[KB7736] Deploy the ESET Management Agent via SCCM or GPO (Windows)

Issue

Required user permissions

This article assumes that you have the appropriate access rights and permissions to perform the tasks below.

If you use the default Administrator user or are unable to perform the tasks below (the option is unavailable), create a second administrator user with all access rights.

  • Configure the ESET Management Agent installer file for deployment via Group Policy Object (GPO) or System Center Configuration Manager (SCCM)
  • Configure an alternative method to deploy the ESET Management Agent for enterprise environments or environments with a high number of client computers
  • Use GPO or SCCM for deployment

Details


Click to expand

Create a modified ESET Management Agent installer file for deployment in large-to-enterprise-level environments. The .msi file for the ESET Management Agent is separated from the .bat file available from ESET PROTECT On-Prem. The .msi file is then modified so that it can recognize the proper certificate and port for communication with your ESET PROTECT Server after distribution to client computers.


Solution

ESET PROTECT

Use GPO or SCCM for deployment

  1. Open ESET PROTECT in your web browser and log in.

  2. Click InstallersCreate installer.

    Figure 1-1
  3. Click Customize installer.

    Figure 1-2
  4. Windows operating system is pre-selected. Select Use GPO or SCCM for deployment next to Distribution and scroll down.

    Figure 1-3
  5. Select the Parent group where the ESET PROTECT will place the computer after an Agent installation. The parent group is mandatory if you use an ESET PROTECT Hub or ESET Business Account with sites or ESET MSP Administrator and optional if you use an ESET PROTECT Hub or ESET Business Account without sites. If you use an ESET PROTECT Hub or ESET Business Account without sites and you do not want to use the Parent group, continue to step 6. Otherwise, click Select.

    Figure 1-4
  6. Select the group you want your computers to fall into and click OK.

    Figure 1-5
  7. Click Finish to generate the installation files.

    Figure 1-6
  8. Click the file icon to download the install_config.ini file. Select the desired agent installer icon (32-bit, 64-bit, ARM64) to download the agent installer .msi file and save them to the same shared folder.

    After you have downloaded both files, click Finish.

    Figure 1-7
  9. Refer to one of the processes below to deploy the package:


ESET PROTECT On-Prem

Use GPO or SCCM for deployment

  1. Open ESET PROTECT On-Prem in your web browser and log in.

  2. Click Quick Links Deploy Agent

    Figure 2-1

  3. Confirm the Windows operating system is selected, select Use GPO or SCCM for deployment next to Distribution and scroll down.

    Figure 2-2

  4. Click Finish. The ESET PROTECT On-Prem certificate is selected by default. For custom certificate users, refer to the custom certificates with ESET PROTECT On-Prem Online Help topic for more details. Peer certificates and Certification Authority created during the installation are, by default, contained in the static group labeled All

    Figure 2-3
  5. Click the file icon to download the install_config.ini file. Select the desired agent installer icon (32-bit-64-bit, ARM64) to download the agent installer .msi file and save it to the same shared folder.
    ESET PROTECT On-Prem 9.0 and earlier users

    Download the agent installer .msi file in the Standalone Installers section from the ESET PROTECT On-Prem download page. Select Agent from the Component drop-down menu, then select a 32-bit or 64-bit Windows operating system from the Operating system | Bitness drop-down menu and click Download

    Figure 2-4

    Client computers need read/execute access

    Verify all appropriate client computers have read/execute access to the folder containing the .msi and .ini files.

    1. Right-click the folder from Section 1, step 2 and click Properties.

    2. Click the Security tab. Review each machine and confirm the check box next to Read & execute is selected under the Allow column. If not, click Edit, adjust the settings and click Apply.
      Figure 2-5
  1. Refer to one of the processes below to deploy the package:

When you have completed the instructions from the appropriate article, proceed to Step 5, deploy ESET endpoint products to your client computers if you are performing a new installation of ESET PROTECT On-Prem.