# Welcome to Adaptiva Docs

Learn about the OneSite Platform, autonomous patching with OneSite Patch, and our other OneSite products.

## Welcome to Adaptiva Docs

Welcome to the Adaptiva Documentation. Here, you can learn about the OneSite Platform, autonomous patching with OneSite Patch, and our other OneSite products.

### Jump right in

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-rocket">:rocket:</i></td><td><strong>Get started with autonomous patching</strong></td><td>Learn how to configure and deploy OneSite Patch for automated vulnerability remediation.</td><td></td><td></td><td><a href="https://docs.adaptiva.com/patch">https://docs.adaptiva.com/patch</a></td></tr><tr><td><i class="fa-cubes">:cubes:</i></td><td><strong>Explore the OneSite Platform</strong></td><td>Discover the full capabilities of the OneSite Platform, including architecture and deployment options.</td><td></td><td></td><td><a href="http://docs.adaptiva.com/platform-install">http://docs.adaptiva.com/platform-install</a></td></tr><tr><td><i class="fa-plug">:plug:</i></td><td><strong>Integrate vulnerability management providers</strong></td><td>Connect your existing vulnerability management tools to OneSite Patch for intelligent patching.</td><td></td><td></td><td><a href="https://docs.adaptiva.com/patch/integrations/integration-partners">https://docs.adaptiva.com/patch/integrations/integration-partners</a></td></tr><tr><td><i class="fa-cloud">:cloud:</i></td><td><strong>Learn about our cloud solution</strong></td><td>Understand how OneSite Cloud simplifies patching and content delivery across distributed environments.</td><td></td><td></td><td><a href="https://docs.adaptiva.com/patch/overview/saas-comparison">https://docs.adaptiva.com/patch/overview/saas-comparison</a></td></tr><tr><td><i class="fa-star">:star:</i></td><td><strong>See what's new</strong></td><td>Check out the latest features, updates, and release notes for the OneSite product suite.</td><td></td><td></td><td><a href="https://docs.adaptiva.com/whats-new">https://docs.adaptiva.com/whats-new</a></td></tr></tbody></table>


# What's New

New updates and improvements

## 10.2.973

*July 7, 2026*

#### NEW AirGap for OneSite Patch

The AirGap for OneSite Patch add-on allows you to distribute patches to air-gapped (network isolated) devices using a secure provisioning process. Learn more about [setting up an air-gapped environment](https://docs.adaptiva.com/patch/airgap/install-airgap).

#### NEW Support for Extra Packages for Enterprise Linux (EPEL)

OneSite Patch now supports Extra Packages for Enterprise Linux (EPEL) for any subscribed Linux devices. OneSite Patch will deliver EPEL feeds that allow administrators to manage the patching of EPEL packages on those machines.

#### NEW Client certificate support

The OneSite Platform now supports [client certificate policies](https://docs.adaptiva.com/platform-guide/platform-management/certificates), enabling use cases such as SSL packet inspection by network appliances.

#### Miscellaneous updates

* **Access Client logs from Server** - You can now [download clients logs](https://docs.adaptiva.com/platform-guide/platform-features/logs#client-logs) from the Admin Portal. This allows better troubleshooting without requiring direct client access.
* **Pause tenant upgrades**\* - You can now [pause tenant upgrades](https://docs.adaptiva.com/cloud/configuration/create-tenant#pause-upgrades) in the Cloud Admin Portal to support your organization's change-freeze windows.
* **Auto-approvals for OneSite Patch** - You can configure [automatic approvals](https://docs.adaptiva.com/patch/get-started/strategies-v2#hot-to-patch) for patch strategies after a pre-defined timeout.
* **AES migration** - For added security, the OneSite Platform will utilize the AES GCM cryptographic method for all encryption.
* **Workbench deprecation** - As part of the ongoing Workbench deprecation, workflow authoring is no longer supported in the workbench.

## 10.1.972

*March 31, 2026*

#### NEW Device Inventory

Collect and explore inventory data from Windows, Mac and Linux devices. Utilize our built-in Sensors or create your own!

Learn more in the [OneSite Device Inventory](https://docs.adaptiva.com/device-inventory) docs.

#### NEW OneSite Aida

OneSite Aida is our purpose-built generative AI agent for OneSite Patch and OneSite Device Inventory.

Check out how you can use [OneSite Aida](https://docs.adaptiva.com/platform-guide/overview/aida-overview) to generate dynamic dashboards and analyze data in real time.

#### NEW Qualys VM integration

OneSite Patch now integrates with Qualys Vulnerability Management, Detection, & Response (VMDR) data and risk prioritization.

#### Broadened platform support

The OneSite platform now supports ARM-based Linux systems as well as additional Linux distributions, including Amazon Linux, OpenSUSE, SLES, and Fedora.

**Linux ARM support**

The Adaptiva Client is now supported on ARM-based Linux for [supported distributions](https://docs.adaptiva.com/platform-install/overview/supported-systems#linux).

**More Linux support**

The OneSite platform now supports more Linux variants:

* Amazon Linux 2023
* OpenSUSE 15.6 and 16.0
* SUSE Linux Enterprise Server 15 SP 7
* SUSE Linux Enterprise Desktop 15 SP 7
* SUSE Linux Enterprise Server 16 (SLES 16)
* Fedora Linux 42
* Fedora Linux 43

#### BIOS/driver/firmware patch improvements

Scanning and patching for BIOS and drivers from Dell, Lenovo, and HP have been improved dramatically, reducing scan times and streamlining patch workflows.

Learn more about [this scenario](https://docs.adaptiva.com/patch/scenarios/bios-driver).

## 10.0.971

*December 10, 2025*

#### New user experience in OneSite Patch

OneSite Patch has a new [guided setup](https://docs.adaptiva.com/patch/get-started/getting-started) and simplified patching experience, as well as a [home dashboard and deployment dashboard](https://docs.adaptiva.com/patch/get-started/dashboards). This advances the promise of our autonomous patching approach, delivering both simplicity and control.

![Get Started](/files/nHmxH0MflyeaVoIDBnaY)

<details>

<summary>OneSite Patch Navigation Changes</summary>

The OneSite Patch user interface has undergone a significant reorganization and optimization in order to simplify the setup and operations of autonomous patching. Below is a map of the navigation elements between version 9 and version 10 of OneSite Patch.

| **Version 9**                             | **Version 10**                                                                      |
| ----------------------------------------- | ----------------------------------------------------------------------------------- |
| *Patch Management*                        |                                                                                     |
| Home                                      | Home                                                                                |
| Patching Analytics > Overview             | *Replaced by* Home *and* Deployments *dashboard*                                    |
| Patching Analytics > Products             | Software > Products                                                                 |
| Patching Analytics > Patches              | Software > Patches                                                                  |
| Patching Analytics > Devices              | Asset Management > Devices                                                          |
| Patching Analytics > Strategy Operations  | Advanced Settings > Intent Schema > Strategy > Strategy Operations                  |
| Flex Controls                             | Advanced Settings > Flex Controls                                                   |
| Approval Requests                         | Approvals                                                                           |
| Risk Assessment Settings                  | Advanced Settings > Risk Assessment Settings                                        |
| *Intent Schema*                           |                                                                                     |
| Business Units > Business Units           | Asset Management > Business Units                                                   |
| Business Units > Rollout Processes        | Advanced Settings > Intent Schema > Rollout Processes                               |
| Strategy > Patching Strategies            | Strategies                                                                          |
| Strategy > Patching Processes             | Advanced Settings > Intent Schema > Strategy > Patching Processes                   |
| Bots > Patch Deployment Bots              | Advanced Settings > Intent Schema > Bots > Patch Deployment Bots                    |
| Bots > Patch Notification Bots            | Advanced Settings > Intent Schema > Bots > Patch Notification Bots                  |
| Chains > Approval Chains                  | Advanced Settings > Intent Schema > Chains > Approval Chains                        |
| Chains > Notification Chains              | Advanced Settings > Intent Schema > Chains > Notification Chains                    |
| Deployment Channels > Deployment Channels | Advanced Settings > Intent Schema > Patch Scheduling > Deployment Channels          |
| Deployment Channels > Processes           | Advanced Settings > Intent Schema > Patch Scheduling > Deployment Channel Processes |
| Deployment Waves                          | Advanced Settings > Intent Schema > Deployment Waves                                |
| Maintenance Windows                       | Advanced Settings > Maintenance Windows                                             |
| Communication Providers                   | Advanced Settings > Communication Providers                                         |
| User Interaction Settings                 | Advanced Settings > User Interaction Settings                                       |
| Customized Products                       | Advanced Settings > Customized Products                                             |

</details>

#### Expanded Role-based Access Control (RBAC)

We have improved RBAC with the ability to author custom roles, as well as introduced new built-in [security roles](https://docs.adaptiva.com/patch/security-and-access-control/rbac) for OneSite Patch, including a [branch office administrator role](https://docs.adaptiva.com/patch/security-and-access-control/branch-admin). With these enhancements you can provide scoped access to locations such as branch offices or testing labs, as well as provide read-only access for scenarios like security audits.

