Kaspersky Endpoint Security for Mac

Install and uninstall Kaspersky Endpoint Security

This section describes remote installation and uninstallation of Kaspersky Endpoint Security on a client computer.

You can also install or uninstall Kaspersky Endpoint Security locally.

In this section

Install the application using the SSH protocol

Install the application using Kaspersky Security Center

Create an installation package

Uninstall the application using Kaspersky Security Center

Page top
[Topic kes127691]

Install the application using the SSH protocol

Before installing Kaspersky Endpoint Security on a remote computer, make sure that the following conditions are met:

  • Kaspersky Security Center Administration Server is deployed on the corporate network.
  • Administration Console is installed on the Kaspersky Security Center administrator's workstation.
  • An installation package for Kaspersky Endpoint Security has been created and is located in a shared folder of Administration Server.
  • A key file for Kaspersky Endpoint Security is located in the shared folder of Administration Server (optional).
  • Remote Login is enabled on the remote computer.
  • The computer account used to install the application is included in sudoers.

Install Kaspersky Endpoint Security on a client computer using the SSH protocol

  1. Start the SSH client on the Kaspersky Security Center administrator's workstation.
  2. Connect to the remote computer.
  3. Connect the shared folder of Administration Server as a network drive on the remote computer. To do this, enter the following commands in the SSH client:

    mkdir /Volumes/KLSHARE

    mount_smbfs //<administrator account>:<password>@<Administration Server IP address>/KLSHARE /Volumes/KLSHARE

    Parameter descriptions:

    • <administrator account> – Name of the administrator account on Administration Server.
    • <password> – Password of the administrator on Administration Server.
    • <Administration Server IP address> – IP address of the server hosting Kaspersky Security Center.
  4. Run the installation script. To do this, enter the following commands in the SSH client:

    cd /Volumes/KLSHARE/<KES package folder>

    sudo ./install.sh

    where <KES package folder> is the folder in which the Kaspersky Endpoint Security installation package is located.

    Important: Administrator rights are required for executing this command.

  5. Disconnect the network drive on the remote computer. To do this, enter the following command in the SSH client:

    umount /Volumes/KLSHARE

Page top
[Topic kes127692]

Install the application using Kaspersky Security Center

Before installing Kaspersky Endpoint Security on a client computer, make sure that the following conditions are met:

  • Kaspersky Security Center Administration Server is deployed on the corporate network.
  • Administration Console is installed on the Kaspersky Security Center administrator's workstation.
  • Network Agent is installed on the client computer.
  • An installation package for Kaspersky Endpoint Security has been created and is stored in the shared folder of Administration Server.
  • A key file for Kaspersky Endpoint Security is stored in the shared folder of Administration Server (optional).
  • The client computer is added to the Managed computers administration group on Administration Server (optional).

For detailed information about administration groups on Administration Server, see Kaspersky Security Center Help.

To install Kaspersky Endpoint Security on a client computer via Kaspersky Security Center, you must create and start an Install application remotely task.

Create a task for remote installation of Kaspersky Endpoint Security on a client computer

  1. Start Administration Console of Kaspersky Security Center.
  2. Maximize the Administration Server <Server name> node.
  3. Select the Tasks folder.
  4. In the workspace, start the New Task Wizard by clicking the Create a task button.
  5. Follow the steps of the New Task Wizard below to create a task for remote installation of Kaspersky Endpoint Security on the client computer.

To proceed to the next step of the wizard, click the Next button. To return to the previous step of the wizard, click the  button. To exit the wizard at any step, click the Cancel button.

The appearance of buttons may vary depending on your version of Windows.

Step 1. Select the task type

  1. In the Select the task type window, maximize the Kaspersky Security Center 10 Administration Server node.
  2. Select the Install application remotely task.

Step 2. Select the installation package

  1. In the Select installation package window, do one of the following:
    • If the Kaspersky Endpoint Security installation package with the required settings has been created previously, select it in the list of installation packages in the upper part of the Select installation package window.
    • If the required installation package has not been created yet, click New to start the New Package Wizard.

