Add new report-Click this button to add a new report. See Add a report on page 128 for details.
l Show Entries—This table is limited to 100 rows. Specify the number of rows to be shown in the
table on each page. Additional rows over the number you select are shown on additional pages
and can be viewed by using the paging buttons at the bottom of the table.
l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—Click on any hyperlink in the table and it will take you to the view for that
report. See View a report on page 130.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 12 Reports 127


Add a report
Use the following instructions to add a new report.
1. Click Add new report from the Reports page.
2. Specify the report definition.

l Report name—Specify a unique name for the report.


l Report layout—Select a layout for the report.
l Report visibility—Select if you want the report to be only visible to you or to be shared
with others. You may not be able to share the report with others depending on your login
permissions. If a report is shared, users can only see the data they have access to.
l Report type—Specify the type of report you want to add.
l Time based report—These reports are based on time.

l Organizational breakdown report—These reports are based on the company or

group.
l Device details report—These reports list all devices.

l User details report—These reports list all users.

l Report dates—For time-based reports, select the time frame you want to use when
generating the report.
l Organization—Select the organization you want the report data to be generated from.
These options will depend on your login permissions.

Chapter 12 Reports 128


l Policy sets to include—Select if you want to include all policy sets in the report data.
l Available data points—Select the data you want in the report by selecting an item in the
Available data points list and clicking Add data point. Some data points have choices
under Show to allow you to select how you want the data point displayed. If you want to
remove a data point from the report, select it in the Report data points list and click
Remove data point.
Once you have all of your data points in the Report data points list, click Move up or
Move down to organize the data.
3. As you are adding your report, click Load report preview at any time to see what your report will
look like.
4. When your report is complete, click Save report.

Chapter 12 Reports 129


View a report
After you have added a report, you can view it by going to the Reports page and clicking the name of the
report you want to view. See View a list of available reports on page 127 for details on searching the
reports table. The view of the report will vary depending on the type of report and the data in the report,
but you will find the report in a table on the displayed page. The controls and links on the report will also
vary.

The following lists the functions and controls when viewing a report, however, what you see will vary
based on the type of report you are viewing.
l Edit report definition—Click this button to edit a report. The report options are the same as
when you added the report. See Add a report on page 128 for details.
l Delete report—Click this button to delete a report.
l Go to report definition—Click this button to view the definition and criteria used to generate the
report.
l Download list—Click this button to download the report in a list format. The list will be
downloaded to your local computer. You can select to download a Microsoft Excel (.xlsx) file or a
comma-delimited file (.csv). If you download the Excel format, you must enable editing for any
hyperlinks to the portal to be active.
l Alternative view—Click this link to see the report data in a different view. For example, instead of
seeing the data by a date, you might want to see it by groups.
l Show Entries—Specify the number of rows to be shown in the table on each page. Additional
rows over the number you select are shown on additional pages and can be viewed by using the
paging buttons at the bottom of the table.

This table is limited to 100 rows. If you need to see a list of all entries, use Download list.

l Table hyperlinks—Many of the report table entries are hyperlinks. Click on any hyperlink to go to
the related page that shows details for that data set.
l Additional row information—If all of the report data cannot be shown in the table easily for the
size screen you are viewing, you will see a plus sign at the left of the table row. Click this button to
see additional report data for that table row.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move

Chapter 12 Reports 130


more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 12 Reports 131


Delete a report
If you no longer need a report, you can delete it.
1. Go to the Reports page and click the name of the report you want to delete. See View a list of
available reports on page 127 for details on searching the report table.
2. On the report view, click Delete report.
3. Click OK to delete the report.

Chapter 12 Reports 132


Chapter 13 QuickCache
QuickCache is an optional backup location used for faster backups in local environments and increased
bandwidth management to the vault.

If there is no QuickCache or it is offline, devices send all backup data directly to the vault, However,
when a QuickCache is online on the network, each device configured to use that QuickCache will send
all backup data to the QuickCache. Devices will still send activity updates directly to the vault so that
information can be displayed in the dashboard. Devices will upload to the QuickCache as fast as the
local network allows, unless device to QuickCache limits are configured.
All data from all devices on the QuickCache is then sent to the vault. The QuickCache can be configured
for peak and off-peak speeds from the QuickCache to the vault. Peak and off-peak hours are
configurable and are based on the time zone configured for the QuickCache.
During a restore, if the data is still on the QuickCache, the restore will use that data. If the data is not on
the QuickCache, the QuickCache will download the data from the vault and send it to the device. Like
backing up the data, you can configure download speeds from the vault to the QuickCache for peak and
off-peak hours.
The QuickCache machine have Windows Server 2016 (English, EN-US locale) with a least 1 TB of disk
space and a minimum of 2 GB of RAM. Ideally, you should have 4 GB of RAM.

