panda cloud systems management guide
TRANSCRIPT
1. Prologue 4Audience 4
Icons 4
2. IntroductIon 5PrincipalFunctionsofPandaCloudSystemsManagement 5
PandaCloudSystemsManagementUserProfile 6
PrincipalComponentsofPandaCloudSystemsManagement7
KeyPlayersofPandaCloudSystemsManagement 8
3. HIerarcHy of levels wItHIn tHe ManageMent console 10SystemLevel 10
Whatisit? 10
Scope 10
Access 11
Functionality 11
ProfileLevel 11
Whatisit? 11
Scope 13
Membership 13
Functionality 13
DeviceLevel 14
Whatisit? 14
Scope 14
Functionality 14
4. BasIc eleMents of tHe console 15GeneralMenu 15
TabBar/TabBarLists 15
IconBar/ActionBar 16
FiltersandGroupPanel 18
ControlLevels 18
System(Account)Level 18
ProfileLevel 19
DeviceLevel 20
5. fIlters and grouPs 21WhataretheGroupsandFilters? 21
TypesofGroupsandFilters 21
Groups 21
Filters 21
6. How to Manage tHe devIces effIcIently 25DifferencesofProfiles,GroupsandFilters 25
Profiles 25
FiltersandGroups 25
GeneralApproachandManagementStructureofDevices 26
7. tHe fIrst 8 stePs to BegIn usIng PcsM 27CreationandconfigurationofthefirstProfile 27
DeploytheAgent 27
ChecktheListofProfileDevicesandBasicFiltering 29
Software,LicenseandHardwareInventory 29
PatchManagement 29
Monitorcreationandconfiguration 30
ComStore 31
RemoteManagedDevicesandResourceAccess 32
8. PolIcIes 35WhatarePolicies 35
HowtodefineaProfilePolicy 35
HowtodefineanAccountPolicy 36
TipsforPolicies 37
1. content
3
Thisguidecontainsbasicinformationandproceduresusedtoobtainthemaximumbenefitoftheproduct Panda cloud systems Management (PcsM, systems Management).
Audience
Thisdocumentationiswrittenwithusersfromtwopossibleenvironmentsinmind:
•TheITDepartmentwhichprovidesinternalsupporttotherestoftheorganization.
•TheManagedServiceProvider(MSP)whichcurrentlyprovidesservicestotheir customeraccountsonsite,remotely,reactivelyorproactively.
Icons
Thisguidewillcontainthefollowingicons:
Additionalinformation,forexample,analternatemethodfor performingaparticulartask.
Suggestionsandrecommendations.
Importantand/orusefultipsforusingPanda cloud systems Management.
1. Prologue
4
Panda cloud systems Managementisasolutionforcloud-basedremotemonitoringandmanagementofdevicesforITdepartmentsthatwanttoofferaprofessionalservicewhileminimizingdisruptionstotheuser.Panda cloud systems ManagementincreasesefficiencythroughcentralizedmanagementofDevices,whilepromotingtheautomationoftasks.TheoverheadcostsdedicatedtoservingeachcustomeroraccountarereducedbecausePCSMincludes:
•Noadditionalinfrastructurerequiredon-siteasthesolutionishostedinthecloud.
•Averygentle learningcurve for technical support,allowingyou todelivervaluefromdayone.
•Toolsaccessiblefromanywhere,anytimeallowingyoutoadministersupportremotelyandavoidinglosttimeandmoneybyremovingtheneedtotraveltothosesites.
•Automatingtasksandresponsestriggeredbyconfigurablealertsthatpreventfailuresbeforetheyoccur.
Panda cloud systems ManagementisaproductthatpromotescollaborationamongTechniciansresponsibleforprovidingsupportandminimizesorcompletelyeliminatesthetimespentinteractingwiththeusertodeterminethecausesoftheproblems.
Principal functions of Panda cloud systems ManagementThefollowingarethemostimportantfeaturesoftheproduct:
2. IntroductIon
feature description
CloudBasedSolution NoadditionalinfrastructureattheclientortheMSP/ITDepartmentsite.Manageallyourdevicesanytime,anywhere.
AgentBased AverylightAgentsupportsNATfirewallandVPNdevicecommuni-cationswiththeManagementConsole.
AutomaticDetectionofDevices
AnAgentinstalledonasingledevicecandetectotherdevicescon-nectedtothesamenetworkandinitiateautomaticinstallation.
ScheduledandCustomAudits Trackallchangesmadetothedevice(hardware,softwareandsys-tem).
SoftwareLicenseManagement Keeptrackofallsoftwareinstalled
AlertsandMonitors Monitorperformance,servicesandExchangeServers,withalerts...allinrealtime.
