Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Group Policy Software Install

Posted on 2011-03-18
Medium Priority
Last Modified: 2012-05-11
I was wondering if there was a software that would allow a user to specify the installation account when deploying through Group Policy in Server 2003.  I also need to be able to make changes to the install package to specify server IP and certain internet settings on the install package.  Does anyone know of a software like this?
Question by:MHCIT
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
LVL 22

Expert Comment

by:Joseph Moody
ID: 35167712
Software is installed by system when deployed in group policy. You could do a startup/login script that does a runas.

Most likely, the server IP/settings are stored in the registry or a local .ini file. You can deploy those settings with Group Policy preferences.
LVL 13

Expert Comment

by:Felix Leven
ID: 35168086
As Jmoody10 mentioned: software istalled by a GPO ist deployed before user login in the context of the system account.

There are Packaging tools like WISE Setup, that can repackage and customize installations of software.

Example: Convert EXE installer to MSI for example:
-First you need a clean windows system (thats what i prefer) only the most critical software installed( drivers, service packs)
-install wise -> start the capture
-install the exe file
-carefully read all the registry file diffs found by the software
-make changes to shortcuts, ini files, whatever
-repack the app as msi file

A must read is covering all aspects of software automation, packaging and deploying it to the end user.

Author Comment

ID: 35168123
The problem is the software is a two part software, the first part puts the installer on the system, then someone has to log on as a user with local admin rights to run the second part to set up the connection to server and add info to trusted sites in IE.  We have approximately 300 pc's that this needs to go on, and with only 2 administrators, it could take a couple of weeks to do.  I know I have seen software somewhere that this can all be set up in the msi file to use as the push, but I can't remember what it is.  I have tried advanced installer, but the options I'm looking for aren't offered in it.
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

LVL 13

Expert Comment

by:Felix Leven
ID: 35168201
wise can do it, but not cheap and you need to work with ist some time.

if the first installer ist msi?

Deploy msi over gpo, then check with a loginscritp if the FIRST MSI installer ist allready deployed -> if it's deployed, check if the second installer deployed already -> if install complete -> quit logonscrip


install the second of the installer with the RUNAS command and whatever user you like use for the installation -> quit logonscrip

Author Comment

ID: 35168218
The package is an exe file, then after the first push, it creates another exe file that has to run to finish set up.
LVL 13

Expert Comment

by:Felix Leven
ID: 35168246
then do a logonscript and run both part in it

check if second exe exists - if not runsas first exe from networkshare else runas second exe from local hdd -> if bost parts are installe do nothing and exit script

Accepted Solution

LikeWindows earned 1000 total points
ID: 35168249
Is it just adding info to trusted sites in IE ? If you would have an Windows Server 2008 Domain Controller available in your network there would be a Group Policy available under User Configuration/Windows Settings/Internet Explorer Maintenance/Security where you could just add info to trusted sites in IE . But that is only available if there is at least one 2008 DC available.

Otherwise I would use the IE Administrative Kit (IEAK) which is available as download from Microsoft to add these settings.


Expert Comment

ID: 35168255
This is the Link to IEAK :

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question