Endpoint Protection

 View Only
  • 1.  Deploying SEP12 through GPO

    Posted Feb 25, 2015 02:53 PM

    I think I might be doing this wrong, I extracted the EXE so I can get to the MSI then created my GPO to deploy the package. Took a couple reboots before the package installer interface popup and just went away but nothing gets installed. 

     

    All the machines have SEP11 on them that was previously installed manually and not through group policy. I can run the MSI manually and successfully installed SEP12. 

    Is it possible to deploy SEP12 through GPO completely silent and force reboot?  Can you point me to the right direction? thanks!



  • 2.  RE: Deploying SEP12 through GPO

    Posted Feb 25, 2015 02:56 PM

    Is there a failure log to review? anything in event viewer?



  • 3.  RE: Deploying SEP12 through GPO

    Posted Feb 25, 2015 04:29 PM

    There are a couple errors

     

    Log Name:      System
    Source:        Application Management Group Policy
    Date:          2/25/2015 1:21:57 PM
    Event ID:      102
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          XXXX
    Computer:      CXXX
    Description:
    The install of application Symantec Endpoint Protection from policy SEP12 Deployment failed.  The error was : %%1603
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Application Management Group Policy" />
        <EventID Qualifiers="0">102</EventID>
        <Level>2</Level>
        <Task>0</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2015-02-25T21:21:57.000000000Z" />
        <EventRecordID>40777</EventRecordID>
        <Channel>System</Channel>
        <Computer>Cxxxxxxx</Computer>
        <Security UserID="S-1-5-21-850837630-2931231608-2184496696-1107" />
      </System>
      <EventData>
        <Data>Symantec Endpoint Protection</Data>
        <Data>SEP12 Deployment</Data>
        <Data>1603</Data>
      </EventData>
    </Event>

     

    Log Name:      System
    Source:        Application Management Group Policy
    Date:          2/25/2015 1:21:57 PM
    Event ID:      108
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          XXXXXX
    Computer:      XXXX
    Description:
    Failed to apply changes to software installation settings.  Software changes could not be applied.  A previous log entry with details should exist.  The error was : %%1603
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Application Management Group Policy" />
        <EventID Qualifiers="0">108</EventID>
        <Level>2</Level>
        <Task>0</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2015-02-25T21:21:57.000000000Z" />
        <EventRecordID>40778</EventRecordID>
        <Channel>System</Channel>
        <Computer>XXXXXXX</Computer>
        <Security UserID="S-1-5-21-850837630-2931231608-2184496696-1107" />
      </System>
      <EventData>
        <Data>Software changes could not be applied.  A previous log entry with details should exist.</Data>
        <Data>1603</Data>
      </EventData>
    </Event>



  • 4.  RE: Deploying SEP12 through GPO

    Posted Feb 26, 2015 01:19 AM

    May be the package is corrupt you can create the msi package agin and try it

    Creating a managed .MSI package in Symantec Endpoint Protection 12.1

    Article:TECH165483  | Created: 2011-07-25  | Updated: 2011-08-15  | Article URL http://www.symantec.com/docs/TECH165483


  • 5.  RE: Deploying SEP12 through GPO

    Posted Feb 26, 2015 01:40 AM

    I was afraid you'd ask me to do something like that. I was only given the setup.exe it would take longer to get any other SEP tools from the POC than it would to deploy this on the 200 computers manually one by one. LOL I think i'm SOL



  • 6.  RE: Deploying SEP12 through GPO

    Posted Feb 26, 2015 07:09 AM

    But run the same package locally and it works?



  • 7.  RE: Deploying SEP12 through GPO

    Posted Feb 26, 2015 01:11 PM

    Hey dannie,

    For using GPO i suggest to create one for call a script and check versions to quit or install, if necessary.

    You can use a Computer Policies to create a shutdown script. For silent mode you need to create a silent package for SEP and call it. You dont need a reboot, cuz u have installed on shutdown. 

    Create a .bat or .vbs to check if an registry exists and run a package.

    WshShell.RegRead("HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\ProductVersion")

    I using here in my environment (13k clients / 350 remote locations) and works great.

    Regards