KACE Systems Management Appliance 9.1 Common Documents - Administrator Guide

About the KACE Systems Management Appliance (SMA) Getting started
Configuring the appliance
Requirements and specifications Power-on the appliance and log in to the Administrator Console Access the Command Line Console Tracking configuration changes Configuring System-level and Admin-level General Settings Configure appliance date and time settings Enable Two-Factor Authentication for all users Verifying port settings, NTP service, and website access Configuring network and security settings Configuring Agent settings Configuring session timeout and auto-refresh settings Configuring locale settings Configuring the default theme Configure data sharing preferences About DIACAP compliance requirements Configuring Mobile Device Access Enable fast switching for organizations and linked appliances Linking Quest KACE appliances Configuring history settings
Setting up and using labels to manage groups of items Configuring user accounts, LDAP authentication, and SSO Using Replication Shares Managing credentials Configuring assets
About the Asset Management component Using the Asset Management Dashboard About managing assets Adding and customizing Asset Types and maintaining asset information Managing Software assets Managing physical and logical assets Maintaining and using manual asset information Managing locations Managing contracts Managing licenses Managing purchase records
Setting up License Compliance Managing License Compliance Setting up Service Desk Configure the Cache Lifetime for Service Desk widgets Creating and managing organizations Importing and exporting appliance resources
Managing inventory
Using the Inventory Dashboard Using Device Discovery Managing device inventory
About managing devices Features available for each device management method About inventory information Tracking changes to inventory settings Managing inventory information Finding and managing devices Provisioning the KACE SMA Agent Manually deploying the KACE SMA Agent Using Agentless management Adding devices manually in the Administrator Console or by using the API Forcing inventory updates Managing MIA devices Obtaining Dell warranty information
Managing applications on the Software page Managing Software Catalog inventory
About the Software Catalog Viewing Software Catalog information Adding applications to the Software Catalog Managing License assets for Software Catalog applications Associate Managed Installations with Cataloged Software Using software metering Using Application Control Update or reinstall the Software Catalog
Managing process, startup program, and service inventory Writing custom inventory rules
Deploying packages to managed devices
Distributing software and using Wake-on-LAN Broadcasting alerts to managed devices Running scripts on managed devices Managing Mac profiles Using Task Chains
Patching devices and maintaining security
About patch management Subscribing to and downloading patches Creating and managing patch schedules Managing patch inventory Managing Dell devices and updates Maintaining device and appliance security
Using reports and scheduling notifications Monitoring servers
Getting started with server monitoring Working with monitoring profiles Managing monitoring for devices Working with alerts
Using the Service Desk
Configuring Service Desk Using the Service Desk Dashboard Managing Service Desk tickets, processes, and reports
Overview of Service Desk ticket lifecycle Creating tickets from the Administrator Console and User Console Creating and managing tickets by email Viewing tickets and managing comments, work, and attachments Merging tickets Using the ticket escalation process Using Service Desk processes Using Ticket Rules Run Service Desk reports Archiving, restoring, and deleting tickets Managing ticket deletion
Managing Service Desk ticket queues About User Downloads and Knowledge Base articles Customizing Service Desk ticket settings Configuring SMTP email servers
Maintenance and troubleshooting
Maintaining the appliance Troubleshooting the KACE SMA
Appendixes Glossary About us Legal notices

Patching workflow

Patching workflow

Patching workflow includes subscribing to patches, selecting patch download settings, using labels to identify patches and the devices to be patched, and scheduling patching jobs.

The patching workflow includes the following tasks.

Figure 9. Patching workflow

The patching workflow image shows the five actions, from downloading patches to deploying them, as explained in the legend.

Legend number

Action

1

Signature files for patches you subscribe to are downloaded to the appliance from Lumension. Patch packages are downloaded from Lumension and from software vendors.

2

Smart Labels group the downloaded patches.

3

Smart Labels select devices to patch.

4

Devices that need the patch are detected according to a schedule.

5

Patches are deployed to devices according to a schedule.

About patch signature files

About patch signature files

Patch signature files include the security bulletins and other files that define patches; they do not include the patch packages that are used to install patches.

Patch signature files are downloaded from Lumension according to the subscription and download options you select. For more information on downloading patch signature files, see Select patch download settings.

About patch packages

About patch packages

Patch packages are the files required to install patches.

Patch packages are downloaded from Lumension according to the subscription and download options you select. In some cases, patch packages are also downloaded directly from vendors, such as Microsoft and Adobe.

There are two options for downloading patch packages:

Downloading only those patches that you need: You can choose to download only those packages that have been detected as required by managed devices. Downloading this way reduces download time and disk space. In addition, you can choose to automatically remove patches after a specified time if detect results show that the patches are not needed.
Maintaining a full cache of patches: You can choose to maintain a full cache of packages regardless of whether the patches are required by managed devices. This method keeps packages available for quick deployment, but it requires more download time and disk space than downloading only those packages that you need.

For more information about package download options, see Select patch download settings.

About patch testing and security

About patch testing and security

Quest partners with Lumension Security, Inc. to provide safe, timely, and high-quality patch signatures for all major operating systems and many popular applications.

Before patch signatures are made available to the appliance, Lumension performs the following security checks:

In addition, Quest performs sanity checks on patch feeds after Lumension security checks are complete. For more information, search for Lumension at https://www.quest.com/kace/.

Documents connexes