• No results found

Administration Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

N/A
N/A
Protected

Academic year: 2021

Share "Administration Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit"

Copied!
32
0
0

Loading.... (view fulltext now)

Full text

(1)

. All right reserved.

For more information about Specops Deploy and other Specops products, visit www.specopssoft.com

Administration Guide

(2)

2

Copyright and Trademarks

Specops Deploy™ is a trademark owned by Specops Software. All other trademarks used in this document belong to their respective owners.

(3)

3

Contents

About Specops Deploy / App 5

Key components 6

Managing Your Deployments 7

Control Center 7

Specops Deploy GPMC snap-in 8

Managing GPOs 9

Deployments 13

Creating a package 14

Selecting a target 21

Configure the deployment 26

Configuring The Specops Deploy Client Side Extension From The Administrative

Template 31

Configure the Specops Deploy Client Side Extension from the Administration Template 31

(4)

4

About this guide

This guide is intended for administrators who are responsible for managing App deployments in their Microsoft Active Directory environment. Before you perform the tasks in this guide, please ensure you have correctly installed Specops Deploy / App. You can find the Specops Deploy / App Installation Guide at www.specopssoft.com/documentation/specops-deploy-

documentation/specops-deploy-installation-guide.

(5)

5

About Specops Deploy / App

Specops Deploy / App automates the installation of software and applications in your Microsoft Active Directory environment. Specops Deploy extends the functionality of Group Policy and can be used to target any number of user and computer objects within Active Directory.

Specops Deploy is a complete deployment management solution. Specops Deploy is a component of the Specops Desktop Management suite. You can learn more about Specops Deploy and other Specops products at www.specopssoft.com.

(6)

6

Key components

You can administer the product from the Specops Deploy Administration Tools. The Administration Tools consist of the following components.

Specops Deploy Control Center: The Specops Deploy Control Center can be used to edit Specops Deploy / App GPOs, and deploy software packages to computers in your network.

Specops Deploy GPMC snap-in: The Specops Deploy GPMC snap-in can be used to edit Specops Deploy / App GPOs from the GPMC, and deploy software packages to computers in your network.

Note: The Specops Deploy Control Center, and Specops Deploy GPMC snap-in have the same functionality. Both tools can be used to edit the same GPOs. The Specops Deploy Control Center hides some of the complexity of the underlying Group Policy infrastructure and is intended for administrators that are not familiar with Group Policy, while the GMPC snap-in integrates with the Group Policy Management Console and is intended for administrators that are familiar with administering Group Policy within Active Directory.

Specops Configuration Tool: The Specops Configuration Tool can be used to import your license keys and monitor the status of your Client Side Extensions.

(7)

7

Managing your deployments

The Specops Deploy Control Center and/or the Specops Deploy GPMC snap-in can be used to manage your deployments.

Control Center

You can access the Specops Control Center via the start menu. When you launch the Control Center for the first time, you will need to select an existing GPO, or create a new GPO.

(8)

8

Specops Deploy GPMC snap-in

You can access the Specops Deploy GPMC snap-in from the Group Policy Management Editor.

1. Open the GPMC and navigate to the GPO you want to the GPO you want to edit.

2. Right click on the GPO and select Edit…

3. In the Group Policy Management Editor, expand:

 Group Policy Name>Computer Configuration>Software Settings>Specops Deploy

And/or

 Group Policy Name>User Configuration>Software Settings>Specops Deploy

(9)

9

Managing GPOs

Specops Deploy stores all information about software deployments in Group Policy Objects.

There are three common strategies when creating a GPO with Specops Deploy / App settings:

 Single GPO: A single GPO is used to store all Specops Deploy / App settings. The GPO is linked high in the Active Directory structure to ensure that it affects as many computer objects as possible. The single GPO uses Targets extensively to narrow down which client should get the software installed.

 Standard + Special Application GPO: A single GPO is used for the most commonly installed application and one or more GPOs are used for special

applications. This can be used when you want to group your deployments based on the application type.

 Administration unit GPO: The administration unit GPO is commonly used in larger organization where software deployment administration is performed in more than a single location.

(10)

10

Create a new GPO using the Control Center

The Specops Deploy Control Center works within the context of one GPO. The scope of the GPO should contain all the computers and users that you want to manage software for.

1. In the navigation pane, expand Options, and click Select Group Policy Object.

2. Click Create and Select a new Group Policy Object.

3. In the text field, enter a name for the Group Policy Object.

4. Select the location you want to link the Group Policy Object to, and click OK.

Note: The GPO will not be created and linked to the selected OU.