#### Multiple feature enhancements

We have added more Business Units for better patch targeting, improved user notifications for interfering applications, and improved data sync controls for CrowdStrike customers.

#### Quality improvements and bug fixes

The Adaptiva Server and Client have been updated to use Java 25. We have also updated several 3rd party libraries.

#### Download the full release notes

For details on any of these changes, the full release notes are available to download from our [Support Site](https://support.adaptiva.com/hc/en-us/articles/208811066-Adaptiva-Cumulative-Release-Notes).

## 9.3.970

*October 6, 2025*

#### Added support for new Linux distributions

* Oracle Linux 8, 9, 10
* Alma Linux 8, 9, 10
* Rocky Linux 8, 9, 10
* Debian 13
* RHEL 8, 10

**Added support for macOS 26**

For more information, see [Supported Systems](https://docs.adaptiva.com/platform-install/overview/supported-systems)

**Linux reboot**

Support has been added for rebooting Linux machines when needed for patching.

#### Improved installation experience

The Server and Client installation process has been updated and simplified, with additional checks run to ensure functionality.

The Server installer includes new checks for cloud services connectivity. The Client installer will now create the appropriate firewall rules on Linux and MacOS client operating systems. The Client installer will also perform several post-setup checks to ensure functionality.

#### Client validation tool

A new client validation tool has been included to perform post-installation connectivity checks.

![Client Validator](/files/n3avABlOhTJVgibHKjaf)

This tool verifies that the client can successfully connect to both local and cloud services. This experience is available cross-platform, both in the windows installer and the *adaptivactl*.

With these changes, administrators will always be certain that new client deployments are successful.

#### Quality improvements and bug fixes

Customers using Falcon Spotlight will see a variety of issues fixed to Falcon Business Unit functionality and user management.

Small updates to the Admin Portal to improve the navigability of Business Units, the creation of Patching Strategies, the status SentinelOne metadata refreshes, and improved row selection in tables.

## 9.3.968

*July 16, 2025*

#### Cross Platform Installation Enhancements

* Cross-platform installers have been enhanced so that they now accept parameters so that installation can be performed with switches at runtime, similar to Windows installer, rather than updating and distributing a config file.
* New auto-upgrade process has been developed to get clients up to the version of the server. This will work for all 9.3+ clients. Previous versions will need to use the old process to get clients to 9.3.

#### Minimum Version of SQL Server Changed

* Minimum SQL Server version has changed. SQL Server must be at least SQL Server 2017. Also, the Adaptiva database compatibility level should be 140 or higher. It is recommended that SQL Server 2019 or later be used with compatibility level 150 or higher.

#### Microsoft 365 patching in OneSite Patch

* **Native Office 365 Patching Support**

  Fully integrated support for Microsoft 365 updates in OneSite Patch—no more manual blob generation or content packaging. Just select and deploy.
* **Delta Updates = Smaller, Smarter Patching**

  Instead of downloading full 3GB updates for each language, OneSite Patch distributes monthly delta updates (30–50 MB), reducing bandwidth usage by up to 95%

#### SentinelOne integration

* We have added SentinelOne to our list of vulnerability management integrations.

To get started with SentinelOne, see the [SentinelOne integration guide](https://docs.adaptiva.com/patch/integrations/integrate-sentinelone)

## 9.2.967

*April 2, 2025*

#### OneSite Patch supported operating systems update

* OneSite Patch supports additional operating systems.
  * Linux (Ubuntu, Debian, CentOS)
  * MacOS

For more information, see [Supported Systems](https://docs.adaptiva.com/platform-install/overview/supported-systems)


# OneSite platform overview

The OneSite Platform enables autonomous endpoint management to rapidly remediate vulnerabilities and deliver content to any number of endpoints—no matter the location or network connection.

This guide explains how to install the OneSite Platform components, including the Adaptiva Server service and the Adaptiva Client agent. The installation process is the same for all Adaptiva products because they are all built on the OneSite Platform.

## OneSite Platform Prerequisites

Before installing the OneSite Platform, review the site planning requirements in the Adaptiva OneSite Platform Site Planning Guide.

## Customer Support

If you need information beyond what our Documentation and [Knowledge Base](https://support.adaptiva.com/hc/en-us) provide, enter a support ticket and request help from [Adaptiva Customer Support](https://adaptiva.com/support).


# Supported systems

Supported operating systems, software, drivers, and BIOS

The following operating systems, software, drivers, and BIOS are supported on the OneSite platform.

## Operating Systems

### Windows

* Windows 10 and newer
* Windows Server 2012 R2, Windows Server 2016 and newer
* Support for BIOS and driver patching for the following third-party solutions:
  * DELL
  * Hewlett-Packard
  * Lenovo workstations and Servers

### Linux

Automated OS package updates, libraries, and applications from official repositories for key Linux distributions (updates within the same distribution release within those repositories).

* Alma Linux 8, 9, and 10
* Amazon Linux 2023
* CentOS Stream 9 and 10
* Debian 11, 12 and 13
* Fedora Linux 42, 43
* openSUSE Leap 15.6 and 16.0
* Oracle Linux 8, 9, and 10
* Red Hat Enterprise Linux (RHEL) 8, 9, and 10
* Rocky Linux 8, 9, and 10
* SUSE Linux Enterprise Server 15 SP6 and SP7
* SUSE Linux Enterprise Desktop 15 SP6 and SP7
* SUSE Linux Enterprise 16 (SLES 16)
* Ubuntu 22.04 LTS and 24.04 LTS

Support for repository-based library and application patching includes:

* OS package updates (security, system services, libraries, and kernel).
* Automated updates from the official repositories of each supported Linux distribution for each supported release.
* Patch support for approximately 18,000+ Products sourced from distribution-specific repositories.
* Popular application support, such as Chromium, Firefox, Apache, OpenSSL, NGINX, and more.
* Patch support for Extra Packages for Enterprise Linux (EPEL)

Some limitations apply. See the [OneSite Patch Cross Platform Customer FAQs](https://docs.adaptiva.com/patch/overview/saas-faq) for details.

### Mac

Third-party patching only. Support for devices running the following macOS versions running on M-Series (No Intel):

* macOS 13 (Ventura)
* macOS 14 (Sonoma)
* macOS 15 (Sequoia)
* macOS 26 (Tahoe)

MacOS patching is not supported at this time.


# System requirements

The OneSite platform requires thoughtful planning of system resources based on the solutions you use and the size of your IT estate. Please see the system requirements below for the Adaptiva Server, SQL Server, and Adaptiva Client.

## Adaptiva Client Requirements

The information in the table below details the minimum requirements for the Adaptiva Client installation.

| Component        | Minimum Requirement                                                                                                                                                                                                                                                                                                                           |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Operating System | Many Windows, Linux, and MacOS operating systems are supported. See [Supported Operating Systems](/platform-install/overview/supported-systems#operating-systems).                                                                                                                                                                            |
| Processor        | 1 gigahertz (GHz) or faster, with 2 or more cores on a compatible 64-bit processor.                                                                                                                                                                                                                                                           |
| RAM              | <p>4 GB minimum.<br>Allocate 256 - 512 megabytes (MB) to the Adaptiva Client Service (average 256 MB reserved, peaking to 512 MB under a full scan).</p>                                                                                                                                                                                      |
| Storage          | <p><em>Installation files</em>: require 800 MB for the Adaptiva Client installation files.<br><em>Logging</em>: approximately 2 GB for the default logging retention.<br><em>Content cache</em>: Variable. See <a href="https://docs.adaptiva.com/platform-guide/platform-features/understand-client-cache">Understand content cache</a>.</p> |

## Adaptiva Server Requirements

The information in the table below details the minimum requirements for the Adaptiva Server installation. If the Adaptiva Server and SQL Server are installed on the same system, take note of the increased RAM requirements.

| Component        | Minimum Requirement                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Operating System | Windows Server, Standard or Datacenter Edition. For more information on the supported operating systems, see [Supported Operating Systems](/platform-install/overview/supported-systems).                                                                                                                                                                                                                                                                                                                 |
| Processor        | Single Quad-core Xeon Processor.                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| RAM              | See [Calculate RAM requirements](#calculate-ram-requirements).                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Storage          | <p><em>Installation files</em>: require 1.5 GB for the Adaptiva Server and Client installation files.<br><em>Logging</em>: approximately 5 GB for the default logging retention.<br><br><em>OneSite Anywhere only</em>: In addition to the general storage requirements, the Adaptiva Server may need disk space to store published content in the Content Library. The estimated size is the same amount of storage used for the content source files, plus 20% for policy files and DIFF files.<br></p> |

## SQL Server Requirements

Review the requirements in the table below when deciding which SQL Server Edition to use with the Adaptiva Server.

| Component                    | Requirement                                                                                                                                                                                                                             |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SQL Server Version           | <p>SQL Server 2025<br>SQL Server 2022<br>SQL Server 2019<br>SQL Server 2017</p>                                                                                                                                                         |
| Database Compatibility Level | <p>Minimum level is SQL Server 2017 (140).<br>SQL Server 2019 (150) or newer is recommended.<a href="#notes"><sup>1</sup></a></p>                                                                                                       |
| Database Sizing              | <p>Minimum database size is 5 GB. Storage allocation per managed device is approximately 2.5 MB. Use the following equation to determine your database size requirements:<br><code>5 GB + (2.5 MB x licensed clients) = x GB</code></p> |
| Memory                       | See [Calculate RAM requirements](#calculate-ram-requirements).                                                                                                                                                                          |
| Disk Infrastructure          | SSD or NVMe drives for the database files (recommended), including tempdb and transaction log files.                                                                                                                                    |

<sup>1</sup> For more information on upgrading to a supported SQL Server edition, see [Supported version and edition upgrades (SQL Server 2017) - Microsoft](https://learn.microsoft.com/en-us/sql/database-engine/install-windows/supported-version-and-edition-upgrades-2017?view=sql-server-ver17\&source=recommendations).

