This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD Sync Automatic Deployment Retry

Hello, we are looking to migrate from McAfee VSE 8.7/EPO 4.5 to Sophos ES&DP 9.5/EC 4.5. At the moment I have our EPO server set to synchronise with AD at 1AM, run a query to see what systems are discovered are unmanaged by the server, then every two ours it tries to push out the McAfee agent to any unmanaged systems in the database. This works great, even catches the people with laptops who rarely plug them in to the network for more than a few hours a month. I've set up a 30 day trial Sophos server and can't seem to replicate this functionality. I set up a Container, set it to Synchronise with an OU in AD, Automatically protect clients etc, Synchronise every 60 mins (also set it to 5 for testing). If the PC is turned off or not on the network when EC first discovers it via AD sync it then logs an error 0000002e but then that's it, it never tries again - is this correct? Is there no way to get the EC to re-try the push either next synchronisation or every two hours or something? If not then it will require us to manually contact the user, get them to plug it in, then Right click > Protect computers (or delete all the errored devices several times a day) - this is obviously no good. Another option of course is AD logon scripts or deploy with Zenworks or SMS but that's just rubbish compared to the EPO set up, I want as much automation as possible with little administrator interaction.

Anyone any ideas?

Thanks,

Paul

:3728


This thread was automatically locked due to age.
Parents
  • Hi Paul,

    Unfortunately all I can tell you is that the last time I worked on this with Sophos support it was NOT possible and all I could do was put in a feature request (which I never heard back on).  This was at EC 3.0 I believe and I know that this feature wasn't available in 4.0 and probably is not on 4.5 as it sounds like you are running 4.5.

    As you said before, the other option was with a logon script which we didn't want to do either.  So far we've just dealt with deleting the objects from the console and re-trying it if it was't able to install on sync on a valid machine.  However, it sounds like you might have a much bigger environment with more "problem" machines that you would need it to re-try on.  Hopefully Sophos support can chime in with a better solution.

    :3791
Reply
  • Hi Paul,

    Unfortunately all I can tell you is that the last time I worked on this with Sophos support it was NOT possible and all I could do was put in a feature request (which I never heard back on).  This was at EC 3.0 I believe and I know that this feature wasn't available in 4.0 and probably is not on 4.5 as it sounds like you are running 4.5.

    As you said before, the other option was with a logon script which we didn't want to do either.  So far we've just dealt with deleting the objects from the console and re-trying it if it was't able to install on sync on a valid machine.  However, it sounds like you might have a much bigger environment with more "problem" machines that you would need it to re-try on.  Hopefully Sophos support can chime in with a better solution.

    :3791
Children
No Data