What does the 'Immutable Protection Group Temporary Unlock Detection' Health Check do?
- This health check monitors protection groups with immutability mode enabled. If a protection group enters a temporary unlocked state, a warning alert is generated. When the protection group remains unlocked for more than 24 hours, an error alert is generated.
- The health check helps ensure that immutable protection groups maintain their security posture and are not left in an unlocked state for extended periods, which could pose a security risk.
What does it mean when it is in a warning (yellow) state?
- A warning state indicates that an immutable protection group has been temporarily unlocked. This is typically done for administrative purposes such as:
- Modifying protection group configuration
- Performing maintenance operations
- Making changes to protected VMs
- The warning serves as a reminder that the protection group is currently in an unlocked state and should be locked again as soon as the administrative task is complete.
What does it mean when it is in an error (red) state?
- An error state indicates that an immutable protection group has remained in a temporary unlocked state for more than 24 hours. This represents a potential security risk, as:
- Snapshots may be vulnerable to modification or deletion
- The protection group is not providing the expected immutability guarantees
- There may be a forgotten or incomplete administrative operation
- This requires immediate attention to restore the protection group to its locked state.
How do I resolve a temporary unlock alert?
- To resolve the alert, you need to lock the protection group again:
- Lock the protection group using the Lock operation (require Broadcom support assistance).
- Navigate to the protection group in the vSAN Data Protection interface
- Verify that any administrative unlock tasks are complete
- The health check will automatically clear the alert once the protection group is locked
If the unlock was not authorized, contact Broadcom Support for assistance.
What information is displayed in the health check results?
- The health check displays the following information:
| Column | Description |
| Protection Group | The name of the immutable protection group that is temporarily unlocked |
| Time | The timestamp when the temporary unlock operation was performed |
Can I view historical unlock events?
- Yes, you can view historical temporary unlock events by clicking "VIEW HISTORY DETAILS" in the health check interface. This provides an audit trail of all temporary unlock operations performed on immutable protection groups.
What is the difference between temporary unlock and permanent unlock?
- Temporary unlock: Allows temporary modifications to an immutable protection group while maintaining its immutable status. The protection group can be locked again after administrative tasks are complete. This operation is tracked by this health check.
- Permanent unlock: Converts an immutable protection group to a regular protection group, removing immutability permanently. This is tracked by a separate health check: "Immutable Protection Group Permanent Unlock Detection".
Why is immutability important for protection groups?
- Immutable protection groups provide ransomware protection by ensuring that snapshots cannot be modified or deleted, even by administrators. This is critical for:
- Cyber Recovery: Ensuring clean recovery points exist after a ransomware attack
- Compliance: Meeting regulatory requirements for data retention
- Data Integrity: Preventing accidental or malicious deletion of backup data
Leaving an immutable protection group in an unlocked state defeats these protections.
Warning State - Temporary Unlock Detected
- The health check shows a warning (yellow) state when an immutable protection group is temporarily unlocked:

Error State - Unlock Duration Exceeds 24 Hours
- The health check shows an error (red) state when the temporary unlock has persisted for more than 24 hours.
Health Check Details Table
- The details table shows which protection groups are temporarily unlocked.
History Details View
- The history details show all temporary unlock events over time.