Example of migration from [KSWS+KEA] to KES

When migrating from Kaspersky Security for Windows Server (KSWS) to Kaspersky Endpoint Security (KES), you can use the follow recommendations to configure server protection and optimize performance. Here we will look at an example of migration for a single organization.

Infrastructure of the organization

The company has the following equipment installed:

Planning the migration

The migration involves the following steps:

  1. Migrating KSWS tasks and policies using the Policies and Tasks Batch Conversion Wizard.
  2. Migrating the Kaspersky Endpoint Agent policy using the Policies and Tasks Batch Conversion Wizard.
  3. Using tags to activate policy profiles in the properties of the new policy.
  4. Installing KES instead of KSWS
  5. Activating EDR Optimum.
  6. Confirming that KES is working.

The migration scenario is initially performed on one of the cluster of SQL servers. Then the migration scenario is performed on the other cluster of SQL servers. Then the migration scenario is performed on the Microsoft Exchange.

Migrating KSWS tasks and policies using the Policies and Tasks Batch Conversion Wizard.

To migrate KSWS tasks, you can use the Policies and Tasks Batch Conversion Wizard (the migration wizard). As a result, instead of the SQL_Policy(1), SQL_Policy(2), and Exchange_Policy policies, you will get a single policy with three profiles for SQL and Microsoft Exchange servers respectively. The new policy profile with KSWS settings will be named UpgradedFromKSWS <Name of the Kaspersky Security for Windows Server policy>. In profile properties, the migration wizard automatically selects the UpgradedFromKSWS device tag as the triggering criterion. Thus the settings from the policy profile are applied to servers automatically.

Migrating the Kaspersky Endpoint Agent policy using the Policies and Tasks Batch Conversion Wizard

To migrate Kaspersky Endpoint Agent policies, you can use the Policies and Tasks Batch Conversion Wizard. The Policy and Task Migration Wizard for Kaspersky Endpoint Agent is only available in the Web Console.

Using tags to activate policy profiles in the properties of the new policy

Select the device tag that you assigned earlier as the profile activation condition. Open policy properties and select General rules for policy profile activation as the profile activation condition.

Installing KES instead of KSWS

Before installing KES, you must disable Password protection in KSWS policy properties.

Installing KES involves the following steps:

  1. Prepare the installation package. In installation package properties, select the Kaspersky Endpoint Security for Windows 12.0 distribution kit and select the default set of components.
  2. Create a Install application remotely task for one of the SQL server administration groups.
  3. In task properties, select the installation package and the license key file.
  4. Wait until the task successfully completes.
  5. Repeat KES installation for remaining administration groups.

Kaspersky Security Center automatically adds the UpgradedFromKSWS tag to names of computers on the console after the KES installation is complete.

To check the KES installation, you can use the Report on protection deployment. You can also check the device status. To confirm application activation, you can use the Report on usage of license keys.

Activating EDR Optimum

You can activate EDR Optimum functionality using a stand-alone Kaspersky Endpoint Detection and Response Optimum Add-on license. You must confirm that the EDR Optimum key is added to the Kaspersky Security Center repository and the automatic license key distribution functionality is enabled.

To check EDR Optimum activation, you can use the Report on status of application components.

Confirming that KES is working

To confirm that KES is working, you can check and see that no errors are reported. The device status must be OK. Update and malware scan tasks and successfully completed.

Page top