cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
465
Views
3
Helpful
5
Replies

Best way to rollout CSA to desktops in Windows environment?

robdog01
Level 1
Level 1

Given the fact that most users do not have local administrative permissions on their WinXP systems, what is the recommended method of rolling out the CSA client in a Win2000 AD environment?

Is there any way to make the Agent Kit a .msi file for AD distribution? Anything else?

Thanks!

5 Replies 5

nkhawaja
Cisco Employee
Cisco Employee

Hi,

Yes there is. I know some folks use remote distribution etc. like Altiris for distributing it to clients

thanks

Nadeem

rabrackett
Level 1
Level 1

We've had good success just using VB scripts to copy the agent executable to the workstation and then executing a scheduled task to install it. There are numberous VB scripting examples on the Web for that.

I did see a customer once try it with PSEXEC from the Sysinternals PSTOOLS kit. There was a particular issue in that about 20% of the agents (this was 4.0.2) didn't report back to the CSA MC after setup completed. We had to uninstall and reinstall those agents to get them working.

frevere
Level 1
Level 1

I have created a security group called "local admims" in our Active Directory. Before distributing the laptops, I added the group "local admins" to the local Administrators group. Then whenever software or a new CSA client needs to be installed, I just add the user to the AD "local admins" group, which gives them Administrator rights to the PC/laptop. After installation, remove the user from the group and they no longer have any adminsrator rights. This works great for all software installations.

How do you prevent the user from performing other priveleged actions during the period they retain enhanced permissions? Couldn't they just add their domain account to the local Administrator's group or create themselves a new local account on the laptop to use when they want to perform a priveleged operation?

Just a tip (or learn from my mistakes):

Do not attempt to install CSA remotely via RDP (Terminal Services). The install interupts the network stack, disconnecting the RDP client. The agent kit installer session ends up in la-la land.