Configuring Windows Endpoints

Prior to using an Agent Management Job to install agents on your Windows endpoints, you must first configure your endpoints.

Prerequisites:

Prior to configuring, review the following requirements:

  • You can perform these steps on endpoints with the following operating systems:
    • Windows 11
    • Windows 10
    • Windows 8.1
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
    • Windows Server 2012 R2
    • Windows Server 2012
  • You have gathered and confirmed the information and tasks in the Agent Management Job checklist. Refer to Agent Management Job Checklist for a description.
  • Verify your Windows endpoint meets the defined hardware and software requirements. Refer to Agent Requirements for a complete list of agent requirements.

If your organization uses a third-party firewall:
Do not complete the steps for creating Windows Firewall exceptions. Your third-party firewall makes them unnecessary.
However, you must create exceptions for Ivanti Endpoint Security within you third-party firewall. For additional information, refer to Port and ICMP Requirements for an Agent Management Job.

  1. Start applicable Windows services.

    Tip: There are specific Windows services that are necessary for successful Agent Management Job completion.

    1. Open Administrative Tools.
    2. Double-click Services.
      The Services dialog opens.
    3. Ensure the necessary Windows services are started for an Agent Management Job.
      The following list itemizes the services that must be started for Agent Management Job completion.
      • DCOM Server Process Launcher
      • Remote Procedure Call (RPC)
      • Server
      • Windows Firewall
      • Windows Management Instrumentation

      In environments that use a third-party firewall, ensure the Windows Firewall service is instead disabled.

    4. If all of the listed services required for your configuration purposes have a Server status of Started, continue to the next step. If any of the listed services for your configuration purposes are not started, complete the following:
      1. Right-click the applicable service and select Properties.
      2. Ensure Startup type list is set to Automatic. If edits are necessary, click Apply after selecting Automatic from the list.
      3. Click Start.
      4. Click OK.
      5. If necessary, repeat the previous steps for each unstarted service.
    5. Close the Services dialog and the Administrative Tools dialog.
      The applicable Windows services for a successful Agent Management Job are started.
  2. Configure Sharing and Discovery settings.

    Tip: The discovery setting allows the endpoint to be seen by the Ivanti Endpoint Security server, while the file sharing setting allows the Ivanti Endpoint Security server to install the agent during agent management. These settings are necessary for a successful Agent Management Job.

    1. From Control Panel, click Network and Internet.
      Control Panel opens to the Network and Internet options.
    2. Click Network and Sharing Center.
      Control Panel opens to the Network and Sharing Center.
    3. Ensure Network discovery is enabled.
      Enabling this setting makes the endpoint publicly known within the network.

      Tip: Ivanti Endpoint Security uses the information shared by this setting to return more detailed information about the endpoint during discovery scanning.

    4. Based on the endpoint operating system, complete the applicable steps.

      Operating System

      Step

      • Windows 8.1
      • Windows Server 2012
      • Windows Server 2012 R2
      • Windows Server 2016
      • Windows Server 2019
      1. Click Change advanced sharing settings.
      2. Expand one of the following network locations:
        • Private
        • Guest or Public
        • Domain
      3. Scroll to Network discovery.
      4. Ensure Turn on network discovery option is selected.
      5. Ensure Turn on automatic setup of network connected devices option is cleared.
      6. If necessary, click Save Changes.
      7. Repeat these steps for each profile section.
    5. Ensure File sharing is enabled.
      Based on the endpoint operating system, complete the applicable steps.
    6. Operating System

      Step

      • Windows 8.1
      • Windows Server 2012
      • Windows Server 2012 R2
      • Windows Server 2016
      • Windows Server 2019
      1. Click Change advanced sharing settings.
      2. Expand one of the following sections:
        • Private
        • Guest or Public
        • Domain
      3. Scroll to File and printer.
      4. Ensure Turn on file and printer sharing option is selected.
      5. If necessary, click Save Changes.
      6. Repeat these steps for each profile section.
    7. Close Network and Sharing Center.
      Network and Sharing Center closes.

    The Sharing and Discovery settings is configured for the Agent Management Job.

  3. Ensure Windows Firewall is configured to allow exceptions.

    Tip: A Windows Firewall that does not allow exceptions will block pings and other agent management processes necessary for a successful Agent Management Job.

