How to install Endpoint Central Agent Using GPO Scheduler?
Endpoint Central Agents can now be installed in an Active Directory environment using the scheduler option. When the installation process is initiated with the Scheduler, it is triggered in the time specified while configuring the same, unlike a normal GPO script where the installation happens when a device is turned on or when a user logs in.
Follow the steps given below to schedule Endpoint Central agent installation task.
Creating/Provisioning Network Share:
- Log on to the Windows Server machine as an administrator.
- Open the Server Manager Console by selecting it from the Administrative Tools menu.
- From the Server Manager Dashboard, select File and Storage Services.
- Now, open the Shares tab, click on Tasks and select New Share.
- On clicking, a New Share Wizard opens up. In the wizard, click on Select Proﬁle, select the option SMB Share - Quick, then click Next.
- On the Shared Location tab, enter the ﬁle path to the shared folder that is created for deploying the agent installer, then click Next.
- On the Specify share name tab, enter a name for your share. Enter a share description, if needed.
- The wizard will now automatically create the local and remote ﬁle paths in the share.
- After this, click Next to configure the settings.
- On the Conﬁgure share settings wizard page, accept the default options in Other Settings (Allow caching of share) and Click Next.
- On the Specify permission to control access page, accept the default permissions and click Next.
- On the Conﬁrm selections page, review your selections, then click Create.
- The new public share is now visible in the Shares pane (It is recommendable to make the network share accessible to everyone).
- Now, right-click on the share and select Open Share.
- Download the agent installable from Endpoint Central's console by navigating to Agent-->Agent Installation-->GPO-->Download Agent.
- Also, copy the text from this page and save it as installagentscript.vbs.
- Place UEMSAgent.msi, UEMSAgent.mst,DMRootCA.crt, DMRootCA-Server.crt and installagentscript.vbs ﬁle in the share.
Kindly include DCAgentServerInfo.json file only if the build version is 10.1.2124.1 and above.
Note: Be sure to capture and store the full network ﬁle path (not the local path), it is needed in the later steps.
Create a GPO to identify targets for deployment
- Open the Group Policy Management Console (GPMC) by opening Run (Windows key + r) and typing gpmc.msc.
- Once in the GPMC, right-click on your target "organizational unit" (typically a domain), and select Create a GPO in this domain, and Link it here option.
- Enter a Name for the new GPO. For example, "Desktopcentral_agent_install."
Note: By default, the GPO applies to all users and computers that successfully authenticate to the Active Directory domain that you selected.
- Once the new GPO is created, you can see it in the GPMC in the left navigation pane, under Group Policy Objects.
Note: You can modify the scope of computers to which the agent is deployed and installed by changing the Security Filtering values for the new GPO.
Create a scheduled task to execute the deployment and installation of the Windows Agent
- Open the Group Policy Management Editor by right-clicking on the new GPO you created, and selecting Edit.
- In the editor navigation tree, under Computer Conﬁguration, click Preferences > Control Panel Settings; then, right-click Scheduled Tasks.
- Now, click on New and select Immediate Task (At least Windows 7).
- This opens the New Task dialog box. Enter a Name and a description (if needed).
- Under Security options, click the Change User or Group button.
- In the dialog box that appears, enter "system" in the text box, then click Check Names. Conﬁrm that you have the correct values and click OK.
- Make sure that the system object resolves to the value "NT Authority\System," as shown in the Security Options group.
- Also ensure the following:
- Ensure that Run whether user is logged on or not is selected.
- Ensure that Run with highest privileges is selected.
- Ensure that Conﬁgure for: is set to Windows Vista or Windows Server 2008.
- Click on the Actions tab and then click New.
- In the New Action dialog box, set the Action drop-down to Start a program. In the Program/script text box, enter the network ﬁle path to the shared folder that was created earlier. Then provide the arguments and Start in folder details and click OK.
UEMSAgent.msi UEMSAgent.mst (for below 10.0.653 version)
UEMSAgent.msi UEMSAgent.mst DMRootCA.crt DMRootCA-Server.crt(for versions after 10.0.653)
- In Conditions tab, select the checkbox for Start only if the following network connection is available, then select Any connection.
- Finally, click OK
You have now successfully initiated agent installation using GPO Scheduler.