{"id":2059,"date":"2026-08-20T09:55:20","date_gmt":"2026-08-20T09:55:20","guid":{"rendered":"https:\/\/integrationobjects.com\/blog\/?p=2059"},"modified":"2026-08-21T15:13:38","modified_gmt":"2026-08-21T15:13:38","slug":"hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments","status":"publish","type":"post","link":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/","title":{"rendered":"Hardening OPC Easy Archiver: Security Best Practices for Industrial Deployments"},"content":{"rendered":"  \r\n    \r\n<div id=\"wpj-jtoc\" class=\"wpj-jtoc wpj-jtoc--main --jtoc-the-content --jtoc-theme-original-v3 --jtoc-title-align-left --jtoc-toggle-icon --jtoc-toggle-position-right --jtoc-toggle-1 --jtoc-has-numeration --jtoc-header-as-toggle --jtoc-headings-full-row-clickable --jtoc-text-hover-soft --jtoc-has-custom-styles --jtoc-is-unfolded --jtoc-animate --jtoc-align-left\" >\r\n  <!-- TOC -->\r\n        <div class=\"wpj-jtoc--toc wpj-jtoc--toc-inline \" >\r\n              <div class=\"wpj-jtoc--header\">\r\n        <div class=\"wpj-jtoc--header-main\">\r\n                    <div class=\"wpj-jtoc--title\">\r\n                        <span class=\"wpj-jtoc--title-label\">Table of contents<\/span>\r\n          <\/div>\r\n                                <div class=\"wpj-jtoc--toggle-wrap\">\r\n                                                          <div class=\"wpj-jtoc--toggle-box\">\r\n                  <div class=\"wpj-jtoc--toggle\"><\/div>\r\n                <\/div>\r\n                          <\/div>\r\n                  <\/div>\r\n      <\/div>\r\n            <div class=\"wpj-jtoc--body\">\r\n            <nav class=\"wpj-jtoc--nav\">\r\n        <ol class=\"wpj-jtoc--items\"><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--1--><\/span>        <a href=\"#why-hardening-matters\"  rel=\"nofollow\"  title=\"Why Hardening Matters\" data-numeration=\"1\">Why Hardening Matters<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--2--><\/span>        <a href=\"#harden-the-host-system\"  rel=\"nofollow\"  title=\"Harden the Host System\" data-numeration=\"2\">Harden the Host System<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--3--><\/span>        <a href=\"#secure-remote-opc-communications\"  rel=\"nofollow\"  title=\"Secure Remote OPC Communications\" data-numeration=\"3\">Secure Remote OPC Communications<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--4--><\/span>        <a href=\"#use-a-dedicated-windows-service-account\"  rel=\"nofollow\"  title=\"Use a Dedicated Windows Service Account\" data-numeration=\"4\">Use a Dedicated Windows Service Account<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--5--><\/span>        <a href=\"#apply-least-privilege-to-database-accounts\"  rel=\"nofollow\"  title=\"Apply Least Privilege to Database Accounts\" data-numeration=\"5\">Apply Least Privilege to Database Accounts<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--6--><\/span>        <a href=\"#secure-database-connections\"  rel=\"nofollow\"  title=\"Secure Database Connections\" data-numeration=\"6\">Secure Database Connections<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--7--><\/span>        <a href=\"#do-not-install-unused-features\"  rel=\"nofollow\"  title=\"Do not Install Unused Features\" data-numeration=\"7\">Do not Install Unused Features<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--8--><\/span>        <a href=\"#minimize-opc-server-permissions\"  rel=\"nofollow\"  title=\"Minimize OPC Server Permissions\" data-numeration=\"8\">Minimize OPC Server Permissions<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--9--><\/span>        <a href=\"#protect-your-opc-easy-archiver-configuration\"  rel=\"nofollow\"  title=\"Protect Your OPC Easy Archiver Configuration\" data-numeration=\"9\">Protect Your OPC Easy Archiver Configuration<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--10--><\/span>        <a href=\"#protect-windows-services\"  rel=\"nofollow\"  title=\"Protect Windows Services\" data-numeration=\"10\">Protect Windows Services<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--11--><\/span>        <a href=\"#secure-dcom-opc-classic\"  rel=\"nofollow\"  title=\"Secure DCOM (OPC Classic)\" data-numeration=\"11\">Secure DCOM (OPC Classic)<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--12--><\/span>        <a href=\"#restrict-firewall-rules\"  rel=\"nofollow\"  title=\"Restrict Firewall Rules\" data-numeration=\"12\">Restrict Firewall Rules<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--13--><\/span>        <a href=\"#monitor-storage-capacity\"  rel=\"nofollow\"  title=\"Monitor Storage Capacity\" data-numeration=\"13\">Monitor Storage Capacity<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--14--><\/span>        <a href=\"#secure-archived-data\"  rel=\"nofollow\"  title=\"Secure Archived Data\" data-numeration=\"14\">Secure Archived Data<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--15--><\/span>        <a href=\"#use-change-based-collection-where-appropriate\"  rel=\"nofollow\"  title=\"Use Change-Based Collection Where Appropriate\" data-numeration=\"15\">Use Change-Based Collection Where Appropriate<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--16--><\/span>        <a href=\"#validate-automatic-recovery-behavior\"  rel=\"nofollow\"  title=\"Validate Automatic Recovery Behavior\" data-numeration=\"16\">Validate Automatic Recovery Behavior<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--17--><\/span>        <a href=\"#periodically-review-configuration\"  rel=\"nofollow\"  title=\"Periodically Review Configuration\" data-numeration=\"17\">Periodically Review