ScriptingandQuickTasks Createyourownscripts,downloadourpreconfiguredscripts fromtheComStoreonline,anddeploythemwithoneclick,eitheronascheduledbasisorasanautomaticresponsetoanalert.
PatchManagement Automatethedeploymentofupdatesandpatchesforsoftwareins-talled.
SoftwareDeployment Centralizedupdateandsoftwaredeployment.
Policies EstablishasetofgeneralsettingstomanageyourITenvironmentinaflexiblemanner.
RemoteAccess Taskmanager,file transfer, registryeditor, commandprompt,dis-playtheevent log,etc.Allofthese integratedtoolsenableyoutorepairmultipledeviceswithoutinterruptingyourusers.
RemoteControl Sharedortakeoveraccesstotheuser’sdesktopthat iscompatiblewithfirewallandNAT.
SecureCommunication Allcommunicationsbetweentheagentsandtheserverareencryp-ted(SSL).
DetailedInformation Mailscheduledorspecialreports.Findoutwhodoeswhat,when,andfindoutwhousesmostofthoseresources.
CollaborativeEnvironment Managetheallocation,stateanddocumentationof incidentswiththeticketsystem.Facilitatethecreationofhistoricaldocumentationin device notes. Communicate livewith the end user through IMMessagingservice.
ComStore Extendthecapabilitiesoftheplatform.Selectanddownloadthecomponentsyouneed.
5
Itisasmallprogramlessthan5megabytesinsizethatisinstalledoneachofthedevicestobemanaged.AfterinstallingtheagentonthedeviceitsinformationwillbecomedirectlyaccessiblethroughtheManagementConsole.
Theagent supportstwomodesofexecution:
–user Mode
InthismodetheAgentismoreorlessunnoticedbytheend-user.MoreaccesstosomeoftheconfigurationoftheAgentcanbedelegatedbytheAdministrators.
– administration Mode
Afterusingvalidcredentials,thetechnicianmayusetheAgentinAdministratorModetoaccessdevicesremotelyandadministersupport.
•administration server / server / PcsM server
The Management console, processes required to collect, synchronize and redirectmessages,events,and informationflowsgeneratedby theagentsand thedatabasesthatsupportthemareallhostedinthecloudandhave24houravailability.
ThestatusinformationthatflowsfromeachofthedevicestotheManagement serverishighlyoptimizedsothattheimpactonthecustomer'snetworkisminiscule.IntheServerthis information is sorted and consolidated tobe shownas a flowof events thatwilldiagnoseandevenefficientlypredicttheproblemsofmanageddevices.
Panda cloud systems Management user Profile
MostusersofPanda cloud systems Managementwill share a technicalmedium–managementanddailymaintenanceofcomputingdevicessubjectedtoaconstantrateofuseandchange.However thereare twospecific, targetedusergroupsofsystems Management:
•enterprise level It technicians
High level techs are employedby a company tooffer companywidea support serviceto the devices and end-users, nomatter their location. These scenarios often includetheexistenceofremoteofficestowhichaccess is restrictedsotechniciansmustutilizemonitoringtoolsandremoteaccessforroamingusersoutsidetheoffice,whichmakesthemsusceptibletoalltypesofproblemswiththeirdevices.
• service Provider (MsP) level technicians
TechnicalstaffisemployedbyacompanydedicatedtoprovidingprofessionalservicetothosecustomeraccountsthathavedecidedtooutsourceorsubcontracttheITDepartmentforthemaintenanceoftheirdevices.
Principal components of Panda cloud systems Management
ThefollowingisasummaryofthecomponentsthatarewithinSystemsManagement:
•Management console / console / PcsM console
Thisisawebportalaccessibleviacompatiblebrowsers,fromanywhere,anytimewithanywebenableddevice.
Mostofthedailytasksoftrackingandmonitoringwillbemadefromthisconsole.Thisconsoleisaresourceavailabletotechnicalsupportonly.
•device agent / agent / PcsM agent
InstalltheAgentinboththeclientdevicesandthosebelongingtothetechniciansinordertohavecompleteaccesstotheentiresolution.
6
Inanycase,theresponsibilityofadministeringandmonitoringthesystemswithinthecompanylieswiththetechnicalstaffoftheITdepartment,ortheMSPcontractedtoprovidetheseservices.
•PcsM administration account / administration account
EachclientorcompanyutilizingPandaCloudSystemsManagementwillhaveaccesstotheAccountManagementtab.Anaccountwiththehighestlevelofprivilegescanmanageallproductfeatures.
EachAdministrationAccounthasasecureenvironment.SettingsandDevicesthatruninotheraccountswillnotbeaccessiblebytheadministrationteam.
