[KB7730] Deploy the ESET Management Agent and ESET endpoint application together from ESET PROTECT or ESET PROTECT On-Prem

Issue

  • ESET PROTECT and ESET PROTECT On-Prem (Windows only) allow you to create a package to install the ESET Management Agent and ESET endpoint/server application together
  • The All-in-one installer contains the ESET Management Agent, ESET application, subscription, policy, ESET PROTECT or ESET PROTECT On-Prem management configuration, and other features specific to the given ESET application in a pre-configured installer package
Click the expanders below to show the procedure for ESET PROTECT or ESET PROTECT On-Prem:

ESET PROTECT

Details


Click to expand

This method is for local installations, and an administrator should run it because:

  • It requires user interaction on the client workstation (unless using the Silent mode installation)
  • It requires a domain administrator account (not a regular user account)
  • The certificate passphrase is embedded in the installer file and may be recoverable by users on the client workstation

The ESET Management Agent can also be installed using Live Installer, deployed remotely or installed manually (a local installation of the ESET Management Agent only). Read more about the deployment of the ESET Management Agent.

The ESET Management Agent facilitates communication between client computers and other ESET PROTECT components. ESET Management Agent must be installed on all client computers where other ESET PROTECT components or ESET endpoint/server applications are installed.


Solution

Create an All-in-one installation package in the ESET PROTECT Web Console

Example application

The example below is used for Windows and ESET Endpoint Security. This guide also applies to ESET Server Security for Microsoft Windows Server and ESET Mail Security for Microsoft Exchange Server.

The settings in step 3 might differ for other operating systems.

Linux users

If you want to install an ESET application for Linux, the Live Installer is currently available only for ESET Server Security for Linux.

Follow the instructions below to use ESET PROTECT to create a Live Installer installation package.

  1. Open the ESET PROTECT Web Console.

  2. Expand Quick links, and click Windows devices.

  3. Select Windows and review the Protection and installation settings section. The Legal documents section cannot be deselected.

    ESET LiveGrid® and Detection of potentially unwanted applications

    See ESET LiveGrid® and Potentially unwanted applications Online Help articles for more information.

    You have four options to distribute and deploy the ESET application:

    • Click Download to download the installer package to your computer
    • Click the Copy icon to copy the download link to the clipboard
    • Click the Envelope icon to send the download link via email
    • Click Customize installer to change some settings before downloading the installer (follow these steps)

  4. Save the respective installer file to a shared location, or send it via email, and access it from the client computer where it will be installed.

  5. Run the All-in-one installer package file on the client computer to start the Setup Wizard using a domain administrator account.


Customize installer
  1. Customize your application setup:

    1. Select Windows

    2. Verify that the Download or send installer, or use ESET Remote Deployment Tool is selected (macOS and Linux users: verify that the Download or send installer is selected)

    3. In the Components section, you can select the check boxes next to Full Disk Encryption and ESET Inspect Connector if you want to include these components in the installer

    4. Review the check box next to Participate in product improvement program

    5. Select or create a Parent group

    6. Click Customize more settings to view more settings

    7. When you are finished customizing settings, click Continue

    Components: Full Disk Encryption and ESET Inspect Connector

    Full Disk Encryption and ESET Inspect Connector are available in the Components section only after the respective activation key has been added to ESET PROTECT manually or via ESET PROTECT Hub, ESET Business Account, or ESET MSP Administrator.

  2. Select or check the following:

    1. To choose another application, click the selected application under Security application

    2. Review your Protection and installation settings

    3. If not preselected, select the check box under Legal documents

    4. To view more settings, click Customize more settings. To choose another subscription, click the selected subscription under Subscription

    5. Click Finish

  3. Click the Copy  icon to copy the download link to the clipboard, or click Download to download the installer. For Windows, you can click Download the Remote Deployment Tool to deploy the Agent remotely. Click Finish.

  4. Save the .exe file to a shared location and access it from the client computer, where it will be installed.

  5. Run the All-in-one installer package file on the client computer to start the Setup Wizard using a domain administrator account.


Setup Wizard

For illustrated instructions for the Setup Wizard for Windows, see the ESET Package Installer Online Help topic.


Run the installation without user interaction (Silent mode installation)

  1. Settings for Silent mode installation
  2. Silent mode installation

I. Settings for Silent mode installation

By default, when performing a silent installation, the following settings will be used:

  • The Terms of Use are accepted
  • ESET LiveGrid® is enabled (Windows users only)
  • Detection of potentially unwanted applications is disabled (Windows users only)

These default settings can be changed after the installation is completed. They can also be modified in your installation package in the Customize installer section:

  1. See step a of the Customize installer sub-section.

    1. Click Customize more settings.

    2. In the Agent configuration section, click Select to select a configuration from the list of policies, or click Create to create a new policy for ESET Management Agent.

  2. See step b of the Customize installer sub-section.

    1. Click Customize more settings.

    2. In the Agent configuration section, click Select to select a configuration from the list of policies or click Create to create a new policy for the ESET security application.