The following tasks are available for QuickCaches.


l View available QuickCaches on page 135
l Add a QuickCache on page 136
l View QuickCache activity on page 138
l View QuickCache details on page 139
l Edit QuickCache server settings on page 140
l Manage the QuickCache bandwidth schedule on page 141
l Manage a QuickCache on page 143

Chapter 13 QuickCache 133


l Assign a device to a QuickCache on page 145
l Delete a QuickCache on page 146

Chapter 13 QuickCache 134


View available QuickCaches
To view your available QuickCaches, go to the QuickCaches page, where you will find high-level
information for your QuickCaches.

You have the following toolbar and table controls available on the QuickCaches page.
l Add QuickCache—Click this button to add a new QuickCache. See Add a QuickCache on page
136 for details.
l Download list—Click this button to download a complete QuickCache list to your local computer.
You can select to download a Microsoft Excel (.xlsx) file or a comma-delimited file (.csv). If you
download the Excel format, you must enable editing for any hyperlinks to the portal to be active.
l Show Entries—Specify the number of rows to be shown in the table on each page. Additional
rows over the number you select are shown on additional pages and can be viewed by using the
paging buttons at the bottom of the table.

This table is limited to 34 rows. If you need to see a list of all entries, use Download list.

l Search—Text entered in the box will narrow the list displayed to only those rows that contain the
search text. The search checks the entire table, not just the visible rows.
l Sort—You can sort the table by clicking on any column heading.
l Table hyperlinks—There are hyperlinks in the table that will take you directly to a page in the
dashboard.
l QuickCache name—This hyperlink will take you to the QuickCache activity tab on the

QuickCache page. See View QuickCache activity on page 138 for details.
l Company—This hyperlink will take you to the Company page. See Company on page 12

for details.
l Table paging buttons—At the bottom of the table are paging buttons allowing you to move
more quickly between pages of the table. Each button will jump to that respective page of the
table.

Chapter 13 QuickCache 135


Add a QuickCache
Use the following instructions to add a QuickCache.
1. On the Company or QuickCaches page, click Add QuickCache.
2. Configure the QuickCache.

lQuickCache name—Specify a unique name for the QuickCache.


l Time zone—Specify the time zone where the QuickCache is located. This time zone will

be used to determine peak hours and off-peak hours for bandwidth management.
l Comment—Specify any desired comment to describe this QuickCache.

3. Once you have configured the QuickCache details, click Add QuickCache.
4. Once you have added the QuickCache, you will be taken to the QuickCache details tab. Copy
the Activation code that is displayed. You will need this code for the next section of the creation
process.
5. Complete the following steps on the server you want to use as the QuickCache.
a. Download the QuickCache installation package from
[Link]
b. Start the QuickCache installation and wait until you get to the license agreement page. This
may take several minutes while the installation configures the server.
c. Accept the terms of the license agreement and click Next.
d. Configure the QuickCache.

Chapter 13 QuickCache 136


l QuickCache locator—Specify the DNS name or IP address of your QuickCache
server. Devices will connect to the QuickCache using this locator.
l Vault server name—Specify the URL for the vault the QuickCache should send

data to.
l Activation code—Specify the activation code that you copied above in step 4 when

you added the QuickCache in the dashboard.


l Activation proxy server—If you need to specify no proxy server or configure

specific settings for a proxy server for QuickCache to vault communication, click
Configure. Specify no server or the proxy server configuration to use and, if needed,
authentication credentials and click OK.
l QuickCache installation location—If you want to change the default installation

location, click Configure. Select a new location and click OK.


l QuickCache data storage location—If you want to change the location where

device data will be stored, click Configure. Select a new location and click OK.
Select a location with a least 100 GB of disk space is required.
e. Once the QuickCache is configured, click Next to continue.
f. Click Install to begin the installation.
g. Once the installation is complete, click Finish.
6. Back in the dashboard, refresh the QuickCache page and see the updated information.

Chapter 13 QuickCache 137


View QuickCache activity
To view QuickCache activity, go to the QuickCaches page and click the name of the QuickCache you
want to view. See View available QuickCaches on page 135 for details on searching the QuickCache
table. On the QuickCache Activity tab on the QuickCache page, you will see the QuickCache activity.

l Current activity—This section shows the current activity on the QuickCache at the date and time
indicated.
l Queue state—This section shows the state of the QuickCache queue from the QuickCache to
the vault.
l Graph—Click any Graph button to change the graph shown at the bottom of the page to that
activity. The graph data is the average over an hour for the time period selected.

