In some VDI infrastructures, after a user session ends, the non-persistent virtual machine is powered off without shutting down the guest operating system or stopping applications. As a result, the Light Agent running on the virtual machine does not transmit information about the shutdown of that virtual machine to Kaspersky Security Center, and the virtual machine is not removed from the list of managed devices in Kaspersky Security Center. At the next startup, the non-persistent virtual machine is registered in Kaspersky Security Center, causing a duplicate to appear in the list of managed devices, representing the previous session for the virtual machine template. As a result, the list of managed devices contains duplicates of temporary virtual machines corresponding to each user session in the VDI infrastructure.
This problem exists, for example, for VDI infrastructures based on Termidesk and Basis.WorkPlace.
To solve this problem, you can configure automatic removal of duplicates of a virtual machine from the list of managed devices in Kaspersky Security Center after the virtual machine is powered off. If the duplicate of a temporary virtual machine could not be removed automatically, you can remove it manually.
Automatic removal of duplicate virtual machines
To have duplicates of virtual machines automatically removed from the list of managed devices in Kaspersky Security Center:
VdiMode section, set Enabled=true.
Depending on the version of the Integration Server, the file is located at one of the following paths:
In Nutanix Acropolis and Microsoft Hyper-V virtual infrastructures, automatic deletion of duplicate virtual machines is performed correctly if for the connection of the Integration Server, you have specified the address of an object located at the top level of the virtual infrastructure hierarchy: Nutanix Prism Central for a Nutanix Acropolis infrastructure, or the hypervisor cluster or Microsoft SCVMM for a Microsoft Hyper-V infrastructure. If the Integration Server connects to an object at a lower level of the hierarchy, virtual machines may be deleted that are not duplicates.
Removing duplicate virtual machines manually
To manually remove a temporary virtual machine from the list of managed devices in Kaspersky Security Center, you can use one of the following methods.
systemctl stop klnagent64
systemctl stop klnagent
net stop klnagent
While shutting down, the Network Agent notifies Kaspersky Security Center about the non-persistent virtual machine shutting down, and the virtual machine is removed from the list of managed devices in Kaspersky Security Center.