Kaspersky Security 11.x for Windows Server

Configuring group tasks in Kaspersky Security Center

June 10, 2022

ID 146626

When managing Kaspersky Security for Windows Server from Kaspersky Security Center Cloud Console, you cannot add custom HTTP and FTP servers or network folders manually.

To configure a group task for multiple protected devices:

  1. In the Kaspersky Security Center Administration Console tree, expand the Managed devices node and select the administration group for which you want to configure the application tasks.
  2. In the details pane of a selected administration group, open the Tasks tab.
  3. In the list of previously created group tasks, select a task you want to configure.
  4. Open the Properties: <Task name> window in one of the following ways:
    • Double-click the name of the task in the list of created tasks.
    • Select the name of the task in the list of created tasks and click the Configure task link.
    • Open the context menu of the task name in the list of created tasks and select the Properties item.

    In the Notification section, configure the task event notification settings. For detailed information on how to configure settings in this section, see Kaspersky Security Center Help.

  5. Depending on the type of configured task, do one of the following actions:
    • To configure an On-Demand Scan task:
      • In the Scan scope section, configure a scan scope.
      • In the Options section, configure the task priority level and integration with other software components.
    • To configure an update task, adjust the task settings based on your requirements:
      • In the Settings section, configure update source settings and disk subsystem optimization.
      • Click the Connection settings button to configure update source connection settings.
    • To configure the Software Modules Update task:
      • Go to the Settings for application software module updates section.
      • Choose an action to perform: copy and install critical updates of software modules or only check for them.
    • To configure the Copying Updates task, specify the set of updates and the destination folder in the Copying updates settings section.
    • To configure the Activation of the Application task:
      • In the Activation Settings section, apply the key file or activation code that you want to use to activate the application.
      • Select the Use as additional key check box if you want to add an activation code or key file for renewing the license.
    • To configure the automatic generation of allowing rules for Device Control, in the Settings section, specify the settings that will be used to create the list of allowing rules.
  6. Configure the task schedule in the Schedule section. You can schedule all task types except Rollback of Database Update.
  7. In the Account section, specify the account whose rights will be used to run the task. For detailed information regarding configuring settings in this section, see the Kaspersky Security Center Help.
  8. If required, specify the objects to exclude from the task scope in the Exclusions from task scope section. For detailed information regarding configuring settings in this section, see Kaspersky Security Center Help.
  9. In the Properties: <Task name> window, click OK.

The newly configured group task settings are saved.

Configurable group task settings are summarized in the table below.

Kaspersky Security for Windows Server group tasks settings

Kaspersky Security for Windows Server task types

Section in the Properties: <Task name> window

Task settings

Rule Generator for Applications Launch Control

Settings

While configuring the Rule Generator for Applications Launch Control task settings you can select how to create allowing rules:

  • Create allowing rules based on running applications
  • Create allowing rules for applications from the folders

Options

You can specify actions to perform while creating allowing rules for applications launch control:

  • Use digital certificate
  • Use digital certificate subject and thumbprint
  • If the certificate is missing, use
  • Use SHA256 hash
  • Generate rules for user or group of users

    You can configure settings for configuration files with allowing rule lists that Kaspersky Security for Windows Server creates upon task completion.

Schedule

You can configure settings to schedule a task.

Rule Generator for Device Control

Settings

  • Select the operation mode: consider system data on all external devices that have ever been connected or only consider currently connected external devices.
  • Configure settings for configuration files with allowing rule lists that Kaspersky Security for Windows Server creates upon task completion.

Schedule

You can configure settings to start the task on a schedule.

Activation of the Application

Activation Settings

To activate the application or to renew the license, you can add an activation code or a key file.

Schedule

You can configure settings to start the task on a schedule.

Copying Updates

Update source

You can specify Kaspersky Security Center Administration Server or Kaspersky update servers as an application update source. You can also create a customized list of update sources: by adding custom HTTP and FTP servers or network folders manually and setting them as update sources.

You can specify the usage of Kaspersky update servers, if manually customized servers are not available.

Connection settings window

In the Connection settings window linked from the Update source section, you can specify whether a proxy server should be used to establish the connection to Kaspersky update servers or any other server.

Copying updates settings

You can specify the set of updates intended for copying.

In the Folder for local storage of copied updates field, specify a path to the folder that will be used by Kaspersky Security for Windows Server to store copied updates.

Schedule

You can configure settings to start the task on a schedule.

Database Update

Settings

You can specify Kaspersky Security Center Administration Server or Kaspersky update servers as an application update source in the Update source group box. You can also create a customized list of update sources: by adding custom HTTP and FTP servers or network folders manually and setting them as update sources.

You can specify usage of Kaspersky update servers if manually customized servers are not available.

In the Disk I/O usage optimization section you can configure the feature that reduces the workload on the disk subsystem:

  • Lower the load on the disk I/O
  • RAM used for optimization (MB)

Connection settings window

In the Connection settings window linked from the Update source section, you can specify whether a proxy server should be used to establish the connection to Kaspersky update servers or any other server.

Schedule

You can configure settings to start the task on a schedule.

Software Modules Update

Update source

You can specify Kaspersky Security Center Administration Server or Kaspersky update servers as an application update source. You can also create a customized list of update sources: by adding custom HTTP and FTP servers or network folders manually and setting them as update sources.

You can specify the usage of Kaspersky update servers, if manually customized servers are not available.

Connection settings window

In the Update source connection settings group box, you can specify whether a proxy server should be used to establish the connection to Kaspersky update servers or any other server.

Settings for application software module updates

You can specify which actions Kaspersky Security for Windows Server should perform when critical software module updates are available or have already been installed, and also whether Kaspersky Security for Windows Server should receive information regarding scheduled updates.

Schedule

You can configure settings to start the task on a schedule.

On-Demand Scan Settings

Scan scope

You can specify a scan scope for the On-Demand Scan task and configure security level settings.

On-demand scan settings window

In the On-demand scan settings window linked from the Scan scope section, you can select one of the predefined security levels or customize a security level manually.

Options

You can activate or deactivate use of the heuristic analyzer for the On-Demand Scan task and set the analysis level using a slider in the Heuristic analyzer group box.

In the Integration with other components group box, you can configure the following settings:

  • Apply Trusted Zone for On-Demand Scan tasks.
  • Apply KSN usage for On-Demand Scan tasks.
  • Set a priority for the On-Demand Scan task: perform task in background mode (low priority) or consider task a Critical Areas Scan.

Schedule

You can configure settings to start the task on a schedule.

Application Integrity Control

Schedule

You can configure settings to start the task on a schedule.

Baseline File Integrity Monitor

Schedule

You can configure settings to start the task on a schedule.

For the Rollback of Database Update task, you can configure only the standard task settings controlled by Kaspersky Security Center in the Notification and Exclusions from task scope sections.

For detailed information on configuring settings in these sections, see Kaspersky Security Center Help.

In this section

Activation of the Application task

Update tasks

Application Integrity Control

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.