## Calculate RAM requirements

To determine how much RAM your server needs, add together the memory required for each major component:

**Total RAM** =

* Base operating system
* Installed tools and utilities
* ConfigMgr (OneSite Anywhere only)
* SQL Server
* Memory required based on number of clients

Each of these consumes memory independently, so the final requirement is the sum of all parts.

### Client-Based Memory Requirements (Adaptiva Server Service)

The Adaptiva Server uses more RAM as it services more clients. Use the chart below to find the baseline RAM needed for clients:

* 0–5,000 clients → 4 GB
* 5,001–10,000 clients → 6 GB
* 10,001–19,999 clients → 10 GB
* 20,000–49,999 clients → 12 GB
* 50,000+ clients → 16 GB
* Each additional 50,000 clients → Add 16 GB more

### SQL Server on the Same Machine (Important)

If SQL Server is installed on the same server as the Adaptiva Server:

* Double the client-based RAM allocation
* Explicitly cap SQL memory

This ensures SQL has enough memory to operate without impacting Adaptiva performance.

### Example Calculations

**Example 1**: OneSite Patch + 2,000 Clients, SQL Express

* Client-based RAM: 4 GB x 2 (SQL)
* Add OS + tools

Minimum RAM = 8 GB + other components

**Example 2**: OneSite Anywhere + OneSite Patch + 25,000 Clients, SQL Standard

* Client-based RAM: 12 GB x 2 (SQL)
* ConfigMgr requirements
* Add OS + tools

Minimum RAM = 24 GB + ConfigMgr + other components

**Example 3**: OneSite Patch + 120,000 Clients, SQL on remote server

* First 50,000 clients: 16 GB
* Additional 50,000 clients: + 16 GB
* Add OS + tools

Minimum RAM = 32 GB + other components

### Useful References

* [Recommended hardware for Configuration Manager](https://learn.microsoft.com/en-us/intune/configmgr/core/plan-design/configs/recommended-hardware)
* [Hardware and software requirements for SQL Server 2022](https://learn.microsoft.com/en-us/sql/sql-server/install/hardware-and-software-requirements-for-installing-sql-server-2022)


# Plan for OneSite platform installation

Plan for the installation and management of the OneSite platform.

The OneSite Platform consists of the following components required for installation:

* Adaptiva Server
* SQL Database
* Adaptiva Client

## Adaptiva Server

The OneSite Platform solution includes both the Server software and the Adaptiva Client instance. The OneSite Platform uses both components to facilitate and simplify complex endpoint management processes, including caching, peer communication, content acquisition, and result reporting.

### Key Integrations

The Adaptiva Server also integrates with a variety of third-party solutions:

|                                                                                                                |                                                                                                      |
| -------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| <p>CrowdStrike Falcon<br>Microsoft Defender<br>SentinelOne Singularity<br>Tenable Vulnerability Management</p> | <p>Tenable Security Center<br>Omnissa Workspace ONE<br>Configuration Manager<br>Microsoft Intune</p> |

### Adaptiva Server Installation Path Details

The Adaptiva Server installation wizard uses the following default location for files and logs:

**%Program Files%\Adaptiva\AdaptivaServer**

{% hint style="warning" %}
**Important** - Do not install the Adaptiva Server on the OS C: drive. The OneSite product log files grow to a maximum size of approximately 5 GB, and the Adaptiva Content Library installed with the Adaptiva Server expands over time. This may impact storage and performance on the OS C: drive. You can [change the location of the content library](https://support.adaptiva.com/hc/en-us/articles/203736410-How-To-Change-the-location-of-the-content-library) later if needed.
{% endhint %}

You may also choose your own installation path.

### Admin Portal Port

The Adaptiva Server hosts a web page for administration. This web page must be configured to a specific HTTP(S) port on the server. This defaults to using the HTTPS port 443. If another service is using port 443, a different port must be specified during installation. Use `NETSTAT -nabo` to return a list of currently used ports. Adaptiva recommends using port 9678 if the default port is unavailable.

### (Optional) Client HTTP Transport Port

*This does not apply to OneSite Anywhere*

Adaptiva Clients use specific UDP ports to communicate with the Adaptiva Server as well as other clients. If UDP communication with the Adaptiva Server does not work, client-to-server communications can be changed to use HTTP. You can use port 9679 or select another port. Run the `NETSTAT -nabo` command to return a list of currently used ports.

{% hint style="info" %}
If not configuring the HTTP Client Transport Port, leave it set to 0.
{% endhint %}

### Installation Account

The account performing the installation requires local administrator permissions on the Adaptiva Server and must be included in the SQL SysAdmin role on the SQL Server. You may change this permission after installation. In addition, you may also change the service account from the local system to a specified service account after installation.

| Server/Location                          | Account                                                                                           | Permissions                                                                                                                                                                                                                                                                                                                                     |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Adaptiva Server                          | <p>Installation account<br>Reporting Account<br><br>Optional Service account<br></p>              | <p>Local Administrators group<br>The installation will grant <code>db\_datareader</code> permissions on the Adaptiva database.<br><br>If used, the account must be granted the Log On As A Service User right.<br></p>                                                                                                                          |
| SQL Server hosting the Adaptiva database | <p>Adaptiva Server SYSTEM Account<br>Installation Account<br><br>Optional Service Account<br></p> | <p>The SQL Server Role requires the sysadmin permissions for installation and upgrade.<br>Minimum permissions (after installation) Adaptivadatabase Security User Mapping (account running the Adaptiva Server service): <code>db\_datareader</code>, <code>db\_datawriter</code>, <code>db\_ddladmin</code>, <code>db\_executer</code><br></p> |
| Content Library                          | <p><code>\<domain>\AdaptivaServer$</code><br>Optional Service Account<br></p>                     | If you choose to [change the location](https://support.adaptiva.com/hc/en-us/articles/203736410-How-To-Change-the-location-of-the-content-library) of the Adaptiva Content Library to a remote drive or share, the Adaptiva Server service account must be granted Modify permissions to the location.                                          |

### Record the Server Details

* Server installation path
* Integration with existing ConfigMgr site
* Integration with Workspace ONE
* Admin Portal communications port is 443 or 9678
* (Optional) HTTP Client Transport port

### Server Activation (OneSite Anywhere only)

If the Adaptiva Server will use OneSite Anywhere and the Adaptiva Cloud Services, then the following steps are required to request an activation code.

This is required when clients are on the internet or cannot communicate directly with the Adaptiva Server using UDP or HTTP.

This can be submitted via a request from the Support Portal.

1. Open a web browser and connect to <https://support.adaptiva.com> and log in.
2. Click **Submit a request**.
3. From the drop down, select **I would like to request Cloud and/or CDN activation for an Adaptiva Server**.
4. Complete the form with the following information and click **Submit**:

   ```
   Server Name (or identifier - required):
   Server Use: Production, Dev, Test, QA, etc (required):
   Request type (required):
   - Cloud Activate & Provision Adaptiva CDN
   - Cloud Activate Only
   - Provision Adaptiva CDN Only
   Support Email Address (required):
   Billing Email Address (required):
   Billing Telephone Number (required):
   ```
5. Within 24 hours an activation code will be sent.

## Adaptiva database

The Adaptiva Server requires its own SQL Server database (Adaptiva database).

### Database Considerations

You can host the Adaptiva database on an existing SQL Server instance or on SQL Server Express Edition, the free version of SQL Server. If hosting the database alongside other solutions (Microsoft Configuration Manager), ensure compliance with the licensing requirements for Microsoft. If choosing to use SQL Server Express, you can either install it manually or allow the Adaptiva Server setup to install and configure it automatically. SQL Server Express Edition supports environments with up to 2,000 devices.

#### Adaptiva database SQL Server

* **Local server:** Microsoft SQL Server is installed on the same server as the Adaptiva Server service.
* **Remote server:** This is a different server running a Microsoft SQL Server instance. The SQL Server instance may use clustering.

