Showing results for 
Search instead for 
Did you mean: 

Remote installation of Computer Protection via Active Directory Group Policy

F-Secure Computer Protection can be installed remotely using SCCM/GPO and any other deployment method using a network installer MSI. This step-by-step article describes how you can install Computer Protection via Active Directory Group Policy.


  1. Domain controller with Active Directory installed and an end-point host joined to domain.
  2. Orca.exe tool available (Microsoft Orca article here).
  3. Installer networkinstaller.msi to deploy Computer Protection. Please obtain the installer from one of the following links:
  4. Your license keycode to deploy Computer Protection.

Installation sequence

  1. Copy the networkinstaller.msi to domain controller shared folder where it is accessible for domain hosts.

    In this example, domain is and file is copied to \\\sysvol\\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Scripts\installers

  2. Use orca.exe tool to open networkinstaller.msi.


  3. Navigate to Property in the left column, and select InstallLicense.
  4. Click Transform from the menu bar, and select New Transform.


  5. Double-click on InstallLicense, and type in your license keycode in the corresponding value cell.
  6. Click Transform from the menu bar, and select Generate Transform....


  7. Save the generated transform file to the same location where the networkinstaller.msi is located. In this example, it is saved as psb.mst.


  8. Close the orca.exe tool and open Group Policy Management Editor.
  9. Navigate to Computer Configuration > Policies > Software Settings > Software installation.
  10. Right-click on the right pane, and select New > Package....


  11. In the open file window, select networkinstaller.msi and click Open.


  12. In the Deploy Software window, select Advanced to configure the package and click OK.


  13. Go to the Modifications tab, and click Add....
  14. In the open file window, select psb.mst (the transform file from orca.exe earlier), and click Open. This adds the transform file to the installation package.


  15. Click OK to save the package.


  16. Now it is ready to be deployed.


Client behaviour

Client installation will be silent. End-point will fetch the Group Policy with timeout. It can be made manually with the command gpupdate /force executed on the client.

Client host must be rebooted and installation begins only at the first user log in.

Note: Installation does not start if user does not log in. In this case, the installation is aborted. You need to redeploy from the Group Policy Management Editor again.

Pricing & Product Info

For product info please go to our products page

Version history
Revision #:
6 of 6
Last update:
‎23-07-2018 03:06 PM
Updated by: