Kaspersky Next XDR Expert

Protection deployment wizard

To install Kaspersky applications, you can use the Protection deployment wizard. The Protection deployment wizard enables remote installation of applications either through specially created installation packages or directly from a distribution package.

The Protection deployment wizard performs the following actions:

  • Downloads an installation package for application installation (if it was not created earlier). The installation package is located at Discovery & deploymentDeployment & assignmentInstallation packages. You can use this installation package for the application installation in the future.
  • Creates and runs a remote installation task for specific devices or for an administration group. The newly created remote installation task is stored in the Tasks section. You can later start this task manually. The task type is Install application remotely.

If you want to install Network Agent on devices with the SUSE Linux Enterprise Server 15 operating system, install the insserv-compat package first to configure Network Agent.

In this section

Starting Protection deployment wizard

Step 1. Selecting the installation package

Step 2. Selecting a method for distribution of key file or activation code

Step 3. Selecting Network Agent version

Step 4. Selecting devices

Step 5. Specifying the remote installation task settings

Step 6. Removing incompatible applications before installation

Step 7. Moving devices to Managed devices

Step 8. Selecting accounts to access devices

Step 9. Starting installation

See also:

Scenario: Kaspersky applications deployment

Page top
[Topic 178756]

Starting Protection deployment wizard

You can start the Protection deployment wizard manually at any time.

To start the Protection deployment wizard manually,

In the main menu, go to Discovery & deploymentDeployment & assignmentProtection deployment wizard.

The Protection deployment wizard starts. Proceed through the wizard by using the Next button.

Page top
[Topic 178757]

Step 1. Selecting the installation package

Select the installation package of the application that you want to install.

If the installation package of the required application is not listed, click the Add button and then select the application from the list.

See also:

Protection deployment wizard

Scenario: Kaspersky applications deployment

Page top
[Topic 178655]

Step 2. Selecting a method for distribution of key file or activation code

Expand all | Collapse all

Select a method for the distribution of the key file or the activation code:

  • Do not add license key to installation package

    The key is automatically distributed to all devices with which it is compatible:

    • If automatic distribution has been enabled in the key properties.
    • If the Add key task has been created.
  • Add license key to installation package

    The key is distributed to devices together with the installation package.

    We do not recommend that you distribute the key using this method because the shared Read access rights are enabled to the repository of installation packages.

If the installation package already includes a key file or an activation code, this window is displayed, but it only contains the license key information.

See also:

Protection deployment wizard

Scenario: Kaspersky applications deployment

Page top
[Topic 178662]

Step 3. Selecting Network Agent version

If you selected the installation package of an application other than Network Agent, you also have to install Network Agent, which connects the application with Kaspersky Security Center Administration Server.

Select the latest version of Network Agent.

Page top
[Topic 178658]

Step 4. Selecting devices

Expand all | Collapse all

Specify a list of devices on which the application will be installed:

  • Install on managed devices

    If this option is selected, the remote installation task is created for a group of devices.

  • Select devices for installation

    The task is assigned to devices included in a device selection. You can specify one of the existing selections.

    For example, you may want to use this option to run a task on devices with a specific operating system version.

See also:

Protection deployment wizard

Scenario: Kaspersky applications deployment

Page top
[Topic 178657]

Step 5. Specifying the remote installation task settings

Expand all | Collapse all

On the Remote installation task settings page, specify the settings for remote installation of the application.

In the Force installation package download settings group, specify how files that are required for the application installation are distributed to client devices:

  • Using Network Agent

    If this option is enabled, installation packages are delivered to client devices by Network Agent installed on those client devices.

    If this option is disabled, installation packages are delivered using the operating system tools of client devices.

    We recommend that you enable this option if the task has been assigned to devices with Network Agents installed.

    By default, this option is enabled.

  • Using operating system resources through distribution points

    If this option is enabled, installation packages are transmitted to client devices using operating system tools through distribution points. You can select this option if there is at least one distribution point on the network.

    If the Using Network Agent option is enabled, the files are delivered using operating system tools only if Network Agent tools are unavailable.

    By default, this option is enabled for remote installation tasks that have been created on a virtual Administration Server.

    The only way to install an application for Windows (including Network Agent for Windows) on a device that does not have Network Agent installed is by using a Windows-based distribution point. Therefore, when you install a Windows application:

    • Select this option.
    • Ensure that a distribution point is assigned for the target client devices.
    • Ensure the distribution point is Windows-based.

Define the additional setting:

Do not re-install application if it is already installed

If this option is enabled, the selected application will not be re-installed if it has already been installed on this client device.

If this option is disabled, the application will be installed anyway.

By default, this option is enabled.

Page top
[Topic 178659]

Step 6. Removing incompatible applications before installation

This step is only present if the application that you deploy is known to be incompatible with some other applications.

Select the option if you want Open Single Management Platform to automatically remove applications that are incompatible with the application you deploy.

The list of incompatible applications is also displayed.

If you do not select this option, the application will only be installed on devices that have no incompatible applications.

Page top
[Topic 178752]

Step 7. Moving devices to Managed devices

Expand all | Collapse all

Specify whether devices must be moved to an administration group after Network Agent installation.

  • Do not move devices

    The devices remain in the groups in which they are currently located. The devices that have not been placed in any group remain unassigned.

  • Move unassigned devices to group

    The devices are moved to the administration group that you select.

The Do not move devices option is selected by default. For security reasons, you might want to move the devices manually.

Page top
[Topic 178661]

Step 8. Selecting accounts to access devices

Expand all | Collapse all

If necessary, add the accounts that will be used to start the remote installation task:

  • No account required (Network Agent installed)

    If this option is selected, you do not have to specify the account under which the application installer will be run. The task will run under the account under which the Administration Server service is running.

    If Network Agent has not been installed on client devices, this option is not available.

  • Account required (Network Agent is not used)

    Select this option if Network Agent is not installed on the devices for which you assign the remote installation task. In this case, you can specify a user account to install the application.

    To specify the user account under which the application installer will be run, click the Add button, select Local Account, and then specify the user account credentials.

    You can specify multiple user accounts if, for example, none of them have all the required rights on all devices for which you assign the task. In this case, all added accounts are used for running the task, in consecutive order, top-down.

Page top
[Topic 178753]

Step 9. Starting installation

This page is the final step of the Wizard. At this step, the Remote installation task has been successfully created and configured.

By default, the Run the task after the wizard finishes option is not selected. If you select this option, the Remote installation task will start immediately after you complete the Wizard. If you do not select this option, the Remote installation task will not start. You can later start this task manually.

Click OK to complete the final step of the Protection Deployment Wizard.

Page top
[Topic 178755]