Deploying Symantec Client (MST format) through Group Policy

Source: Internet
Author: User
Tags requires firewall

Deploying Symantec Client (MST format) through Group Policy

Recently, the company requires users to install Symantec client, our current version is endpoint protection 12.1.100, so that all of us will think of is distributed through the Group Policy deployment software to each domain user's computer; Of course, we all know that Microsoft released the WINDOWS8 system last year, but we can not open or run normally after installing Symantec client on Windows8, after communicating with Symantec that the Symantec version is not compatible with WINDOWS8, It was necessary to Symantec them to develop compatible Symantec versions of Windows8, and after 2 months Symantec also released a new version, Endpoint protection 12.1.2015 (RU2), This version can support WINDOWS8 system and 2012 system; After seeing very excited to start to the server upgrade also through the SEPM policy upgrade Symantec Client, there is no big problem after the upgrade, but many customers do not install Symantec client clients, said that the system will slow down after installation, so they will not install, but the company for the annual ISO audit, requires no users to install, so we finally through Group Policy push Symantec client to no domain users, but in the push after a new problem; I'm pushing Symantec. Clien install packages, only require the installation of virus spyware download protection components, do not need to install proactive threat protection and network theate components, However, after the Group Policy push was found not installed according to the rules, three components will be installed; forced to call Symantec to consult, they said this problem should not appear, Admit that there are a lot of problems with this version of 12.1.1205, but they say that they didn't receive a similar case, they just shirk the responsibility to tell me that their products are not a problem, double-click the installation is a component, through Group Policy push to have three components, but also said that Microsoft's product issues, I was very silent, the truth is that the idea of smoking the engineer thought ...... Finally in the tangle they give me the recommendation through the SEPM server to the client remote push, but after the trial also found the problem, through the SEPM push has certain conditions, the client must meet the following conditions:

Incorrect user name or password

This problem can happen if the user name or password so you entered is incorrect. Enter the correct user name and password to solve the problem.
Simple file sharing are enabled or the "Sharing and security model for local accounts" policy are set to Guest only

This problem can occur if simple File sharing (or the sharing Wizard) are enabled on the target computer, or if the client Has the ' sharing and security model for local accounts ' policy set to Guest only, the manager isn't able to authenticate As Administrator. To solve the problem, read the document being the sharing and security model for local accounts ' policy set to Guest only?
User Account Control is enabled

If User Account Control was enabled, the manager may isn't able to access the administrative shares C $ and admin$. This can cause remote deployment to fail. is the document ' User Account Control ' enabled on the client?
The Administrator account in the target computer does not have a password

If the Administrator account is in the target does not have a password set, authentication'll fail. To solve this problem, read the document does the Administrator account have a password?
Port 445 is blocked

If the Microsoft Windows Firewall isn't configured to allow File and Printer sharing (port 445), authentication'll fail . To solve this problem, read the document is the Microsoft Windows Firewall blocking port 445?
The Remote Registry Service is set to disabled on the client computer

If the Remote Registry Service is stopped and set to Disabled on the client computer, the manager cannot scan the client R Egistry because the service cannot be started. To solve this problem, make sure which the Remote Registry Service is set either to Manual or Automatic.

As we all know, this is certainly not the case, as an administrator how to meet the conditions of the installation of Sep to check whether the client meets the above conditions or to change the client to meet the conditions of the installation of SEP, finally they said there is no better way to ... So on the Internet to see if there is any good way; finally found a very good way, I have always believed that everything is Providence, an embarrassment, the ship to the bridge natural straight ... that is through the MST file to deploy, after the MST deployment of the problem is resolved, specifically see below:

The first is to edit the MSI file through the tool, and the tool we use today is: Orca MSI Editer tools

The file is very small, only 1.8M

Next, export the Symantec Client installation package with the MSI file

We set up an export installation with only one anti-virus component

Export the 32bits 64bits installation package to the specified location; Note that the exported file will not be compressed (EXE)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.