Use DriveErase on Windows Server

Applies to: Enterprise and Audit

Licence requirement

Windows Server use requires DriveErase Enterprise or Audit. Standard and Pro do not permit operation when a Windows Server environment is detected.

Operational planning

A DriveErase job restarts the server into the Privileged Execution Environment. Before proceeding:

  1. Obtain an approved maintenance window;
  2. Stop or migrate workloads;
  3. Confirm cluster, replication, backup, monitoring, and failover consequences;
  4. Record the server asset, chassis, controller, enclosure, and device mapping;
  5. Disconnect or isolate shared storage that is not part of the approved job;
  6. Confirm remote-console access for the restart and completion screen;
  7. Confirm stable power and management-controller availability;
  8. Notify affected service owners.

Storage-controller visibility

Servers commonly use RAID controllers, HBAs, SAN paths, multipath drivers, and hot-swap enclosures. DriveErase can sanitize only the physical devices or logical storage objects presented to it through a supported path.

A logical RAID volume does not provide direct evidence that every member disk received a device-level sanitization command. For individually controlled media disposition, expose and identify each physical device according to the controller vendor’s approved procedure.

Boot and system disks

The active Windows system disk cannot be selected from the running server. To sanitize it, remove or reassign the device and process it as a non-system target on another supported host.

Virtualized server roles

When DriveErase runs inside a virtual machine hosted by Windows Server, the virtual-machine scope and limitations also apply. Sanitizing a guest-visible virtual disk does not sanitize the physical drives or copies maintained by the host, cluster, storage array, backup platform, or replication service.

Evidence

Enterprise and Audit reports should be retained with the maintenance ticket, physical bay mapping, controller evidence, custody record, and final disposition. Document any difference between the DriveErase target identity and the asset-management identity.