×
×
×
×

Remote Office | Endpoint Central

Most companies have their branch offices spread across the world. Managing computers in these branch offices effectively is always a tedious job for the system administrators. With Endpoint Central in hand, managing computers in WAN across remote offices will turn out to be a much easier process. To manage computers in a remote location you have to add remote offices. You can add and modify the remote offices according to your requirement.

Remote Office

Remote Office refers to a location-based group that represents the geographical locations of an organization's network. Each geographical presence of an organization can be created as a different Remote Office to manage the computers in each location. Kindly note that only one Distribution Server can be configured per remote office and vice-versa.

To know more about adding a remote office, click here

Communication Type

Computers in different locations can either communicate directly with the Central Server or via a Distribution Server. Each method has its own advantages depending on factors like network bandwidth, proximity to the Central Server, and the number of computers being managed.

Two categories of Remote Offices depending on the communication method used by Agents to connect with the Central Server:

Direct Communication with Central Server

Each computer communicates directly with the Central Server to receive scripts or workflows. This method is best for LAN or smaller locations where computers are on the same network as the Central Server or where the WAN bandwidth is sufficient to handle multiple direct connections to download updates and configurations.

Each computer communicates directly with the Central Server to receive updates, patches, configurations, and software. This method is best for LAN or smaller locations where computers are on the same network as the Central Server or where the WAN bandwidth is sufficient to handle multiple direct connections to download updates and configurations.

When to use direct communication

When you choose your communication type as Direct communication, all the remote office computers will get the required data from the Endpoint Central server directly. You can use this option, if you have limited computers in your remote office, say less than 10, or if you do not have any bandwidth limitation.

Distribution Server

The Distribution Server is a lightweight software component installed on one of the computers in remote offices. This component acts as an intermediary between the Central Server and Agents for pulling updates, patches, and configurations from the Central Server and replicating them to Agents. While configuring Distribution Server, kindly ensure that both Distribution Server and Central Server are able to communicate with each other.

The Distribution Server is a lightweight software component installed on one of the computers in remote offices. This component acts as an intermediary between the Central Server and Agents for pulling scripts or workflows from the Central Server and replicating them to Agents. While configuring Distribution Server, kindly ensure that both Distribution Server and Central Server are able to communicate with each other.

Note
The term "Distribution Server" does not imply that it must be installed on a Windows Server OS. It can also be deployed on Windows client OS machines. For more information on the supported operating systems for the Distribution Server component, kindly refer to the official documentation.

When to use Distribution Server

Distribution server acts as a communication layer between your remote office computers and the Endpoint Central server. It replicates the software and patch binaries from the Endpoint Central server and gives it to the computers in that remote office. The remote office computers, instead of getting the patch and software binaries individually from the Endpoint Central server, gets it from the Distribution server, thus saving your WAN bandwidth. So, it is ideal to use a Distribution Server, if you have a limited WAN bandwidth and if you can afford to keep a dedicated computer which should be always running, to serve as the Distribution server. We recommend Distribution server when you manage more than 10 computers in your remote office.

  • Efficient bandwidth usage, as only one agent periodically communicates with the Central Server.
  • Retrieves configuration details, software packages, patches, and more from the UEMS, making them available to other computers in the branch.
  • Secure communication is supported via SSL/HTTPS with the Central Server.
  • One-time installation, with future upgrades being automatically handled.

This setup streamlines the management of remote office computers while minimizing network load.

When to use Distribution Server

Distribution server acts as a communication layer between your remote office computers and the Endpoint Central server. It replicates the scripts or workflows from the Endpoint Central server and gives it to the computers in that remote office. The remote office computers, instead of getting the scripts or workflows individually from the Endpoint Central server, gets it from the Distribution server, thus saving your WAN bandwidth. So, it is ideal to use a Distribution Server, if you have a limited WAN bandwidth and if you can afford to keep a dedicated computer which should be always running, to serve as the Distribution server. We recommend Distribution server when you manage more than 10 computers in your remote office.

  • Efficient bandwidth usage
  • Retrieves scripts and workflows, making them available to other computers in the branch.
  • Secure communication is supported via SSL/HTTPS with the Central Server.
  • One-time installation, with future upgrades being automatically handled.

This setup streamlines the management of remote office computers while minimizing network load.

Note
The Distribution Server can download the task files from the Central Server and serve them to the Agents. For other activities, agents should have a connection to the Central Server.

This method is ideal for remote offices or locations with limited WAN bandwidth where numerous computers need to be managed, particularly for large branch offices with many computers, ensuring efficient bandwidth usage.

Comparison Matrix

Comparison matrix for Direct Communication and through the Distribution Server for different aspects.

AspectDirect CommunicationThrough Distribution Server
Best forLocal offices or small offices with sufficient bandwidth / Less than 50 computersRemote/branch offices with limited WAN bandwidth or large numbers of computers (more than 50)
Setup ComplexitySimple, no intermediary server neededRequires setting up a Distribution Server in each remote office
Bandwidth UsageHigh, as each device connects directly to the Central ServerOptimized, as only the Distribution Server communicates with the Central Server
Server LoadHigher, as more computers contact the server directlyLower, as fewer direct connections are made to the Central Server
ScalabilityMay strain bandwidth in large environmentsScales well for large remote offices with many computers

Remote Office Movement

Managing the devices of the sales and marketing teams is a challenging task for an IT administrator. This is because people in these teams tend to be traveling around the country and even the globe to other branch offices or to an event. Tracking their devices and maintaining compliance in situations like this can be a tricky process. However, using Remote Office movement capabilities supported in Endpoint Central, those computers can be tracked and managed efficiently under the appropriate Remote Offices. To know how to move remote office click here.

Bandwidth Planning in Remote Office

Scenario
Say you have 40,000 computers or endpoints to be managed, and there are 80 remote offices with 500 endpoints in each one of them.
Note
In this example, we'll assume that all 500 endpoints in each remote office can communicate with their corresponding Distribution Servers.

The endpoints in the remote offices will communicate with the corresponding distribution servers in the same office, and the distribution servers will communicate with the Endpoint Central server either during the configured Replication Interval or when performing an on-demand task. Broadly, the objective of the communication can be any one of the following:

  • Replicate patch binaries
  • Replicate software binaries
  • Replicate scripts

In this example, the endpoints are running on any one of the following operating systems:

  • Windows 10 (Feature pack 1607, 1703, 1803, or 1903)
  • Windows Server 2016 standard (Feature Pack 1607, 1703, 1803, or 1903)

Microsoft releases cumulative patch updates every month for Windows 10 and Windows Server 2016. This cumulative patch update's size can range anywhere from 120MB to 1.5GB, or may be even more for each operating system. The size of these patches increases regularly. Furthermore, the patches of various applications are released in different sizes; for example, Microsoft Office 365 is around 3GB to 4GB.

The download size for the example environment is around 4GB to 5GB per month, and the size will increase each month.

Therefore, whenever there is a cumulative patch update, the minimum bandwidth required by each Distribution Server is 1Mbps to allow the patches to be downloaded within 24 hours.

For the main Endpoint Central server, or central server, the minimum bandwidth required is 80Mbps so it can serve 80 Distribution Servers simultaneously. Since the patches also have to be downloaded from the vendor's website, it's advisable to have additional bandwidth to facilitate the process of updating patches.

Note
It is highly recommended to have a separate replication window for each Distribution Server to prevent any bandwidth bottleneck issues. For example, if the available bandwidth is only 50Mbps for the main Endpoint Central server, then the replication window can be configured to serve up to 30 Distribution Servers at any particular point in time. The remaining 20Mbps is used to download patches from various vendors' websites. This means there can be three replication windows of eight hours each. This might cause some delay in replication, but bandwidth-choking can be prevented.

Summary

To summarize, for an organization with 40,000 endpoints, 80 remote offices, 500 endpoints, and each remote office having one Distribution Server, the recommended bandwidth requirements for a replication window of 24 hours are:

ComponentBandwidth required in Mbps
Distribution Servers2
The main Endpoint Central server100

For three replication windows of eight hours each (i.e., 12am-8am, 8am-4pm, and 4pm-12pm), the minimum bandwidth requirements are:

ComponentBandwidth required in Mbps
Distribution Servers2
The main Endpoint Central server50