Prerequisites
Before deploying the Mimecast Security Agent for Windows to client machines, you must ensure the following prerequisites have been met:
Creating a Transform File (.MST)
These instructions describe how to create a transform file (.MST) using Orca. You can use other third-party software capable of creating transform files, but these are not covered here.
You can create a transform file using Orca by using the following steps:
- Download and install Orca.
- On the machine where Orca is installed, download the Mimecast Security Agent for Windows MSI File. See Installing the Mimecast Security Agent for Windows.
- Extract the .ZIP file to a directory.
- Start Orca via the Start Menu.
- Click on the File | Open.
- Select the MimecastSecurityAgentWorkstation64.msi file from the extracted .ZIP file directory.
- Click on the Open button.
- Click on the Transform | New Transform.
- Select the Property table.
- Click on Tables | Add Row.
Newer versions of the agent already have the LICENSEKEY property, meaning step 10 can be skipped.
- Complete the Add Row dialog as follows:
-
-
- Property: LICENSEKEY
-
Value: Enter the license key and click OK. This can be obtained either from the:
- Mimecast Administration Console. Navigate to Web Security | Agent Settings and select the Installation tab.
- Customerkey file that forms part of the Mimecast Security Agent installation download.
-
- Click on the OK button to add the LICENSEKEY property to the table.
- Click on the Transform | Generate Transform menu item. The Save Transform As dialog is displayed.
- Specify a transform File Name in your chosen directory.
- Click on the Save button.
Installing the Mimecast Security Agent for Windows using GPO
You can install the Mimecast Security Agent for Windows using GPO with the .MST file by using the following steps:
- Open the Group Policy Management Console on the machine you use to manage your GPOs.
- Create a GPO in the Forests | Domains | Group Policy Objects folder, giving it an appropriate name (e.g. Mimecast Security Agent for Windows). See Microsoft's Create Group Policy Object support documentation.
- Right-click the GPO node.
- Select the Edit menu item. The Group Policy Management Editor dialog is displayed.
- Right-click the Computer Configuration | Policies | Software Settings | Software Installation node.
- Select the New | Package.
- Select the .MSI File using the UNC path of the network shared location (e.g. \\server1\MimecastWSAgent). See Microsoft's Use Group Policy to remotely install software support documentation.
The .MSI file must be placed on a shared network drive to enable the GPO option to install the MSA remotely.
- Click on the Open button. The Deploy Software dialog is displayed.
- Select the Advanced option and click on the OK button. The Mimecast Security Agent Properties dialog is displayed.
- In the Mimecast Security Agent Properties dialog, click on the Add button in the Modifications tab.
- Select the .MST File created above and click on the Open button.
- It is recommended that the following settings be configured to ensure the MSI distribution process is smooth and seamless:
Setting Value Computer Configuration\Policies\Administrative Templates\Windows Components\Window Installer\Always install with elevated privileges Enabled Computer Configuration\Policies\Administrative Templates\System\Logon\Always wait for the network at computer startup and logon Enabled Computer Configuration\Policies\Administrative Templates\System\Group Policy\Configure software Installation policy processing Enabled and check Allow processing across a slow network connection - It is recommended that the following settings be configured to ensure the MSI distribution process is smooth and seamless:
- Depending on how you control the deployment of GPOs in your organization, assign the GPO to an Organization Unit (OU) that contains either the:
-
-
- Target machines
- Security groups that contain your target machines.
We recommend you test the GPO with a test machine before deploying it to production machines.
-
- Once the machines have picked up the GPO, they must be restarted twice:
-
-
- The first restart is for the installation of the Microsoft Security Agent, due to changes to the GPO.
- The second post installation restart is for the agent to enter Protected Mode.
-
The automated install process installs the following prerequisite software automatically:
-
-
- Microsoft Visual C++ 2017 Redistributable.
- Microsoft Message Queue (MSMQ) Server.
- Microsoft Visual C++ 2017 Redistributable.
-
Comments
Please sign in to leave a comment.