Isolate and protect the underlying SQL Server database hosting your ePO assets, policies, and event data.
Enforce least privilege: Configure the SQL Server account used by ePO for daily operations with limited permissions restricted to the Public and db_execute role, see KB75766.
Use custom database ports: Configure SQL Server to use a custom static port instead of the default port 1433. This prevents automated scanners from easily identifying your database. For detailed configuration steps, see Configuring a custom SQL Server port for Trellix ePO.
Execute disaster recovery (DR): Back up the database daily. Verify that the ePO Disaster Recovery snapshot task completes successfully before performing database backups, and rotate the DR passphrase Periodically. For task configuration details, see Disaster Recovery and Configure Disaster Recovery Server Task.