Configuration<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--18--><\/span>        <a href=\"#hardening-checklist\"  rel=\"nofollow\"  title=\"Hardening Checklist\" data-numeration=\"18\">Hardening Checklist<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--19--><\/span>        <a href=\"#modernize-your-data-archiving-with-siothr\"  rel=\"nofollow\"  title=\"Modernize Your Data Archiving with SIOTH\u00ae\" data-numeration=\"19\">Modernize Your Data Archiving with SIOTH\u00ae<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--20--><\/span>        <a href=\"#conclusion\"  rel=\"nofollow\"  title=\"Conclusion\" data-numeration=\"20\">Conclusion<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--21--><\/span>        <a href=\"#frequently-asked-questions\"  rel=\"nofollow\"  title=\"Frequently Asked Questions\" data-numeration=\"21\">Frequently Asked Questions<\/a>\r\n                    <\/div><\/li><\/ol>      <\/nav>\r\n          <\/div>\r\n      <\/div>\r\n    <\/div>\r\n\n<style>.site-main ol{padding-left:15px;font-weight:900;}thead tr{background:linear-gradient(135deg,#fff5f0 0,#fef2ed 100%)}th{padding:.875rem 1.25rem;text-align:left;font-weight:600;font-size:12px;text-transform:capitalize;letter-spacing:.6px;color:#de5d2a;border:1px solid #de5d2a;border-bottom:2px solid #de5d2a}th:first-child{padding-left:1.5rem;border-left:4px solid #de5d2a !important}td{padding:1.125rem 1.25rem;border:1px solid #e8d4c8;vertical-align:top;transition:background-color .2s ease}tbody tr:nth-child(odd){background:#fff}tbody tr:nth-child(even){background:#fffbf8}tbody tr:hover{background:#fff0e8}td:first-child{border-left:4px solid #de5d2a !important;font-weight:600;width:18%;min-width:140px;padding-left:1.5rem;color:#1a1a1a}tbody tr:nth-child(3n+1) td:first-child{border-left-color:#de5d2a}tbody tr:nth-child(3n+2) td:first-child{border-left-color:#d4481a}tbody tr:nth-child(3n) td:first-child{border-left-color:#c23010}td:last-child{width:82%;color:#2d2d2d}@media (max-width:640px){table{font-size:14px}td,th{padding:.75rem .875rem}td:first-child,th:first-child{padding-left:.875rem}td:first-child{width:25%;min-width:110px}td:last-child{width:75%}.io-title{font-size:16px}}<\/style>\n<p>Hardening <a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-data-archiving\/opc-easy-archiver\">OPC Easy Archiver<\/a> means reducing its attack surface across five layers: the Windows host it runs on, the Windows service and database accounts it uses, its network communications (including DCOM for remote OPC Classic connections), its configuration and GUI access, and the archived data itself.<\/p>\n<p>Industrial data historians and archivers often become a bridge between operational technology (OT) and enterprise IT. As such, an improperly configured archiver can become an attractive target for attackers seeking access to industrial data or control systems.<\/p>\n<p>This article provides practical recommendations for securely deploying and operating <a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-data-archiving\/opc-easy-archiver\">OPC Easy Archiver<\/a> in production environments. The recommendations are based on industrial cybersecurity best practices (<a href=\"https:\/\/integrationobjects.com\/blog\/legacy-ot-cyber-security-best-practices-for-connecting-legacy-operational-technology-systems\/\">IEC 62443<\/a>, NIST CSF) and the capabilities of the OPC Easy Archiver product, as well as Integration Objects\u2019 extensive experience delivering industrial connectivity and OT cybersecurity solutions.<\/p>\n<p style=\"text-align: center;\"><a id=\"download\" class=\"btn_product_download\" href=\"https:\/\/integrationobjects.com\/download\/sioth-opc\/sioth-opc-data-archiving\/opc-easy-archiver?code=25&amp;name=OPC+Easy+Archiver&amp;product=sioth-opc%2Fsioth-opc-data-archiving%2Fopc-easy-archiver\" target=\"_blank\" rel=\"noopener\"><strong>Download OPC Easy Archiver for Free<\/strong><\/a><\/p>\n<h3>Why Hardening Matters<\/h3>\n<p>OPC Easy Archiver typically has access to:<\/p>\n<ul>\n<li>Multiple OPC DA, HDA and AE servers<\/li>\n<li>SQL databases<\/li>\n<li>Real-time production data<\/li>\n<li>Historical production data<\/li>\n<li>Alarm and event information<\/li>\n<\/ul>\n<p>Compromise of the archiver or its host system could expose sensitive operational data, disrupt data collection, or provide attackers with a pivot point into the OT environment.<\/p>\n<ol>\n<li>\n<h2>Harden the Host System<\/h2>\n<\/li>\n<\/ol>\n<p>OPC Easy Archiver is primarily an archiving service that runs on Microsoft Windows. Consequently, it relies on the host operating system for user authentication, authorization, access control, and many other platform-level security functions. Therefore, hardening an OPC Easy Archiver deployment begins with hardening the underlying Windows host.<\/p>\n<p>Apply your organization&#8217;s Windows security baseline, including:<\/p>\n<ul>\n<li>Install the latest security updates and patches.<\/li>\n<li>Remove or disable unnecessary software, services, and features.<\/li>\n<li>Restrict local and remote administrative access.<\/li>\n<li>Enable Windows Defender or an equivalent endpoint protection solution.<\/li>\n<li>Enable audit logging and forward security events to a centralized logging or SIEM solution where applicable.<\/li>\n<li>Restrict access to the installation and configuration directories using NTFS permissions.<\/li>\n<li>Apply security policies in accordance with your organization&#8217;s standards (e.g. password policies, account lockout, and device control).