You are on page 1of 10

Ingress Client Silent-Mode Installation in AD Domain

Network Topology

1. PC and AD domain server can communicate with each other.


2. PC has been joined to AD domain.
(Notes: The screenshots provided in this document are based on Windows Server 2008 R2
Standard Edition. For other servers, the configuration guide is similar)

Configuring IAM Unit

1. Enable silent mode in Access Mgt > Advanced > Ingress Policy.
2. Click Download MSI Installer to download singress.msi installation package and then copy it
to AD domain server.
Configuring AD Domain Server

1. Share a folder from domain server to store the software that you want to distribute to
domain users, select whom you want to share the software with and choose Reader as
Permission Level.

Note: The shared folder location is vital and will be used in the subsequent steps.
2. Log in to AD domain server and follow the instruction below to open Group Policy
Management. (Click Start, then select All Programs > Administrative Tools > Group Policy
Management)
Select the domain policy under the domain that you want to configure and right click on it
and then choose Edit. You may also select Group Policy Object > New to add a new group
policy.
Here, we take Default Domain Policy for example.
3. Open Group Policy Management Editor, right click on the right side of the Software
Installation in Computer Configuration Policies > Software Settings, select New and then
click on Package to add singress.msi installation package.
Note: The installation package should be shared to the group to which domain users are in and
associated with the ingress policy, then grant them Read permission.
4. Right click on singress.msi and select Properties to enter the Ingress Properties dialog.
Then, choose Assigned as deployment type and check the option Install this application at
logon.
Note: The installation package should be shared to the group to which domain users are in and
associated with the ingress policy, then grant them Read permission. In this example, select
Domain Users, as shown below.
5. Close Group Policy Management Editor. Select an organizational unit(OU) that you want to
apply the domain group policy to and choose Link an Existing GPO. In this example, link the
OU with default domain policy that you have configured above.
6. On AD domain server, click Start and then type cmd into search box to enter command
console. Then, execute the gpupdate /force command to update new domain group policy.
Effect

1. It takes less than one minute to install ingress client when domain user logs into computer
with domain account.
2. Domain users cannot uninstall ingress client.
3. Users will not be prompted to install Ingress Client when visiting websites.
4. IM chats and outgoing files can still be audited through silent mode is enabled.

Notes:

1. When editing domain group policy, the location of the singress.msi installation package must
be a shared path but not c:\xxx\singress.msi, otherwise the installation package cannot be
distributed to domain users’ computers.
2. Singress.msi installation package can only be automatically installed at next login since
domain group policy is configured to push installation package of ingress client.
3. As long as domain user’s PC is connected to IAM unit(working as gateway), ingress client will
automatically check for updates and request a new update package from IAM. Therefore,
there is no need to update ingress client using group policy on domain controller.
4. To uninstall ingress client from domain users’ computers, right click on the software you
have installed and select All Tasks > Remove to enter Remove Software dialog. Then check
the option Immediately uninstall the software from users and computers, as shown in the
figures below:

You might also like