Running the Transporter on Hardened Windows (MSCT, CIS, STIG)
Product version: 11.2.1
Last modified: 28 August 2026
Problem
On Windows machines hardened with a security baseline, such as a Microsoft Security Compliance Toolkit (MSCT), CIS, or DISA STIG baseline, the behavior of NAKIVO Backup & Replication components can be affected by the baseline policies.
The following issue is known: jobs and inventory operations that involve a Microsoft Hyper-V host hardened with the MSCT baseline fail with an error stating that the username or password is incorrect, although the provided credentials are valid. A "Failed to create secure channel" error may also appear in the product logs.
Background
The MSCT baseline sets the Encryption Oracle Remediation policy to Force Updated Clients. With this policy value, the hardened host rejects the CredSSP authentication used by earlier versions of NAKIVO Backup & Replication, and the Director cannot authenticate to the host.
Running NAKIVO Backup & Replication components on a hardened Windows OS is a best-effort configuration. NAKIVO has verified core Transporter operations on Windows Server 2022 hardened with the MSCT security baseline:
-
Transporter installation, in-place upgrade, and uninstallation
-
Full and incremental backup of Microsoft Hyper-V virtual machines and physical machines
-
Recovery, including Flash Boot, recovery of Microsoft SQL Server objects, and recovery to the hardened host
-
Backup repository creation on the hardened host and backup copy jobs to and from this repository
-
Bandwidth throttling
During this verification, one cosmetic issue was found and resolved: the buttons of the uninstall wizard were rendered too narrow, and their captions were clipped.
Other hardening baselines and operating system versions are not validated configurations: their policies may affect the product in ways not listed in this article.
Solution
If jobs or inventory operations fail with the credentials error described above:
-
Update NAKIVO Backup & Replication to the latest version. For details, see Updating NAKIVO Backup & Replication.
-
After the update, refresh the affected host in Inventory and verify that the host and its virtual machines are accessible.
-
If the issue persists, set the Encryption Oracle Remediation policy on the hardened host to Mitigated and restart the host. The policy is located in Computer Configuration > Administrative Templates > System > Credentials Delegation. Note that this change partially reduces the hardening posture of the host and may require approval from your security team.
Note
Running NAKIVO Backup & Replication components on hardened operating systems is a best-effort configuration. NAKIVO Support can advise on identified limitations but cannot guarantee full functionality on every hardened baseline.