<\/li>\n<\/ul>\n<ol start=\"2\">\n<li>\n<h2>Secure Remote OPC Communications<\/h2>\n<\/li>\n<\/ol>\n<p>OPC Easy Archiver natively uses OPC Classic to collect industrial data. For remote OPC connections, OPC Classic relies on Microsoft <a href=\"https:\/\/integrationobjects.com\/blog\/what-is-dcom\/\">DCOM<\/a>, which presents both security and configuration challenges. As a best practice, deploy OPC Easy Archiver together with <a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-tunneling\/opcnet-broker-da-hda-ae\">OPCNet Broker (ONB).<\/a> OPCNet Broker securely tunnels OPC Classic communications over a single configurable TCP port, <a href=\"https:\/\/integrationobjects.com\/blog\/dcom-vulnerability-opc-alarm-systems\/\">eliminating the need for DCOM<\/a> across the network while providing encrypted communications and authenticated connections between OPC clients and servers. This approach simplifies firewall configuration and significantly strengthens the security of remote OPC deployments.<\/p>\n<p>Recommended architecture:<\/p>\n<figure id=\"attachment_2060\" aria-describedby=\"caption-attachment-2060\" style=\"width: 240px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2060\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-opcnet-broker-secure-architecture.png\" alt=\"Recommended secure architecture: OPCNet Broker tunneling OPC Classic data from the OT network to OPC Easy Archiver in the industrial DMZ \" width=\"240\" height=\"461\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-opcnet-broker-secure-architecture.png 240w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-opcnet-broker-secure-architecture-156x300.png 156w\" sizes=\"auto, (max-width: 240px) 100vw, 240px\" \/><figcaption id=\"caption-attachment-2060\" class=\"wp-caption-text\">Figure 1: Recommended OPC Easy Archiver architecture. OPCNet Broker tunnels OPC Classic between the OT network and the industrial DMZ, removing DCOM from the enterprise-facing path.<\/figcaption><\/figure>\n<p>Best practices:<\/p>\n<ul>\n<li>Separate OT from IT using firewalls.<\/li>\n<li>Allow only required communications.<\/li>\n<li>Never expose OPC Classic\/DCOM directly and outside the OT network.<\/li>\n<li>Avoid installing OPC Easy Archiver directly on business network workstations.<\/li>\n<\/ul>\n<ol start=\"3\">\n<li>\n<h2>Use a Dedicated Windows Service Account<\/h2>\n<\/li>\n<\/ol>\n<p>OPC Easy Archiver runs as Windows services. Do not run these services using:<\/p>\n<ul>\n<li>Local System<\/li>\n<li>Local Administrator<\/li>\n<li>Domain Administrator<\/li>\n<\/ul>\n<p>Instead:<\/p>\n<ul>\n<li>Create a dedicated service account.<\/li>\n<li>Grant only the permissions required to:\n<ul>\n<li>Connect to OPC servers<\/li>\n<li>Access the configured databases<\/li>\n<li>Access with read\/write to the OPC Easy Archiver installation folder<\/li>\n<li>Access with read\/write to the Windows registry<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Example: DOMAIN\\svc_OPCArchiver<\/p>\n<p>Permissions:<\/p>\n<p>\u2713 Log on as service<\/p>\n<p>\u2713 Database access<\/p>\n<p>\u2713 OPC access<\/p>\n<p>\u2717 Interactive logon<\/p>\n<p>\u2717 Local administrator<\/p>\n<ol start=\"4\">\n<li>\n<h2>Apply Least Privilege to Database Accounts<\/h2>\n<\/li>\n<\/ol>\n<p>Avoid using: sa, root, postgres, SYSTEM accounts<\/p>\n<p>Instead create a dedicated account such as: opc_archiver<\/p>\n<p>Grant only:<\/p>\n<ul>\n<li>INSERT<\/li>\n<li>UPDATE<\/li>\n<li>SELECT<\/li>\n<\/ul>\n<p>Avoid granting:<\/p>\n<ul>\n<li>ALTER<\/li>\n<li>CREATE DATABASE<\/li>\n<li>DROP TABLE<\/li>\n<li>sysadmin<\/li>\n<\/ul>\n<ol start=\"5\">\n<li>\n<h2>Secure Database Connections<\/h2>\n<\/li>\n<\/ol>\n<p>Whenever supported by the database platform:<\/p>\n<ul>\n<li>Enable TLS encryption<\/li>\n<li>Require certificate validation<\/li>\n<li>Disable anonymous database access<\/li>\n<li>Restrict SQL access using firewall rules<\/li>\n<\/ul>\n<p>Configure the database server to accept connections only from authorized hosts. Ensure that the OPC Easy Archiver host is explicitly authorized to connect, while blocking access from untrusted systems.<\/p>\n<p>For example, if you are using a remote <a href=\"https:\/\/integrationobjects.com\/blog\/opc-data-logger\/\">SQL database<\/a> server, communications between the OPC Easy Archiver and SQL can be protected using TLS to prevent interception or tampering. This is a configuration enabled on both SQL server and in the OPC Easy Archiver connection settings.<\/p>\n<figure id=\"attachment_2061\" aria-describedby=\"caption-attachment-2061\" style=\"width: 452px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-2061\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-encrypt-sql-connection-option.png\" alt=\"Encrypt connection checkbox in the OPC Easy Archiver Add New DA Archiver Wizard for SQL Server\" width=\"452\" height=\"345\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-encrypt-sql-connection-option.png 671w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-encrypt-sql-connection-option-300x229.png 300w\" sizes=\"auto, (max-width: 452px) 100vw, 452px\" \/><figcaption id=\"caption-attachment-2061\" class=\"wp-caption-text\">Figure 2: Encrypt Connection Option in OPC Easy Archiver<\/figcaption><\/figure>\n<ol start=\"6\">\n<li>\n<h2>Do not Install Unused Features<\/h2>\n<\/li>\n<\/ol>\n<p>Unused functionality represents unnecessary attack surface. When installing the OPC Easy Archiver, select the required features only.