Step 3. Install additional applications

In the Advanced window, select the Install Network Agent checkbox and the Nagent for Mac checkbox if you want to install Network Agent on the client computer.

Note: The installation package for Network Agent must be created beforehand.

Step 4. Configure the installation settings

In the Settings window, configure remote installation of the application.

Step 5. Select an administration group to add computers to after installation

In the Moving to the list of managed computers window, select a group to which computers will be moved after installation if necessary.

Note: The Moving to the list of managed computers window appears if you select to install Network Agent in step 3.

Step 6. Define how to select client computers for which the task will be created

In the Select devices to which the task will be assigned window, select the method you want to use to specify client computers:

  • To select from among computers detected on the network by Administration Server, select the Select networked devices detected by Administration Server option.
  • To specify the IP addresses of computers manually or import the IP addresses of computers from a file, select the Specify device addresses manually, or import addresses from list option.
  • To create a task for a selection of devices based on a preset criterion, select the Assign task to a device selection option.
  • To select computers from a specific administration group, select the Assign task to an administration group option.

Step 7. Select client computers

In the window that opens (Select devices, Device selection, or Select Administration group, depending on the option you selected in the previous step), select the client computers, specify the IP addresses of computers, specify a computer selection, or select the administration group to which the task will be applied.

Step 8. Select an account to run the task

In the Selecting an account to run the task window, select the No account required (Network Agent installed) checkbox.

It is assumed that you have installed Network Agent before starting this wizard.

Step 9. Configure the task schedule

  1. In the Configure task scheduling settings window, select the start mode in the Scheduled start drop-down list.
  2. If necessary, configure a scheduled task to start automatically (by specifying the task start date and time).
  3. If you want to run tasks that the application was unable to start according to schedule (for example, because the computer was turned off at the scheduled time), select the Run missed tasks checkbox.

    Kaspersky Endpoint Security starts the task as soon as the obstacle preventing the task from being started is eliminated.

Step 10. Specify the task name

In the Define the task name window, in the Name field, enter the name of the task you are creating.

Step 11. Finish creating the task

In the Finishing creating the task window, do the following:

  1. If you want the task to start as soon as the wizard is finished, select the Run task after Wizard finishes checkbox.
  2. Click the Finish button to close the wizard.

The task that you have created appears in the workspace of the Tasks folder.

Page top
[Topic kes127693]

Create an installation package

When you create the Install application remotely task, you can either use an existing installation package or create a new one. Installation packages are located in the Advanced > Remote installation > Installation packages node.

Create an installation package in Kaspersky Security Center

  1. Start Administration Console of Kaspersky Security Center.
  2. Maximize the Administration Server <Server name> node.
  3. In the console tree, select the Advanced folder, then Remote installation subfolder, and then the Installation packages subfolder.
  4. In the workspace, click the Create installation package button.
  5. In the Select installation package type window, click Create an installation package for Kaspersky Lab application.
  6. In the Defining installation package name window, type the name of the new installation package in the Name field and click Next.
  7. In the Selecting the distribution package for installation window, click the Browse button.

    The window for selecting a file for creating the installation package opens.

  8. Open the folder with the contents of the Kaspersky Endpoint Security installation package and select the kesmac.kud file.

    The Selecting the distribution package for installation window shows the name and version of the application to be installed remotely using the file that has been added.

  9. Select the Copy updates from repository to installation package checkbox to copy application updates from the Kaspersky Security Center storage into the installation package if necessary and click Next.

    The License Agreement window opens.

  10. In the License Agreement window, select the I accept the terms of the License Agreement checkbox and click Next.

    The installation package starts uploading to Administration Server. When the upload is finished, the Installation Type window opens.

  11. In the Installation Type window, do the following:
    1. In the Packages to install section, deselect the checkboxes next to the names of the components that you want to skip during installation on the client computer.

      If you skip installation of the Graphical User Interface (GUI) component, the user of the client computer will not be able to activate Kaspersky Endpoint Security and manage the application via the local graphical user interface or configure the application settings and Kaspersky Security Network usage settings via the local GUI.

    2. If you want to participate in , in the Kaspersky Security Network settings section, select the I agree to participate in Kaspersky Security Network checkbox.
    3. If you want to read the text of the Kaspersky Security Network Statement, click the KSN Statement button.

      As you continue to use Kaspersky Endpoint Security, you can opt in or out of participation in Kaspersky Security Network at any time.

  12. In the Installation Type window, click Next.

    The Kaspersky Endpoint Security installation package is created with the specified settings.

  13. In the last window of the wizard, click the Finish button to exit the New Package Wizard.
Page top
[Topic kes135503]

Uninstall the application using Kaspersky Security Center

Before removing Kaspersky Endpoint Security from a client computer via Kaspersky Security Center, make sure the following conditions are met:

  • Kaspersky Security Center Administration Server is deployed on the corporate network.
  • Administration Console is installed on the Kaspersky Security Center administrator's workstation.
  • Network Agent is installed on the client computer.

To uninstall Kaspersky Endpoint Security from the client computer via Kaspersky Security Center, you have to create and start the Uninstall application remotely task.

Important: Removing Kaspersky Endpoint Security from a client computer may lead to a risk of infection.

Create a task for remote uninstallation of Kaspersky Endpoint Security from a client computer

  1. Start Administration Console of Kaspersky Security Center.
  2. Maximize the Administration Server <Server name> node.
  3. Select the Tasks folder.
  4. In the workspace, start the New Task Wizard by clicking the Create a task button.
  5. Follow the steps of the New Task Wizard below to create the task for remote uninstallation of Kaspersky Endpoint Security from the client computer.

To proceed to the next step of the wizard, click the Next button. To return to the previous step of the wizard, click the  button. To exit the wizard at any step, click the Cancel button.

The appearance of buttons may vary depending on your version of Windows.

Step 1. Select the task type

  1. In the Select task type window, expand the Kaspersky Security Center 10 Administration Server node.
  2. Expand the Advanced child node.
  3. Select the Uninstall application remotely task.

Step 2. Select the application to uninstall

In the Select application to be removed window, select Uninstall application supported by Kaspersky Security Center 10.

Step 3. Configure uninstallation settings

In the Settings window, in the Application to be removed drop-down list, select Kaspersky Endpoint Security 10 Service Pack 2 for Mac.

Step 4. Select the operating system restart option

In the Selecting operating system restart option window, select the Do not restart the computer option.

Step 5. Define how to select client computers for which the task will be created

In the Select devices to which the task will be assigned window, select the method you want to use to specify client computers:

  • To select from among computers detected on the network by Administration Server, select the Select networked devices detected by Administration Server option.
  • To specify the IP addresses of computers manually or import the IP addresses of computers from a file, select the Specify device addresses manually, or import addresses from list option.
  • To create a task for a selection of devices based on a preset criterion, select the Assign task to a device selection option.
  • To select computers from a specific administration group, select the Assign task to an administration group option.

Step 6. Select client computers

In the window that opens (Select devices, Device selection, or Select Administration group, depending on the option you selected in the previous step), select the client computers, specify the IP addresses of computers, specify a computer selection, or select the administration group to which the task will be applied.

Step 7. Select a user account to run the task

In the Selecting an account to run the task window, select the No account required (Network Agent installed) checkbox.

It is assumed that you have installed Network Agent before starting this wizard.

Step 8. Configure the task schedule

  1. In the Configure task scheduling settings window, select the start mode in the Scheduled start drop-down list.
  2. If necessary, configure a scheduled task to start automatically (by specifying the task start date and time).
  3. If you want to run tasks that the application was unable to start according to schedule (for example, because the computer was turned off at the scheduled time), select the Run missed tasks checkbox.

    Kaspersky Endpoint Security starts the task as soon as the obstacle preventing the task from being started is eliminated.

Step 9. Specify the task name

In the Define the task name window, in the Name field, enter the name of the task you are creating.

Step 10. Finish creating the task

  1. To start the task as soon as the wizard is finished, in the Finish creating the task window, select the Run task after Wizard finishes checkbox.
  2. Click the Finish button to exit the wizard.

The task that you have created appears in the workspace of the Tasks folder.

Page top
[Topic kes127736]