Remotely Installing the Initial Client

You remotely install the Initial Client from the Push Operations view or from the Asset Management view.

To install the Initial Client remotely from the Push Operations view

  1. From the left navigation panel, click Push Operations.

  2. From the top toolbar, click (+) Add.

    The Add Push Operation window opens.

  3. On the Select push operation page.

    1. From the menu, select Agent Settings.

    2. In the list of options, click Deploy New Endpoints.

    3. At the bottom, click Next.

  4. On the Select devices page.

    1. Click (+).

    2. Select devices that do not have Endpoint installed and are not in the process of deployment.

      Note:
      • To select several non-adjacent entries, press and hold the CTRL key while you click the applicable entries.

      • To select several adjacent entries, press and hold the SHIFT key, click the applicable top entry, and then, click the applicable bottom entry.

      • To clear a selection, press and hold the CTRL key while click the applicable entry again.

      • You can select up to 5,000 entries.

    3. At the bottom, click Update Selection.

    4. In the table with the entries, select the checkboxes of applicable devices.

    5. At the bottom, click Next.

  5. On the Configure Operation page.

    1. In the Comment field, enter the applicable text.

    2. In the Select deployment agent field, select one device for this push operation.

    3. In the Endpoint version menu, select the applicable version.

      Only devices with Windows 7 and higher are supported.

    4. In the Scheduling section, configure one of the applicable settings.

      • Execute operation immediately

      • Schedule operation for, and click the calendar icon to configure the date and time

    5. Click Finish.

To install the Initial Client remotely from the Asset Management view

  1. From the left navigation panel, click Asset Management.

  2. Select the checkboxes of applicable devices (up to 5,000).

  3. From the top toolbar, click Push Operation > from the menu that appears click Agent Settings > Deploy New Endpoints.

    The Push Operation Creation Dialog window opens.

  4. Enter the required values.

    1. In the Comment field, enter the applicable text.

    2. In the Select deployment endpoint field, select one device for this push operation.

    3. In the Endpoint version menu, select the applicable version. Only devices with Windows 7 and higher are supported.

    4. In the Scheduling section, configure one of the applicable settings.

      • Execute operation immediately

      • Schedule operation for, and click the calendar icon to configure the date and time

  5. Click Create.

Windows Task Scheduler on endpoint devices

  1. After a connection to the Task Scheduler service on Windows OS, the Deployment Agent registers a new task: "CP_Deployment_{unique ID}".

  2. The Deployment Agent runs the task from the domain administrator's account on the target computer.

  3. The Task Scheduler spawns the msiexec.exe to download the client installer and launch it in silent mode.

  4. The installation proceeds with the MSI script instructions.

Security Considerations

  • The Deployment Agent does not store the administrator password in clear text.

  • The client UI collects the credentials and passes them to the device agent to store in separate values of a registry key under EP root.

  • The password stores as an encryption and the principal name stores in plain text.

  • Administrator accounts have access permissions of FULL CONTROL for the registry key.

  • The SYSTEM account has READONLY access permissions for the registry key.

  • The user and password never pass to the target devices. They establish the Task Scheduler connection.

Progress of Installation and Error Handling

The installation status shows at the bottom page of the Push Operation view.

Target devices that fail to install and download the Initial Client, set their status accordingly. In case of a connection failure, the Deployment Agent tries to connect to the target service three more times with increasing interval between attempts. The default is ten seconds. This mechanism increases the success rate in case of network-related issues.

The Deployment Agent Cannot Reach the Remote Task Scheduler

If the Deployment Agent cannot reach the remote task scheduler on the target device, the specific installation procedure fails. The target device's Operation Status changes to "Failed to access remote task scheduler".

The Target Device Fails to Download the Initial Client

If the target device cannot download the Initial Client, the target device's Operation Status changes to "Failed to download client".

Invalid Credentials

If the domain administrator credentials are invalid, the Deployment Agent stops connecting to remote targets, and the target device's Operation Status changes to "Access denied due to Invalid credentials".

Missing Credentials

If the domain administrator credentials are missing, the Deployment Agent stops connecting to remote targets, and the target device's Operation Status changes to "Deployment agent is not configured".

Failed to Install Initial Client on Target Device

If the target device fails to install the Initial Client, the target device's Operation Status changes to "Failed to install agent on target device".

Target Device Already Has an Agent installed

If the target device has an agent already installed, the Initial Client installation fails. The target device's Operation Status changes to "Agent already installed".

The Deployment Agent is Not Available to Deploy Targets

If the Deployment Agent cannot be reached while a push operation takes place, the push operation aborts, fails and sets the entire push-operation status to "The deploying Agent is not available to deploy targets".

Ports and Permissions

For installations that traverse a perimeter Firewall, enable this port: Port 135 for RPC over TCP traffic.

Upgrades

Upgrades are seamless to our users. A new type of Push Operation are rolled out and added to all Endpoint Security users.