BASIC DOCUMENTATION AND A SIMPLIFIED GUIDE TO DEPLOYING KASPERSKY LAB PRODUCTS
Kaspersky Security Center 11 Central Management installation file
A current version of the installation package for the central management of the Kaspersky Security Center, including the entire documentation, is available for download in the “Downloads & Info” section via the “Files” button. The difference between the “Full Package” and the “Lite Package” is described in the KL knowledgebase – further information.
How to install the Kaspersky Security Center 11 server side
If you don’t have full SQL server, so I recommend download and install MS SQL Server 2017 Express (download here).
After launching the installation process, use the “Install Kaspersky Security Center 11” option.
Select the “Standard” installation mode.
Enter the number of managed computers (based on the number of selected workstations, the setup will modify some parameters which you can change in the administration interface later, if necessary)
The administration console is installed automatically with the server and starts automatically afterwards. If you want to install the administration console on another workstation and use the workstation to control the KSC administration server, use the “Install Kaspersky Security Center Administration Console” option.
How to first start the Kaspersky Security Center Central Management
Once you have launched the administration console, use the Quick Start Wizard – it will help you to create basic settings and tasks. You can change each setting later or delete it and run the Quick Start Wizard (Administration Server > Action > All tasks > Quick Start Wizard) again.
Close the wizard using the “Finish” button. Before deploying the product, it’s advisable to modify the settings based on your business needs; then perform the installation on workstations and servers separately.
Basic settings of the KSC Central Management and KES products for workstations and servers
Settings of both the central management and all other products have been performed during the development phase to avoid any complex customization. The following chapter focuses on principles and settings that can differ in each company, based on its IT environment.
Disable “Assign update agents automatically” if you want to assing update agent manually later.
A task for Kaspersky Network Agent – Find vulnerabilities and application updates
How to set the policy for Kaspersky Endpoint Security 11 for Windows
How to add your licence key to the KSC, including distribution to workstations.
How to make additional policy settings for Kaspersky Endpoint Security 11 for Windows
Preparations before installing Kaspersky Network Agent and Kaspersky Endpoint Security 10 for Windows on workstations and servers (if you want to use an English version of KES, you can skip this step)
How to add another language version of Kaspersky Endpoint Security 10 for Windows to KSC
By checking the “Copy updates from repository to installation package” option you add current virus definitions to the installation package. This option is also available when the installation package has already been created.
How to set up installation packages
How to create groups
Create groups in Managed Computers, e.g., Installation, Stations, Servers. Each group can have separate Tasks and Policies in KSC. Both the NA and KES11 installation packages are the same for all Windows platforms. The installation is then performed within one group (can be divided into two groups; first the NA installation and then the second group to install KES11). Once the installation process has finished, you can move stations and servers and put them into groups in Managed Computers, if necessary.
How to configure rules to arrange computers in groups
Simplifying IT management to cut operational costs and achieve better efficiency. Kaspersky Systems Management centralizes a wide range of functions related to the system management.
HOW TO INSTALL KASPERSKY NETWORK AGENT AND KASPERSKY ENDPOINT SECURITY 11 FOR WINDOWS ON WORKSTATIONS AND SERVERS
In every group, you can define which installation packages will be automatically installed on each station within the group. To demonstrate the procedure, we will automatically install Kaspersky Network Agent and Kaspersky Endpoint Security 10 for Windows. Once a station or a server has been moved to this group, the installation process starts automatically.
If you don’t want to utilize the automatic installation feature on all computers, cancel these automatic package installations and move the computers to a group of your choice. Once Kaspersky Network Agent has been installed, you can create a task to be run on each computer within the group. NA is already installed on the computers where the task has run, and the installation process won’t repeat.
How to install using a predefined, fully automated installation package
To create a fully automated installation package, e.g., for Kaspersky Endpoint Security 11 for Windows, including Kaspersky NA, use the “Create stand-alone installation package” option. The fully automated package can contain the licence key and predefined settings – further information.
How to remove incompatible software
It is suitable and advisable to remove incompatible applications before installing Kaspersky Endpoint Security 10 for Windows on workstations. This way, you can avoid possible problems. Kaspersky Network Agent can provide information about installed incompatible software on workstations.