•client account / client
AclientaccountisacontractbetweentheManagedServiceProviderandacompanythatcomestothemwiththeintentionofoutsourcingtheirdaytodayITSupportneeds.AclientaccountgenerallymeansalltheclientdevicesaretobemanagedbytheMSP.ForcompaniesthatacquirePandaCloudSystemsManagementforinternalusetheClientAccountisamoreorganizationallevel:thedifferentaccountswillbecreatedtoorganizethemanagementofdifferentdepartmentsofthecompany.
•user
TheUseristhepersonusingthedevicethatrequiresdirectsupportoftheMSPorITdepartment.
•device
ADeviceisacomputerthathasinstalledanagentandisoperatedbytheuserintheirdailywork.
Key Players of Panda cloud systems ManagementThekeyplayersthatareinvolvedandwillbereferredtothroughouttheguidearelistedbelow:
•It administrator / administrator / Managed service Provider / MsP / It department / support technician
ThesetermsincludeallthosewhohaveaccesstotheManagementConsole,regardlessofprivilegelevelassociatedwiththecredentialssupplied.
General communication architecture: Devices and technical team interacting with the PCSM Server.
7
3. HIerarcHy of levels wItHIn tHe ManageMent console
Inordertoseparatethemanagementofdevicesfromdifferentcustomeraccounts,reuseandlimitproceduresestablishedbytheTechnicalStaffintheConsole,andtoexpediteandrefinetheirmanagement,PandaCloudSystemsManagementprovidesthreelevelsoforganization:
1. Systemlevel
2. Profilelevel
3. Devicelevel
SystemLevel
what is it?TheSystemLevelalsoreferredtoasAccountorAccountlevelentityclusteristhehighestlevel,andisalsouniqueforeachMSP/ITDepartment.Underitsrooffallalldevicesma-nagedbytheMSP/ITDepartmentbelongingtotheircustomersandusers,andhaveanAgentinstalled.
scopeTheactionstakenatthislevelwillaffectalldevicesbelowthesystemlevelalthoughtheymaybelimitedtoasubsetofdevicesusingfiltersandgroups,describedbelow.
accessAccesstotheresourcesoftheSystemLevelisreachedfromtheSystemmenu.
functionalityTheSystemLevelhastheabilitytoperformactionsonaglobalbasis,soyoucangetthestatusofallmanageddevices,consolidatedreportsfromyourenvironmentandactionsonallorpartoftheregistereddevices.Administration hierarchy in 3 levels.
8
u custom labels:FivefieldswithinformationdefinedbytheAdministrator
•contact Information
Thedefaultemailaccountswhichareusedforsendingreportsandalerts.
– alert Mail recipients
– report Mail recipients
•local cache
ThisfieldwillservetoidentifytheProfile’slocalcachetospeedupclientsoftware,patchesorscriptsthatarelaterdistributedamongtheneighboringdevices.Thisidentifiesasinglesystemtohandlethesefiles,thusreducingbandwidthconsumptionbypreventingthemfromhavingtodownloadtheaforementioneditemsindividually.
•login Information
Theexecutionofscriptsintheuser’sdeviceinheritsthepermissionsassociatedwiththelocalhostaccount,butiftheProfileneedstorunscriptswiththe“RunAs”commandyoucanentertheloginandpasswordinformationhereintheWebconsoleforuse.
•consumer Information
Wecanassociatepowerconsumptioninformationforeachofthedevicestoshowoverallconsumptionaswellascontrastitagainstvariationsinthepowersavingsettings,throughPolicieswhichareexplainedbelow.
TheaboveinformationhasbeenembeddedwithintheAgentasProfilemembership,andassuchisdirectlydownloadablefromthesamescreenasProfileManagement.
ProfileLevel
what is it?TheProfileLevelisagroupingentityimmediatelybelowtheSystemLevel.Itisalogicalgroupingthatcontainsthedevicesthatbelongtothesamecustomeraccountorsetofprofileconfigurations.
ThelistofProfilesandaccesstoconfigurationatthislevelisundertheProfilestab.
EachProfileisassociatedwithanumberofconfigurationsaccessiblefromtheSettingstabintheManagementConsole,whichinturnarepackagedwiththeAgent.
Configurationoptionscanbedividedintoseveralgroups.
•Profile Identification
ThisisusedtoidentifyaProfilefromtherestofProfilesgeneratedandusedinfiltersorsearches.Fieldsconfigurableare:
ugeneral:NameofProfileanddescription
u variables:Environmentalvariablessothatthedevicesmaybeinvokedfromascriptforfutureuse
9
WhentheagentisinstalledonclientdevicestheyareautomaticallyaddedtothecorrectProfileintheManagement console.
scopeTheconfigurationsetattheProfilelevelcanaffectalldevicesbelongingtothatProfile,whilesomeactionsandconfigurationmaybelimitedtoasubsetofdevicesusingfiltersandgroups,describedbelow.
