Skip to Main Content
IBM System Storage Ideas Portal


This portal is to open public enhancement requests against IBM System Storage products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Submitted
Created by Guest
Created on Jul 24, 2026

Support SSH-less Deployment and Lifecycle Management for IBM Storage Defender DRS Sensors

Many enterprise and regulated environments prohibit the SSH protocol on production Windows and Linux servers, including temporary access over TCP port 22.

The currently documented IBM Storage Defender Data Resiliency Service sensor deployment model requires a Sensor Control Node—either the internal node in the Connection Manager or an external Ansible Control Node—to connect to target virtual machines using SSH over TCP port 22.

This requirement applies not only to the initial sensor installation but also to subsequent lifecycle operations such as updates and removal. SSH key authentication removes the need for a password, but it does not remove the SSH protocol requirement.

For Windows environments, enabling OpenSSH Server introduces an additional remote-management service that may conflict with established security baselines. Many customers already use approved software-distribution and endpoint-management platforms and do not permit a separate SSH management channel.

The current public IBM documentation does not describe a supported alternative based on WinRM, PowerShell Remoting, Microsoft Configuration Manager, Intune, other enterprise deployment tools, or a locally executed installation and registration package.

We request an IBM-supported SSH-less deployment and lifecycle-management option for Defender sensors on supported Windows and Linux virtual machines.

The solution should support:

  • Sensor installation, registration, update, repair and removal without SSH or TCP port 22.
  • Secure association of the sensor with the correct Connection Manager and DRS tenant.
  • Non-interactive deployment suitable for enterprise automation.
  • Digitally signed installation packages and configuration artifacts.
  • Short-lived or one-time registration credentials.
  • Central deployment status and audit information in the DRS user interface.
  • Credential rotation and sensor re-registration.
  • Compatibility with restricted and disconnected network segments.
  • A documented rollback and troubleshooting procedure.
  • Clear support boundaries for customer-managed deployment tools.

This capability would significantly improve adoption in regulated environments and reduce the need for security exceptions.

Idea priority High