<\/p>\n<figure id=\"attachment_2062\" aria-describedby=\"caption-attachment-2062\" style=\"width: 510px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-2062\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-installer-select-features.png\" alt=\" Feature selection screen in the OPC Easy Archiver InstallShield installer\" width=\"510\" height=\"382\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-installer-select-features.png 691w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-installer-select-features-300x225.png 300w\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" \/><figcaption id=\"caption-attachment-2062\" class=\"wp-caption-text\">Figure 3: Features Selection During OPC Easy Archiver Installation<\/figcaption><\/figure>\n<ol start=\"7\">\n<li>\n<h2>Minimize OPC Server Permissions<\/h2>\n<\/li>\n<\/ol>\n<p>Only configure access to the OPC servers that are actually required.<\/p>\n<p>Avoid:<\/p>\n<ul>\n<li>Browsing unnecessary servers<\/li>\n<li>Connecting to unused remote OPC servers<\/li>\n<\/ul>\n<p>Only subscribe to:<\/p>\n<ul>\n<li>Required OPC tags<\/li>\n<li>Required AE subscriptions<\/li>\n<\/ul>\n<p>Reducing the attack surface also improves performance.<\/p>\n<ol start=\"8\">\n<li>\n<h2>Protect Your OPC Easy Archiver Configuration<\/h2>\n<\/li>\n<\/ol>\n<p>Recommendations:<\/p>\n<ul>\n<li>Backup your XML and oda configuration files<\/li>\n<li>Do <strong><u>not<\/u><\/strong> keep the graphical configuration environment open. Once you configure your connections and archivers, you may close the GUI. The services will remain working in the background.<\/li>\n<li>Lock access to the graphical configuration environment to avoid unauthorized access or changes by enabling the built-in GUI authentication feature to help prevent unauthorized configuration changes. This feature complements, but does not replace, Windows authentication and file system permissions.<\/li>\n<\/ul>\n<figure id=\"attachment_2063\" aria-describedby=\"caption-attachment-2063\" style=\"width: 342px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2063\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-enable-user-authentication-gui.png\" alt=\"Enable user authentication checkbox in OPC Easy Archiver admin credential settings\" width=\"342\" height=\"384\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-enable-user-authentication-gui.png 342w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-enable-user-authentication-gui-267x300.png 267w\" sizes=\"auto, (max-width: 342px) 100vw, 342px\" \/><figcaption id=\"caption-attachment-2063\" class=\"wp-caption-text\">Figure 4: Enable User Authentication in OPC Easy Archiver<\/figcaption><\/figure>\n<p>This will prompt the user to login whenever he opens the configuration GUI:<\/p>\n<figure id=\"attachment_2064\" aria-describedby=\"caption-attachment-2064\" style=\"width: 406px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2064\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-configuration-login-window.png\" alt=\"OPC Easy Archiver login window shown when opening the configuration GUI with authentication enabled\" width=\"406\" height=\"168\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-configuration-login-window.png 406w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/opc-easy-archiver-configuration-login-window-300x124.png 300w\" sizes=\"auto, (max-width: 406px) 100vw, 406px\" \/><figcaption id=\"caption-attachment-2064\" class=\"wp-caption-text\">Figure 5:Login Window When Opening OPC Easy Archiver GUI<\/figcaption><\/figure>\n<ol start=\"9\">\n<li>\n<h2>Protect Windows Services<\/h2>\n<\/li>\n<\/ol>\n<p>Ensure:<\/p>\n<ul>\n<li>Only administrators can stop services.<\/li>\n<li>Service recovery actions are configured.<\/li>\n<li>Unexpected service termination generates alerts.<\/li>\n<\/ul>\n<p>Recommended recovery:<\/p>\n<ul>\n<li>First failure \u2192 Restart service<\/li>\n<li>Second failure \u2192 Restart service<\/li>\n<li>Subsequent failures \u2192 Restart service<\/li>\n<\/ul>\n<ol start=\"10\">\n<li>\n<h2>Secure DCOM (OPC Classic)<\/h2>\n<\/li>\n<\/ol>\n<p>Because OPC Easy Archiver communicates with OPC Classic servers, <a href=\"https:\/\/integrationobjects.com\/blog\/what-is-dcom\/\">DCOM security<\/a> is important.<\/p>\n<p>Recommendations:<\/p>\n<ul>\n<li>Restrict Launch Permissions<\/li>\n<li>Restrict Access Permissions<\/li>\n<li>Restrict Configuration Permissions<\/li>\n<li>Remove Everyone permissions<\/li>\n<li>Remove Anonymous access<\/li>\n<li>Limit Remote Activation<\/li>\n<\/ul>\n<p>Having said that, refer to the section \u201cSecure Remote OPC Communications\u201d for a secure replacement of DCOM.<\/p>\n<p>If remote OPC communications are unnecessary, disable remote DCOM access.<\/p>\n<ol start=\"11\">\n<li>\n<h2>Restrict Firewall Rules<\/h2>\n<\/li>\n<\/ol>\n<p>Only allow required ports.<\/p>\n<p>Examples:<\/p>\n<ul>\n<li>SQL Server<\/li>\n<li>Oracle<\/li>\n<li>PostgreSQL<\/li>\n<li>MySQL<\/li>\n<li>Required DCOM traffic (if unavoidable)<\/li>\n<li>Required ONB tunnel<\/li>\n<\/ul>\n<p>Block all other inbound connections.<\/p>\n<ol start=\"12\">\n<li>\n<h2>Monitor Storage Capacity<\/h2>\n<\/li>\n<\/ol>\n<p>An archiver can stop archiving data if storage becomes exhausted.<\/p>\n<p>Monitor:<\/p>\n<ul>\n<li>Disk utilization<\/li>\n<li>Database growth<\/li>\n<li>CSV storage<\/li>\n<li>Log file size<\/li>\n<\/ul>\n<p>Configure alerts before reaching critical thresholds.<\/p>\n<p>In such cases, OPC Easy Archiver will store the collected data in local flat files to be used later for data recovery when issues with database servers are resolved.<\/p>\n<ol start=\"13\">\n<li>\n<h2>Secure Archived Data<\/h2>\n<\/li>\n<\/ol>\n<p>Historical production data may contain sensitive operational information.<\/p>\n<p>Protect it using:<\/p>\n<ul>\n<li>Database access controls<\/li>\n<li>Encryption at rest (where supported)<\/li>\n<li>Secure backups<\/li>\n<li>Retention policies<\/li>\n<li>Audit logging<\/li>\n<\/ul>\n<ol start=\"14\">\n<li>\n<h2>Use Change-Based Collection Where Appropriate<\/h2>\n<\/li>\n<\/ol>\n<p>When possible, use <strong>OnDataChange<\/strong> subscriptions instead of aggressive polling when configuring your OPC groups in the OPC Easy Archiver.