[KB7844] Change the ESET PROTECT Server address used by the ESET Management Agent


Required user permissions

This article assumes that you have the appropriate access rights and permissions to perform the tasks below.

If you use the default Administrator user or are unable to perform the tasks below (the option is unavailable), create a second administrator user with all access rights.

  • Direct clients to connect to a new ESET PROTECT Server by migrating certificates and setting your policy to the new server's address


Communication between ESET PROTECT Server and ESET business edition products is managed by the ESET Management Agent. When migrating to a different ESET PROTECT Server, the easiest way to change the server address used by the ESET Management Agent is to redeploy the agent.


There are three ways to specify a new server address for the ESET Management Agent to use when migrating to a new ESET PROTECT Server.

Migrate certificates and create new ESET Management Agent Policy

Default certificates - The Peer certificates and Certification Authority that were created during the installation are by default contained in the static group All.

  1. Open ESET PROTECT On-Prem in your web browser and log in.

  2. Click More Peer Certificates, and then select the check box next to your default Agent certificate.
  3. Click ActionsExport and save the .pfx file to a save location of your choice.
    Figure 1-1


  4. Click MoreCertification Authorities, and then select the check box next to the Certification authority used to sign your exported Agent Certificate.
  5. Click Actions → select Export Public Key and then save the .der file to a save location of your choice.
    Figure 1-2


  6. Click Start Control PanelProgramsPrograms and Features.
  7. Select ESET Management Agent and click Change.
    Figure 1-3
  8. Click Next.
    Figure 1-4
  9. Click Repair.
    Figure 1-5
  10. In the Agent configuration screen, enter the address of your new ESET PROTECT Server into the Server host field. Other settings should be left unchanged unless you are using a different port than the default port for ESET PROTECT Server. Click Next when you are finished.
    Figure 1-6
  11. In the Peer certificate window, browse for the Agent Certificate (.pfx) file you exported in step 3 and Certification Authority (.der) file you exported in step 5 and then click Next.
    Figure 1-7
  12. If the Agent is password protected, type the ESET Management Agent password. Otherwise, leave the password field blank. Click Next.
    Figure 1-8
  13. Click Repair. Your client computers will be able to communicate with your new ESET PROTECT Server after the changes have been made.
    Figure 1-9
  14.  If the installer asks you for the .msi file, you can download the .msi from the ESET Web page. When the Installation Wizard completes the repair, click Finish.


Redeploy the ESET Management Agent

When migrating to a new ESET PROTECT Server, you can send an updated instance of the ESET Management Agent from your new server to client machines. During the ESET Management Agent deployment process, you will be prompted to enter connection information for your new ESET PROTECT Server.