### Choosing the SQL Server Edition

The Adaptiva Server installation wizard requires specific input depending on the SQL Server Edition you choose to use. You may choose to install one of the following SQL Server Editions:

* SQL Server Express
* SQL Server Standard
* SQL Server Enterprise

Use the information in this section to help determine which SQL Server Edition works best in your environment to host the Adaptiva database. For a full list of the differences between Editions, see [Compare SQL Server versions (Microsoft)](https://www.microsoft.com/en-us/sql-server/sql-server-2022-comparison).

#### SQL Server Express Edition Details

The Adaptiva Server Setup wizard will automatically download, install, and configure SQL Server Express. You can also manually install it and reference the installation in the wizard.

The following settings will be installed when the Adaptiva Server Setup completes the installation:

* Installs SQL Server 2022 Express Edition
* Creates a Named Instance called `AdaptivaSQL`

The server will require an Internet connection to download and install the free SQL Server Express Edition from Microsoft. If using this version, you must enable Microsoft .NET Framework 4.0. For details on how to download .NET Framework 4.0, see [Microsoft .NET Framework 4 Full Language Pack (x86 x64)](http://go.microsoft.com/fwlink/?LinkId=186791).

* You can pre-download SQL Server 2022 Express Edition (`SQLEXPR_x64_ENU.exe`). Copy the downloaded `SQLEXPR_x64_ENU.exe` file to **C:\Users\\%ACCOUNTNAME%\AppData\Local\Temp**.

SQL Server Express Edition has the following limitations:

* No Built-In Scheduled Backups (workaround available)
* SSRS is only available with SQL Express with Advanced Services
* Maximum Allowed Memory Capacity is 1410 MB
* Maximum Database Size is 10 GB
* Maximum Number of Cores is 1 socket, up to 8 cores
* No High Availability.

**SQL Server 2025**

SQL Server 2025 - Express Edition allows up to a 50GB database, which can support approximately 18,000 devices. See [Scale limits for SQL Server 2025](https://learn.microsoft.com/en-us/sql/sql-server/editions-and-components-of-sql-server-2025?view=sql-server-ver17\&preserve-view=true#scale-limits) for more details. If you wish to support a larger database and more devices, you can pre-install it on your server and choose "Existing SQL Server" in the installer wizard.

#### SQL Server Standard Edition Details

* Install on the Adaptiva Server or in a remote location.
* Standard SQL licensing requirements apply. Consult with a Microsoft licensing specialist to ensure you have purchased the proper licenses.
* Required with more than 2000 (SQL 2022) / 18000 (SQL 2025) licensed devices.
* Supports high-availability configuration (single database).

#### SQL Server Enterprise Edition Details

* The Enterprise edition includes the SQL Server Standard Edition statements.
* Supports high-availability configuration (multiple databases).

### Account Permissions

#### Installation Account Permissions

The account performing the installation on the Adaptiva Server must be granted the sysadmin role on the SQL Server. These permissions can be reduced after installation.

#### Database Access Account

The Adaptiva Server installation defaults to using the Local System account. You can change this to a local account or, preferably, a domain account. When you integrate with ConfigMgr, you must grant the selected account the necessary permissions in ConfigMgr. See [ConfigMgr Planning](/platform-install/planning-guides/configmgr-planning).

#### Adaptiva Reporting Account

The Adaptiva Server uses a read-only SQL login to display product dashboards. All data providers for the Adaptiva Server query the Adaptiva database using this read-only SQL login.

During installation, the setup wizard grants this login the `db_datareader` permission on the Adaptiva database. Consider the following options when planning for the Adaptiva Reporting Account:

**Quick installation (recommended)**

* This option will download, install and configure SQL Express Edition on the Adaptiva server. It will create and configure a SQL account to be used by the data providers.

{% hint style="info" %}
This is the recommended option for OneSite Patch installations.
{% endhint %}

**Advanced installation**

**SQL Server is not installed**

* This option will download, install and configure SQL Express Edition. The Adaptiva Reporting Account page will need to use Windows Authentication, so you must provide the pre-created domain or computer service account credentials.

**SQL Server is already installed on the same server**

* This option allows you to choose either a SQL account or a Windows Authenticated account. To allow the installation to create an account, leave the account information blank after deselecting Windows Authentication.
* If Windows Authentication is checked, you must provide the pre-created domain or computer service account credentials.

**SQL Server is already installed on a remote server**

* This option requires you to use Windows Authentication. You must provide the pre-created domain service account or a local service account credentials on the remote SQL server.

All service accounts should have a non-expiring password.

{% hint style="warning" %}
**Important** - When Windows Authentication is used with a domain account, enter the NETBIOS Domain name, not the Fully Qualified Domain name.
{% endhint %}

### Record the Server and SQL Server Edition Details

Record the server details and the chosen SQL Server Edition. The Adaptiva Server installation may require configuration details, such as the following:

* If using SQL Express, using the following download and installation paths:
  * For the download folder location, use the following path:

    `C:\Users\<accountname>\AppData\Local\Temp`
  * For the SQL Server installation location, use the following path:

    `C:\Program Files\Microsoft SQL Server`

{% hint style="info" %}
It is recommended not to install SQL Server on the C: drive.
{% endhint %}

* Database Server FQDN (if using Remote Server)
* **Instance Name:** Default or `AdaptivaSQL` for SQL Server Express Edition
* **SQL Server Port:** Defaults to 1433
* **Database name:** Adaptiva
* Encryption status of the SQL database
* Account when not using the Local System username and password. Domain names must be entered as a NetBIOS name, not an FQDN.
* For SQL Authentication Protocol, use NTLM V2 unless integrating with ConfigMgr, Adaptiva databases, and ConfigMgr databases are on different servers (add additional security as necessary), and then add Kerberos.
* For the Reporting Account domain name, use the username and password if using Windows Authentication. Do not use FQDN for the domain name.

## Security Certificate Options

The Server installation defaults to creating a TLS-based certificate for use with HTTPS. The Adaptiva Server installation provides the following TLS security options:

* Add your own TLS certificate, authorized through a Certificate Authority (CA) such as Active Directory Certificate Services or a third-party CA (i.e., GoDaddy, DigiCert, Let's Encrypt, etc).
* Use the self-signed TLS certificate that the Adaptiva Server creates during Server installation. This certificate is 4096 bits, uses SHA-512 hash, and expires in 12 years from the date of creation.
* Use plain HTTP protocol. The Adaptiva Server installation allows this option for lab testing only. Adaptiva does not support this choice on production servers.

When deciding on the type of TLS certificate to use for your Server installation, consider whether your security organization has any requirements for using certificates, such as the following:

* Self-signed certificates versus CA certificates.
* Wildcard certificates versus a certificate specific to a server.
* Key size, Hash algorithm, and expiration length requirements.

Record the TLS certificate option you chose.

### CA Requirements

The CA-issued certificate should be 4096 bits and use a SHA-512 hash.

Set an expiration that complies with the security policy for your company. Be sure to create a reminder to renew the certificate before expiration.

CAs issue SSL certificates as PFX files, which you must convert to PEM files for use with the Adaptiva Server. The two separate `.pem` files required by the Adaptiva Server include a certificate file and an unencrypted private key file in the UTF-8 format.

The easiest way to convert the `.pfx` files to `.pem` files is to use OpenSSL. Note that you will need the secure password that was used to protect the PFX file.

A version of OpenSSL can be found under **%ADAPTIVACLIENT%\bin\openssl.exe**. If you don't already have OpenSSL installed for Windows PowerShell, you can use the following commands to temporarily add the location to your PATH environment variable:

```powershell
# Add the path to the version of OpenSSL included with the Adaptiva client.
$env:PATH += ";$env:ADAPTIVACLIENT/bin"

# Verify that OpenSSL is working.
openssl version
```

Once you have verified that OpenSSL is working, you can use the following commands to extract the .pem files from the .pfx file:

```powershell
# Replace the following line with the appropriate path and filename.
$pfx_cert = "C:\mycerts\certfile.pfx"

# Extract the certificate. You will be prompted for the PFX password.
openssl pkcs12 -in $pfx_cert -clcerts -nokeys -out cert.pem

# Extract the private key as an unencrypted file. You will be prompted for the PFX password again.
openssl pkcs12 -in $pfx_cert -nocerts -nodes -out key.pem
```

### Self-signed Certificate Requirements

List the X.500 protocol common and alternate comma-separated names you want to use for the self-signed certificate. These include the following server details:

* FQDN
* DNS aliases
* IP addresses
* NETBIOS name

Every Administrator using the Admin Portal must install this certificate into their Trusted Root Certification Authorities certificate store.

## Communication Ports and Flow Diagrams

OneSite Platform communicates between the server and clients on a range of different ports as a network application. For a list of required ports, see [Communication Port and Flow Diagrams](https://adaptiva.com/hubfs/Docs/OneSite-Communications-Port-and-Flow-Diagram.pdf).

