Deployment steps - GPO

Follow the steps below to deploy the ERA Agent to clients using GPO:

Download the ERA Agent installer .msi file from ESET download page.

Click Deploy ERA Agent... in the Quick Links section of the menu bar, pop-up window will open where you can choose Use GPO or SCCM for deployment, click button Create Script configuration will be open.

icon_section Certificate - A Peer Certificate and ERA Certification Authority are chosen automatically based on the available certificates. If you want to use a different certificate than the one automatically selected, click ERA Certificate description to see a list of available certificates and choose the one you want to use. If you want to use your Custom certificate click the radio button and upload a .pfx certificate file. See Custom certificates with ERA for further details.

Enter Certificate passphrase if needed. For example if you've specified the passphrase during the installation of your ERA, or if you are using Custom certificate with a passphrase. Otherwise, leave the Certificate passphrase field blank.

icon_section Configuration - Lets you customize the all-in-one installer package:

1.Initial installer configuration - you can choose from the two configuration types:

oDo not configure - only the policies that are merged to a Parent Static group will be applied.

oSelect configuration from the list of policies - use this option if you want to apply configuration policy to ERA Agent. Click Select and choose from the list of available policies. If none of the predefined policies are suitable, you can create new policy or customize existing first. When you try selecting the policy again, your new policy will appear in the list.

2.Other - if necessary, you can specify ERA Server Hostname and Port number. Otherwise, leave default values unchanged.

3.Parent group (optional) - you can either select existing Static group or create new one. Click Select to choose Parent Static group for the client machine on which you'll use the all-in-one installer package. If you want to create new Parent Static group, click New Static group button and use the wizard. Newly created group will automatically be selected.

4.Select Create Package, will be open pop-up window with install_config.ini file, click Save file.

5.Put the ERA Agent installer .msi file and created install_config.ini file in a shared folder that can be accessed by your target client(s).

folder_agent_deploy_sccm

validation-status-icon-warning IMPORTANT

Client computers will require read/execute access to this shared folder.

fs_agent_deploy_config08

6.Use an existing Group Policy Object or create a new one (right-click GPO and click New). In the GPMC (Group Policy Management Console) tree, right-click the GPO you want to use and select Edit...

fs_agent_deploy_edit

7.In Computer Configuration, navigate to Policies > Software Settings.

8.Right-click Software installation, select New, and click Package... to create a new package configuration.

fs_agent_deploy_config

9.Browse to the location of the ERA Agent .msi file. In the Open dialog box, type the full Universal Naming Convention (UNC) path of the shared installer package    that you want to use. For example \\fileserver\share\filename.msi

icon_details_hoverNOTE

Make sure that you use the UNC path of the shared installer package.

fs_agent_deploy_config02

10. Click Open and choose the Advanced deployment method.

fs_agent_deploy_config04

11. Confirm the package configuration and proceed with GPO deployment.

fs_agent_deploy_config06