<\/p>\n<p>Benefits include:<\/p>\n<ul>\n<li>Reduced network traffic<\/li>\n<li>Lower CPU utilization<\/li>\n<li>Smaller database footprint<\/li>\n<li>Reduced risk of overwhelming OPC servers<\/li>\n<\/ul>\n<p>OPC Easy Archiver supports OnDataChange, synchronous, and asynchronous read modes for OPC DA communications.<\/p>\n<ol start=\"15\">\n<li>\n<h2>Validate Automatic Recovery Behavior<\/h2>\n<\/li>\n<\/ol>\n<p>OPC Easy Archiver supports the following features to assist users to manage network or database outages<\/p>\n<ul>\n<li>Automatic reconnection<\/li>\n<li>Store-and-forward buffering<\/li>\n<li>Manual recovery capabilities<\/li>\n<\/ul>\n<p>Regularly test:<\/p>\n<ul>\n<li>Database outages<\/li>\n<li>OPC server failures<\/li>\n<li>Network interruptions<\/li>\n<li>Recovery after restart<\/li>\n<\/ul>\n<p>This helps ensure data integrity during fault conditions.<\/p>\n<ol start=\"16\">\n<li>\n<h2>Periodically Review Configuration<\/h2>\n<\/li>\n<\/ol>\n<p>At least annually, verify:<\/p>\n<ul>\n<li>Unused OPC connections removed<\/li>\n<li>Service account permissions<\/li>\n<li>Database permissions<\/li>\n<li>Firewall rules<\/li>\n<li>User accounts<\/li>\n<li>Windows updates<\/li>\n<li>Latest configuration backups<\/li>\n<\/ul>\n<p>If you are using the rules feature in the OPC Easy Archiver, review all rules periodically to ensure they remain necessary and behave as intended.<\/p>\n<h2>Hardening Checklist<\/h2>\n<table style=\"height: 673px;\" width=\"619\">\n<tbody>\n<tr style=\"background: linear-gradient(135deg, #fff5f0 0%, #fef2ed 100%); font size: 18px;\">\n<th style=\"font-size: 16px; font-weight: 800; font-family: 'Poppins';\">Area<\/th>\n<th style=\"font-size: 16px; font-weight: 800; font-family: 'Poppins';\">Recommendation<\/th>\n<\/tr>\n<tr>\n<td>Windows Services<\/td>\n<td>Use dedicated least-privilege service account<\/td>\n<\/tr>\n<tr>\n<td>Database<\/td>\n<td>Dedicated account with minimal privileges<\/td>\n<\/tr>\n<tr>\n<td>Network<\/td>\n<td>Deploy behind industrial firewalls<\/td>\n<\/tr>\n<tr>\n<td>DCOM<\/td>\n<td>Eliminate DCOM configuration complexity and vulnerabilities by using OPCNet Broker tunneling product<\/td>\n<\/tr>\n<tr>\n<td>Firewall<\/td>\n<td>Open only required ports<\/td>\n<\/tr>\n<tr>\n<td>OPC Servers<\/td>\n<td>Connect only to required servers and tags<\/td>\n<\/tr>\n<tr>\n<td>Database Connections<\/td>\n<td>Use encrypted connections where supported<\/td>\n<\/tr>\n<tr>\n<td>Logging<\/td>\n<td>Enable Windows auditing and centralized log collection<\/td>\n<\/tr>\n<tr>\n<td>Updates<\/td>\n<td>Keep Windows, dependencies, and OPC Easy Archiver current<\/td>\n<\/tr>\n<tr>\n<td>Backup<\/td>\n<td>Regularly back up configuration and archived data<\/td>\n<\/tr>\n<tr>\n<td>Storage<\/td>\n<td>Monitor disk and database growth<\/td>\n<\/tr>\n<tr>\n<td>Access Control<\/td>\n<td>Limit administrative and OPC Easy Archiver configuration access to authorized personnel<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Modernize Your Data Archiving with SIOTH\u00ae<\/h2>\n<p>Need an archiver with native OPC UA connectivity? SIOTH\u00ae is designed for modern industrial systems, enabling you to securely collect real-time data, historical data, and alarms &amp; events from OPC UA servers and archive them in SQL-compatible databases. With native OPC UA support, SIOTH eliminates the complexity of OPC Classic and DCOM while providing a secure and scalable foundation for industrial data management.<\/p>\n<p style=\"text-align: center;\"><a id=\"download\" class=\"btn_product_download\" href=\"https:\/\/integrationobjects.com\/sioth\" target=\"_blank\" rel=\"noopener\"><strong>See SIOTH\u00ae in Action<\/strong><\/a><\/p>\n<h2>Conclusion<\/h2>\n<p>Although OPC Easy Archiver is primarily a lightweight OPC Classic data collection service rather than a user-facing application, it occupies a critical position between industrial control systems and data repositories. Hardening its Windows host, service accounts, network connectivity, database access, and operational configuration significantly reduces cybersecurity risk while improving the reliability and integrity of archived industrial data.<\/p>\n<p>Following these recommendations also helps organizations align with the cybersecurity principles of IEC 62443, and common industrial security best practices, even where specific controls are implemented through the underlying Windows operating system rather than the application itself.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<style>#sp-ea-2065 .spcollapsing { height: 0; overflow: hidden; transition-property: height;transition-duration: 300ms;}#sp-ea-2065.sp-easy-accordion>.sp-ea-single {margin-bottom: 10px; border: 1px solid #e2e2e2; }#sp-ea-2065.sp-easy-accordion>.sp-ea-single>.ea-header a {color: #444;}#sp-ea-2065.sp-easy-accordion>.sp-ea-single>.sp-collapse>.ea-body {background: #fff; color: #444;}#sp-ea-2065.sp-easy-accordion>.sp-ea-single {background: #eee;}#sp-ea-2065.sp-easy-accordion>.sp-ea-single>.ea-header a .ea-expand-icon { float: left; color: #444;font-size: 16px;}.sp-easy-accordion .sp-ea-single .ea-header a{\r\n  display: block;\r\n    text-decoration: none;\r\n    cursor: pointer;\r\n    font-weight: 600;\r\n    color: #444;\r\n    font-size: 16px;\r\n    line-height: 1;\r\n  box-shadow: none;}<\/style><div id=\"sp_easy_accordion-1787306681\"><div id=\"sp-ea-2065\" class=\"sp-ea-one sp-easy-accordion\" data-ea-active=\"ea-click\" data-ea-mode=\"vertical\" data-preloader=\"\" data-scroll-active-item=\"\" data-offset-to-scroll=\"0\"><div class=\"ea-card ea-expand sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20650\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20650\" aria-controls=\"collapse20650\" href=\"#\" aria-expanded=\"true\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-minus\"><\/i> Do I need OPCNet Broker\u00ae (ONB\u00ae) to secure OPC Easy Archiver, or is it optional?