The installers automatically create firewall rules on Windows and CentOS for ports in all network profiles. If using a firewall other than the default included with the operating system for the device, you may need to manually configure the required ports to ensure communications are available.

## Internet Access

The Adaptiva Server must be allowed to access the internet. This is an outbound connection only and uses the standard HTTP(S) ports TCP 80 and 443. Managed devices that cannot reach the Adaptiva Server across the company network must also allow for this connectivity.

### Internet Access Requirements

The Adaptiva Server and Adaptiva Client require access to the following URL:

`http[s]://*.adaptiva.cloud`

Ensure that the following Request Methods are allowed:

`HEAD`, `GET`, `POST`

When using proxies, verify whether you must explicitly allow these request methods. Additionally, allow the `DELETE` request method for the Adaptiva Server when CDN services are provisioned.

{% hint style="warning" %}
Ensure SSL Inspection is disabled.
{% endhint %}

### Linux Repository Access

OneSite Patch uses the native Linux package manager on each client — **APT**, **DNF/YUM**, or **Zypper** — to apply updates. Clients must be able to resolve and reach the repositories configured on the system for patching to succeed. Network egress rules and any HTTP(S) proxy must allow outbound access to those repo endpoints. OneSite Patch supports standardized repo sources for consistency and restricted/air‑gapped environments. It does not bypass OS security or repo policies. If the client can update/refresh and fetch packages from its repos, OneSite Patch can patch that system using the same paths, proxies, and trust settings.

You can view the repo configuration files for your client to determine what repositories you need to define access for:

| Package Manager | Repo Config Location                                      |
| --------------- | --------------------------------------------------------- |
| **APT**         | `/etc/apt/sources.list`, `/etc/apt/sources.list.d/*.list` |
| **DNF/YUM**     | `/etc/yum.repos.d/*.repo`                                 |
| **Zypper**      | `/etc/zypp/repos.d/*.repo`                                |

You will need to configure repository access according to your strategy (direct to public mirrors, via a proxy, or using an internal mirror/cache). Allow outbound **HTTPS (443)** to the FQDNs present in your repo configurations (and to any mirrors they redirect to). Examples include `cdn.redhat.com`, `archive.ubuntu.com`, and `download.opensuse.org`. Ensure clients can resolve these FQDNs via DNS. You can find more information in your vendor package management documentation for more configuration details.

#### Test client connectivity

You can easily test connectivity using the native package manager on a client:

* Debian/Ubuntu:

  ```bash
  sudo apt-get update
  ```
* RHEL family:

  ```bash
  sudo dnf clean all && sudo dnf makecache
  ```
* SUSE:

  ```bash
  sudo zypper refresh
  ```

A successful metadata refresh will confirm network access, GPG (GNU Privacy Guard) trust, and proxy configuration. The signature of the metadata is explicitly checked by the package manager when it downloads.

### Internet URLs

Adaptiva Server and managed clients not able to communicate directly with the Adaptiva Server must be allowed to connect to the internet destinations in the table below. All ports are outbound only.

### Clients

| Source                                                 | Description                                                                                                                                                                                                                                                           | Destination                                                                                                                                                                           | Ports                                                      |
| ------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- |
| All Clients                                            | Internet Peering                                                                                                                                                                                                                                                      | `*.adaptiva.cloud`                                                                                                                                                                    | HTTP/HTTPS (TCP port 80, TCP port 443), ICMP, and UDP 3478 |
| All Clients                                            | Internet Client Discovery                                                                                                                                                                                                                                             | `*.opendns.com`[<sup>1</sup>](#notes)                                                                                                                                                 | DNS calls to UDP 53                                        |
| All Clients                                            | <p>Adaptiva CDN<br>When OneSite Patch is licensed, metadata and fallback content originates here.</p>                                                                                                                                                                 | `*.adaptivacdn.cloud`                                                                                                                                                                 | HTTPS (TCP port 443)                                       |
| Devices in the Central Office or CDN-enabled Locations | Patch clients in the Central Office or CDN-enabled Locations will download content from third-party vendor sites. The server and any internet-capable clients require a connection to these locations. Clients will always look to 3rd party sites for content first. | <p>Third-party vendor site<br><br>For Microsoft Updates:<br><code>*.microsoft.com</code>, <code>*.windowsupdate.com</code>, <code>*.windows.com</code>, <code>*.office.com</code></p> | HTTPS (TCP port 443)                                       |
| Devices in the Central Office or CDN-enabled Locations | Patch clients in the Central Office or CDN-enabled Locations will download Driver and BIOS content from the system manufacturer's CDN. The server and any internet-capable clients require a connection to these locations.                                           | <p><code>*.hp.com</code><br><code>*.lenovo.com</code><br><code>\*.dell.com</code><a href="#notes"><sup>2</sup></a></p>                                                                | HTTPS (TCP port 443)                                       |

### Server

Note that the Adaptiva Client will always be installed on the Adaptiva Server. Be sure to review the table above.

| Source          | Description                                                                                           | Destination                                                                                          | Ports                                  |
| --------------- | ----------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | -------------------------------------- |
| Adaptiva Server | Adaptiva Cloud Services                                                                               | `*.adaptiva.cloud`[<sup>3</sup>](#notes)                                                             | HTTP/HTTPS (TCP port 80, TCP port 443) |
| Adaptiva Server | <p>Adaptiva CDN<br>When OneSite Patch is licensed, metadata and fallback content originates here.</p> | `*.adaptivacdn.cloud`                                                                                | HTTPS (TCP port 443)                   |
| Adaptiva Server | Adaptiva CDN storage                                                                                  | <p><code>*.bunnycdn.com</code><br><code>*.b-cdn.net</code><br><code>\*.bunnyinfra.net</code></p>     | HTTPS (TCP port 443)                   |
| Adaptiva Server | Approval messaging, email messages, and SMS messages                                                  | <p><code>api.sendgrid.com</code><br><code>api.twilio.com</code><a href="#notes"><sup>4</sup></a></p> | HTTPS (TCP port 443)                   |

### Integrations

| Source                          | Description                   | Destination                                                                                                                                                 | Ports                |
| ------------------------------- | ----------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
| Adaptiva Server                 | CrowdStrike Falcon            | <p><code>\<region>.crowdstrike.com</code><a href="#notes"><sup>5</sup></a><br><br>Example: <em>api.us-2.crowdstrike.com</em>.<br></p>                       | HTTPS (TCP port 443) |
| Adaptiva Server                 | Microsoft Defender            | `*.api.security.microsoft.com` or `<region>.api.security.microsoft.com` where `<region>` is the nearest server.[<sup>6</sup>](#notes)                       | HTTPS (TCP port 443) |
| Adaptiva Server                 | Tenable Vulnerability Manager | `cloud.tenable.com`                                                                                                                                         | HTTPS (TCP port 443) |
| Adaptiva Server                 | Tenable Security Center       | `<Security_Center_IP_OR_HOSTNAME>`                                                                                                                          | HTTPS (TCP port 443) |
| Adaptiva Server                 | SentinelOne Singularity       | <p><code>\<region>.sentinelone.net</code><a href="#notes"><sup>7</sup></a><br><br>Example: <em>usea1-partners.sentinelone.net</em>.<br></p>                 | HTTPS (TCP port 443) |
| Adaptiva Server                 | Qualys                        | Either a Qualys API Server URL (eg. `https://qualysapi.qualys.com`) or a private hosted URL (`https://qualysapi.<customer_base_url>`)[<sup>8</sup>](#notes) | HTTPS (TCP port 443) |
| Adaptiva Server and All Clients | OneSite for Intune            | <p><code>*.microsoft.com</code><br><code>*.windows.net</code><br></p>                                                                                       | HTTPS (TCP port 443) |

#### Notes

<sup>1</sup> OpenDNS is the primary way to detect the public IP of the client. If this fails, the client will fallback to a STUN request to a known STUN server.

<sup>2</sup> If you are patching client system BIOS, you will need to add the system manufacturer endpoint to your allowlist.

<sup>3</sup> If you have a SaaS tenant and cannot use a wildcard, you can use `nslookup` with your tenant name to get all of the possible IP addresses for that tenant.

<sup>4</sup> Twilio/SendGrid will keep message content for a brief time. No personally identifiable information, other than an email address or phone number, is sent over this channel.

<sup>5</sup> For more information, see [CrowdStrike](https://falcon.us-2.crowdstrike.com/documentation/page/a2a7fc0e/crowdstrike-oauth2-based-apis) (requires a login).

<sup>6</sup> For more information, see [Supported Microsoft Defender for Endpoint APIs](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list).

<sup>7</sup> For more information, see [SentinelOne Mgmt API Source](https://help.sumologic.com/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sentinelone-mgmt-api-source/).

<sup>8</sup> For more information, see [Identify your Qualys platform](https://www.qualys.com/platform-identification).

