Importing Computers by Automatic Installation of Agent
The 'Deploy' wizard will install the ESM agent software on network endpoints that can be reached from the ESM service computer. Computers can be imported from Active Directory, from a Workgroup or by specifying individual IP addresses or host names. The wizard also allows to update installed Comodo software in managed computers. See 'Updating Comodo Software on Managed Computers' for more details.
To import endpoints
-
Click the 'deploy' tile from the 'computers' area to start the wizard:

Step 1 - Select the Target Type
Computers can be imported into ESM in the following ways:
-
Active Directory - imports computers from an Active Directory Domain.
-
Workgroup - imports computers from a Workgroup.
-
Network Address – imports individual computers specified by their IP Addresses or Host Names.
-
Managed Computers - allows to update installed Comodo software in managed computers. See 'Updating Comodo Software on Managed Computers' for more details.
|
Note: Targets are contacted by the ESM service computer and its network connection, not the computer running the management console. |
ESM SME can manage a large number of networked computers so, administrators should repeat this process until all computers for which management is required have been successfully imported.
|
Note: In most editions, licenses are required for each computer you wish to manage. |
Explanations of importing using the sources can be found below in the sections that follow: Import from Active Directory, Import from Workgroup and Import Computers by Network Address.
-
Select the appropriate method to import the computers from Active Directory or Workgroup or select IP Addresses if you want to import computers by specifying their IP addresses or DNS names.

Importing from Active Directory
- Choose 'Active Directory' and move to the next step by clicking the right arrow.
Step 2 - Domain Name
- Select Current Domain or Custom Domain. Current Domain should be chosen if the ESM service computer is currently a member of the domain you wish to use to target for installation. If you select Custom Domain, you have to enter the details of domain controller, an administrator user name and password.

|
Domain Import Settings - Table of Parameters |
|
|---|---|
|
Current Domain |
Selecting this option will import any computers from the Active Directory domain that the CESM server is a member of. |
|
Custom Domain |
Selecting this option allows the administrator to specify an alternative Active Directory domain from which computers will be imported. Choosing this option requires administrators to specify the following details: |
|
Enter the IP address or host name of the Active Directory domain controller from which they wish to import. |
|
Enter the user-name of a user with administrative rights to the domain controller. |
|
Enter the password of the user specified in the 'User Name' field. |
- Swipe to the left or click the right arrow. The wizard moves to next step to select the target endpoints.
The Active Directory structure for the selected domain will be listed.

-
Click the
icon to expand or collapse the tree structure
-
Select the target endpoints onto which you wish to install the agent and import into ESM
-
Click the right arrow or swipe left to move to step 3 to select the endpoints
Importing Computers from Workgroup
- Choose 'Workgroup' and move to the next step by swiping to left or clicking the right arrow.
Step 2 - Workgroup Name
The next step is to select the workgroup(s) from which the endpoints are to be imported.

ESM enables the administrator to specify the workgroup name in two ways:
-
Find workgroups – Makes ESM to search for the workgroups associated with the network and enables administrator to select the workgroup(s) from which the endpoints are to be imported in the next step.

|
Note: The Workgroup is discovered from the local area network attached to the ESM service computer. |
-
Select the workgroup(s) and swipe to the left or click the right arrow to move to step 3 to select the endpoints.
-
Specify workgroup manually – allows the administrator to enter the name of the workgroup from which the endpoints are to be imported in the 'Workgroup:' text box.

-
Enter the name of a network workgroup and click the right arrow. The wizard moves to step 3 , to select the target endpoints.
Importing Computers by Specifying Network Addresses
- Choose 'Network Addresses' and move to the next step by swiping to the left or clicking the right arrow.
Step 2 - Adding IP Addresses
The next step is to add the target computers by specifying their IP address(es) or the host names.

Computers can be added in four ways:
-
Import individual computers by specifying their IP addresses one-by-one - Enter the IP address of the computer and click 'add'. The IP address will be added and displayed below the text box. To add more computers, repeat the process.
-
Import individual computers by specifying their names one-by-one - Enter the name of the target computer as identified in the network and click 'add'. The computer name will be added and displayed below the text box. To add more computers, repeat the process.
-
Import a group of computers by specifying their IP Address range - Enter the IP Address range of the target computers with the Start address and End address separated by a hyphen (e.g. 192.168.111.111-192.168.111.150) and click 'add'. The entered IP address range will be added and displayed below the text box. To add more IP address ranges, repeat the process.
-
Import a group of computers by specifying IP Addresses and Subnet mask – Enter the IP Address and Subnet mask (e.g. 192.168.111.111/24 or 192.168.111.111/255.255.255.0) in the text field and click 'add'. The entered IP address/subnet mask will be added and displayed below the text box. To add more IP address/subnet mask, repeat the process.
-
To remove a computer/computer group added by mistake, select computer(s)/computer group(s) from the text box and click 'remove'.
-
Swipe to the left or click the right arrow to move to the step 3 to select the endpoints.
|
Note: IP addresses are specified relative to the ESM service computer. |
In this step, all the endpoints included in the previous Step 2 will be displayed.

