Once the console is installed, you can deploy clients to the computers on your domain in one of the following ways:
- Client Deployment Settings Wizard: Deploy or uninstall clients on your computers in one pass.
(Available only in Privilege Manager Professional and Professional Evaluation editions) - Client Windows Installer file: Use PAClient.msi to install the client locally on a computer (administrative privileges are required).
- Microsoft Group Policy Management Console: Use login scripts or other software deployment techniques for mass-deployment.
Client Deployment Settings Wizard:
1. Under the Getting Started section of the left navigation menu, click Setup Tasks.
2. Select the Deploy Client Wizard icon in the Advanced Configuration section on the right.
3. Choose one of the following options:
Not Configured: Enable child GPOs to inherit client deployment settings from their parent.
Install Client: Install/upgrade client software.
Remove Client: Remove client software (for versions 3.0 and higher).
Unregister: Stop client software installation GPO settings from applying
4. Click NEXT.
5. Click the BROWSE button to select the Privilege Manager Server that was configured in the Basic Setup Tasks.
6. Use the TEST button to test the selected server's connection to the ScriptLogic PA Reporting Service. If the test fails, check to see if there are network or firewall problems.
7. Click the "Clear the server name" link if you want to configure another server. The displayed service will not be uninstalled.
8. Check any Advanced Settings that will be used for client deployment. These settings can be reconfigured later if needed.
9. Click Next.
10. Use Validation Logic to target the settings to specific client computers or user accounts within the GPO.
11. Click Next.
12. Select Create GPO.
13. Name the GPO that will be created.
14. Click OK.
15. Click Link GPO.
16. Link the GPO either to the Domain or to a Specific OU.
Client Windows Installer file:
1. To locate the client MSI setup file, open the console.
2. Click Additional Resources | Open Client Installation Folder. The client file will display in a browser window.
Microsoft Group Policy Management Console:
1. Copy the PAClient.msi file to a network share that can be read by all users. Or if the Server was already configured in the basic steps a share named “PAServer” already exists.
2. Open Group Policy Management Console.
3. Right-click on Group Policy Objects and select New to create a new GPO.
4. Name the GPO
5. Click OK
6. Right-click on the new GPO and select Edit to open it.
7. In the Group Policy Management Editor, select Computer Configuration | Policies | Software Settings | Software installation. In the right pane, right-click, and select New > Package.
8. In the dialog box that will open, browse to the PAClient.msi file on the network share where it was copied to or to the PAServer share. You must use the File name field to specify the client location in the (UNC) format: \\computername\sharename\filename.msi.
9. Click Open.
10. Select Assigned in the Deploy Software dialog.
11. Click OK
12. Close out the editor.
13. Assign the new GPO to a domain or OU, by right-clicking on the domain or OU and select Link an Existing GPO.
14. Select the GPO in the dialog box and click OK.
Check that the client has been successfully deployed onto the computer. Ensure that:
a. The CSEHost.exe process is running;
b. The client record is shown in the Add/Remove Programs tool; and
c. The Privilege Manager icon and the right-click menu are available in the system tray on the client computer.
NOTE: New GPO rules created via Privilege Manager will be applied to client computers following a group policy update.