// MILESTONE XPROTECT HEALTH CHECK · HANS STUDY · ONTARIO, CANADA

Milestone XProtect Health Check

XProtect is the platform where the constraint is most often commercial rather than technical. Editions, Device Packs and support entitlement each set a ceiling, and estates routinely run into one of them years after the decision that put it there was made by somebody who has since left.

What the Health Check covers

XProtect separates its functions across several servers and versions several things independently of each other. That flexibility is the platform's strength and the source of most of the confusion in estates that were installed once and left alone.

Edition and licensing position

Which edition you are on, what it can and cannot do, and whether the features being asked for sit behind an edition wall. Device licence count against devices actually connected.

Support entitlement

Whether care and support entitlement is current. This decides whether an upgrade is an upgrade or a repurchase, and it is the single most expensive thing to discover late.

Device Pack currency

Device Packs version independently of the platform. A camera that will not connect, or connects without its full feature set, is frequently a Device Pack question rather than a camera fault.

Server roles and topology

Management, recording, event, log and mobile server placement. Where roles have been collapsed onto one box, and whether that was a decision or an accident of the original install.

Recording and storage

Storage configuration and archiving behaviour, retention against real bitrates, write performance under sustained load, and whether archiving is doing what was intended.

Failover and resilience

Failover recording servers where deployed, whether failover has ever been tested rather than assumed, and what is actually lost during a switch.

SQL and database health

Database placement, maintenance, growth and backup. Frequently installed alongside the management server and then never looked at again.

Security and hardening

Service accounts and privilege, certificate and encrypted communication configuration, operator roles, device credentials, and the distance from the published hardening guide.

Where XProtect estates commonly sit

The structural traps on this platform are well documented and they are mostly about version and entitlement rather than about configuration.

  • An edition chosen for the original site that now constrains a much larger estate, where the feature everyone wants requires a different edition entirely.
  • Support entitlement lapsed without anyone noticing, so the upgrade path carries a cost nobody has budgeted.
  • Device Pack well behind the platform, which surfaces as individual cameras behaving oddly and gets chased at the camera instead of at the server.
  • Roles collapsed onto a single server during a small initial deployment and never separated as the estate grew.
  • Failover configured and never tested, which is not resilience so much as an assumption.
  • Smart Client performance blamed on the network when the constraint is client-side decoding and hardware acceleration.

Who this is for

Organisations running XProtect at scale who need to know where they stand before an upgrade, an expansion, or a budget cycle. Particularly useful where the estate was installed by an integrator who is no longer involved, or where the platform decision predates everyone currently responsible for it.

What you receive

The deliverable is a prioritized remediation plan, not a pile of observations you have to triage yourself.

  • A findings report organized by severity and by system layer, readable by both the security team and the IT team.
  • A clear position on edition, licensing and entitlement, with the cost consequences of each option set out plainly.
  • Specific, configuration-level recommendations tied to published guidance.
  • A working session to walk through the findings and answer what the report raises.

Recommendations do not change based on who is selling. There is no product being steered toward at the end of this.

Scope and pricing

Fixed price, agreed in writing before the work starts. No hourly meter, no scope creep, and no invoice larger than the conversation suggested. Nothing is sold at the end of it either, which is the independence policy.

// Start here

Starter health check

$500

One system, any size

Remote, 90 minutes, live

  • Version position against end of life and end of support
  • The upgrade path in order, with the traps on it
  • Obvious risks visible without a full review
  • A straight answer on whether a full health check is worth your money

Credited in full against a full health check booked within 30 days.

// Most common

Health check, single site

$4,500

One site, up to 150 cameras

Remote. Remote unit or on site available

  • Full review across every layer listed on this page
  • Findings report by severity and by system layer
  • Configuration-level recommendations tied to published guidance
  • Prioritized action list separating now, scheduled, and design-around
  • A 90-minute working session to walk it through

// Multi-site

Health check, multi-site

$9,500

Up to 3 sites, up to 500 cameras

Remote. Remote unit or on site available

  • Everything in the single-site review, across the estate
  • Redundancy, failover and database availability reviewed as one system
  • Cross-site behaviour checked against what the design assumed
  • A 90-minute working session to walk it through

// Larger estates

Enterprise

From $18,000

Beyond 3 sites or 500 cameras

Scoped per engagement

  • Scoped and priced in writing before anything starts
  • Unusual integration, compliance or jurisdictional requirements accommodated

Extend a tier instead of jumping to the next one

Estates rarely land neatly on a boundary. If yours sits just past one, add to the tier below rather than paying for the one above. The rates follow the same slope as the tiers, so extending is never a worse deal than upgrading.

Additional 100 devices $1,200

Cameras, doors, readers or controllers beyond the tier allowance. Counted as configured, not as licensed. (per 100)

Additional site $2,000

A further site beyond the tier allowance, reviewed to the same depth and included in the same report. (per site)

Remote unit deployment $450

Pre-configured appliance shipped to site and returned. See delivery below. (per deployment)

On-site day $2,400

Where physical inspection is required. Travel agreed in writing before it is incurred. (per day, plus travel at cost)

Additional working session $650

A further 90-minute session, usually for a different audience such as IT, operations or a vendor. (per session)

Board-ready executive summary $800

The findings translated into a short document for a board, council or executive, written to be read by somebody non-technical. (one-off)

Expedited turnaround 25% surcharge

Findings inside five business days rather than the standard window. Subject to availability.

How the work is delivered

Remote Included

Screen share, supplied configuration exports, logs and documentation. Most of what a health check examines is visible without anyone travelling, and this is how the majority of engagements run.

Remote unit $450

A pre-configured unit ships to the site. Somebody on site plugs it into power and network, which takes minutes and needs no technical skill. It provides the access needed to examine the system properly, then ships back. Covers configuration, shipping both directions, and retrieval.

Cheaper and faster than travel for a single site, and it is what makes distance stop mattering. A site in another province costs the same to review as one an hour away.

On site Quoted

Where the work genuinely requires being in the room: physical inspection, cabling and rack conditions, commissioning witness, or an environment that cannot be reached remotely. Day rate plus travel at cost, agreed in writing up front and never added afterwards.

What a health check does not include

Listed because an unstated exclusion is what turns a fixed price into an argument at invoice time, and that is the exact failure this practice exists to review other people for.

  • Remediation. The report says what to fix; fixing it is a separate engagement or your own team.
  • Configuration changes. Nothing is altered on a live system during a review.
  • Licence, hardware or software costs, which are yours and are bought direct.
  • Vendor support cases, escalations, or dealings with your integrator on your behalf.
  • On-site attendance, unless added explicitly.
  • Ongoing monitoring or a retainer. A health check is a point-in-time assessment.

Prices are for a Milestone XProtect environment and are held for 30 days from quotation. Travel, where an on-site day is added, is charged at cost and agreed in writing before it is incurred.

Related advisory areas

Video Surveillance Design →

Purpose per view, pixel density, storage sizing. Platform neutral, before selection.

Pre-Purchase Design Review →

If an upgrade or migration has been quoted and you want it checked before signing.

Security Network Design →

The network under the recording servers, which is where a share of the faults live.

Health checks for other platforms

Same structure and the same fixed pricing across every platform. The layers reviewed differ, because the ways these systems fail differ.

Genetec Security Center →

Architecture, roles and sizing under real load.

C-CURE 9000 →

CrossFire, iSTAR estate, SQL dependency and integrations.

Avigilon Unity and Alta →

Which product family you are in, and what that decides.

AXIS Camera Station →

Edge analytics, and the device estate that limits them.

Lenel OnGuard →

Version position, database age, and access level sprawl.

Kantech EntraPass →

Edition ceiling, gateway topology, and controller firmware.

Know your position before the budget cycle

On this platform the expensive surprises are commercial. Finding out where you stand on edition and entitlement while there is still time to plan is worth considerably more than finding out during a quote.