<\/a><\/h3><div class=\"sp-collapse spcollapse collapsed show\" id=\"collapse20650\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20650\"> <div class=\"ea-body\"><p>It's not strictly required, but it's the recommended approach for any deployment involving remote OPC connections. Without ONB, OPC Easy Archiver falls back to native DCOM, which requires more complex, error-prone Windows security configuration and exposes more attack surface across the network. If OPC Easy Archiver only connects to local OPC servers on the same host, DCOM isn't in play and ONB isn't necessary.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20651\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20651\" aria-controls=\"collapse20651\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Can I run OPC Easy Archiver without any Windows domain, using local accounts only?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20651\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20651\"> <div class=\"ea-body\"><p>Yes. A dedicated local service account with least-privilege permissions works the same way a domain account does. The important part is that the account isn't Local System, Local Administrator, or any other broad-privilege account, regardless of whether it's local or domain-based.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20652\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20652\" aria-controls=\"collapse20652\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> What happens to data collection if the database becomes unreachable?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20652\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20652\"> <div class=\"ea-body\"><p>OPC Easy Archiver's store-and-forward capability keeps collecting to local flat files during the outage, then recovers the buffered data into the database once connectivity is restored. This is why monitoring local disk capacity (Section 12) matters as much as monitoring the database itself. If local storage fills up during an extended outage, data loss becomes possible.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20653\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20653\" aria-controls=\"collapse20653\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Is TLS encryption for database connections mandatory?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20653\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20653\"> <div class=\"ea-body\"><p>It should be treated as mandatory whenever the database is on a separate host from OPC Easy Archiver, since that traffic crosses the network and could be intercepted.<\/p><p>Having said that, from a technical perspective, it is not inherently mandatory for every deployment. Some organizations may rely on other controls, such as a fully isolated network segment, VPN\/IPsec encryption, physical network protections, or strict access controls.<\/p><p>If the database runs locally on the same machine, the risk is lower, but enabling TLS is still good practice wherever the database platform supports it.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20654\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20654\" aria-controls=\"collapse20654\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Does hardening DCOM mean OPC Easy Archiver will stop working with older OPC DA servers?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20654\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20654\"> <div class=\"ea-body\"><p>It can, if those servers were built against outdated DCOM authentication defaults and don't support the hardened authentication levels Microsoft now enforces. This is one of the main reasons this guide recommends replacing DCOM with ONB tunneling rather than trying to fully harden DCOM itself. Tunneling sidesteps the compatibility problem entirely instead of requiring every legacy OPC server on the network to support modern DCOM security settings.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20655\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20655\" aria-controls=\"collapse20655\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> How often should the hardening checklist actually be reviewed?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20655\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20655\"> <div class=\"ea-body\"><p>At minimum, annually, per Section 16,\u00a0 but any change to the environment should trigger an out-of-cycle review too: a new OPC server added, a service account permission change, a new firewall rule, or a Windows or OPC Easy Archiver version upgrade.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20656\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20656\" aria-controls=\"collapse20656\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Does this guide cover OPC UA deployments, or only OPC Classic?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20656\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20656\"> <div class=\"ea-body\"><p>This guide is specifically for OPC Easy Archiver's native OPC Classic (DA\/HDA\/AE) connectivity, since that's where DCOM and its associated hardening challenges apply.<\/p><p>For OPC UA support, you may combine OPC Easy Archiver with <a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-unified-architecture\/opc-ua-proxy\">OPC UA Proxy<\/a> product.