How to install Network Agent in Kaspersky Security Center 10 via group policies
Latest update: September 09, 2019
ID: 10639
You can install Network Agent remotely using group policies. An installation package in the Microsoft Installer (MSI package) format is moved to the shared folder. The package is registered in the installation section of the Active Directory policy, which is distributed to the domain computers. Next time you enter the domain, computers download the installation package from the shared folder and install it according to the group policy.
To install Network Agent using group policies:
- Open the Administration Console.
- Go to Managed devices and select Install application from the shortcut menu of the device or group.
- Select the Network Agent installation package and click Next.
- Select the checkbox Assign the package installation in the Active Directory group policies and clear the remaining checkboxes. Click Next.
- Specify the account included in the local administrators group on the server with Kaspersky Security Center installed, the Group Policy Creator Owners domain group.
- Grant the account the necessary permissions.
- Finish the wizard.
During this type of installation, the Administration Server creates:
- A group policy named Kaspersky_AK {GUID} and includes in it all the accounts on the computers the task is being applied to.
- A new domain level group policy object with the same name, Kaspersky_AK {GUID}, and assigns it the installation of the Network Agent MSI package, which is located in the server’s public folder.
How to grant the account the necessary permissions
- Open the Group Policy Management console.
- Select the domain and go to Delegation.
- In the Permission drop-down list, select Link GPOs.
- Click Add and select the necessary account.
- Select the account you have just added and click Advanced → Advanced.
- In the Permission entries list, find the account and grant the permissions:
- Object creation: Create Group objects
- Object deletion: Delete Group objects
- Create groupPolicyContainer objects
- Delete groupPolicyContainer objects
- Save the changes.