Deploy OSCE agent using GPO


TREND AGENTS AND ENDPOINT LOCATION

Please read through the article regarding how to download the Trend agents from the agent repository and the importance of using the correct agent for the right network.

For the method described below, you will want to use the MSI installers that are available in the agent repository.

CREATING THE GPOS

The following steps will walk through creating a GPO to distribute the OSCE agent.

  1. Right-click on the "Group Policy Objects" branch in the left-hand pane and select "Create a new GPO"

  2. Create a name for your GPO (please be sure to prefix the name with your unit's identifying abbreviation)

  3. Leave "Source Starter GPO" at (none) and click OK

  4. Locate your new GPO under "Group Policy Objects", right-click, and open it for Edit

  5. Drill down to Computer Configuration, Policies, Software Settings, Software Installation.

  6. Right Click, and select New Package

  7. Navigate to your install point. Remember, this must be open to read to all of your computers so they can install the package. Give "Domain Computers" read access to this location. DO NOT USE THE UFEM AGENT REPOSITORY AS YOUR INSTALL POINT.

  8. Select the MSI file. Click "Open"

  9. Select "Assigned" and click OK

  10. Close the "Group Policy Management Editor" window to save your work

  11. Under the "Domains" branch, drill down till you find the OU that you want to deploy to

  12. Right-click the OU and select "Link an existing GPO"

  13. Select your new GPO from the list and click OK

  14. Click on your new GPO to bring up its properties in the right-hand pane

  15. On the "Scope" tab, under the "WMI Filtering" section, there is a drop down box with a listing of pre-made WMI filters. There are 2 filters that we are interested in:

  16. UFIT-UFEM: Machine is NOT on a Closed or Protected HSC network

  17. UFIT-UFEM: Machine IS on a Closed or Protected HSC network

  18. Select the filter that applies to your endpoints

USING THE CORRECT WMI FILTER

  • If you choose the "UFIT-UFEM: Machine is NOT on a Closed or Protected HSC network" filter, your GPO should be using the MSI that is found in the "Campus" agent repo folder

  • If you choose the "UFIT-UFEM: Machine IS on a Closed or Protected HSC network" filter, your GPO should be using the MSI that is found in the "HSC" agent repo folder

WMI FILTERS AND HSC NETWORKS

The WMI Filters have been populated with all of the closed and restricted HSC networks that have Trend agents running on them. Please submit a Cherwell ticket if you find a network that isn't included but should be.