Solved

GPO  install all component on clients instead of the preselect

Posted on 2008-06-24
8
434 Views
Last Modified: 2013-11-13
I have an issue with the depolyment of SEP 11 clients in my organization.
I created an msi installation file that installs only specific componenents
The msi runs fine when installing manually, but when distributed through GPO it will install all components instead of specific one.
Thanks
0
Comment
Question by:cesarebalena
  • 2
  • 2
  • 2
  • +1
8 Comments
 
LVL 7

Accepted Solution

by:
daveforster earned 500 total points
ID: 21854293
Have you made a MST (Transform) for the MSI?  This will tell the MSI what to do during installs.
0
 

Author Comment

by:cesarebalena
ID: 21854303
No, I didn't. How can I achieve this? any step or tips?
Thanks
0
 
LVL 7

Expert Comment

by:daveforster
ID: 21854345
Well, you will need to get something that packages applications and creates Transforms.  I use Wise Packaging Studio, but it's not the easiest thing out there to use and it's quite expensive.  There's the InstallShield software that is along the same lines.

There is something out there called ORCA, but I've never used it, but it's free! :)

Cheers,

Dave
0
 
LVL 40

Expert Comment

by:Vadim Rapp
ID: 21854743
please explain the following:

1. how you created the msi? what tool did you use?
2. how you created it so that it installs only certain components?
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 

Author Comment

by:cesarebalena
ID: 21854815
please explain the following:

1. how you created the msi? what tool did you use?  I used SEPM 11.2000 symantec end point protection manager console
2. how you created it so that it installs only certain components? I created and installation package that include only few feature (AV + Antispyware) and not all package that include (av+antyspyware+firewall)
When ilaunch and ionstall locally is working fine and the cretaed package are install only with the previous feature. If a deploy trough GPO on windows server 2003 r2 all package is be install that contain all feature that i don' need it.
Thanks
0
 
LVL 40

Expert Comment

by:Vadim Rapp
ID: 21855410
according to this page

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007082915561148?Open&seg=ent

you are supposed to distribute the client using its own means; read after "To deploy the client software with the Push Deployment Wizard"

The following is only my speculation, since I'm not familiar with this software. If it does not work, and you don't want to use the recommended method, you will see better help in a forum or EE area more related to Symantec software.

I think what this console does is it creates the transform, an .mst file. Then it pushes the installation along with the transform to the clients.

If so then you need to
1. find the transform - an .mst file created at the time when you save your configuration
2. put msi and mst on network share
3. in group policy, when you add the msi, select "advanced", then go to the tab "Modifications" and add the mst. This is only available when you are adding the package, you can't add transform to existing package.

0
 
LVL 16

Expert Comment

by:ThinkPaper
ID: 21876723
vadimrapp is correct.

Why aren't you using the Symantec Mgmt to deploy the clients? You should be setting it up so that it is deployed via the server instead of GPO. Basically thru the wizard, you create an installation package of what you want deployed on the clients. YOu can set policies to push out what settings you wish all the clients to receive. This is a lot easier (and more flexible) than trying to incorporate it with GPO as you could enable to auto-deploy to any new clients found on the network.
0
 
LVL 16

Expert Comment

by:ThinkPaper
ID: 21876772
>>1. find the transform - an .mst file created at the time when you save your configuration

I'm not 100% sure - but i not sure Symantec uses MSTs.. SEP mgr basically creates a new customized MSI which you then use to deploy.
0

Featured Post

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

Join & Write a Comment

Synchronize a new Active Directory domain with an existing Office 365 tenant
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now