Categories: System Center

Solved: How To Perform An Offline Install of System Center Endpoint Protection

In anything but the simplest networks, there will always be a few machines that need Antivirus but do not connect to the domain.  These could be lab machines, dedicated PC’s that run manufacturing equipment, field machines, loaners… So the question of how to install System Center Endpoint Protection on these disconnected machines is a valid one.

Determine the Location of Your Endpoint Install File

  1. In System Center Configuration Manager, expand SOFTWARE LIBRARY > APPLICATION MANAGEMENT, PACKAGES
  2. Right click on the CONFIGURATION MANAGER CLIENT PACKAGE and select PROPERTIES
  3. Click on the DATA SOURCE tab and find your SOURCE FOLDER

Copy Endpoint Protection Installation File

  1. Go to that Source folder (note that you may need to approve your own NTFS permission changes to access that folder)
  2. Copy scepinstall.exe to a folder on your PC (or thumbdrive or…)

Copy the Endpoint Protection Policy File

Here you have a choice to make.  If you want to use the default policy just copy ep_defaultpolicy.xml from the same folder as SCEPINSTALL.EXE.  If you want to apply the same policy you have used on your other machines, you need to export it.  To export your existing customized policy:

  1. In System Center Configuration Manager, expand ASSETS AND COMPLIANCE > OVERVIEW > ENDPOINT PROTECTION > ANTIMALWARE POLICIES
  2. Right click on the policy you wish to apply to your offline machine and select EXPORT
  3. Copy that file to the same location as the SCEPINSTALL.EXE that completed in the step above

Install Endpoint Protection on an Offline Machine

  1. Copy SCEPINSTALL.EXE and your configuration files to the offline machine
  2. Bring up CMD window (be sure to right click and RUN AS ADMINISTRATOR)
  3. Change to the directory that the files are in
  4. Type SCEPInstall.exe /policy C:\<path to files>\ep_defaultpolicy.xml
  5. Wait for the install to complete, reboot and have a nice day

When doing research for this article, I found the following items useful and you might too, if you have questions:

http://www.css-security.com/blog/how-to-perform-a-manual-fep-client-installation

http://larslohmann.blogspot.ca/2014/03/identify-weather-sccm-2012-r2-cu1-has.html

If you are a Microsoft Partner, you can also read THIS thread from our fine friend at MS Partner Support.

 

Published by
Ian Matthews

This website uses cookies.