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20657\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20657\" aria-controls=\"collapse20657\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Is enabling user authentication on the configuration GUI enough to prevent unauthorized changes?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20657\" data-parent=\"#sp-ea-2065\" role=\"region\" aria-labelledby=\"ea-header-20657\"> <div class=\"ea-body\"><p>It prevents unauthorized access to the configuration interface, but it doesn't replace OS-level access control. Anyone with sufficient Windows privileges on the host could still stop services, modify configuration files directly, or alter permissions outside the GUI, which is why Sections 1, 3, and 8 all need to be applied together rather than relying on any single control.<\/p><\/div><\/div><\/div><script type=\"application\/ld+json\">{ \"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"@id\": \"sp-ea-schema-2065-6aae920e3c57a\", \"mainEntity\": [{ \"@type\": \"Question\", \"name\": \"Do I need OPCNet Broker\u00ae (ONB\u00ae) to secure OPC Easy Archiver, or is it optional?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"It's not strictly required, but it's the recommended approach for any deployment involving remote OPC connections. Without ONB, OPC Easy Archiver falls back to native DCOM, which requires more complex, error-prone Windows security configuration and exposes more attack surface across the network. If OPC Easy Archiver only connects to local OPC servers on the same host, DCOM isn't in play and ONB isn't necessary.\" } },{ \"@type\": \"Question\", \"name\": \"Can I run OPC Easy Archiver without any Windows domain, using local accounts only?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"Yes. A dedicated local service account with least-privilege permissions works the same way a domain account does. The important part is that the account isn't Local System, Local Administrator, or any other broad-privilege account, regardless of whether it's local or domain-based.\" } },{ \"@type\": \"Question\", \"name\": \"What happens to data collection if the database becomes unreachable?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"OPC Easy Archiver's store-and-forward capability keeps collecting to local flat files during the outage, then recovers the buffered data into the database once connectivity is restored. This is why monitoring local disk capacity (Section 12) matters as much as monitoring the database itself. If local storage fills up during an extended outage, data loss becomes possible.\" } },{ \"@type\": \"Question\", \"name\": \"Is TLS encryption for database connections mandatory?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"It should be treated as mandatory whenever the database is on a separate host from OPC Easy Archiver, since that traffic crosses the network and could be intercepted. Having said that, from a technical perspective, it is not inherently mandatory for every deployment. Some organizations may rely on other controls, such as a fully isolated network segment, VPN\/IPsec encryption, physical network protections, or strict access controls. If the database runs locally on the same machine, the risk is lower, but enabling TLS is still good practice wherever the database platform supports it.\" } },{ \"@type\": \"Question\", \"name\": \"Does hardening DCOM mean OPC Easy Archiver will stop working with older OPC DA servers?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"It can, if those servers were built against outdated DCOM authentication defaults and don't support the hardened authentication levels Microsoft now enforces. This is one of the main reasons this guide recommends replacing DCOM with ONB tunneling rather than trying to fully harden DCOM itself. Tunneling sidesteps the compatibility problem entirely instead of requiring every legacy OPC server on the network to support modern DCOM security settings.\" } },{ \"@type\": \"Question\", \"name\": \"How often should the hardening checklist actually be reviewed?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"At minimum, annually, per Section 16,\u00a0 but any change to the environment should trigger an out-of-cycle review too: a new OPC server added, a service account permission change, a new firewall rule, or a Windows or OPC Easy Archiver version upgrade.\" } },{ \"@type\": \"Question\", \"name\": \"Does this guide cover OPC UA deployments, or only OPC Classic?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"This guide is specifically for OPC Easy Archiver's native OPC Classic (DA\/HDA\/AE) connectivity, since that's where DCOM and its associated hardening challenges apply. For OPC UA support, you may combine OPC Easy Archiver with OPC UA Proxy product.\" } },{ \"@type\": \"Question\", \"name\": \"Is enabling user authentication on the configuration GUI enough to prevent unauthorized changes?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"It prevents unauthorized access to the configuration interface, but it doesn't replace OS-level access control. Anyone with sufficient Windows privileges on the host could still stop services, modify configuration files directly, or alter permissions outside the GUI, which is why Sections 1, 3, and 8 all need to be applied together rather than relying on any single control.