Automatic Deployment of Endpoint Clients
Software deployment rules are supported for both Windows and macOS.
Use deployment rules to automatically download and install pre-configured packages on endpoint devices.
To deploy Endpoint Security clients with automatic deployment, install one of these deployment packages on the Endpoint clients.
Tiny Agent
The Tiny Agent functionality introduces a few major improvements to the current Initial Client package (which is a very thin client, without any blade, used for software deployment purposes).
The Initial Client is the Endpoint Agent that communicates with the Endpoint Security Management Server.
You can extract the Initial Client from the Tiny Agent.
The improvements include:
-
The Tiny Agent has a very small executable (smaller than 1 MB).
-
It can be shared in various forms, enabling fast, easy, and seamless first-time deployment.
-
When combined with the Dynamic Package, it installs only what is necessary for each machine.
-
It is agnostic to the client version.
-
It passes Smart Screen validation - no more download warnings.
-
It reduces network traffic for installing selected blades.
It is available for cloud deployments and for on-premises deployments running Endpoint Security Management Server R81 or higher.
To download the Tiny Agent:
-
Do one of these:
-
Click Overview, and then click Download Endpoint on the top banner.
-
Click Policy > Deployment Policy > Software Deployment, and then click Download Endpoint on the top banner.
The Download Endpoint Security window appears.
-
-
Select a Download version and a Virtual group, and then click Download for an OS.
-
For Windows OS, the system downloads the EndpointSetup.exe file. Run the
.exefile on the endpoint to install the Endpoint Security client.Note:To extract the
MSIfile, run:EndpointSetup.exe /CreateMSI -
For macOS, the system downloads the EPS_TINY.zip file. Transfer the zip file to the endpoint.
CAUTION:Do not change the EPS_TINY.zip file name.
-
Unzip the file and open the EPS_TINY folder.
-
To install the Endpoint Security client, do one of these:
-
Run the EPNano.app file.
-
In the terminal window, run:
./EPNano.app/Contents/MacOS/EPNano
-
-
-
For Linux OS, the system downloads the installScript.sh file. Run the installScript.sh file on the endpoint to install the Endpoint Security client.
You can deploy the Initial Client to all your endpoint devices, using a third-party deployment tool, manually or remotely (see ).
Troubleshooting Issues with the Tiny Agent on Windows OS
The Tiny Agent shows simple error messages in cases of network issues (connectivity problems, proxy issue, and so on).
Log File Location
The log file is located here:
C:\Windows\System32\LogFiles\WMI\EndpointSetup.etl
Silent Installation
Run:
PsExec.exe -accepteula -nobanner -s "C:\Users\Administrator Username>\Desktop\EndpointSecurity.exe"
Endpoint Security Component Package
Endpoint Security Component Package
This package includes the specified components to be installed on the endpoint device.
You can distribute it automatically with deployment rules.
You can configure the policies for the components before or after you deploy the component package.
Deploy the Endpoint Security component package with deployment rules.
For more details on deployment methods of the Endpoint clients, see the Endpoint Security Server Administration Guide for your version.
Deployment Rules
Deployment rules let you manage Endpoint Security Component Package deployment and updates.
Deployment rules work on both Windows OS and macOS. Linux OS is not supported yet.
The Default Policy rule applies to all Endpoint devices for which no other rule in the Rule Base applies.
You can change the default policy as necessary.
You can define more rules to customize the deployment of components to groups of Endpoint devices with different criteria, such as:
-
Specific Organizational Units (OUs) and Active Directory nodes.
-
Specific computers.
-
Specific Endpoint Security Virtual Groups, such as the predefined Virtual Groups ("All Laptops", "All Desktops", and others.). You can also configure your own Virtual Groups.
Deployment rules do not support user objects.
Mixed groups (that include both Windows OS and macOS objects) intersect only with the applicable members in each rule.