(11)

11

Change the selected GPO using the Control Center

1. In the navigation pane, expand Options, and click Select Group Policy Object.

2. Click Select an existing Group Policy object.

3. The dialog box will display a list of all the Group Policy Objects in your domain.

4. Select the Group Policy Object you want to manage software for.

Note: Verify that the Group Policy Object you select is linked to a User and/or Computer.

5. Click OK.

Note: When a GPO targets an OU, only the computers in the OU where the Specops Deploy Client Side Extension have been installed will receive deployments.

(12)

12

Create a new GPO using the GPMC snap-in

The Specops Deploy GPMC snap-in works within the context of one GPO. The scope of the GPO should contain all the computers and users that you want to manage software for.

1. In the Group Policy Management Console, expand your domain node and locate the OU you want to link the Group Policy Object to.

2. Right click on the OU, and select Create a GPO in the domain and link it here.

3. In the text field, enter a name for the new GPO, and click OK.

Note: When a GPO targets an OU, only the computers in the OU where the Specops Deploy Client Side Extension have been installed will receive deployments.

(13)

13

Deployments

A Deployment is the package and target combined with additional deployment parameters such as when and how the package will be deployed.

 Software Package: Information about the software you want to deploy, such as: name, version, and path to setup files.

 Target: The computers or users that should receive the package.

(14)

14

Creating a package

Specops Deploy packages contain information about a software installation, such as network file path to the installation files and any parameters needed to install the software.

There are four different package types:

 Windows Installer: A Windows Installer package uses an msi-file as the installation source and is applied on the client through Windows Installer.

 Windows Installer Patch: A Windows Installer Patch, or msp-file is a type of msi- package that updates an existing software installation. Windows Installer patches are applied through Windows Installer and require little or no configuration.

 App-V package: Microsoft Application Virtualization packages are based on App-V 4.6 or 5.0 package files. These applications can only be installed on clients that have the App-V client installed.

 Legacy Setup: The legacy package type indicates that the installation is run through a separate executable, typically a Setup.exe installation program. The setup file is fully responsible for all actions it performs during the software installation and typically requires many configuration parameters to silently install the software without end user intervention. In order to remove the installed software, you must also specify

uninstallation commands for legacy setups. remote

 Windows Store Applications: Windows Store applications are applications that are designed for the Windows 8 start screen. Before you can deploy your Windows Store App you need to package and sign it using the App Packager (MakeAppX.exe) and SignTool (SignTool.exe) executables shipped with Visual Studio 2012 and the Windows 8 SDK.

(15)

15

Create a package using the Control Center

1. In the navigation pane expand tasks, and click Deploy Package.

2. Click Create new package.

3. Select the type of package you want to create, and click OK.

1. In the package category field, click New to create a new Package Category.

Note: You can use an existing Package Category.

2. Enter a name and description for the Package Category, and click OK.

Note: Selecting a package category is not mandatory but it will allow you to easily sort and view the deployments.

3. Browse to the location of the file, and click Open.

Note: The path to the source files must be in the UNC format.

4. Verify that the Package Properties field has automatically been updated and enter a description for the package in the text field.

5. In the navigation pane, select Installation options and modify the following settings:

Setting Step

Additional Windows Installer Properties  Enter parameters to the install command in the text field.

Pre-installation commands and parameters

1. Expand Show advanced options.

2. In the Pre installation command text field, enter the full path to a command that will be executed before a package is installed.

3. Enter parameters to the pre-installation command in the parameters text field.

4. In the text field, enter the exit code value that represents a successful execution. You can also choose to ignore the exit code.

Post-installation commands and parameters

1. Expand Show advanced options.

2. In the Post installation command text field, enter the full path to a command that will be executed after a package is installed.

3. Enter parameters to the pre-installation command in the parameters text field.

(16)

16 4. In the text field, enter the exit code value that

represents a successful execution. You can also choose to ignore the exit code.

6. Once you have modified the installation options, select Uninstallation options from the navigation pane to configure the parameters that will be used when you choose to uninstall a package. You can modify the following settings:

Setting Step

Pre-installation commands and parameters

1. Expand Show advanced options.

2. In the Pre installation command text field, enter the full path to a command that will be executed before a package is installed.

3. Enter parameters to the pre-installation command in the parameters text field.

4. In the text field, enter the exit code value that represents a successful execution. You can also choose to ignore the exit code.

Post-installation commands and parameters

1. Expand Show advanced options.

2. In the Post installation command text field, enter the full path to a command that will be executed after a package is installed.