Chapter 13 QuickCache 138


View QuickCache details
To view QuickCache details, go to the QuickCaches page and click the name of the QuickCache you
want to view. See View available QuickCaches on page 135 for details on searching the QuickCache
table. On the QuickCache page, select the QuickCache details tab, and you will see details about the
QuickCache.

l Edit QuickCache—Click this button to modify the QuickCache settings. See Edit QuickCache
server settings on page 140 for details.
l Table hyperlinks—The Company hyperlink will take you to the Company page. See Company
on page 12 for details.

Chapter 13 QuickCache 139


Edit QuickCache server settings
1. To edit the QuickCache server settings, go to the QuickCaches page and click the name of the
QuickCache you want to edit. See View available QuickCaches on page 135 for details on
searching the QuickCache table.
2. On the QuickCache page, go to the QuickCache details tab and click Edit QuickCache.
3. Modify the QuickCache server settings as needed. See Add a QuickCache on page 136 for
details on the QuickCache settings.

4. After you have modified the QuickCache settings, click Save changes.

Chapter 13 QuickCache 140


Manage the QuickCache bandwidth schedule
1. To manage the QuickCache bandwidth schedule, go to the QuickCaches page and click the
name of the QuickCache you want to manage. See View available QuickCaches on page 135 for
details on searching the QuickCache table.
2. On the QuickCache page, go to the Bandwidth schedule.
3. Review the Speed limits. If you want to modify any of the limits, click Edit speed limits, make
the modifications, and then click Save changes.

l Peak time period


l Maximum upload speed from QuickCache to vault—This is the speed, in KB/s,

that will be used when sending data during the peak time period from the
QuickCache to the vault.
l Maximum priority upload speed from QuickCache to vault—When a device is

trying to restore, the files in the upload queue will use this speed, in KB/s, to send the
data during the peak time period from the QuickCache to the vault.
l Maximum priority download speed from vault to QuickCache—When a

device is trying to restore, files that are not on the vault will use this speed, in KB/s, to
send the data during the peak time period from the vault to the QuickCache.
l Off-peak time period
l Maximum upload speed from QuickCache to vault—This is the speed, in KB/s,

that will be used when sending data during the off-peak time period from the
QuickCache to the vault.

Chapter 13 QuickCache 141


lMaximum priority upload speed from QuickCache to vault—When a device is
trying to restore, the files in the upload queue will use this speed, in KB/s, to send the
data during the off-peak time period from the QuickCache to the vault.
l Maximum priority download speed from vault to QuickCache—When a

device is trying to restore, files that are not on the vault will use this speed, in KB/s, to
send the data during the off-peak time period from the vault to the QuickCache.
l Device to QuickCache limits

l Maximum upload speed from a device to QuickCache—This it the speed, in

KB/s, that will be used, unless a lower limit is established by policy, when sending
data from a device to the QuickCache.
l Maximum download speed from QuickCache to device—This it the speed, in

KB/s, that will be used, unless a lower limit is established by policy, when sending
data from the QuickCache to a device.
4. Review the off-peak hours. If you want to modify the hours, click Edit off-peak hours, make the
modifications, and then click Save changes. Off-peak hours are indicated by a green checkmark.
Peak hours have no indicator.

Chapter 13 QuickCache 142


Manage a QuickCache
To manage or administer a QuickCache, go to the QuickCaches page and click the name of the
QuickCache you want to manage. See View available QuickCaches on page 135 for details on
searching the QuickCache table. On QuickCache page, go to the Manage state tab, and you will see
the tasks available.

The available tasks will depend on the state of the QuickCache.

l Pause QuickCache—Click this button to pause the QuickCache. This will stop all upload activity
from devices to the QuickCache and from the QuickCache to the vault. It will also stop all
download activity from the vault to the QuickCache and from the QuickCache to all devices.
Devices will upload and download directly from the vault when the QuickCache is paused. Keep in
mind that devices that are restoring data that is in the QuickCache upload queue will have to wait
until the QuickCache is restarted before the restore will complete. When prompted, confirm the
pause by clicking OK.
l Reactivate QuickCache—Click this button when you want to restart a paused