Select the endpoint(s) that you want to deploy the agent and CIS to. You can use the filter option to select the endpoints from the list displayed.
-
Click the filter icon
in the 'Target Computer' column header to search for a particular endpoint and click 'Apply'
-
Click the filter icon
in the 'IP Address' column header to search for endpoints with particular IP(s) and click 'Apply'
-
Click the filter icon
in the 'Status' column header to search for endpoints that are 'Ready' or 'Unavailable' and click 'Apply'
-
Click the filter icon
in the 'Is Managed' column header to search for endpoints that are 'Managed' or 'Not Managed' and click 'Apply'
-
Click the right arrow or swipe left to move to the next step
The next step is to select the administrative account (login) credentials that will be used to remotely upload the installation package using the administrative share on all target computer(s).

|
Credentials - Table of Parameters |
|
|---|---|
|
Current User Credentials |
Selecting this option will install the agent using the credentials of the currently logged -in ESM administrator account in each endpoint |
|
Custom Credentials |
Selecting this option allows the administrator to specify an administrative account for installation of the agent. Choosing this option requires administrators to specify the following details: |
|
Enter the user-name of the dedicated network administrator. |
|
Enter the password of the dedicated network administrator. |
- Click the right arrow or swipe left after entering the credentials to move to the next step
Step 5 - Checking for Updated Software
The next stage 'Packages' displays the version details of ESM Agent and CIS. You can also check for updates of these applications and download it in your server for deployment on to the end-points.

-
Click 'Check for Updates' to find out if any newer version of ESM Agent and CIS are available
-
If any newer versions are available, you can choose to download them to the ESM server by clicking 'Download'
-
Swipe to the left or click the right arrow to move to the next step
The next step is to choose installation options for Comodo Internet Security (CIS):

-
Select 'Install Comodo Internet Security' check box if you wish CIS to be installed along with the agent.
|
Note: If the option to install CIS is not be selectable, your license for Comodo Endpoint Security Manager did not include CIS software. |
-
Select the version of CIS you wish to install on the selected endpoints from the drop-down. Note - the drop-down will be empty the first time ESM is run. You must first click 'Check For Updates' then 'Update' to populate the drop-down as explained the previous Step - Checking for Updated Software.

-
Select whether you want to include all the components (Firewall and Antivirus), Antivirus only or Firewall only from the Components drop-down.

-
Suppress reboot after installation - CIS installation will restart of the endpoints for the installation to take effect. If you do not want the endpoints to be restarted on completion of installation, select this check box. CIS installation will complete but will take effect only on the next restart of the endpoint.
-
Uninstall all incompatible products - Selecting this option uninstalls select third party antivirus, firewall and other desktop security software from the endpoints, prior to the installation of CIS. Performing this step will remove potentially incompatible products and thus enable CIS to operate correctly. Some incompatible products can be detected, but not automatically uninstalled and must be removed manually. If your product is detected but not uninstalled, please consult your vendor’s documentation for precise uninstallation guidelines.
However the following steps will help most Windows users:
-
Click the Start button to open the Windows Start menu
-
Select Control Panel > Programs and Features (Win 7, Vista); Control Panel > Add or Remove Programs (XP)
-
Select your current antivirus or firewall program(s) from the list
-
Click Remove/Uninstall button
-
Repeat process until all required programs have been removed
Click Here to see the full list of incompatible products.
- Click the right arrow to move to the next step.
|
Tip:
You can also:
|
- Click 'Start Deployment'

ESM will start installing the agent/CIS on to the selected endpoints and the progress will be displayed.

If any of the selected endpoints have older versions of CIS than the one selected in the previous Step 6, they will be automatically uninstalled and the selected version will be installed.
Step 8 – Deployment Complete
On completion of installation, the results screen will appear.

-
If deployment fails, click on the words 'Deployment Failed' to discover the reason. The info box also contains advice that may remediate the issue.

-
Click Finish icon
or swipe the screen to the left to exit the wizard.
The endpoints selected in Step 3 are now added to ESM and are ready for management through ESM. Refer to the section 'Viewing Endpoints' for more details on how to view the list of imported endpoints.
The newly added computers will be added to the default group 'Unassigned'. If this group has been changed to use a specific policy, that policy will be applied after the agent installation is completed. The administrator can create and name new groups according to the structure of the organization and move the added computers into them from 'Unassigned' group. Once created, admins can run tasks on entire groups of computers (such as applying security policy to CIS, running AV scans, deploying agents, updating AV databases and more). Refer to Creating Endpoint Groups for more details.