\" } }] }<\/script><\/div><\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hardening OPC Easy Archiver means reducing its attack surface across five layers: the Windows host it runs on, the Windows service and database accounts it<\/p>\n","protected":false},"author":1,"featured_media":2066,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[189],"tags":[53],"class_list":["post-2059","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opc-data-archiving","tag-opc-easy-archiver"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Hardening OPC Easy Archiver: Security Best Practices<\/title>\n<meta name=\"description\" content=\"16 practical steps to harden OPC Easy Archiver: secure the host, DCOM, service accounts, and databases, aligned with IEC 62443 and NIST CSF.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hardening OPC Easy Archiver: Security Best Practices\" \/>\n<meta property=\"og:description\" content=\"16 practical steps to harden OPC Easy Archiver: secure the host, DCOM, service accounts, and databases, aligned with IEC 62443 and NIST CSF.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/\" \/>\n<meta property=\"og:site_name\" content=\"OPC Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Integration.Objects.OPC\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T09:55:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-21T15:13:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/Hardening-OPC-Easy-Archiver.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1248\" \/>\n\t<meta property=\"og:image:height\" content=\"832\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"OPCBlogAdmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@IntegObjects\" \/>\n<meta name=\"twitter:site\" content=\"@IntegObjects\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"OPCBlogAdmin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hardening OPC Easy Archiver: Security Best Practices","description":"16 practical steps to harden OPC Easy Archiver: secure the host, DCOM, service accounts, and databases, aligned with IEC 62443 and NIST CSF.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/","og_locale":"en_US","og_type":"article","og_title":"Hardening OPC Easy Archiver: Security Best Practices","og_description":"16 practical steps to harden OPC Easy Archiver: secure the host, DCOM, service accounts, and databases, aligned with IEC 62443 and NIST CSF.","og_url":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/","og_site_name":"OPC Blog","article_publisher":"https:\/\/www.facebook.com\/Integration.Objects.OPC\/","article_published_time":"2026-08-20T09:55:20+00:00","article_modified_time":"2026-08-21T15:13:38+00:00","og_image":[{"width":1248,"height":832,"url":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/Hardening-OPC-Easy-Archiver.png","type":"image\/png"}],"author":"OPCBlogAdmin","twitter_card":"summary_large_image","twitter_creator":"@IntegObjects","twitter_site":"@IntegObjects","twitter_misc":{"Written by":"OPCBlogAdmin","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/","url":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/","name":"Hardening OPC Easy Archiver: Security Best Practices","isPartOf":{"@id":"https:\/\/integrationobjects.com\/blog-\/#website"},"primaryImageOfPage":{"@id":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/#primaryimage"},"image":{"@id":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/#primaryimage"},"thumbnailUrl":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/Hardening-OPC-Easy-Archiver.png","datePublished":"2026-08-20T09:55:20+00:00","dateModified":"2026-08-21T15:13:38+00:00","author":{"@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/6efbaf488a07e418b93ff77f00af386b"},"description":"16 practical steps to harden OPC Easy Archiver: secure the host, DCOM, service accounts, and databases, aligned with IEC 62443 and NIST CSF.","breadcrumb":{"@id":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/#primaryimage","url":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/Hardening-OPC-Easy-Archiver.png","contentUrl":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/08\/Hardening-OPC-Easy-Archiver.png","width":1248,"height":832,"caption":"hardening OPC Easy Archiver"},{"@type":"BreadcrumbList","@id":"https:\/\/integrationobjects.com\/blog\/hardening-opc-easy-archiver-security-best-practices-for-industrial-deployments\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/integrationobjects.com\/blog-\/"},{"@type":"ListItem","position":2,"name":"Hardening OPC Easy Archiver: Security Best Practices for Industrial Deployments"}]},{"@type":"WebSite","@id":"https:\/\/integrationobjects.com\/blog-\/#website","url":"https:\/\/integrationobjects.com\/blog-\/","name":"OPC Blog","description":"OPC and related technologies news from Integration Objects","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/integrationobjects.com\/blog-\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/6efbaf488a07e418b93ff77f00af386b","name":"OPCBlogAdmin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f2d787c3c48eb147d5b4d0c9d05c6f35a5946c7dc40af2eedbe64030e99ea299?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f2d787c3c48eb147d5b4d0c9d05c6f35a5946c7dc40af2eedbe64030e99ea299?s=96&d=mm&r=g","caption":"OPCBlogAdmin"}}]}},"_links":{"self":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/comments?post=2059"}],"version-history":[{"count":4,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2059\/revisions"}],"predecessor-version":[{"id":2070,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2059\/revisions\/2070"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/media\/2066"}],"wp:attachment":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/media?parent=2059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/categories?post=2059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/tags?post=2059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}