Proxmox Backup to NAS: NFS vs SMB Setup and Restore Checklist

Preparation date: September 17, 2026. Scope: This is a documentation-based implementation and verification guide, not a claim about a completed customer incident. It covers ordinary Proxmox VE VZDump backups written to NAS storage. A Proxmox Backup Server datastore is a different architecture and is called out separately. The short answer is: choose NFS when Proxmox is the main consumer and your NAS can restrict the export to the Proxmox node addresses. Choose SMB/CIFS when the same share must also fit a Windows-oriented operating model or your NAS administration is already built around named users and SMB permissions. The protocol choice matters, but the restore test matters more. A green backup task proves that an archive was written; it does not prove that you can recover a VM on replacement storage. Proxmox backup to NAS verification flow A Proxmox node writes a VZDump backup over NFS or SMB to a NAS, then a separate restore test validates recovery. ...

Horizon Screen Protection: Pilot Acceptance Tests and Exceptions

Test the security requirement, not just whether a watermark is visible. This acceptance worksheet is for a Horizon screen-protection pilot after settings have been selected. It is not a completed test report or a second configuration tutorial.

Correction, September 12, 2026: The previous article asserted that every client and capture application would be blocked, and supplied unverified policy paths and variables. The replacement defines separate test surfaces and records exceptions rather than claiming universal enforcement.

Define the pilot boundary

Record exact Client and Agent versions, endpoint OS, desktop or published-app session, display protocol, effective user/machine policies, and the allowed business workflows. Use a small approved group and non-sensitive test documents. The scope should reflect the real devices users will use, not only the administrator's laptop.

Test surfaceRecord separatelyAcceptance question
Endpoint screenshotTool/version, captured surface, watermark visibilityDoes the supported endpoint enforce the intended restriction?
Capture inside the remote desktopRemote application and resulting outputDoes the policy requirement include this distinct path?
Meeting/screen-sharing workflowWhere the meeting application runs and optimization modeIs permitted collaboration usable without exposing restricted content?
Redirected contentBrowser/media redirection configurationDoes the documented exception conflict with the requirement?
Reconnect and another supported endpointFresh session, versions, effective policyIs behavior consistent within the stated support boundary?

Set expected results from documentation

Use the matching release's official feature guidance. The 2406 Agent policy reference documents platform-specific screen-capture behavior and exceptions. The 2309 watermark guide illustrates why a visible overlay is not a guarantee for every recording path. These are version-scoped references, not evidence that an unlisted platform passes.

Write the expected outcome before each test, then record the actual outcome, timestamp, configuration and evidence file. Mark unsupported or untested combinations explicitly. Do not convert an empty result cell into “passed.” Avoid repeatedly capturing real sensitive records just to demonstrate that a control does not cover them.

Decide whether to expand

  • If effective policy is missing, correct delivery and rerun the same test.
  • If behavior matches a documented exception but violates the business requirement, stop expansion and ask the security owner for an alternative supported control or approved access restriction.
  • If a supported combination behaves unexpectedly, preserve logs and a sanitized reproduction for vendor support.
  • If essential support, accessibility, or collaboration breaks, roll back the pilot and review the requirement with the affected owner.

Close the pilot

Keep a record of supported combinations, accepted exceptions, rollout group, policy version, rollback settings, and responsible owner. Recheck after Client/Agent upgrades rather than treating the first pilot as permanent certification. This process can expose a mismatch between a control and a requirement; it cannot guarantee that all screen content is impossible to copy or photograph.

Related troubleshooting guides

Comments

Popular posts from this blog

Horizon vdpConnect_Failure: Connection-Stage Triage Before Reinstalling

Horizon Agent Unreachable: Registration and Desktop-Health Triage

Horizon Protocol Error: Trace the Display-Session Handoff