***

As of December 1, 2020, the Adaptiva CDN Service Level Agreement provides CDN storage without additional cost, unless storage exceeds certain limits. The table below shows the included storage and overage costs for the Adaptiva CDN service.

| Storage Use            | Included Storage                     | Overage Costs                             |
| ---------------------- | ------------------------------------ | ----------------------------------------- |
| Data Storage           | 2 TB per customer                    | $300 per 1 TB (or part thereof), per year |
| Data Transfer / Egress | 1 GB per licensed endpoint per month | $0.02 per 1 GB, per month                 |

## Antivirus Exceptions

The OneSite Platform acquires content directly from the Adaptiva Content Library on the Adaptiva Server and from the `AdaptivaCache` folder on individual devices with the Adaptiva Client.

Because antivirus scanning of these files can cause performance degradation, Adaptiva recommends excluding Adaptiva folders from antivirus scans. Adaptiva uses a secure hash to protect all distributed content against tampering or corruption, either in transit or when stored.

### Creating Antivirus Folder Exclusions

Exclude the folders listed in the list below. The exclusions below are parent folders only. Exclude all subfolders.

**Adaptiva Server**

* `<path>\Adaptiva\AdaptivaServer`

**Adaptiva Server Content Library**

* The location where the Adaptiva Content Library will be located. This path must be excluded only if the Adaptiva Content Library is located in a different location from the default location.

**Adaptiva Client - Windows**

* `C:\Program Files\Adaptiva\AdaptivaClient`

  Update this exclusion if using a different location.
* `<drive>\AdaptivaCache`

  All physical drives will automatically have an Adaptiva Cache folder.
* `%windir%\SoftwareDistribution`

**Adaptiva Clients - Linux and MacOS**

* `/opt/adaptiva`

  This includes both the `adaptivacache` and `adaptivaclient` folders for both platforms.

**ConfigMgr Exclusions**

If using Adaptiva OneSite with ConfigMgr, ensure that the exclusions listed below are already in place. The following paths are included here for reference and completeness:

* `%windir%\CCM\Logs`
* `%windir%\CCM\ServiceData`
* `%windir%\CCMCache`
* `%windir%\CCMSetup`

**Intune Management Extension Exclusions**

* `%ProgramFiles(x86)%\Microsoft Intune Management Extension\Content`
* `%windir%\IMECache`

### Creating Antivirus Process Exclusions

In some cases, administrators prefer to exclude processes rather than folders, particularly when aggressive antivirus programs consider the executables to be a high-risk process.

**Adaptiva Server**

* `<path>\Adaptiva\AdaptivaServer\bin\AdaptivaServerService.exe`

**Windows Client Service**

* `C:\Program Files\Adaptiva\AdaptivaClient\bin\AdaptivaClientService.exe`
* `C:\Program Files\Adaptiva\AdaptivaServer\bin\AdaptivaUserPortal.exe`
* `C:\Program Files\Adaptiva\AdaptivaClient\bin\OneSiteClient.exe`
* `C:\Program Files\Adaptiva\AdaptivaClient\bin\OneSiteClient64.exe`
* `C:\Program Files\Adaptiva\AdaptivaClient\bin\amd64\OneSiteDownloader.exe`

**Linux and Mac Client Daemon**

* `/opt/adaptiva/adaptivaclient/bin/adaptivaclientd`

**MacOS-Only Client Daemon**

* `/opt/adaptiva/adaptivaclient/bin/adaptivauserd`

**ConfigMgr Client Service**

If using Adaptiva OneSite with ConfigMgr, ensure that the exclusions listed below are already in place. The following paths are included here for reference and completeness:

* `%windir%\CCM\CCMExec.exe`
* `%windir%\CCM\CMRCService.exe`

## Supported Browsers

Adaptiva OneSite supports the following browsers:

* Google Chrome
* Microsoft Edge
* Safari
* Mozilla Firefox \*

{% hint style="warning" %}
Do not use Microsoft Internet Explorer.
{% endhint %}

\* If you receive an Admin Portal login error when using Mozilla Firefox, see [Resolve the Mozilla Firefox Active Directory Login Issue](https://support.adaptiva.com/hc/en-us/articles/37109022499341-Resolve-the-Mozilla-Firefox-Active-Directory-Login-Issue) KB article.

## Adaptiva Client

The Adaptiva Client is an integral component of the Adaptiva OneSite Platform and must be installed on the Adaptiva Server for the OneSite Platform to function as expected. Install additional Adaptiva Clients on managed devices on the same subnet to share the content load.

### Adaptiva Client Requirements

The information in the table below details the minimum requirements for the Adaptiva Client installation.

| Component        | Minimum Requirement                                                                                                                                                |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Operating System | Many Windows, Linux, and MacOS operating systems are supported. See [Supported Operating Systems](/platform-install/overview/supported-systems#operating-systems). |
| Processor        | 1 gigahertz (GHz) or faster, with 2 or more cores on a compatible 64-bit processor.                                                                                |
| RAM              | <p>4 GB minimum.<br>Allocate 256 - 512 megabytes (MB) to the Adaptiva Client Service (average 256 MB reserved, peaking to 512 MB under a full scan).</p>           |
| Storage          | 64 GB or larger storage device.                                                                                                                                    |

### Adaptiva Client Installation Best Practices

Use the following best practices when installing the Adaptiva Client:

* Install the Adaptiva Client on the Adaptiva Server.
* Install the Adaptiva Client on all managed devices.
* Install additional Adaptiva Clients on the same subnet or Office as the Adaptiva Server to support content load sharing.

### Adaptiva Client Installation Options

When setting up the Adaptiva Client, you have the following installation options:

* Manually [install the Adaptiva Client](https://github.com/AdaptivaDocs/docs/tree/main/platform/install-guide/client-install.md) on the Adaptiva Server using the Adaptiva Client Installer. The Adaptiva Server Installer automatically launches the Adaptiva Client Installer dialog after installing the server.
* [Deploy the Adaptiva Client](https://github.com/AdaptivaDocs/docs/tree/main/platform/install-guide/deploy-clients.md) using an existing Software Distribution mechanism like Group Policy, Microsoft Intune, Jamf, WorkSpace ONE, or Microsoft ConfigMgr.

#### Identify the Adaptiva Client Installation Path

The Adaptiva Client installation uses the following default location:

`C:\Program Files\Adaptiva\AdaptivaClient`

You may also choose your own installation path.

{% hint style="info" %}
When installing the Adaptiva Client on the Adaptiva Server, use the same parent folder you used for the Adaptiva Server.
{% endhint %}

Record the installation path.

#### Record the Client Count

Determine the number of clients that will be connecting to the OneSite Platform and record the total count for licensing and sizing purposes.

## Admin Portal Communication

If another service is using port 443, a different port must be used during installation. Use `NETSTAT -nabo` to return a list of currently used ports. Adaptiva recommends using port 9678, which you can use if the default port is unavailable. Record this port to log in to the Admin Portal.


# Plan for ConfigMgr integration

Whether your ConfigMgr hierarchy includes a CAS with multiple child primary site servers, or a single, standalone primary site server, Adaptiva OneSite provides integration options during and after installation. Adaptiva recommends installing Adaptiva Server on a Primary Site Server or on a server within close network proximity of the Primary Site Server. The server installation location varies based on how your organization has designed the ConfigMgr environment.

## ConfigMgr Integration Best Practices

Use the following best practices when preparing to install the Adaptiva Server with your ConfigMgr hierarchy:

* Adequate disk space is available for Adaptiva and to store Adaptiva content.
* If the Adaptiva Server is not co-located with the Adaptiva Server ConfigMgr Site Server, you must grant the Adaptiva Server computer system account for the Adaptiva Server the necessary permissions.
* Use the NTLM V2 Authentication protocol when the ConfigMgr and Adaptiva databases are hosted on the same SQL Server. Or, if these databases are hosted on separate SQL Servers or need additional security, use Kerberos Authentication.

## ConfigMgr Integration Options

Based on the ConfigMgr hierarchy at your site, decide which of the Adaptiva Server installation locations works best for your organization. The placement of the Adaptiva Server services may vary based on the design and configuration of the ConfigMgr environment. Review the following integration options when choosing the installation location for the Adaptiva Server:

* Where can I install the Adaptiva Server?
  * Adaptiva Server on the Primary Site Server
  * Adaptiva Server on the ConfigMgr CAS only
  * Adaptiva Server on the ConfigMgr CAS and each child Primary Site Server
  * Adaptiva Server on a stand-alone server
* Where can I host the Adaptiva database?
  * Adaptiva database on the Adaptiva Server
  * Adaptiva database on the same SQL Server as the ConfigMgr database
  * Adaptiva database on a dedicated SQL Server

### Adaptiva Server on the Primary Site Server

Integrating Adaptiva OneSite and a single ConfigMgr Primary Site is the simplest configuration. In this scenario, the Adaptiva Server is installed on the same server that hosts the ConfigMgr Primary Site Server and the SQL database.

![Primary Site Server with SQL and Adaptiva](/files/lfVgowonmLA9v5b8sruy)

### Adaptiva Server on the ConfigMgr CAS only

In this configuration, the Adaptiva Server is only installed on the CAS Site Server and not the Primary Site servers. ConfigMgr clients report to their Primary sites and Adaptiva Clients on these devices report to the Adaptiva Server on the CAS. All content and deployments must be sourced at the CAS level to function properly. Adaptiva will not detect any content or deployments originating from the Primary Site servers.