UnliketheSystemLevel,theAdministratormaycreateasmanygroupsasneededwithintheProfile.
MembershipThemembershipofagivendevicetoaProfileisdeterminedbytheAgentinstallation.
functionalityTheProfile levelhastheabilitytoperformactionsonallofthedevicesthatarecon-tainedwithinit.Thismakesitpossibletocreatereports,alertsandtaskstorunonthedeviceswhichmakeuptheProfile.
DeviceLevel
what is it?Thisrepresentsasinglenode,end-point,ordevicewhichhasanagentinstalledandisreportingtothePcsM Management console.devicesareautomaticallycreatedwithinthePcsM consolewhentheyhaveagentsinstalledonthem.
scopeAllactionstakenatthislevelaffectonlytheselecteddevice.
functionalityThedevice levelhastheabilitytoperformactionsonaparticulardevice.Thismakesitpossibletocreatereports,alertsandtaskstorunonasingleend-point.
DownloadtheagentfromtheProfilepagechosensothatwheninstalledontheuser’sdeviceitwillbeaddedautomaticallytotheProfileinquestionintheMana-gementconsole.
TominimizethetasksinthedeploymentphaseitisrecommendedtofirstcreateaProfileandthendownloadtheagentfromit,sothatownershipofthemanageddeviceisautomaticallyassignedtothecorrectProfile.
YoucanmovedevicesfromoneProfiletoanotherfromthedevice actionBarafteryouinstalltheagent.
10
4. BasIc eleMents of tHe console
ThePcsM Management consoleisstructuredinanintuitiveandvisualmanner,sothatmostmanagementresourcesareaclickaway,avoidingtheclutterofunnecessarycheckboxesandconfiguration.
ThegoalisaConsolewhichisclean,quicktouse,andcomfortable,whileavoidingwhe-reverpossiblethefullpagereloadsandsteeplearningcurveofothersolutions,allowingyoutodelivervaluetoaclientordepartmentfromthedateofdeployment.
Thebasicelementsoftheconsoletowhichwewillrefertothroughoutthisguideare:
general MenuThismenuisaccessiblefromanywhereintheConsole.Itconsistsof6entries:
Elements:
Menu description
system SystemLevelAccess
Profiles ProfileLevelAccess
components Applications,Tools,andScriptsaccessiblebytheAdministrator
comstore RepositoryofcomponentscreatedbyPandaSecuritythatex-tendthefunctionalityofPcsM
scheduled Jobs ListofActiveandFinishedJobs
scheduled reports ListofConfiguredandDefaultReports
TabBar/TabBarListsThetab Barprovidesaccesstothevariousavailableactionsandinformationinthecon-solecorrespondingtotheparticularDevicesandLevelsatwhichitisaccessed.Itallowsaccesstoconfigurationchanges,auditinformation,policycreation,etc.,andisgenerallywheremostoftheworkisdoneatintheManagementConsole.
Thisbarisslightlydifferentifitisaccessedfrom Profile, system,ordevice level,andforeachlevelthemanagementscopeisalsodifferent.
11
tab accessible from description
summary Profile,Device Information
dashboard System MasterInformationControlPanel
devices Profile devices accessiblewithassociatedinformation
audit System,Profile,Device Inventoryofhardware,softwareandlicenses
Manage System,Profile,Device Patch Managementwithbothpendingandappliedlists
Monitor System,Profile,Device alertscreatedbymonitorsorfinishedjobs
support System,Profile,Device Generatedtickets
report System,Profile,Device Customandpredefinedreports
Policies System,Profile,Device GeneratedPolicies(explainedlater)
settings Profile Profileassociatedconfiguration
suspended devices System Uninstalleddevices
IconBar/ActionBarTheIconBarorActionBarallowsaccesstoactionsaimedatchangingthestatusorcon-figurationofthedevices.ThisbardoesnotexistintheSystemmenuandvariesslightlyifaccessedfromthemenuorfromaProfileDevicesincethescopeofmanagement isdifferent.