II. Silent mode installation

You can install an All-in-one installation package generated from the ESET PROTECT Web Console on the client device without user interaction (silent mode). Ensure the following requirements are met before using this method: 

  • Store the installation package locally on the designated device
  • Perform the silent installation on an account with administrator privileges
  • We recommend that you run the command prompt as an administrator
  • Use the .exe installer type

If all of the above requirements are met, follow the steps below to perform a silent install:

  1. In the command line, navigate to the installation package location.

  2. Execute the installation package with the --silent and --acceptterms parameters, for example:

    C:\Users\Admin\Downloads\epi_win_live_installer.exe --silent --acceptterms
  1. The installation will now proceed in silent mode, and no window or progress bar will appear during the installation.

  2. The package will be installed with default settings.


ESET PROTECT On-Prem

Details


Click to expand

This method is for local installations, and an administrator should run it because:

  • It requires user interaction on the client workstation (unless using the Silent mode installation)
  • It requires a domain administrator account (not a regular user account)
  • The certificate passphrase is embedded in the installer file and may be recoverable by users on the client workstation

The ESET Management Agent can also be installed using Live Installer, deployed remotely or installed manually (a local installation of the ESET Management Agent only). Click for more options to deploy the ESET Management Agent.

The ESET Management Agent facilitates communication between client computers and other ESET PROTECT On-Prem components, such as the ESET PROTECT Server. The ESET Management Agent must be installed on all client computers where other ESET PROTECT On-Prem components or ESET endpoint/server applications are installed.


Solution

Create an All-in-one installation package in the ESET PROTECT Web Console

Follow the instructions below to use ESET PROTECT On-Prem to create an installation package that includes the ESET Management Agent, the ESET Windows endpoint/server applications, subscription, policy, and ESET PROTECT On-Prem management configuration.

Windows users only

The deployment of the ESET Management Agent and the ESET endpoint application together from ESET PROTECT On-Prem is available only on Windows.

ESET Server/Mail Security users

ESET Endpoint Security for Windows is selected in the example screenshots below.

The process also applies to ESET Server/Mail Security (Windows only) applications. ESET Server/Mail Security users must select the application that applies to their system.

  1. Open the ESET PROTECT Web Console.

  2. Click Quick Links → Deploy Agent.

  3. Select WindowsDownload installer or use ESET Remote Deployment Tool. In the Components section, select the components that you want to include in the installer.

    Full Disk Encryption and ESET Inspect Connector

    These components will be available only after their subscriptions are added to ESET PROTECT Hub and synchronized with ESET PROTECT On-Prem.

  4. You can access additional settings by clicking the Customize more settings option. Then click Continue.

  5. Customize your application setup:

    • You can click the selected application to choose another one
    • Verify that the check boxes next to Enable ESET LiveGrid® feedback system and Enable detection of potentially unwanted applications are selected
    • Select the check box in the Legal documents section
    • Click Customize more settings to access additional settings
    • You can click the selected subscription to choose another one
    • If you want to use the installer with a full set of ESET modules, select the check box in the Application modules installation section
    • Scroll down to access more settings

  6. If you selected Full Disk Encryption and ESET Inspect Connector in step 3, select the check box under Legal documents in both sections. You can also access additional settings by clicking the Customize more settings option. Click Finish.

  7. Select the target platform to download the installer for your system. Save the file to a shared location and access it from the client computer where it will be installed.

    Alternatively, you can download the .msi installer from the ESET download page. If you want to deploy the agent in bulk, click Download the Remote Deployment Tool. Click Finish.

  8. Run the All-in-one installation package file on the client computer to start the Setup Wizard using a domain administrator account.

    ESET Server/Mail Security users

    ESET Server/Mail Security users must restart the server after the upgrade.

For illustrated instructions for the Setup Wizard, see the ESET Package Installer Online Help topic.


Run the installation without user interaction (Silent mode installation)

  1. Settings for Silent mode installation
  2. Silent mode installation

I. Settings for Silent mode installation

By default, when performing a silent installation, the following settings will be used:

  • The Terms of Use are accepted
  • ESET LiveGrid® is enabled (Windows users only)
  • Detection of potentially unwanted applications is disabled (Windows users only)

These default settings can be changed after the installation is completed, or they can be modified in your installation package by following the steps below:

  1. In step 4, click Customize more settings. In the Agent configuration section, click Select to select a configuration from the list of policies, or click Create to create a new policy for the ESET Management Agent. Click Continue.

  2. In steps 5 and 6, there are additional settings under every component.

    Click Customize more settings under the ESET security application and ESET Inspect Connector (scroll down to see this section). Click Select to select a configuration from the list of policies or click Create to create a new policy for the selected component. Click Finish.


II. Silent mode installation

You can install an All-in-one installation package generated from the ESET PROTECT Web Console on the client device without user interaction (silent mode). Ensure the following requirements are met before using this method:

  • Store the installation package locally on the designated device
  • Perform the silent installation on an account with administrator privileges
  • We recommend that you run the command prompt as an administrator
  • Use the .exe installer type

If all of the above requirements are met, follow the steps below to perform a silent installation:

  1. In the command line, navigate to the installation package location.

  2. Execute the installation package with the --silent and --acceptterms parameters, for example:

    C:\Users\Admin\Downloads\PROTECT_Installer_x64_en_US.exe --silent --acceptterms
  3. The installation will now proceed in silent mode, with no window or progress bar appearing during the installation.

  4. The package will be installed with default or custom settings defined in Settings for Silent mode installation.