Product
Agent deployment by GPO across the whole domain
When a customer with a domain comes in, installing the agent machine by machine does not scale. KairosLink builds the group policy for you: you pick the domain machines and the deployment goes out from the panel, without writing a script or touching GPMC.
The panel builds the policy, you pick the machines
The Domain Controller, through its own agent and running as SYSTEM, copies the installer into SYSVOL, where machine accounts can read it, and creates a policy with an immediate task whose action is the Windows installer itself.
No script on the device, which is why antivirus lets it through
That detail is what makes it work. There is no script on the target machine, no download on the target machine and no download-and-run pattern: that is why antivirus does not block it. The previous attempt embedded a script that downloaded the installer and ran it, and Defender flagged it as a dropper.
Machines install at the next policy refresh, which is roughly 90 minutes to 2 hours, or at reboot. Nobody has to restart anything for it to work.
Automatic, or exported to import with GPMC
Automatic delivery creates the policy, filters it to the machines you picked and links it itself. Backup delivery does the same but does not link it: it exports the policy so you import and link it once with GPMC, which is what a domain where someone reviews policies first will ask for.
With backup delivery, until you link it yourself, no machine installs anything no matter how created the campaign looks. The panel says so; it is worth reading.
Everything rolls back, and progress is checked on the right side
Every deployment is reversible. The panel stores the identifier of the policy it created, and rolling back unlinks and deletes it, along with the installer it left in SYSVOL and the backup. Nothing of yours stays behind in the customer domain.
The policy having been created and linked correctly only tells you what the Domain Controller did, which is precisely the part that never fails. That is why the panel carries a diagnosis from the machines' side, up to 25 per run, telling you for each one whether it never processed the policy, whether it reports it as denied, whether the task ran and the installer failed and with which code, or whether it installed fine and the agent has not made contact, which is the case where the problem is network and not deployment.
Frequently asked questions
Do I have to write a script or build the GPO by hand?
Will the customer antivirus block it?
When do the machines install?
Can I review the policy before it applies?
What if I change my mind?
How do I know whether the machines installed?
How many machines fit in one campaign?
Who can deploy and which plan includes it?
All modules included. No credit card.