Hardening Commvault installation directory restricts Access Control Lists (ACLs) on the files and directories created by Commvault installer to only the users and principals that require access. Combining this with the least privilege principle helps secure Commvault installation.
New Commvault installations are automatically hardened. Existing installations aren't hardened during upgrades. To harden an existing installation, run this command from the Base directory under Commvault installation directory:
CVHardening -Instance <instance_name> -Mode FSHardening
Note
For Windows operating systems, launch Command Prompt or PowerShell as Administrator, then run the command.
For Linux or UNIX operating systems, run the command as root or with equivalent elevated privileges.