Icon accessible from description
Move device to Profile,Device Moves a devicetoanotherProfile
agent Based Profile,Device adds devicestoaselectedGroup
edit Profile add notes and custom fieldsforaselectedDevicethatcanbeusedbyfilters(discussedlater)
toggle Profile,Device MarkasfavoriteDevicesforquickaccessfromSummary/Dashboard
delete Profile,Device deletes a device from a Profile.TheoptioninstructstheAgenttorunanuninstallinstructionandtheDeviceisaddedtothesuspended devices tabundersystem
request audit Profile,Device forces and Inventory oftheselected device
schedule Job Profile,Device create a scheduled Jobforalaterdate
run a Quick Job Profile create and run a Jobusingaselectedcomponent
download csv Profile,Device downloads a list of Profile devices
add/remove cache Profile,Device Mark the device as local cache
turn Privacy on Profile,Device Prevents remote access By the administratorofthedevicesunlessapprovedbytheUser
send a message Profile,Device sends a messagetotheselecteddevices
schedule reports Profile configure and schedule reportsforalaterdate
refresh Profile,Device Refreshesthedataonthescreen
Initiate Device Initiates a deploymentfromtheselecteddevicetoothernodesconnectedtothesamenetworkasthedevice
Qr code Device QRcodeassociatedwiththedeviceforpaperinventory
ThescopeoftheTabBarreferstothecurrentlevel.Thus,ifyouaccesstheTabBaratSystemLevelitwillshowyoutheinformationforallDevices;ifyoulookonProfileLevelthedatareflectedwillshowonlyDeviceparticipantswithinthatcorrespondingProfile.IfyoulookatDeviceLevel,itwillonlyshowinformationforthatparticulardevice.
Elements:
12
FiltersandGroupPanelTheleftsideoftheconsolewillhavethreepanelswithdifferentgroups:
ThescopeoftheIcon Bar willbeformedbymanualselectionofDevicesthathavebeenmarkedinaProfile.
IfyouwanttoperformactionsattheSystemLevelyouwillneedtocreateafilterorgroup(explainedbelow)astheSystemLeveldoesnotdisplaythetoolbarbydefault.
• default filters: Filters automaticallygeneratedbythesystem
•Profile/custom filters:Filterscreatedby the Administrator in the Profile orSystemLevelrespectively
•Profile/system groups:Groupscrea-tedbytheAdministratorintheProfileorSystemlevelrespectively.
control levelsTheControlLevelsreflectthestatusofasetofdevices.TherearethreetypesofControlLevels:
System(Account)LevelTheSystemLevelreflectsthestatusofallProfilesandDevicescontainedthataremana-gedbytheMSP.ThisisthehighestlevelandthereisonlyoneSystem(Account)LevelMenuperaccount.
13
ProfileLevelTheProfileLevelreflectsthestatusofallDevicesthatbelongtotheselectedProfile.TherewillbeaProfileMenuforeachProfilecreated.
DeviceLevelTheDeviceLevelreflectsthestatusofaparticularDevice.
14
5. fIlters and grouPs
what are the Groups and Filters?GroupsandFiltersareresourcesdesignedtogenerateclustersofsimilarDeviceswithinaProfile.SowhilecreatingaProfileisconsideredastaticaspectofmarkingDevicesasbe-longingtoaspecificcontainer,GroupsandFiltersaredesignedtobemodifiedwitheaseinresponsetotemporarycharacteristicsorcriteriaofthoseDevices.
types of Groups and FiltersTherearetwotypesofGroupsandFilters:
u Profile groups/Profile filters:CreatedwithinaselectedProfile,theycanonlycontainDeviceswithinthecorrespondingProfile
u account (multi Profile) groups / custom filters:CreatedfromtheProfilestab,withoutselectingaspecificProfile,theycancontainDevicesthatbelongtoone,several,orallProfiles
GroupsGroupsarecollectionsofstaticdevices.MembershipofaDevicetoaGroupismanualbydirectallocation.
FiltersFiltersaredynamicgroupsofDevices.Membershipofadeviceisautomatic,astheysettheirconditionsformembership.Theconditionsofmembershipofafiltercanbeoneormorecharacteristicsandarelinkedbylogicaloperators(AND/OR).
Thefollowingarethestepstobuildafilter
•name the filter.Itisrecommendedthatthenamebedescriptive,indicatingthecommoncharacteristicsofthedevicesgrouped(i.e.“MicrosoftExchangeServers”,“Workstationswithlittlefreespace”)
•Iftherearemultipleconditionsthelogicaloperationthatcanbeappliedare:
uAny:Anydevicethatmeetsatleastoneconditionwillbeincludedinthefilter
uAll:Onlydevicesthatmeetalltheconditionswillbeincludedinthefilter
15
•criteria:Eachlineconsistsofseveraltermsthatdescribefields,bytype:
ufield:Fieldisthemainfeatureofthedevicethatitwillincludeaspartofthefilter.Themainareasarelistedandclassifiedbelow.
ucondition:SetsthefieldforcomparisonwhichtheAdministratorcanestablish.
usearch term:DescribesthecontentintheField.DependingonthetypeofField,theSearchTermConditionwillreflectchangesmadetodateranges,sections,etc.
Herearethedifferentvaluesforeachconditionline:
field condition search term
String Empty–Notempty,Contains–DoesNotContain,Startswith–Doesnotstartwith,Finisheswith–Doesnotfinishwith
Stringsmayuse%asawildcard
Integer Greater–Greaterthanorequal,Less–Lessthanorequal,Includes,Excludes
Numerical.