> **Note**
>
> The Adaptiva OneSite Policy Bandwidth Management feature cannot detect any applicable policy changes when the Adaptiva Server is installed on the CAS only.

![Adaptiva on CAS](/files/rtJeALgeUPe1vHIixNml)

### Adaptiva Server on the ConfigMgr CAS and each child Primary Site Server

In this scenario, the Adaptiva Server is installed on the CAS and each Primary site server. Installing Adaptiva on the CAS provides visibility into policies and published content originating on the CAS. Installing Adaptiva on each Primary Site Server provides visibility for content published on the Primary as well as the ability to notify clients of policy changes. This configuration is necessary when sourcing content or deployments from any of the Primary Site servers.

Depending on how your company uses Adaptiva, the administrative overhead for this configuration may be higher than other options, because there is no hierarchy in the OneSite Platform.

![Adaptiva on CAS and children](/files/H2c6DcDkO3aR1pyl0Wcg)

### Adaptiva Server Separate from the ConfigMgr

Another option is to install Adaptiva OneSite separately from the ConfigMgr Site server with SQL Server. This option is often used when there is a security requirement to isolate applications. For example, when integrating the Adaptiva Server with ConfigMgr High Availability.

Carefully consider the placement of your database. For instance, if the SQL Server is separate, you must set up the SPNs, Kerberos, and Linked servers. See [Database Considerations](/platform-install/planning-guides/onesite-platform-planning#database-considerations).

![Adaptiva separate from ConfigMgr](/files/dn1TgKr6fSGfpmyFHqWF)

### Additional Database Considerations - Linked Servers

Because the Adaptiva Server uses a separate database, a link between the ConfigMgr database and the Adaptiva database must be created to enable cross-database reporting. The Adaptiva Server setup creates the necessary links in only one of the two scenarios below.

#### Adaptiva and ConfigMgr databases Share Same SQL Server but use Separate Instances

The Adaptiva Client setup creates two links, one in each instance linking to the other instance. The links are named using the FQDN of the SQL Server system hosting the default instance or the instance name for a named instance.

For example, if the FQDN of the server is `SQL-123.MyOrg.MyDomain.com`, and the default instance is used, then the link in the other instance is named `SQL-123.MyOrg.MyDomain.com`. If the database is in an instance named `Instance1` on the SQL-123 server, then the link in the other instance is named `SQL-123.MyOrg.MyDomain.com\Instance1`.

#### Adaptiva and ConfigMgr databases Hosted by Separate SQL Servers

Before installing the Adaptiva Server, you must manually create links in each instance of SQL Server. The linked server name on Server A must be the FQDN (including the instance name, if used) of the other SQL Server. During setup, the server checks for the existence of the link and verifies the appropriate permissions to ensure a successful installation. For additional information, see [Create linked servers (SQL Server Database Engine) (Microsoft)](https://docs.microsoft.com/en-us/sql/relational-databases/linked-servers/create-linked-servers-sql-server-database-engine?view=sql-server-ver15).

### ConfigMgr Security Settings

The Adaptiva Server requires the necessary permissions, including Site System, Content Library, Inboxes, and SQL Server, to communicate with the ConfigMgr server. No changes are required when installing the Adaptiva Server on the ConfigMgr server, and the Local System account is used.

#### Account Options

When installing the Adaptiva Server, you have the following account options to access ConfigMgr:

* Grant the Adaptiva Server access to ConfigMgr with its system account (default).
* Grant the Adaptiva Server access to ConfigMgr with a domain account.

It is not recommended to grant any accounts or groups the Full Administrator role. See the following minimum permissions:

* Download and import the custom Security role from the following location: `https://adaptiva.com/hubfs/Docs/Adaptiva%20Administrator.xml`

  > **Tip**
  >
  > You can also create a custom Security Role named **Adaptiva Administrator** based on the **Read-Only Analyst** Built-in role and modify with the permissions found in the table below.
* Add the Administrative User that was chosen to be used.
* Add the Administrative User to the Adaptiva Administrator role.
* If using custom Security Scopes, select all instances of the objects that are related to the assigned security roles.
* Add the chosen account to the Local Administrators group on the Site Server, any Server hosting the SMS Provider role and the server hosting the ConfigMgr Content Library.

#### ConfigMgr Database Account Permissions

When installing the Adaptiva Server, you have the account options below to access ConfigMgr database on the SQL Server.

**Installation Account**

The account performing the installation on the Adaptiva Server must be granted the sysadmin role on the SQL Server where the ConfigMgr database is hosted or `db_owner` on the ConfigMgr database. These permissions can be reduced after installation. See the Adaptiva OneSite Platform Installation User Guide for more information.

**Database Access Account**

The Adaptiva Server installation defaults to using the Local System account. You can change this to a local account or a domain account. A SQL account could also be used. When you integrate with ConfigMgr, you must grant the selected account the sysadmin role on the SQL Server where the ConfigMgr database is hosted or `db_owner` on the ConfigMgr database. These permissions can be reduced after installation. See the Adaptiva OneSite Platform Installation User Guide for more information.

#### Other Account Permissions

**Reporting Services Point**

The Installation will create SQL Server Reporting Services (SSRS) reports on the ConfigMgr Reporting Server if it is already configured. The ConfigMgr Reporting Services Point Account must be granted `db_datareader` to the Adaptiva database so that reports can be executed.

**Child Site ConfigMgr Database**

When using PXE, the service account that the CAS SQL database server uses requires access to the child Primary Site databases.

ConfigMgr Database Security User Mapping minimum permissions (after installation):

* `db_datareader`
* `db_datawriter`
* `db_executer`

**File Systems**

The Adaptiva Server service will require access to the ConfigMgr Content Library and Inboxes defined by the ConfigMgr Site Servers. Add the chosen account to the Local Administrators group on the respective ConfigMgr Site Server.

#### Account Permission Details

The table below lists the permissions required for any service account running the Adaptiva Server service. Follow the instructions to make these changes in SQL Management Studio.

| Server                                               | Account                                                    | Permissions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ---------------------------------------------------- | ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ConfigMgr Site Server                                | Adaptiva Server System account or Optional Service account | Local Administrators group                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| SQL Server hosting ConfigMgr database                | Installation account or Optional Service account           | <p>During installation, assign either Sysadmin or <code>db\_owner</code> to the installation account for the ConfigMgr database.<br>ConfigMgr Database Security User Mapping (optional service account) minimum permissions (after installation):<br><code>db\_datareader</code><br><code>db\_datawriter</code><br><code>db\_ddladmin</code><br><code>db\_executer</code><br></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| SQL Server hosting Adaptivadatabase                  | ConfigMgr Reporting Services Point account                 | <p>Adaptiva database Security User Mapping:<br><code>db\_datareader</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| In a CAS SQL Server hosting a child Primary database | Adaptiva Server System account or Optional Service account | <p>When using PXE, the service account that the CAS SQL database server uses requires access to the child Primary Site databases.<br>ConfigMgr Database Security User Mapping minimum permissions (after installation):<br><code>db\_datareader</code><br><code>db\_datawriter</code><br><code>db\_executer</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ConfigMgr Security                                   | Adaptiva Server System account or Optional Service account | <p>Adaptiva recommends granting the following minimum permissions:<br>\* Import the attached Security role or create a Custom Security role with the name AdaptivaAdministrator. This name is based on the default Read-Only Analyst role.For more information, see <a href="https://learn.microsoft.com/en-us/mem/configmgr/core/servers/deploy/configure/configure-role-based-administration">Configure role-based administration for Configuration Manager (Microsoft)</a>.<br>You can also use the Adaptiva Administrator.xml file to upload the permissions.<br>\* Add the following permissions:<br>- Application: Create, Delete, Modify, Modify Report<br>- Boot Image Package: Create, Delete, Modify<br>- Collection: Create, Delete, Delete Resource, Modify, Modify Collection Setting, Modify Resource<br>- Driver Package: Create, Delete, Modify<br>- Operating System Image: Create, Delete, Modify<br>- Operating System Upgrade Package: Create, Delete, Modify<br>- Package: Create, Delete, Modify, Modify Report<br>- Query: Create, Delete, Modify<br>- Site: Modify, Modify Report<br>- Software Updates: Modify Report<br>- Status Messages: Create, Delete, Modify Report<br>- Task Sequence Package: Modify Report</p> |
| Inboxes (SMS\_ share location)                       | Adaptiva Server System account or Optional Service account | <p>If this account is not in the Local Administrators group, grant Full Control to the following path:<br><code>\\\<ConfigMgrSiteServer>\SMS\_\<sitecode>\inboxes</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Content Library                                      | Adaptiva Server System account or Optional Service account | <p>If this account is not in the Local Administrators group, grant read-only permissions to the Content Library.<br>The <code>db\_executer</code> role is created in each database using the following SQL command:<br><code>CREATE ROLE db\_executer</code><br><code>GRANT EXECUTE TO db\_executer</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |

#### Record the Integration Details

When integrating the Adaptiva Server with an existing ConfigMgr Site, you must provide the necessary details to successfully connect the ConfigMgr Site Server during the Adaptiva Server installation. This integration also requires access to the SMS Provider, ConfigMgr database, Site Server inboxes, and the Content Library file system hosted by the ConfigMgr Site Server.