3. Enter parameters to the pre-installation command in the parameters text field.

4. In the text field, enter the exit code value that represents a successful execution. You can also choose to ignore the exit code.

7. If the package you are creating is a Windows Installer package, click Transforms in the navigation pane and follow the below steps. If you are not creating a Windows Installer Package, skip to step 14.

a. Click Add to add a transform MST file to the package.

b. Click OK.

8. Click Advanced options in the navigation pane.

9. If you want to allow computers to reboot if it is required by the package, enable the checkbox. If the checkbox is enabled, you can also force computers to reboot after installing or uninstalling the package.

10. If the package file is not in the root directory of the files and directories required by the package, you will need to change the path. Click Change.

(17)

17 11. Enable the Use HTTP URL as package source checkbox if you want to use a HTTP

URL as the package source.

a. Enable an HTTP directory for the package.

12. To view a list of changes made to the package, click Modify history in the navigation pane.

13. Click OK to save the new package.

(18)

18

Create a package using the GPMC snap-in

1. Open the GPMC and navigate to the GPO you want to the GPO you want to edit.

2. Right click on the GPO and select Edit…

3. In the Group Policy Management Editor, expand:

 Group Policy Name>Computer Configuration>Software Settings>Specops Deploy

or

 Group Policy Name>User Configuration>Software Settings>Specops Deploy

4. Select Click here to deploy a package.

5. Click Create new package.

6. Select the type of package you want to create, and click OK.

7. In the package category field, click New to create a new Package Category.

Note: You can use an existing Package Category.

8. Enter a name and description for the Package Category, and click OK.

Note: Selecting a package category is not mandatory, but it will allow you to easily sort and view the deployments.

9. Browse to the location of the file, and click Open.

Note: The path to the source files must be in the UNC format.

10. Verify that the Package Properties field has automatically been updated and enter a description for the package in the text field.

11. In the navigation pane, select Installation options and modify the following settings:

Setting Step

Additional Windows Installer Properties  Enter parameters to the install command in the text field.

Pre-installation commands and parameters

5. Expand Show advanced options.

6. In the Pre installation command text field, enter the full path to a command that will be executed before a package is installed.

7. Enter parameters to the pre-installation command in the parameters text field.

8. In the text field, enter the exit code value that represents a successful execution. You can also choose to ignore the exit code.

(19)

19 Post-installation commands and

parameters

5. Expand Show advanced options.

6. In the Post installation command text field, enter the full path to a command that will be executed after a package is installed.

7. Enter parameters to the pre-installation command in the parameters text field.

8. In the text field, enter the exit code value that represents a successful execution. You can also choose to ignore the exit code.

12. Once you have modified the installation options, select Uninstallation options from the navigation pane to configure the parameters that will be used when you choose to uninstall a package. You can modify the following settings:

Setting Step

Pre-installation commands and parameters

5. Expand Show advanced options.

6. In the Pre installation command text field, enter the full path to a command that will be executed before a package is installed.

7. Enter parameters to the pre-installation command in the parameters text field.

8. In the text field, enter the exit code value that represents a successful execution. You can also choose to ignore the exit code.

Post-installation commands and parameters

5. Expand Show advanced options.

6. In the Post installation command text field, enter the full path to a command that will be executed after a package is installed.

7. Enter parameters to the pre-installation command in the parameters text field.

8. In the text field, enter the exit code value that represents a successful execution. You can also choose to ignore the exit code.

13. If the package you are creating is a Windows Installer package, click Transforms in the navigation pane and follow the below steps. If you are not creating a Windows Installer Package, skip to step 14.

a. Click Add to add a transform MST file to the package.

b. Click OK.

(20)

20 14. Click Advanced options in the navigation pane.

15. If you want to allow computers to reboot if it is required by the package, enable the checkbox. If the checkbox is enabled, you can also force computers to reboot after installing or uninstalling the package.

16. If the package file is not in the root directory of the files and directories required by the package, you will need to change the path. Click Change.

17. Enable the Use HTTP URL as package source checkbox if you want to use a HTTP URL as the package source.

a. Enable an HTTP directory for the package.

18. To view a list of changes made to the package, click Modify history in the navigation pane.

19. Click OK to save the new package.

(21)

21

Selecting a target

Once a package has been created, it can be configured for deployment using targeting criteria.

A target consists of a set of criteria which the client will match against its own environment. If the criterion matches the client environment, the target is considered valid and the deployments associated with the target should be acted on. The Client will evaluate all targets in every GPO with Specops Deploy / App settings.