Binary Profile IntervalofDates
•AddseverallinesoftypeCriteriawith“+”and“-“iconsontheright
•select the area of the filter:
uAllDevicesinallProfiles
uOnlyDevicesintheselectedProfiles
•SelectUsersoftheConsolewhichhaveaccesstotheFilter
ThefeaturesdescribedintheFieldcanbegroupedasfollowsaccordingtotheirfunctionDevicedescriptor:
device role organization by os, client type, or server type
DeviceType:Server,Works-tation,Smartphone,Laptop
SpecifictypeofinstalledDevice
OperatingSystem Allowssystemorganizationofserverorclient
software version software data
ServicePack Servicepackversion
SoftwarePackage Softwareinstalled
Softwareversion Specificsoftwareversions
Hardware Information on model, version, device type, etc.
CPU Processortype
BIOSName/Release/version InstalledBIOSandversioninformation
DisplayAdapter Typeofdisplayadapterinstalled
Manufacturer Systemmanufacturername
Memory AmountofincludedRAM
Model Systemmodelname
Monitor Typeofmonitorconnected
Motherboard Typeofmotherboardmodel
NetworkAdapter SpecificnameandmodelnumberofNetworkAdapter
device status option definition
Status–Online/Offline Deviceonoroff
Statussuspended SuspendedDevice
AntivirusOn/Off NoAVDetected
FirewallOn/Off NoFirewallDetected
Freediskcapacity Detectsthedevice’sfreestorage
WindowsupdatesOn/OFF DetectsifthedevicehasWindowsUpdatesconfiguredornot
16
device Id Information that identifies and describes the device
Description BriefDevicedescription
ProfileDescription User-creatednotestodescribetheprofile
Profilename NameoftheprofiletheDevicebelongsto
Domain NetworkDomainthesystemisapartof
IPAddress IndividualsystemIP
MACAddress AvailableMACaddressofhardwareinstalledonDevice
Serialnumber Deviceserialnumber
Hostname NameassignedbytheOS
other states
Favorite ForquickaccessfromtheDashboard
Lastseen Previoustimestampofconnectioninformationsent
Lastaudit Previoustimestampoffullauditinformationsenttoconsole
Lastuser Lastusertohaveloggedintothesystem
FunctionDevicedescriptorpart2:
17
•Limitations:
u TheGroups/Filtershavelimitedfunctionalityastheyloseaccessto the tab bar so it is not possible to generate consolidatedlistings.
u ReportsgeneratedviaGroups/Filterswillonlycontaininformationofthosesingulardevices.
general approach and Management structure of devicesThefollowinggeneralrulesareapplied:
•group devices in Profiles to separate different customer accounts or configuration sets.
TheProfilesdonotimposeanyinherentlimitationsongeneratingreportsorconsolidatedlistingsandallowconfigurationtoalloftheDevicesbelongingtothatProfile.
•create Profile groups to group devices by similar features such as hardware, software, or configuration.
Forexample,configureProfileGroupstoseparateDevicesbydepartmentswithinaclientaccountwithsimilarfeatures(softwareutilized,generalrequirements,printeraccess,etc.)orbydifferentroles(Servers/Workstations)
•create Profile filters to find computers with common states within a Profile.
6. How to Manage tHe devIces effIcIently
ThedistributionintheconsoleofthemanageddeviceswithinanMSPorITdepartmentwithmultipleclientaccountsandvariouslevelsofdelegationdrasticallyaffectstheireffi-ciencysincemanyproceduresandactionscanbeconfiguredtorunonmanydevices.Thiscanbealleviatedthroughtherightcombinationofprofiles,groups,andfilters.
differences of Profiles, Groups and FiltersThefollowingdescribestheadvantagesandlimitationsofthethreewaysofgroupingthataresupported.
Profiles•Benefits:
uAssociatesthesameoutboundInternetsettingstoalldevices:Devicesavesmanualconfigurationtolocalcache
uLinkedcontactinformationforsendingreports,alerts,etc.viaemail
uAccesstothetabsbarandtheiconbarthatallowtheexecutionofactionsanddisplayofListingsandConsolidatedreports,whichcoversalloftheProfileDevicesforeaseofuse
•Limitations:
uAnyDevicecanonlybelongtooneProfileuItisnotpossibletonestaProfilewithinaProfile
FiltersandGroups•Benefits:
uTheGroups/Filtersletyoucreatesubsetsofdeviceswithinoneormore
TheGroups/Filtersarecrossfunctionalbetweenprofilesandareunlimited(asmanyasyoulike)buthavelimitedaccesstoconsolidatedreportingandtabbarfunctio-nality
18
Use filters to quickly and automatically search abnormal conditions that fall outsidepredeterminedthresholds(insufficientdiskspace,littlephysicalmemoryinstalled,softwarenotallowedetc.)proactively,ortosearchDeviceswithspecificfeatures.
