This article describes how to remotely deploy the Symantec Management Agent (SMA) to Windows computers using the Symantec Management Console.
Push installation allows centralized deployment of the SMA to individual computers or managed targets using administrative credentials and Windows administrative shares.
This article specifically describes Windows push installation workflows. UNIX, Linux, and Mac installations use platform-specific deployment methods.
IT Management Suite (ITMS) 8.6 and later
Client Management Suite (CMS) 8.6 and later
NOTE:
ITMS 8.6 RU3 and later releases include improvements related to agent deployment reliability and installation handling.
Customers experiencing persistent deployment failures should verify they are running a supported ITMS release and review related release notes for known issues and fixes.
The Symantec Management Platform (SMP) remotely deploys the Symantec Management Agent (SMA or Altiris Agent) using administrative credentials and Windows administrative shares.
During a push installation:
After registration, the managed computer begins normal communication with the SMP Server or assigned Site Server.
Navigate to:
Actions > Agents/Plug-ins > Push Symantec Management AgentNote: Installation timing depends on network connectivity, DNS resolution, firewall configuration, client responsiveness, and package download performance. Installations may require 10 minutes or longer in large or distributed environments.
Navigate to:
Actions > Agents/Plug-ins > Push Symantec Management AgentClick Apply To and select the desired target.
Common example:
Windows Computers with no Symantec Management Agent InstalledThe rollout policy installs the SMA on computers that become members of the selected target.
The account used for push installation must have:
The following services and protocols must be accessible between SMP and target computers:
The following services should be operational on target systems:
After installation, verify the following:
Confirm the following Windows service exists and is running:
Altiris AgentRun the following command on the client computer:
aexagentutil.exe /serverVerify the client reports the correct SMP Server assignment.
In the Symantec Management Console, verify the computer appears under:
Manage > ComputersConfirm the agent successfully downloads:
| Symptom | Possible Cause |
|---|---|
| RPC server unavailable | RPC/DCOM or firewall issue |
| Access denied | Invalid credentials or UAC restrictions |
| Failed to open Service Control Manager | Insufficient privileges |
| HTTP 401 Unauthorized | Credential or IIS authentication issue |
| Agent installs but does not register | DNS, IIS, or communication issue |
| Push policy never triggers | Target membership or scheduling issue |
| Installation hangs or fails silently | Antivirus or EDR interference |
Verify the following if push installations fail:
Group Policy does not deny:
Log on as a servicefor the account used during push installation.
Typical NS log location:
C:\ProgramData\Symantec\SMP\Logs\a*.logExample indicators:
Failed to open the Service Control Manager
Access denied
RPC server unavailable
HTTP 401 UnauthorizedAfter partial installation, client logs may exist under:
C:\ProgramData\Symantec\Symantec Agent\Logs\Agent*.logaexnsc-xxxx.logPush installation behavior and success rates may vary depending on:
For persistent deployment failures, review SMP and client logs together to determine whether the failure occurs during:
Methods for Installing the Symantec Management Agent
Installing the Symantec Management Agent on Windows Computers
Installing the Symantec Management Agent for Windows with a Manual Push
Installing the Symantec Management Agent for Windows with a Manual Pull
Symantec Management Agent for Windows Installation Options
Installing the Symantec Management Agent on UNIX, Linux, and Mac Computers