QuickCache. All uploads and downloads will use the QuickCache once it is reactivated.
When prompted, confirm the reactivation by clicking OK.
l Suspend QuickCache—Click this button to suspend the QuickCache. This action is identical to
pausing a QuickCache, except devices that are restoring data that is in the QuickCache upload
queue will get errors instead of waiting to complete the restore. When prompted, confirm the
suspension by clicking OK.
l Reactivate QuickCache—Click this button when you want to restart a suspended

QuickCache. All uploads and downloads will use the QuickCache once it is reactivated.
When prompted, confirm the reactivation by clicking OK.
l Make unavailable to devices—Click this button to make the QuickCache unavailable to devices
only. Data will continued to be uploaded to and downloaded from the vault. When prompted,
confirm making the QuickCache unavailable by clicking OK.

Chapter 13 QuickCache 143


l Reactivate QuickCache—Click this button when you want to make the QuickCache
available to devices again. When prompted, confirm the reactivation by clicking OK.
l Cancel QuickCache—Click this button if you want to delete the QuickCache. This action cannot
be undone. Confirm you want to delete the QuickCache and click OK.

Chapter 13 QuickCache 144


Assign a device to a QuickCache
1. Go to the Devices page and click the name of the device you want to assign the QuickCache to.
See View available devices on page 100 for details on searching the device table.
2. On the Device details tab on the Device page, click Edit device.
3. Select the QuickCache this device can use.

4. After you have modified the device settings, click Save changes.

Chapter 13 QuickCache 145


Delete a QuickCache
When you delete a QuickCache, devices will upload and download directly from the vault. Deleting a
QuickCache cannot be undone. Any devices that were assigned to the QuickCache you are deleting will
be assigned to no QuickCache.
1. Go to the QuickCaches page and click the name of the QuickCache you want to delete. See
View available QuickCaches on page 135 for details on searching the QuickCache table.
2. On the Manage state tab on the QuickCache page, click Cancel QuickCache.

3. Confirm you want to delete the QuickCache and click OK.

Chapter 13 QuickCache 146


Chapter 14 Single sign-on
Single sign-on allows users to log in using their existing company user name and password. If your
company has a SAML 2.0 compliant identity provider, you can use this service to validate user identity.
When using single sign-on, all logins go to the identity provider. The identity provider passes SAML
tokens to Carbonite Endpoint, which uses the email address in the SAML token to find the user in the
Carbonite Endpoint database. Users' permissions within Carbonite Endpoint are defined by their
Carbonite Endpoint user configuration, not their identity provider configuration.

Users must exist in Carbonite Endpoint even if you are using single sign-on. You can use the
LDAP feature to automatically add users from a company directory. See Manage users with
LDAP on page 85 for details.

If you want to have two-factor authentication, you will need to integrate with a SAML-compliant
single sign-on provider.

The ability to enable and configure single sign-on through the console is hidden by default on all
Carbonite vaults. If you are using another vault, you will need to work with Carbonite Professional
Services to expose single sign-on in the console. Once it is visible in the console, you can enable and
configure it.

The following tasks are available for single sign-on.


l View single sign-on details on page 148
l Enable single sign-on for the first time on page 149
l Edit single sign-on configuration on page 151
l Disable single sign-on for one user on page 153
l Disable single sign-on on page 154

You may want to consider having an admin user in your company that has single sign-on
disabled specifically for that user. That way if there are issues with your single sign-on or your
identity provider, you can still have an admin user who can log in to Carbonite Endpoint. See
Disable single sign-on for one user on page 153 for details.

Chapter 14 Single sign-on 147


View single sign-on details
To view your single sign-on details, go to the Company page and click Single sign-on. You will see the
single sign-on details for your company. (The ability to enable and configure single sign-on through the
console is hidden by default on all Carbonite vaults. If you are using another vault, you will need to work
with Carbonite Professional Services to expose single sign-on in the console. Once it is visible in the
console, you can enable and configure it.)

You have the following toolbar controls available on the Single sign-on tab.
l Disable—Click this button to disable single-sign on. Users will no longer be using the identity
service provider for single sign-on. They will be logging in to Carbonite Endpoint directly.
l Enable—Click this button to re-enable single-sign on that has been disabled. Users will go back
to using the identity service provider for single sign-on.

If you see the Enable button but do not see the identity provider details, you have not yet
configured single sign-on. See Enable single sign-on for the first time on page 149 for
details.

l Edit settings—Click this button to edit the identity provider configuration. See Edit single sign-on
configuration on page 151 for details.

Chapter 14 Single sign-on 148


Enable single sign-on for the first time
The ability to enable and configure single sign-on through the console is hidden by default on all
Carbonite vaults. If you are using another vault, you will need to work with Carbonite Professional
Services to expose single sign-on in the console. Once it is visible in the console, you can enable and
configure it.
1. On the Company page, click Single sign-on.

2. Specify your single sign-on configuration.

After each field description are two examples for Active Directory Federation Services 2.0
(ADFS) and Okta. If you are uncertain about how to configure ADFS or Okta or are using
a different identity provider (Azure AD, Google, and so on), see the documentation for
your identity provider. Okta provides Carbonite Endpoint specific single sign-on
documentation at [Link]
[Link].

Keep in mind that Okta cannot use URLs that contain an underscore. If your identity
provider server has an underscore in the name, you will need to change that before using
Okta for single sign-on.

l Identity provider ID—Specify the ID of the identity provider.


l ADFS—Specify the Federation Service Identifier found in the Federation

Service Properties.

Chapter 14 Single sign-on 149


lOkta—Specify the Identity Provider Issuer found in the View Setup Instructions
on the Sign-On settings for the new application you added using the Okta classic UI.
l Identity provider URL—Specify the URL of your identity provider.

l ADFS—Specify secure http (meaning use [Link] the host name of your ADFS

server, and /adfs/ls. For example, if the identity provider ID is


[Link] then your URL would be
[Link]
l Okta—Specify the Identity Provider Single Sign-On URL found in the View

Setup Instructions on the Sign-On settings for the new application you added
using the Okta classic UI.
l Identity provider certificate—Specify the secure certificate to use with the identity

provider.
l ADFS—Use the exported .cer file from the ADFS server.

l Okta—Use the X.509 certificate downloaded from the View Setup Instructions on

the Sign-On settings for the new application you added using the Okta classic UI.
3. Once the identity provider and certificate are configured, click Save.

Chapter 14 Single sign-on 150


Edit single sign-on configuration
Use the following instructions to edit your single sign-on configuration.
1. Go to the Company page and click Single sign-on.
2. Click Edit settings.
3. Modify the identity provider configuration as needed.

After each field description are two examples for Active Directory Federation Services 2.0
(ADFS) and Okta. If you are uncertain about how to configure ADFS or Okta or are using
a different identity provider (Azure AD, Google, and so on), see the documentation for
your identity provider. Okta provides Carbonite Endpoint specific single sign-on
documentation at [Link]
[Link].

Keep in mind that Okta cannot use URLs that contain an underscore. If your identity
provider server has an underscore in the name, you will need to change that before using
Okta for single sign-on.

l Identity provider ID—Specify the ID of the identity provider.


l ADFS—Specify the Federation Service Identifier found in the Federation

Service Properties.
l Okta—Specify the Identity Provider Issuer found in the View Setup Instructions

on the Sign-On settings for the new application you added using the Okta classic UI.
l Identity provider URL—Specify the URL of your identity provider.
l ADFS—Specify secure http (meaning use [Link] the host name of your ADFS

server, and /adfs/ls. For example, if the identity provider ID is


[Link] then your URL would be
[Link]
l Okta—Specify the Identity Provider Single Sign-On URL found in the View

Setup Instructions on the Sign-On settings for the new application you added
using the Okta classic UI.
l Identity provider certificate—Specify the secure certificate to use with the identity
provider.

Chapter 14 Single sign-on 151


lADFS—Use the exported .cer file from the ADFS server.
l Okta—Use the X.509 certificate downloaded from the View Setup Instructions on

the Sign-On settings for the new application you added using the Okta classic UI.
4. Once the identity provider and certificate are configured, click Save.

Chapter 14 Single sign-on 152


Disable single sign-on for one user
You can disable single sign-on for a specific user, if needed. For example, if there are issues with your
single sign-on or your identity provider. In this case, you can still have an admin user who can log in to
Carbonite Endpoint.
1. Go to the Users page and click the name of the user you want to disable single sign-on for. See
View available users on page 68 for details on searching the user table.
2. On the User details tab on the User page, click Edit user details.
3. Enable Password managed locally.

4. Click Save changes.

Chapter 14 Single sign-on 153


Disable single sign-on
Use the following instructions to disable single sign-on.
1. Go to the Company page and click Single sign-on.
2. Click Disable. When disabled, users will no longer be using the identity service provider for single
sign-on. They will be logging in to Carbonite Endpoint directly.

3. To re-enable single sign-on, click Enable.

Chapter 14 Single sign-on 154

You might also like