• associate account groups and filters to technical Profiles.
IfthesizeofanMSPorCompanyisverylargetheremaybehighleveltechniciansonstaff.In thiscase thoseTechniciansmayonly supporthigh levelenvironments suchasCitrixFarmsorExchangeServers.AGrouporAccounttypeFilterhelpsthemlocateandgroupthesecomputerswithouthavingtogoProfilebyProfileintheirsearch.
Itisnotadvisabletousefiltersforstaticcharactergroups.
19
IftheProfileDevicesrequireadditionalHTTPproxytoaccesstheInternetthisinformationcanbeprovidedhereorcanbeaddedatalatertime.OncetheProfile iscreated, it isrecommendedthattheSettingstabisconfigured.Thisconfigurationwillbe incorporatedwithin theAgent installedoneachmanageddevicebelongingtotheProfile.
deploy the agentTheAgentinstalledontheDeviceswillrequirecertainbasicinformationinorderforittofunction:
uTheProfilewhichitwillbelongto.
uTheminimuminformationrequiredforittoreachtheInternetandconnecttothe PcsM Management console.
ProfilemembershipisautomaticallyestablishedifthedistributionoftheAgentisstartedfromwithintheProfileAgent.
TheinformationsetwithintheProfileSettingstabrequiredtosuccessfullyconnecttotheInternetwasindicatedinthepreviousstepsoanysubsequentinstallationsoftheAgentwillautomaticallycontainthatinformation.
TheAgentdownloadcanbedoneintwoways:
uDirectAgentdownloads(mail,GPOpackage,etc.).
uDirectemaillinktotheAgent.
7. tHe fIrst 8 stePs to BegIn usIng PcsM
creation and configuration of the first ProfileFirstyoumustdeterminewhether tocreateanewProfileor reuseonealready inuse,dependingonthecriteriayouareusing.Generally,anewCustomeraccountorconfigu-rationsetwillcorrespondtoanewProfile.
Fillintheinformationaccordinglyandkeepinmindthatthedescriptionfieldmaybesub-sequentlyusedbyfilters.
20
TheinstallationanddeploymentoftheAgentonlargenetworkscanbelongandtediousifyouhavetosendittoeachdeviceindependently.Itcanbefasterandeasierifyouper-formamassdeployment:
u SendtheAgenttothefirstDeviceontheNetwork.
NormallyAgentinstallationonlyrequiresadoubleclickonthedownloadedpackage,andperformstheinstallcompletely“silent”withoutconfirmations.Onceinstalled,theagentwillconnecttothePCSMConsoleandwillappearinthelistofmanageddevicesintheselectedProfile
u AutoDeploytoothernetworkdevices.
SelectingtheDevicewiththefirstAgentinstallationyoucanstartamassdeploymentwithintherestofyournetwork.
check the list of Profile devices and Basic filteringYoucanfavoritetheDevices,organizethelists,orquicklyfilteraccordingtotheroleofthedeviceandchangethesizeofthelist.
21
software, license and Hardware InventoryIntheAudittabyouinventoriedallthedetailsofthedevicesbelongingtotheProfileor,ifaccessedfromadevice,itwillshowtheinformationaboutthedeviceinmoredetail.
Patch ManagementApprovepatchesthathavenotbeeninstalledonmanageddevicesorrunarollbackofthoseyouwanttouninstallintheManage tab.
Configurewhentoapplypatches,stepstobetakenaftertheapplication,andotherpa-rameterscreatingaWindowsUpdatePolicyfromthePoliciesTabintheProfile(explainedlater).
Monitor creation and configurationClickaDevice selected from thoseavailable in theProfileanduse theMonitor tab toregisteranewMonitor,byselectingMonitorsontheright.
22
Choosetheappropriatemonitortypefromthoseavailable.
ConfiguretheparametersoftheMonitor.
ComStoreExtends the functionality of PcsM and installs third-party software as publishedcomponents,fromthistab.
ThecomponentsuseddirectlybythePartner/ITManagermustbedownloadedfromtheComstore.
Under “My Components” shows the components already downloaded and available for use.
Under “ComStore” components are available for download.
Inordertodownloadacomponent,selectone,andclick“Buy”.Atthattimeitwillpo-pulateundertheMy componentssection.AllcomponentsarefreefromtheComStore.
Dependingonthetypeofcomponent,itcanberunasataskorinresponsetoanalertgeneratedbyamonitor.
UndertheDevicetabwithintheProfileyoucanselectthedevices,applyacomponentandconfigureaschedule(Scheduleajob)orrunthecomponentimmediately(RunaquickJob).
23
remote Managed devices and resource accessAlthoughmanydailyoperationscanbeperformeddirectlyfromtheconsole,itmaybenecessarytodirectlyaccessthedeviceusingtheRemoteSupportfromtheAgent.ThisrequirestheinstallationoftheAgentontheDevicesotheTechniciancanperformremotesupportandloginwiththeirusernameandpassword.
Onceloggedin,locatetheDevicebynamewithintheProfilestheTechnicianhasaccessto,orthroughtheDevicestheyhavedesignatedasfavorites.
OncetheyhavelocatedandselectedtheDevice,alloftheoptionsforremoteaccessandcontrolshallbeaccessiblethroughbothiconsandmenus.
24
Theoptionsthatdonotpreventtheuserfromcontinuingtoworkonthesystemare:
u remote screen capture:TakesascreenshotanddisplaysitwithintheAgent.
uwindows services tab:Remoteaccesstostopandresumeservices.
u screen sharing session:RemoteDesktopSharing.TheuserseeswhatthetechnicianisdoingontheirDevice.
u command shell:RemoteaccesstotheDOScommandlineshell.
u agent deployment:LaunchthedeploymentoftheAgent.
u task Manager:RemoteaccesstoTaskManager.
u file transfer:Sendandreceivefiles.
u registry:RemoteaccesstoRegedittool.
u Quick Jobs:Launchjobs.
u event viewer:Remoteaccesstotheeventviewer.
Theoptionsthatwillimpedetheuser’sabilitytousetheirdeviceare:
u windows rdP:RemoteDesktopAccesswhichwillclosetheuser’ssession.
u shut down / reboot:shutdownorrestartthetargetdevice.
25
8. PoLICIeS
what are PoliciesPoliciesarecommonconfigurationsofSystemandProfilelevelgroupsorCustomFilters.Inthiscase,aPolicycreatedattheSystemLevel(AccountPolicy)requestswhatGroup/FilterappliesfromtheSystemLevel,whereasifthePolicywascreatedattheProfileLevel(ProfilePolicy)youwouldchoosebetweentheGroups/FiltersavailableattheProfileLevel.
How to define a Profile PolicyFromtheProfilestab,selectaspecificprofilethenclickonpoliciesontherightfollowedby“Addprofilepolicy”withinthewindow.
ItwillshowawindowindicatingthenameofthePolicy,andifthetypeisbasedononecreatedearliertoexpeditetheconfiguration.
CreatingPoliciescannotbeperformedatthedevicelevel.AtthislevelwecanonlyseethelegacyPoliciesdefinedathigherlevelsandaffectingthatdevice.
ThedatarequestedinthenextscreenchangesdependingonthetypeofPolicyyouhavechosen.
26
HerewehavecreatedanAgentPolicyso“AgentPolicyOptions”willaffecttheconfigu-rationoftheAgentonthedevices.
AlltypesofPolicieswillrequireconfigurationoftheTargetdefinedasaGrouporFilter.AsthisisaPolicycreatedattheProfilelevelitwillonlyshowtheGroupsorFilterspre-viouslycreated.
How to define an account PolicyFromtheSystemMenuclickonthetablabeled“Policies”.
TheremainingstepsareidenticaltothecreationofaProfilePolicy.
tips for PoliciesThefollowingarethe5differenttypesofPolicies.
•agent
ThistypeofPolicydeterminestheappearanceandinteractionoftheagentinstalledforboththeuserandtheconsole.
u Install service only:Thisoptionhidestheiconfromthetraysotheusercannotaccesstheconfigurationwindows.
u active Privacy Mode:Remoteconnectiontothedesktopoftheuserdevicerequiresexplicitacceptancebytheuser.
u disable settings:TheusercannotaccessthecontextmenuoftheAgent.
u disable audits:TheselectedDeviceswillnotsendAudit,orhardware/softwaredata.
u disable Incoming Jobs:PreventssendingjobstotheAgent.
u disable Incoming support:DisablesaccesstotheAgentbytheAdministrator.
u agent Browser Mode:TheAgenthasthreemodesofoperation.
odisabled
ouser:TheAgentwindowwilldisplaybutpreventsaccessthoutauthentication.
27
oadministrator:Completeaccessisgivenwiththecorrectauthenticationcredentials.
• Monitoring
ThisallowsyoutoaddaMonitorPolicy.Monitorswillbeexplainedinalaterchapter
•Power
ThisPolicycanconfigurethepowersavingsettingsofthedevicesthatsupportthem.
•windows update
ThisPolicyisatranspositionoftheoptionsavailableinaWSUSserverandtoconfigurethemostcommonoptionsforPatchManagementforMicrosoftsystems.