This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD Sync Automatic Deployment Retry

Hello, we are looking to migrate from McAfee VSE 8.7/EPO 4.5 to Sophos ES&DP 9.5/EC 4.5. At the moment I have our EPO server set to synchronise with AD at 1AM, run a query to see what systems are discovered are unmanaged by the server, then every two ours it tries to push out the McAfee agent to any unmanaged systems in the database. This works great, even catches the people with laptops who rarely plug them in to the network for more than a few hours a month. I've set up a 30 day trial Sophos server and can't seem to replicate this functionality. I set up a Container, set it to Synchronise with an OU in AD, Automatically protect clients etc, Synchronise every 60 mins (also set it to 5 for testing). If the PC is turned off or not on the network when EC first discovers it via AD sync it then logs an error 0000002e but then that's it, it never tries again - is this correct? Is there no way to get the EC to re-try the push either next synchronisation or every two hours or something? If not then it will require us to manually contact the user, get them to plug it in, then Right click > Protect computers (or delete all the errored devices several times a day) - this is obviously no good. Another option of course is AD logon scripts or deploy with Zenworks or SMS but that's just rubbish compared to the EPO set up, I want as much automation as possible with little administrator interaction.

Anyone any ideas?

Thanks,

Paul

:3728


This thread was automatically locked due to age.
Parents
  • Thanks for the info!

    When it comes to AD Sync for us, I decided to leave Servers out of it. They just don't get added to the domain as often as workstations, and they are the ones that typically require more customization with policies anyhow.

    Since policies can't be managed through some sort of global policy management feature within the console, making any sort of "same" changes (ex: exclusions) to specific sets of policies becomes tedious IMO. With a large environment like ours 1000+, it's almost a given that strategic planning has to be processed beforehand- like major consolidation of policies.

    You mentioned the mirroring of AD hierarchy, and I have a question about that. Does it really have to be mirrored to work?...or do you simply have to know/point which group ties in with which group?

    For example...

    Let's say I've got AD looking like this for three locations (Germany, Paris and Roosendaal):

    EU\germany\workstations\laptops

    EU\germany\workstations\desktops

    EU\paris\workstations\laptops

    EU\paris\workstations\desktops

    EU\roosendaal\workstations\laptops

    EU\roosendaal\workstations\desktops

    In Sophos, I've got 2 EUROPE groups that would (currently like this with older console) house all EUROPE based laptops and desktops:

    Europe\Laptops

    Europe\Desktops

    The question is... would AD Sync be able to work in this fashion... without an identical "mirror" so-to-speak?

    Like this essentially:

    [AD]                                                                              [Sophos]
    EU\germany\workstations\laptops       <------>   Europe\Laptops

    EU\germany\workstations\desktops   <------->  Europe\Desktops
    EU\paris\workstations\laptops              <------>  Europe\Laptops
    EU\paris\workstations\desktops          <------>   Europe\Desktops

    I have not upgraded yet, so forgive me if this is a "well, duh!" thing that's obviously understandable after upgrading. :smileyhappy:

    :6875
Reply
  • Thanks for the info!

    When it comes to AD Sync for us, I decided to leave Servers out of it. They just don't get added to the domain as often as workstations, and they are the ones that typically require more customization with policies anyhow.

    Since policies can't be managed through some sort of global policy management feature within the console, making any sort of "same" changes (ex: exclusions) to specific sets of policies becomes tedious IMO. With a large environment like ours 1000+, it's almost a given that strategic planning has to be processed beforehand- like major consolidation of policies.

    You mentioned the mirroring of AD hierarchy, and I have a question about that. Does it really have to be mirrored to work?...or do you simply have to know/point which group ties in with which group?

    For example...

    Let's say I've got AD looking like this for three locations (Germany, Paris and Roosendaal):

    EU\germany\workstations\laptops

    EU\germany\workstations\desktops

    EU\paris\workstations\laptops

    EU\paris\workstations\desktops

    EU\roosendaal\workstations\laptops

    EU\roosendaal\workstations\desktops

    In Sophos, I've got 2 EUROPE groups that would (currently like this with older console) house all EUROPE based laptops and desktops:

    Europe\Laptops

    Europe\Desktops

    The question is... would AD Sync be able to work in this fashion... without an identical "mirror" so-to-speak?

    Like this essentially:

    [AD]                                                                              [Sophos]
    EU\germany\workstations\laptops       <------>   Europe\Laptops

    EU\germany\workstations\desktops   <------->  Europe\Desktops
    EU\paris\workstations\laptops              <------>  Europe\Laptops
    EU\paris\workstations\desktops          <------>   Europe\Desktops

    I have not upgraded yet, so forgive me if this is a "well, duh!" thing that's obviously understandable after upgrading. :smileyhappy:

    :6875
Children
No Data