(22)

22

Select a target using the Control Center

1. In the navigation pane, expand Objects, and click Targets.

2. Click New Target.

3. Select the type of target you want to create, and click OK.

Note: Computer and user targets are different. Packages deployed to a Computer target will install software to a specific set of computers while packages deployed to a user target will install on any computers where the users logon.

4. Enter a name and description for the target in the text field.

5. Select Target criteria from the navigation pane.

6. To add Target Criteria select the Add Target Criterion drop box. You can add the following criteria:

Criteria Description

Membership criteria The Membership criteria consists of the following items:

 Security groups

 Organizational units

 User names

 Computer names

 Sites

 Ip address range

Environment criteria The Environment criteria consists of the following items:

 Languages

 Environment variables

 Registry settings

Hardware criteria The Hardware criteria consists of the following items:

 Computer models

 BIOS versions

 Hard drive free space

 Processor

 Memory size

Software criteria The Software criteria consists of the following items:

 Operating systems

 Windows installer installations

 Files

WMI Query  Query the Windows Management

Instrumentation

(23)

23 7. Once you have added the target criteria, they will be displayed in the list. From the list

you can:

 Edit a criterion

 Remove a criterion

8. To view a list of changes made to the package, click Modify history in the navigation pane.

9. Click OK to save the new user target.

(24)

24

Select a target using the GPMC Snap-in

1. In the Group Policy Management Editor, expand:

 Group Policy Name>Computer Configuration>Software Settings>Specops Deploy

or

 Group Policy Name>User Configuration>Software Settings>Specops Deploy

Note: Computer and user targets are different. Packages deployed to a Computer target will install software to a specific set of computers while packages deployed to a user target will install on any computers where the users logon.

2. Select the target node, and click New Target.

3. Enter a name and description for the target in the text field.

4. Select Target criteria from the navigation pane.

5. To add Target Criteria select the Add Target Criterion drop box. You can add the following criteria:

Criteria Description

Membership criteria The Membership criteria consists of the following items:

 Security groups

 Organizational units

 User names

 Computer names

 Sites

 IP address range

Environment criteria The Environment criteria consists of the following items:

 Languages

 Environment variables

 Registry settings

Hardware criteria The Hardware criteria consists of the following items:

 Computer models

 BIOS versions

 Hard drive free space

 Processor

 Memory size

Software criteria The Software criteria consists of the following items:

 Operating systems

(25)

25

 Windows installer installations

 Files

WMI Query  Query the Windows Management

Instrumentation

6. Once you have added the target criteria, they will be displayed in the list. From the list you can:

 Edit a criterion

 Remove a criterion

8. To view a list of changes made to the package, click Modify history in the navigation pane.

9. Click OK to save the new user target.

(26)

26

Configure the deployment

Once you have the package and the target you can configure additional deployment parameters such as when and how the package will be deployed.

(27)

27

Configure the deployment using the Control Center

1. In the navigation pane, expand Objects and select Deployments.

2. Click New Deployment.

3. Select the package you want to deploy, and click OK.

4. From the Target drop down menu select the target the package will be deployed to.

5. Select the installation type. You will be given the following options:

Option Description

Install A full installation that completely installs the package on the computer.

Advertise only The package is prepared for installation but the files are not installed.

Publish in Add/Remove programs The package is published in the available programs list in Add/Remove programs

6. In the navigation pane, select Deployment options. You can configure the following items:

Option Description

Installation time  As soon as possible

 Not before

Installation options  Only install during user logon

 Only install after the user has logged on

 Both

Source file options  Download and install, remove source files from cache

 Download and install, leave source files in cache

 Install from network Uninstall the package if the

deployments falls “Out of the Scope of Management”

 Uninstalls the package if the GPO no longer applies

7. In the navigation pane, select End User Interaction. You can configure the following items:

Option Description

Installation popup dialog  None

(28)

28

 Display popup Use custom end user message

8. To view a list of changes made to the package, click Modify history in the navigation pane.

9. Click OK to start deployment.

View deployment feedback using the Control Center

You can use the Control Center to monitor, in real time, the status of deployments.

1. In the navigation pane, expand Objects and select Deployments.

2. Click Deployment feedback to view the status of deployments.

(29)

29

Configure the deployment using GPMC snap-in

1. In the Group Policy Management Editor, expand:

 Group Policy Name>Computer Configuration>Software Settings>Specops Deploy / App

or

 Group Policy Name>User Configuration>Software Settings>Specops Deploy / App

2. Click Deployments.

3. Select the package you want to deploy, and click OK.

4. From the Target drop down menu select target the package will be deployed to.

5. Select the installation type. You will be given the following options:

Option Description

Install A full installation that completely installs the package on the computer.

