Enroll Windows Devices Via AD Group Policy
- You can enroll devices in bulk by creating an Active Directory (AD) group policy
- You need to download the communication client package and, if required, the transformed MST file. You then need to add these items to the GPO.
- The MST file includes information about the proxy that the client should use to connect to Endpoint Manager and other Comodo servers.
- By default, all devices enrolled via AD are assigned to the currently logged-in admin. You can change the person to whom the devices are assigned during the package download process.
- After enrollment, you can assign devices to their correct owners in the 'Devices' interface. See Change a Device's Owner for more details.
Download the installation package
- Click 'Devices' > 'Bulk Installation Package'
- Select the 'Bulk Installation Package' tab
- Create your custom installer by completing the form. Scroll down for a table that explains the form fields.
- Download Installer - Download the setup file for installation via Group Policy Object (GPO),
- The installer package is created in .msi format. You can transfer the file to the required network location and create a software installation policy for deployment to your endpoints. Once the agent is installed, it establishes communication with the EM server and begins importing devices.
- Download MST File - Download an installer that includes proxy server information for client communication with Endpoint Manager.
- As above, save the file on the AD server from where you want to enroll the endpoints, and add to the GPO created for the .msi file. After the agent is installed, it will establish communications with EM via the proxy servers and begin importing devices.
- For help to create a GPO for bulk enrollment, see https://help.comodo.com/topic-399-1-856-11229-EM---Bulk-Enrollment-via-Active-Directory.html.
- Imported devices inherit the configuration profile of the device owner. The configuration profile of the device user is automatically applied to the device.
Bulk Installation Package - Form Parameters |
|
---|---|
Parameter |
Description |
User |
Devices enrolled by AD GPO
are assigned to the currently logged-in admin by default. Specify a different user if required.
|
Customer |
Choose the company to which the endpoints should be assigned.
|
Device Group |
The device group to which the enrolled devices should be added (optional). Any group profiles will also be applied to the devices you add. See Assign Configuration Profiles to a Device Group if you want more help with this |
Package Options |
Operating system –
Select Window OS version (64 bit, 32 bit or hybrid package) Clients:
If CCS is selected, you can also configure the following: Additional Options:
|
Restart Control Options | CCS only. Endpoints need to
be restarted to complete CCS installation. You have the following
restart options:
Optional. Type a custom message in the 'Reboot Message' field. |
UI Options |
Configure which messages are shown to the user regarding the installation.
|
Proxy Settings |
Specify a proxy server through which the clients should connect to Endpoint Manager and other Comodo servers. If you do not set a proxy then the clients will connect directly as per network settings.
Note:
If you specify a proxy here then you must also configure the same
proxy settings in the profile on the device:
|
Tip: For more help on using GPO for remote installation of software, please see https://support.microsoft.com/en-us/kb/816102. |