Scenario: Protection deployment (tenant management through virtual Administration Servers)

December 9, 2024

ID 219967

If you have never used Kaspersky Security Center and you want to manage your tenants through virtual Administration Servers, proceed as described in this section. After you complete this scenario, your customers' devices will be protected.

If you manage several tenants, then perform the scenario for each of the tenants separately.

The scenario proceeds in stages:

  1. Creating a virtual Administration Server

    Create a virtual Administration Server for your customer. The new virtual Administration Server appears in the hierarchy of Administration Servers:

    The created virtual Administration Servers are nested in the Managed devices node.

    Virtual Administration Servers in the hierarchy of Administration Servers

  2. Selecting a device to act as a distribution point

    Among the devices of the customer, decide which device will act as a distribution point.

    You cannot have more than 100 distribution points within one workspace.

  3. Creating a stand-alone installation package for Network Agent

    Switch to the created virtual Administration Server, and then create a stand-alone installation package for Network Agent. You can switch Administration Servers in the main menu by clicking the chevron icon () to the right of the current Administration Server name, and then selecting the required Administration Server. During creation of the stand-alone installation package, specify the Managed devices administration group to move the device to.

  4. Installing Network Agent on the selected device to act as a distribution point

    You can use any method that is suitable for you:

    • Manual installation

      To deliver the stand-alone installation package to the device, you can, for example, copy it to a removable drive (such as a flash drive) or place it in a shared folder.

    • Deployment by using Active Directory
    • Deployment by using your remote monitoring and management (RMM) software solution
  5. Assigning a distribution point

    Assign the device with Network Agent installed to act as a distribution point.

  6. Network polling

    Configure and perform network polling through the distribution point.

    Kaspersky Security Center Cloud Console provides the following methods of network polling:

    • IP range polling
    • Windows network polling
    • Active Directory polling

    After network polling according to schedule is complete, your customers' devices are discovered and placed in the Unassigned devices group.

  7. Moving the discovered devices to the administration groups

    Set up the rules for automatically moving the discovered devices to the required administration groups; or move these devices to the required administration groups manually. If you plan to manage the customer's devices in a single administration group, you can move the devices to the Managed devices group.

  8. Creating installation packages for Network Agent and managed Kaspersky applications

    Create installation packages for Kaspersky applications.

  9. Removing third-party security applications

    If third-party security applications are installed on your customers' devices, remove them before installing Kaspersky applications.

  10. Installing Kaspersky applications on client devices

    Create remote installation tasks to install Network Agent and managed Kaspersky applications on your customers' devices.

    If necessary, you can create several remote installation tasks to install managed Kaspersky applications for different administration groups or different device selections.

    After the tasks are created, you can configure their settings. Make sure that the schedule for each task meets your requirements. First, the task to install Network Agent must be run. After Network Agent is installed on your customers' devices, the task to install managed Kaspersky applications must be run.

  11. Verifying initial deployment of Kaspersky applications

    Generate and view the Report on Kaspersky application versions. Make sure that the managed Kaspersky applications are installed on all of the devices of your customer.

  12. Creating policies for Kaspersky applications

    Create a policy for the required Kaspersky application. If you want to create a universal policy for all your customers, switch the current virtual Administration Server to the primary Administration Server, and then create a policy for the required Kaspersky application.

');
Kaspersky Endpoint Security for Business Advanced: Adaptive security of your company
Web and device controls. Data encryption. Centralized and convenient management from a single console.
');
Kaspersky Premium Support (MSA): High‑priority incident processing
Telephone and web ticket support. Fast response, monitoring and health check. Submit a request and activate the contract (MSA).