    1. Open a run prompt using the Start Menu or Start Screen.
      The Run prompt opens.
    2. Type gpedit.msc in the Open field and press ENTER.
      The Local Group Policy Editor opens.
    3. Expand the local computer policy tree to Computer Configuration > Administrative Templates > Network > Network Connections > Windows Firewall > Domain Profiles. Ensure Domain Profiles folder is selected.
      The Domain Profile windows opens.
    4. Ensure the following settings (and their subsettings) are configured for the Domain Profile.
    5. Name

      Step

      Windows Firewall: Do not allow exceptions

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Disabled option is selected.
      3. Click OK.

      Windows Firewall: Allow inbound file and printer sharing exception

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Enabled option is selected.
      3. Define an IP range in the Allow unsolicited incoming messages from field.

        Ivanti recommends defining this field using your Ivanti Endpoint Security Server IP address. This input is not validated. To define a range, you may use the following syntax:

        * (any IP address)

        10.3.2.0/24 (specific Class C subnet)

        localsubnet (for local subnetwork access only

      4. Click OK.

      Windows Firewall: Allow ICMP exceptions

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Enabled option is selected.
      3. Click OK.

      Windows Firewall: Allow inbound remote administration exception

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Enabled option is selected.
      3. Define an IP range in the Allow unsolicited incoming messages from field.

        Ivanti recommends defining this field using your Ivanti Endpoint Security Server IP address. This input is not validated. To define a range, you may use the following syntax:

        * (any IP address)

        10.3.2.0/24 (specific Class C subnet)

        localsubnet (for local subnetwork access only

      4. Click OK.
    6. Expand the local computer policy tree to Computer Configuration > Administrative Templates > Network > Network Connections > Windows Firewall > Domain Profiles. Ensure Standard Profiles folder is selected.
      The Standard Profile windows opens.
    7. Ensure the following settings (and their subsettings) are configured for the Standard Profile.

      Tip: These settings will mimic the Domain Profile.

    8. Name

      Step

      Windows Firewall: Do not allow exceptions

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Disabled option is selected.
      3. Click OK.

      Windows Firewall: Allow inbound file and printer sharing exception

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Enabled option is selected.
      3. Define an IP range in the Allow unsolicited incoming messages from field.

        Ivanti recommends defining this field using your Ivanti Endpoint Security Server IP address. This input is not validated. To define a range, you may use the following syntax:

        * (any IP address)

        10.3.2.0/24 (specific Class C subnet)

        localsubnet (for local subnetwork access only

      4. Click OK.

      Windows Firewall: Allow ICMP exceptions

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Enabled option is selected.
      3. Click OK.

      Windows Firewall: Allow inbound remote administration exception

      1. Right-click and select Edit to open the setting dialog.
      2. Ensure Enabled option is selected.
      3. Define an IP range in the Allow unsolicited incoming messages from field.

        Ivanti recommends defining this field using your Ivanti Endpoint Security Server IP address. This input is not validated. To define a range, you may use the following syntax:

        * (any IP address)

        10.3.2.0/24 (specific Class C subnet)

        localsubnet (for local subnetwork access only

      4. Click OK.
    9. Close the Local Group Policy Editior (or the Group Policy Object Editor).
    10. The creation of Windows Firewall exceptions opens the following ports, which are required for job completion:

      • 445/TCP
      • 139/TCP
      • 135/UDP
      • 137/UDP

      The Windows Firewall is configured to allow exceptions for an Agent Management Job.

  4. Complete the configuration of your endpoint by verifying that the C$ and ADMIN$ network shares are enabled.

    Tip: The C$ and ADMIN$ network shares are necessary for remote management. This is necessary for a successful Agent Management Job completion.

    1. Open Windows Control Panel.
    2. From the Command Prompt, type net share and press ENTER.
      The endpoint network shares are listed.
    3. Ensure that the following shares are listed in the Share name column.
      • C$
      • ADMIN$

        If these shares are not listed, complete the following steps to enable them. If one of the necessary shares is enabled but not the other, only enable the share that needs to be enabled.

    4. From the Command Prompt, type the necessary commands to enable the required network shares.

      Example: Complete the following:

      • To enable the C$ share, type NET SHARE C$=C and press ENTER.
      • To enable the ADMIN$ share, type NET SHARE ADMIN$ and press ENTER.

      You have enabled the required share(s). All enabled shares remain active until the system reboots.

    5. Close the Command Prompt window.
      The Command Prompt closes.

    You have completed the configuration of your endpoint for an Agent Management Job by verifying that the C$ and ADMIN$ network shares are enabled.

You have completed all necessary configuration steps.

After Completing This Task:

Refer to Agent Management Job Checklist prior to beginning the Agent Management Job.