# High Availability (HA) & Disaster Recovery (DR) for Endpoint Central (Formerly Known as Failover Server) from the Build 11.5.2627.01 Last Updated On: 30 Sep 2026 High Availability (HA) and Disaster Recovery (DR) in **Endpoint Central** is an active-standby protection model that keeps endpoint management operational when a server or an entire site fails. One server is designated Active and handles all patch deployments, policy enforcement, agent communication, and console access, while one or more Standby servers stay continuously synchronized and ready to take over. The feature covers two distinct failure scopes — a single server going down at the same site (HA), and an entire site going offline (DR) — through four selectable deployment configurations. ## Why Uptime Matters Every enterprise prioritises business continuity, but no one can predict when a critical server will fail - and in a single-server deployment, any hardware fault, OS crash, or power disruption takes **Endpoint Central** completely offline, staying down until an administrator manually diagnoses, repairs, and restarts the server, a process that can take hours or days, during which patches go undeployed, policy violations go undetected, and compliance gaps widen. **Endpoint Central** addresses this with built-in **High Availability and Disaster Recovery**, a layered protection model that removes the dependency on manual recovery by automatically detecting failures through a synchronised Standby server that takes over, keeping endpoint management running without failure - and by extending the same model across a geographically separate site, it protects against failures that take down an entire data centre due to power grid failure, fire, or regional network outage, not just a single machine. ## High Availability (HA) vs. Disaster Recovery (DR) | Strategy | What It Protects Against | How Recovery Happens | |---|---|---| | **High Availability (HA)** | A single server goes down - hardware fault, OS crash, or power cut at your Data center site | A standby server at the same site takes over automatically within few minutes | | **Disaster Recovery (DR)** | An entire site goes offline - data centre outage, fire, or power grid failure | A server at a geographically separate site takes over automatically within few minutes | Endpoint Central supports both strategies through four configuration models. You can start with a simple 2-node setup at a single site for server-level protection, extend it across two sites for disaster recovery coverage, or go further with a 3-node or 4-node model that gives you full High Availability within your data centre, along with one or two Disaster Recovery nodes placed at a completely separate site for additional protection. ## How High Availability and Disaster Recovery Works ### The Active-Standby Model Endpoint Central High Availability and Disaster Recovery runs on an Active-Standby model. At any given time, one server is **Active** and the other is **Standby**. The Active server handles everything: patch deployments, policy enforcement, agent communication, and the admin console. The Standby server does one job - it watches the Active server and stays synchronised, with a replication gap of up to 2 minutes between each sync. This same Active-Passive model applies at every level - between the two servers within the Data Center servers, and between the Data Center and the Disaster Recovery site. Regardless of whether it is a 2-Node, 3-Node, or 4-Node configuration, the model remains the same - if the Active server or the entire Active site becomes unavailable, the Standby servers or Disaster Recovery server takes over. When the Active server fails: 1. The Standby servers detects the failure through the below mentioned two independent health checks. 2. Once both checks confirm the failure, the Standby promotes itself to Active. 3. It takes over the Virtual IP or standby server address, so agents reconnect automatically. 4. The switchover typically completes within a few minutes, depending on the environment. When the failed server comes back online, it does not immediately take control again. Instead, it rejoins as the Standby server and waits. This is intentional — because during the outage, the Standby server was actively managing operations and writing new data. If the original server were to take control automatically, it could overwrite that new data and cause data loss. An admin manually decides when it is safe to switch back. ### Health Detection Each standby servers continuously monitors its active server using two independent checks simultaneously. **Both checks must fail** before failover triggers - ensuring High Availability only occurs during a genuine failure, not a temporary disruption. - **Database Heartbeat Check:** The Active server periodically update heartbeat into the shared database to confirm it is running. The Standby server monitors these entries - if no new entry is received, it treats the Active server as unresponsive. This is verified across 3 checks within 40 seconds before the High Availability switchover is initiated. - **HTTPS Request Check:** The Standby server periodically sends HTTPS requests to the Active server to confirm that the server is running. If no response is received, it treats the Active server as unresponsive. This is verified across 3 checks within 2 minutes before the High Availability switchover is initiated. ## How Switchover and Synchronisation Works ### The Virtual IP (VIP) - Handover Since agents are pre-configured with both Data Center(DC) and Disaster Recovery(DR) Virtual IPs, they reconnect to the Active site automatically. **Within the same site:** When the active server fails, the standby at the same site takes over, the Virtual IP automatically rebinds to the new active server - with no DNS change, no firewall update, and no agent reconfiguration. Agent server communication after failover is completely seamless. **Across sites (Data Center to Disaster Recovery):** When the entire Data Center site fails and the Disaster Recovery site takes over, agents automatically reconnect to the Disaster Recovery site using the Disaster Recovery Virtual IP address, ensuring endpoint management continues without interruption. **Note:** Virtual IP is only applicable in same-site High Availability failover. For cross-site Disaster Recovery — whether two-node or three-node — no Virtual IP is used or required, as each site operates with a single active machine and agents reconnect directly using the Disaster Recovery site address. ### Active-Standby Servers Data Synchronisation The Standby server replicates data from the Active server, with a maximum gap of 2 minutes between replications. Each cycle replicates the full server database (users, devices, policies, logs), patch packages, licence files, SSL certificates, and all server system files across all configured nodes. ## RTO and RPO - **RTO (Recovery Time Objective):** Designed to be low, with actual recovery time varying based on server specifications, network speed, and environment conditions. - **RPO (Recovery Point Objective):** Designed to be low, as data is replicated frequently between servers. In the event of a failure, only data since the last successful replication may be lost. ## High Availability and Disaster Recovery Configurations ### High Availability Deployment with 2 Node Same Site Two servers at the same location and subnet share a single Virtual IP. Node 1 (Data Center Server) is Active; Node 2 (High Availability for Data Center server) is Standby. On failure, Node 2 claims the Virtual IP automatically - zero reconfiguration anywhere. This is the **recommended minimum** for any production deployment. However, this configuration protects only against server-level failures. If the entire site loses power or connectivity, both nodes go offline together. For protection against a complete site failure, consider the 3-Node or 4-Node configuration. | Node | Site | Virtual IP Behaviour | |---|---|---| | Node 1 - Data Center server(Active) | Data Center | Holds Virtual IP during normal operation | | Node 2 - High Availability for Data Center server(Standby) | Data Center | Claims Virtual IP automatically when active server fails | ![HA 2Node Same Site](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/ha-2node-same-site.png) **Warning:** The Data Center Virtual IP and Disaster Recovery Virtual IP must each be a free, unused IP address within their respective site's subnet. Assigning a Virtual IP that is already in use will cause IP conflicts and disrupt network connectivity across the site. **Recommendation:** Consult your network or system administrator before assigning Virtual IPs. It is advisable to use an IP address from a dedicated reserved pool — one that is guaranteed to remain unassigned to any other machine, both during initial configuration and in the future. This ensures the Virtual IP remains exclusively available for failover use at all times. Learn more about [setting up High Availability and Disaster Recovery.](https://www.manageengine.com/products/desktop-central/help/server/how-to-configure-high-availability-and-disaster-recovery.html)