Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Migrating Worry-Free Business Security (WFBS) agent to Worry-Free Business Security Services (WFBS-SVC) Agent using Windows Group Policy Object (GPO)

    • Updated:
    • 16 Mar 2016
    • Product/Version:
    • Worry-Free Business Security Services 5.8
    • Platform:
    • N/A N/A
Summary

This article shows the steps in using the Windows GPO to migrate the WFBS to WFBS-SVC Agent.

Details
Public
  1. Download MSI file from WFBSS portal
     
    Skip this step if you already have the MSI file from Trend Micro.
    1. Log on to WFBSS portal.
    2. Go to Devices and select the target group.
    3. Click the Add Devices button.
    4. Choose the Download Package button to download MSI file.

      Click Download Package

    5. Click Download.

      Click Download

    6. Double-click the WFBS-SVC_Downloader.exe file to start the download process. The downloader will download the Installation Package to your computer.
  2. Copy the MSI file to a shared folder where the target client(s) can access it.
     
    Make sure that the shared folder has “Read” permissions for “Authenticated Users”.

    Folder Permission

  3. Prepare the VBS (or batch file) to be executed on boot.
    1. Download and decompress the example deployment script from WFBSS portal > Administration > Tools. 

      Click Tools

    2. Click Download.

      Click Download

    3. Open the example script (WFBS-SVC Example Deployment Script.vbs) with an editor.
    4. Locate the first line from pathOfWFBSHInstaller="msiexec /qn /i HostedAgent.msi", then modify it to the following:
      • For Non-Service Providers: pathOfWFBSHInstaller="msiexec /i \\ShareFolder\WFBS-SVC_Agent_Installer.msi /L*v C:\Windows\Temp\WFBS_Debug\wofie_msi.log”
      • For Service Providers: pathOfWFBSHInstaller=”msiexec /i \\ShareFolder \WFBS-SVC_Agent_Installer.msi IDENTIFIER=Identifier ABANDON=0 SILENTMODE=1 /L*v C:\Windows\Temp\WFBS_Debug\wofie_msi.log”

    For Example:

    pathOfWFBSHInstaller="msiexec /i \\1.2.3.4\GPO\WFBS-SVC_Agent_Installer.msi IDENTIFIER=BCD6Xb2RpJ6f9oBC1BfVykbbrnl3ZtWTm4GZY5ZMKxx0cBlh5Nlj09BD8pnHv+PVOICwCYfKJ5i+p7qtdTfKMc6W/In2ZZaCWTu8FXC5l74UtwOipVG2FdVUeMfQ/2d3Q09hNhycejMMxceYKmLg0w== ABANDON=0 SILENTMODE=1 /L*v C:\Windows\Temp\WFBS_Debug\wofie_msi.log"
    • * Check FAQ No.2 for how to get the identifier.
    • * Check FAQ No.4 if you want to use batch file for GPO deployment.
  4. Create or Edit an existing GPO and deploy it.
    1. Open the Group Policy Management from your AD server.
    2. Select a target OU or create a new OU, then create a new GPO by clicking Create a GPO in this domain, and link it here…

      Create GPO

    3. After creating a new GPO, right-click it and then click Edit. The Group Policy Management Editor will open.
    4. Go to Computer Configuration > Policies > Windows Settings > Scripts (Startup/Shutdown), and then double-click Startup to edit it.

      Click Startup 

    5. In the Startup Properties window, click Show Files. A new window will pop-up and the path of the VBS file will be displayed.

      Startup Properties 

    6. Copy the path and close the pop-up window.
    7. In the Startup Properties window, click Add… to add the script.
    8. In the Add a Script window, browse to copied path and put the batch file inside.

      Startup Path 

    9. Choose the batch file, and the click OK to finish the setup.

      Add Script

    10. In the Group Policy Management window, select the GPO and check its “Scope” settings to make sure your target user group is in “Security Filtering”, and the “Links” contains correct OU.
    11. Right-click your target OU and click Group Policy Update… to trigger the GPO deployment
  1. On client (target) machine, open the Command Prompt.
  2. Enter the command “gpupdate /force” and then reboot the machine to test the deployment.
    Run the GPupdate command 
  1. Why are clients not getting the GPO?

    Check the Firewall and make sure that it is set correctly. You can also disable the firewall temporarily and try again.

  2. Where to get the identifier?
    1. Go to the WFBS-SVC web console and choose the group that you want to deploy.

      Select Group

       
    2. Choose Add Devices.

      Add Device

       
    3. Under Download the Installer Package (Advanced), click the For Service Providers link.

      Service Provider

       
    4. Copy your identifier.
      Copy the Identifier 
  3. Why does the client console display the incorrect language?
    Answer: The Agent will always detect language and reset the client's UI language at service start up. It uses the Windows API GetUserDefaultLangID. According to MSDN, it will use the user locale and return its language.
    If you have language problems, do the following:
    1. Check if the correct language is set under the Registry Key: Software\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.\Lang

      Language code list: (MSDN language code)
      DA-DK , DE-DE , EN-US , ES-ES , FR-FR , IT-IT , JA , NB-NO , NL-NL , PL , PT-BR , RU , SV-SE , TR , ZH-CN , ZH-TW

    2. Check the problematic computer’s user local setting. Do the following:
      1. Go to Control Panel > Clock, Language, and Region > Change date, time, or number formats.
        Region and Languages 
      2. Under the Formats tab, choose the correct language.
        Select Language 
      3. If both settings are not consistent, use CDT tool to collect information.
      4. If you directly deploy the MSI with GPO, not with a batch file, it may display an incorrect MSI language on GPO, check this KB article: Arabic language appears when deploying the Worry-Free Business Services (WFBS-SVC) MSI agent via Global Policy Management.
        We recommend users to use VBS or batch file to deploy the Agents instead of using the MSI directly, because it may result to installation failure.
  4. Prepare the batch file as following and then follow the same steps with VBS to prepare the GPO.

    File name: WFBSS_Migration.bat

    msiexec /i “\\ShareFolder \WFBS-SVC_Agent_Installer.msi” IDENTIFIER=”Identifier” ABANDON=0 SILENTMODE=1 /L*v “C:\Windows\Temp\WFBS_Debug\wofie_msi.log”

    Example:

    msiexec /i "\\1.2.3.4\GPO\WFBS-SVC_Agent_Installer.msi" IDENTIFIER="BCD6Xb2RpJ6f9oBC1BfVykbbrnl3ZtWTm4GZY5ZMKxx0cBlh5Nlj09BD8pnHv+PVOICwCYfKJ5i+p7qtdTfKMc6W/In2ZZaCWTu8FXC5l74UtwOipVG2FdVUeMfQ/2d3Q09hNhycejMMxceYKmLg0w==" ABANDON=0 SILENTMODE=1 /L*v "C:\Windows\Temp\WFBS_Debug\wofie_msi.log"
Premium
Internal
Rating:
Category:
Configure; Deploy; Install
Solution Id:
1113632
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.