Advertise only The package is prepared for installation but the files are not installed.

Publish in Add/Remove programs The package is published in the available programs list in Add/Remove programs

6. In the navigation pane, select Deployment options. You can configure the following items:

Option Description

Installation time  As soon as possible

 Not before

Installation options  Only install during user logon

 Only install after the user has logged on

 Both

Source file options  Download and install, remove source files from cache

 Download and install, leave source files in cache

 Install from network Uninstall the package if the

deployments falls “Out of the Scope of Management”

 Uninstalls the package is the GPO no longer applies

(30)

30 7. In the navigation pane, select End User Interaction. You can configure the following

items:

Option Description

Installation popup dialog  None

 Display popup Use custom end user message

8. To view a list of changes made to the package, click Modify history in the navigation pane.

9. Click OK to start deployment.

View deployment feedback using the GPMC snap-in

You can use the GMCP snap-in to monitor, in real time, the status of deployments.

1. In the Group Policy Management Editor, expand:

 Group Policy Name>Computer Configuration>Software Settings>Specops Deploy / App

or

 Group Policy Name>User Configuration>Software Settings>Specops Deploy / App

2. Click Deployments.

3. Click Deployment feedback to view the status of deployments.

(31)

31

Configuring the Specops Deploy Client Side Extension from the Administrative Template

The Specops Deploy Client Side Extension can be configured using the administrative template in the Group Policy Management Console. You can configure the following settings using the Administrative Template:

 Control how often (in days) the client side extension sends heartbeats to the server.

 Disable the Software Updater on the client.

 Time in minutes that the Software Updater will wait before automatically starting processing Deployments.

Configure the Specops Deploy Client Side Extension from the Administration Template

1. Open the GPMC and navigate to the GPO you want to edit.

2. Right-click on the GPO and select Edit…

3. In the Group Policy Management Editor dialog box, expand Computer Configuration, Policies, Administrative Templates, Specops Deploy.

4. You can configure the following settings:

 Client Side Heartbeat Interval

 Software Updater

5. Double-click the setting you want to configure.

6. Make the necessary changes, and click OK.

After you finish: Create a Central Store for Group Policy Administrative Templates and add the Specops Deploy Administrative template.

Create a Central Store for Group Policy Administrative Templates

The Central Store for Administrative Templates allows you to store all template files in a single location on SYSVOL where they can be accessed and presented on any server from your domain. To create a Central Store for Group Policy Administrative Templates, copy the

%windir%\PolicyDefinitions folder from your Windows machine to the policies folder on the SYSVOL share in your domain. For more information about the Central Store and best practices, visit http://www.support.microsoft.com/kb/929841.

(32)

32

Support

For helpful tips and solutions for troubleshooting the product, download the Specops Deploy / App Troubleshooting Guide from:

www.specopssoft.com/documentation/specops-deploy-documentation/specops-deploy- troubleshooting-guide

If you are unable to resolve a product related issue, contact Specops Support for assistance.

Online

We recommend submitting your case directly on our website at: www.specopssoft.com/support.

Telephone International +46 8 465 012 50

Monday - Friday: 09:00 - 17:00 CET North America

+1-877-SPECOPS (773-2677) Monday - Friday: 09:00 - 17:00 EST

References

Related documents

For example, the command alias D represents the command sequence "DISPLAY Document" (see Default Command Aliases for a description of all command aliases that are supplied

You can use Specops Inventory to collect and report information on hardware, software, registry, user settings, operating system, security data, and Active Directory data..

The Domino Sync Provider, in the Specops Password Sync Server, posts web service requests to a web service in the Specops Password Domino Application to unlock users, reset HTTP

Specops Deploy Client Side Extension: You can automatically configure an existing Group Policy Object with Software Installation settings to deploy the Client in your domain6.

 Administrative Tools: Specops Inventory Administrative Tool is used to configure what information the Specops Inventory Group Policy Client Side Extension should collect and

From the Setup Assistant, select Deploy Specops Command Client Side Extensiona. The Setup Assistant will check that you have met the

At LANL, one of the High Efficiency Neutron Counters has been used to determine the appropriateness of both passive neutron and quantitative gamma ray methods for measuring lead

| ANNUAL REPORT 2020 136,000 m 3 of water annually, contributing to the long term sustainability of water supply to Sungai Selangor, which is the main source of raw water to