Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 14 Next »

Macrium Image Guardian Overview


______________

Macrium Image Guardian protects your backup files from unauthorised modification.

MIG grants write access to existing backups file for Macrium Reflect 7.1, any image tools created by us, and optionally, MS RoboCopy. All other process attempting to update existing backup files will be denied access.

MIG protects local NTFS volumes and allows Macrium Reflect 7.1 and later to use the protected volume as a shared network resource.

Macrium Image Guardian protection architecture

 


Macrium Image Guardian protecting backups in a networked environment

 



In the above illustration, the PC sharing the backup repository (Shared Volume) has a full install of Macrium Reflect, including MIG. A local drive is shared over the network and MIG has been enabled on that drive in the Macrium Reflect user interface.

The other PC’s on the network can backup to this shared drive and do not require MIG to be installed. Backup file write access is automatically granted to Macrium Reflect 7.1, and later, write access for earlier versions of Macrium Reflect and other processes will fail. 

The PC hosting the share with MIG installed can be used as a standalone Macrium Reflect installation. The protected drive will prevent unauthorised access to backup files on that drive if the local PC creates backups to the protected volume.


Installing Macrium Image Guardian

MIG is an optional component in the Macrium Reflect installer, It is selected by default and is available for Windows 7 and above in all editions of Macrium Reflect except for the Free Edition. 

 

 

After installation, if MIG has automatically protected any local back drives for existing backup definitions then the following message box is displayed the first time Macrium Reflect is started:


Activating Macrium Image Guardian

MIG is active directly after installation and will automatically protect backup destination drives.

To turn MIG on or off, take the 'Other Tasks' > 'Macrium Image Guardian Settings..' menu option:

 

 

Turn on Image GuardianStarts the Image Guardian Service
Automatically protect local backup drives

When turned on, all saved backup definitions are searched and Image Guardian is enabled for local backup drives

When creating a new backups, unprotected target drives will be automatically protected by enabling Image Guardian on the drive.

When the PC is restarted, Image Guardian will be re-enabled on all backup drives. This prevents accidentally leaving your drives unprotected by manually turning protection off.

Allow RoboCopy to sync and move backup files on protected volumes

Enables the MS utility RoboCopy to delete and overwrite backup files on protected volumes with the /MOV, /MOVE, /PURGE and /MIR parameters.


ParameterRule
/MOVE
/MOV

If the source folder is on a protected volume then the /MOVE /MOV parameters will only delete backup files in the source folder if the destination folder is also on a protected volume.

This ensures that existing files cannot be moved to an unprotected volume and compromised.
/MIR
/PURGE

If the target folder is on a protected volume then the the /MIR  /PURGE parameters will only delete backup files in the target folder if both of the following conditions are true:

  1. The source folder is a backup destination in any saved backup definition xml file.
  2. The target folder is not a backup destination in any saved backup defintion xml file

This ensures that the synchronisation operation cannot inadvertently, or otherwise, delete files in a folder that is used as a backup destination in Macrium Reflect.

All overwrite operationsIf the result of any parameter is to overwrite an existing backup file on a protected volume then this will only be allowed if the target folder is not a backup destination in any saved backup definition xml file.

RoboCopy and Network Shares

If the source of a /MOVE /MOV or target of a /MIR /PURGE operation is a MIG protected volume on a network share then all delete operations are blocked. This is because RoboCopy 'Rules' can only be applied if the Windows session that's opening the files is the same Windows session that's running RoboCopy. In the case of a network share, the remote computer is opening the files and will block all delete operations.



 

Off

Turns off the Image Guardian service.

Restart service on rebootThe service will remain 'Off' until the next Windows startup. If not selected the service will remain 'Off' until re-enabled in this dialog.


Macrium Image Guardian Events

To view Image Guardian windows events, take the 'Other Tasks' > 'Macrium Image Guardian Settings..' menu option and select the 'Events' tab:


 

Number

Event NameSeverityDescription

100

EVT_MIG_SERVICE_STARTEDInformationalImage Guardian service started
110EVT_MIG_DRIVER_STARTED_BY_SERVICEInformationalImage Guardian driver started by service
200EVT_MIG_SERVICE_STOPPEDInformationalImage Guardian service stopped
300EVT_MIG_VOLUME_PROTECTEDInformationalVolume (\\?\Volume{6a2d53fe-c79a-11e1-b189-806e6f6e6963}\) is protected
310EVT_MIG_BLOCK_VERIFICATION_FILE_ACCESSInformationalBlocking process (processname.exe) creating verification file as process is not Macrium certified
320EVT_MIG_BLOCKED_FILE_ACCESSWarningBlocked unauthorised process (processname.exe) accessing file (\\?\Volume{6a2d53fe-c79a-11e1-b189-806e6f6e6963}\Folder\filename.mrimg)
330EVT_MIG_USER_PROTECTED_VOLUMEInformationalUser has enabled Image Guardian on volume (\\?\Volume{6a2d53fe-c79a-11e1-b189-806e6f6e6963}\)
340EVT_MIG_USER_DISABLED_VOLUMEInformationalUser has disabled Image Guardian on volume (\\?\Volume{6a2d53fe-c79a-11e1-b189-806e6f6e6963}\)
500EVT_MIG_ERROR_BAD_EVENTErrorError could not open Image Guardian verification event. Error code = 123
510EVT_MIG_ERROR_PROTECTING_VOLUMEErrorError protecting volume (\\?\Volume{6a2d53fe-c79a-11e1-b189-806e6f6e6963}\). Error code = 123
520EVT_MIG_ERROR_UNPROTECTING_VOLUMEErrorError unprotecting volume (\\?\Volume{6a2d53fe-c79a-11e1-b189-806e6f6e6963}\). Error code = 123
When an unauthorised process attempts to write to, delete or rename a Macrium backup file the action will be blocked and Windows Event 320 will be generated


 

 

 

  • No labels