Deployment of Enforcement Agent Using GPO Deployment

Deploy the Enforcement Agent for Windows to multiple computers using GPO (Group Policy Object). Before the deployment, read the guidelines in Enforcement Agent Deployment.

Windows Server 2012 GPO Deployment

  1. Download the installation package from the management console and then copy it to a shared computer in your network.

    For information on downloading the installation package, see Enforcement Agent Settings and Downloads.

  2. Log on to the Active Directory server as an administrator.
  3. Go to Start > Server Manager > Tools > Group Policy Management.

    The Group Policy Management window appears.

  4. From the left navigation tree, go to Forest: <your forest> > Domains > <your domain>.
  5. Right-click <your domain>, and then select Create a GPO in this domain, and Link it here....

    The New GPO dialog box appears.

  6. Type a name for the new Group Policy Object in the Name text box and click OK.

    The newly created GPO displays under Group Policy Objects.

  7. Right-click the GPO and then select Edit.

    The Group Policy Management Editor window appears.

  8. From the left navigation tree, go to Computer Configuration > Policies > Windows Settings and then click Scripts (Startup/Shutdown).
  9. On the right pane, double-click Startup.

    The Startup Properties window appears.

  10. Click the Scripts tab, and then click Add....

    The New Script dialog box appears.

  11. Type the path of the TMWS Enforcement Agent.

    For example, type \\GPO_controller server\shared_folder\enforcement_agent\SilentSetup.bat.

  12. Click OK.

    The Startup Properties window appears.

  13. Click Apply, and then click OK.

    The Enforcement Agent installs after client computers restart.

  14. (Optional) Close any window opened during this procedure.

Windows Server 2016 GPO Deployment

Note:

This procedure also applies to Windows Server 2019.

  1. Download the installation package from the management console and then copy it to a shared computer in your network.

    For information on downloading the installation package, see Enforcement Agent Settings and Downloads.

  2. Log on to the Active Directory server as an administrator.
  3. Go to Start > Server Manager > Tools > Group Policy Management.

    The Group Policy Management window appears.

  4. From the left navigation tree, go to Forest: <your forest> > Domains > <your domain>.
  5. Right-click <your domain>, and then select Create a GPO in this domain, and Link it here....

    The New GPO dialog box appears.

  6. Type a name for the new Group Policy Object in the Name text box and click OK.

    The newly created GPO displays under Group Policy Objects.

  7. Right-click the GPO and then select Edit.

    The Group Policy Management Editor window appears.

  8. From the left navigation tree, go to Computer Configuration > Policies > Windows Settings and then click Scripts (Startup/Shutdown).
  9. On the right pane, double-click Startup.

    The Startup Properties window appears.

  10. Click the Scripts tab, and then click Add....

    The New Script dialog box appears.

  11. Type the path of the TMWS Enforcement Agent.

    For example, type \\GPO_controller server\shared_folder\enforcement_agent\SilentSetup.bat.

  12. Click OK.

    The Startup Properties window appears.

  13. Click Apply, and then click OK.

    The Enforcement Agent installs after client computers restart.

  14. (Optional) Close any window opened during this procedure.