Chat now with support
Chat with Support

NOTICE! We are upgrading our support telephone services, implementing Genesys, starting the week of May 19, 2025

KACE Desktop Authority 11.2.1 - Getting Started Guide

GPO Deployment

GPO Deployment*

GPO Deployment will push out and install an MSI file to each computer in the targeted Domain or OU(s). The MSI file contains Desktop Authority’s client files and must be installed to every computer that is to be managed by Desktop Authority.

The GPO is configured by selectively targeting the root of the domain or OUs (Active Directory Organizational Units) within the enterprise. 32-bit and 64-bit systems can also be selectively targeted. It is important to note that all computers within the selected domain or OU(s) will receive the client files unless a computer is defined as an exception.

Computer(s) to be excluded from the installation of the Desktop Authority client files are configured in the Global Common Management Exception Options. Excluded computers will not receive the necessary Desktop Authority client files that are necessary for the computer to be managed by Desktop Authority.

IMPORTANT: Client provisioning will determine the best way to install the client files to each workstation. This may include the use of GPO Deployment. Client provisioning provides a way to install the client files successfully on most computers in the network.

IMPORTANT: GPO Deployment requires the Authenticated Users group to have Read, Execute and List NTFS permissions on the %windir%\SYSVOL\sysvol\%DomainName%\Policies\Desktop Authority\Desktop Authority Agent 8.0 folder. If this requirement is not configured, Desktop Authority will automatically add the Authenticated Users group to this folder with the required permissions.

General

Preferred domain

Select a preferred domain from the drop list to be used as the default domain against which queries are run. This includes the types of queries where domain specific information, such as a list of domain controllers, is required.

Domain controller

If the client files location is set to SYSVOL, select a server from the drop list as the target for the client files.

WMI Filtering

Use WMI Filters

WMI Filters are used to fine tune the application of GPOs during a Group Policy refresh. A WMI Filter includes one or more WMI Query Language (WQL) queries. If any of these queries evaluate to True then the WMI filter is considered to evaluate to True and the GPO to which it is linked is applied. If the queries do not return anything in the resultant set then the GPO is not applied.

In most cases, this box should be selected. If however, WMI is posing a specific environment issue, unselect this option.

GPO Deployment List

The GPO Extension will be deployed to the selected domain or OUs in this list. The extension is set to either Install or Uninstall the MSI. Click on a column header to sort the list either ascending or descending by the selected column.

Organizational Unit

The Organizational Unit to which the extension will be installed to or removed from.

32-bit systems/64-bit systems

The selected install mode for 32-bit and 64-bit computers.

Add

Click Add to configure an OU for GPO deployment. The selected OU will be added to the GPO Deployment list.

GPO Deployment is supported on Windows 7 and above, Server 2008, Windows Server 2008 R2, Windows 2012, Windows 2012 R2, Windows Server 2016, Windows Server 2019, Windows 7, Windows 8.1 and Windows 10. Windows Installer and .NET 4.6 are required on the target computers. Desktop Authority will install these software requirements, if necessary.

First, the OU must be selected. To do this, navigate to the OU on the left hand pane. As you click on the OU, the Deploy DA Client to in the right hand pane will be filled in with the selection from the left pane.

Next, select Install or Uninstall for 32-bit systems and 64-bit systems.

NOTE: Global Option Exceptions will be respected.

Confirm the selected settings and click Save to complete the GPO Deployment configuration for the selected OU.

Click Cancel to exit without saving any GPO Deployment configurations.

Remove

Click Remove to unlink the GPO from the OUs selected in the GPO Deployment list.

After unlinking the GPO, the following dialog provides the opportunity to remove the GPO and the associated files.

This dialog is only visible when the last GPO element is removed from the GPO Deployment list.

Figure 28: Delete GPO and associated files confirmation dialog

Delete Desktop Authority GPOs

Selecting this box will delete the GPOs and WMI filters.

Delete Desktop Authority Client files from SYSVOL

Selecting this box will remove the Desktop Authority Agent 8.0 folder under SYSVOL. The default path to this folder is C:\WINDOWS\SYSVOL\sysvol\[domain]\Policies\Desktop Authority\Desktop Authority Agent 8.0. This folder will be removed from one Domain Controller. During the course of normal replication on the domain, it will be removed from all other Domain Controllers.

Delete Desktop Authority device policy master files from SYSVOL

Selecting this box will remove the Device Policy Master folder under SYSVOL. The default path to this folder is C:\WINDOWS\SYSVOL\sysvol\[domain]\Policies\Desktop Authority\Device Policy Master. This folder will be removed from one Domain Controller. During the course of normal replication on the domain, it will be removed from all other Domain Controllers.

If both checkboxes, Delete Desktop Authority Client Files from SYSVOL and Delete Desktop Authority Device Policy Master files from SYSVOL are selected, the Desktop Authority folder under SYSVOL will be removed along with all the folders and files underneath it. The default path to this folder is C:\WINDOWS\SYSVOL\sysvol\[domain]\Policies\Desktop Authority.

Edit

Click to edit the selected OU settings. Change either the 32-bit or 64-bit install modes.

Verify GPOs

Click Verify GPO's to confirm that the Desktop Authority GPO extensions and WMI filters are up to date correctly configured.

Update GPOs

Click this button to increment the GPO extension internal version to the specified OUs. Once the version is incremented, the GPO will be recognized as a new version. It will be executed on any client whose version is different.

Refresh

Click Refresh to update the GPO Deployment list.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating