Agent deployment using GPO and SCCM

Apart from local deployment or remote deployment using a Server task, you can also use management tools such as Group Policy Object (GPO), System Center Configuration Manager (SCCM), Symantec Altiris or Puppet.

Follow the steps below to deploy the ESET Management Agent to clients using GPO or SCCM:

Download the Agent installer .msi file from ESET download page - Standalone installers section.

Click Other Deployment Options in the Quick Links section of the menu bar, pop-up window will open where you can choose Use GPO or SCCM for deployment, click the button Create Script.


Deselect the check box Participate in product improvement program if you do not agree to send crash reports and telemetry data to ESET. If the check box is left selected, telemetry data and crash reports will be sent to ESET.

A Peer Certificate and ESMC Certification Authority are chosen automatically based on the available certificates. If you want to use a different certificate than the one automatically selected, click ESMC certificate description to see a list of available certificates and choose the one you want to use. If you want to use your Custom certificate click the radio button and upload a .pfx certificate file. See Custom certificates with ESMC for further details.

Enter Certificate passphrase if needed. For example if you have specified the passphrase during the installation of your ESMC, or if you are using Custom certificate with a passphrase. Otherwise, leave the Certificate passphrase field blank.

validation-status-icon-warning IMPORTANT

The certificate passphrase must not contain the following characters: " \ These characters cause critical errors during the initialization of the Agent.


You can customize the ESET Management Agent installation package:

Enter the Name and Description (optional) of the installation package

Parent group (optional) - you can either select existing Static group or create new one. Click Select to choose Parent Static group for the client machine on which you'll use the installer. If you want to create new Parent Static group, click New Static group button and use the wizard. Newly created group will be automatically selected.

Initial installer configuration - you can choose from the two configuration types:

oDo not configure - only the policies that are merged to a Parent Static group will be applied.

oSelect configuration from the list of policies - use this option if you want to apply configuration policy to ESET Management Agent. Click Select under Agent configuration (optional) and choose from the list of available policies. If none of the predefined policies are suitable, you can create a new policy or customize the existing ones.

If necessary, you can specify ESMC Server Hostname (optional) and Port number. Otherwise, leave default values unchanged.

Select Finish and when a new popup window with install_config.ini file opens, click Save file.

If you want to set ESET Management Agent connection to Proxy to enable forwarding of communication between ESET Management Agent and ESMC Server, specify the following parameters in install_config.ini file:






Click the appropriate link below to view step-by-step instructions for two popular ESET Management Agent deployment methods:

1.Deployment of ESET Management Agent using Group Policy Object (GPO)

2.Deployment of ESET Management Agent using System Center Configuration Manager (SCCM)