The Adaptiva Server installation may require configuration details such as the following:

* Collect the ConfigMgr Site Server FQDN.
* Collect the ConfigMgr three-character site code.
* Account chosen with access to the ConfigMgr Site Server components when not using Local System username and password. Domain name should be entered as Netbios name, not FQDN.
* Collect the ConfigMgr SQL Server FQDN.
* Collect the ConfigMgr Database Name.
* **Instance Name:** The default or `AdaptivaSQL` for SQL Server Express Edition.
* **SQL Server Port:** Defaults to 1433.
* Encryption status of the SQL database
* Account chosen that can access the ConfigMgr Database when not using Local System username and password. Domain name must be entered as Netbios name, not FQDN.


# Plan for Workspace ONE integration

Whether your Workspace ONE configuration includes the Adaptiva Server and AirWatch Cloud Connector (ACC) installed on the same server, two separate servers, or each component completely isolated, Adaptiva OneSite provides integration options at installation. Workspace ONE uses the ACC to contact the Adaptiva Server.

Adaptiva recommends installing the Adaptiva Server and ACC on the same server. The SQL Server is also installed on this server. This ensures platform performance and security as there is no outside network access to the Adaptiva Server with all components installed on one server.

## AirWatch Cloud Connector

Workspace ONE uses the ACC as a proxy to securely contact the Adaptiva Server by calling the Adaptiva APIs. The ACC must be installed before installing the Adaptiva Server. Install the correct version of the ACC. For more information, see [Enable AirWatch Cloud Connector from the Workspace ONE console (Omnissa)](https://docs.omnissa.com/bundle/AirWatchCloudConnectorVSaaS/page/EnableAirWatchCloudConnectorfromtheWorkspaceONEUEMconsole.html).

## ACC Account and Permissions

Grant Adaptiva the ACC permissions to integrate the Adaptiva Server with Workforce ONE during the server installation.

| Permissions | Account                  | Permission                                                                                                                                                                                                                                                                                                                                |
| ----------- | ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ACC         | AirWatch Service Account | <p>Local Administrators group<br>Minimum permissions:<br>Registry Full Control access to the following paths:<br>- <code>HKLM\Software\Adaptiva</code><br>- <code>HKLM\Software\Microsoft\SystemCertificates</code><br>File System Read access for the following Adaptiva DLLs file path:<br>- <code>C:\Program Files\Adaptiva</code></p> |

## ACC Integration Options

Based on the security requirements for your site configuration, decide which of the integration options below works best for your organization. In all cases, Workspace ONE requires the ACC installed on a server to communicate with the Adaptiva Server.

* Adaptiva Server, the ACC, and the Adaptiva Server on the same server.
* Adaptiva Server is separate from the ACC.
* Adaptiva Server, the ACC, and the SQL Server are each on separate servers.

### Adaptiva Server and the ACC on the same server

In this example, integrating the ACC and the Adaptiva Server on the same server is the simplest configuration and eliminates any network communications between the components.

![AirWatch Cloud Connector co-hosted](/files/NluEg00Dc21yUw8H9hZM)

### Adaptiva Server separate from the ACC

In this example, the Adaptiva Server and the ACC are installed on different servers. This configuration is often with SQL Server Express installed with Adaptiva.

![AirWatch Cloud Connector separate from Adaptiva](/files/fiTgNSbfu1oacUwvRdSh)

### Adaptiva Server, the ACC, and the SQL Server each on separate servers

In this example, the `AdaptivaServerSetup.exe`, SQL Server, and ACC are completely separated, with each component installed on a different server. This enables the database administration team to maintain all databases on managed servers. This also provides for the use of Always On Availability Groups to cluster the SQL servers.

![AirWatch Cloud, Adaptiva, SQL on separate server](/files/izxiUn0nMwE87PaUIkS6)

## Setting up the ACC

Enable the ACC in the Workspace ONE console, and then download the VSEC certificate to a designated installation path.

### Install the ACC

1. If the ACC is already installed, navigate to the following file path to open the log file **CloudConnect.log**:

   `%InstallPath%\Airwatch\Logs\CloudConnector`
2. Search for **Starting CloudConnector**. The ACC must be version **19.7.0.0** or later.
3. If the ACC is not installed or if the ACC version is older than 19.7.0.0, open the Workspace ONE UEM console and navigate to **Groups & Settings | All Settings | System | Enterprise Integration | Cloud Connector**.
4. Select **Download AirWatch Cloud Connector Installer**.
5. Select **Open File** after the download has completed to start the installation.
6. In the UEM console, select **Test Connection** to verify if the ACC is active.

### Download the vSEC Certificate

1. Open the Workspace ONE UEM console, and navigate to **Groups & Settings | All Settings | System | Enterprise Integration | Peer Distribution | Adaptiva**.
2. Select the **Download vSEC Certificate** link to download the certificate to a location on your computer. This will be used later.

   ![Download vSEC Certificate](/files/3Ab2l9ovEROaHauJqlUL)

### Adaptiva Certificate for Workspace ONE Installation

After the Adaptiva Server setup is complete, you must return to the Workspace ONE UEM console to upload the Certificate on the **Adaptiva Peer Distribution Software Setup** page. Adaptiva automatically generates the `AdaptivaServer.cer` file and downloads it to a location on your computer during the Adaptiva Server installation.

### Adaptiva APIs

The ACC communicates with the Adaptiva Server by calling the **Adaptiva APIs**. The ACC requires access to the Adaptiva DLLs to call the Adaptiva APIs. The `.dlls` act as a shared library of content that allows multiple components simultaneous access. Adaptiva recommends installing the `.dlls` on the server hosting the ACC.

#### Install the DLLs

1. Locate the Adaptiva installation files from downloaded `.zip` file.
2. Copy the file `AdaptivaWorkspaceONEACCInstaller.exe` from Installers or Windows to the ACC.
3. Right-click on the `AdaptivaWorkspaceONEACCInstaller.exe`, select **Run as an administrator**, and then select **Yes** (if prompted).

   ![Run Adaptiva Workspace ONE ACC installer](/files/q2PZ5t1pmjBLV1OexymU)
4. This opens the **Installs Adaptiva DLLs To The Workspace ONE AirWatch Cloud Connector (ACC)** dialog. The current installation status appears on the dialog.

   ![Install Adaptiva DLLs](/files/vlbgh7aBcoUgyMHu41JE)
5. Select **Install**, and then select **Yes** on the **Are You Sure You Wish To Install Adaptiva DLLs?** dialog.
6. Select **OK** on the **Installation Was Successful** dialog.

You are now ready to install the Adaptiva Server and integrate it with Workspace ONE.

#### Record the Location Details

* Record either the FQDN or the internal IP address of the Adaptiva Server.
* Record the location of the downloaded vSec certificate.
* Record the location of the Adaptiva Server certificate, which defaults to the following path:

  `<path>\Adaptiva\Adaptiva Server\data\security`


# OneSite platform installation

Intro page for OneSite platform

This guide explains how to install the Adaptiva Platform components, which includes the Adaptiva server service and the Adaptiva Client agent. The installation is the same for all Adaptiva products (like OneSite Patch) since they are built upon the Adaptiva Platform. The server setup process installs components shared between OneSite Anywhere, OneSite for ConfigMgr, OneSite for Intune, OneSite for Workspace ONE, OneSite Patch, OneSite Health, and OneSite Wake. You can enable these products simply by adding the appropriate license key in the Admin Portal.

## Install the OneSite Platform

The Adaptiva Server will be installed first (which will include the Adaptiva Client on the server), followed by the workbench and finally, the endpoint devices.

* [Prerequisites](/platform-install/server-install/install-platform-prerequisites)
* [Install the OneSite Platform](/platform-install/server-install/install-platform)
* [Client installation](/platform-install/client-install-and-uninstall/client-install)

### Additional configuration

Some additional configuration may be required depending on your network topology or SQL configuration.

* [Network and connectivity requirements](/platform-install/additional-configuration/platform-communication-ports)
* [SPNs and Delegation](/platform-install/additional-configuration/platform-spns-delegation)
* [Optional Answer File](/platform-install/server-install/install-platform/install-platform-answer-file)

### Uninstall the OneSite Platform

The products also uninstall cleanly and leave no files or database entries behind.

* [Uninstall the Adaptiva Server](https://github.com/AdaptivaDocs/docs/blob/main/platform/install-guide/uninstall-adaptiva-server.md)
* [Uninstall client](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-uninstall)


# Platform pre-requisites

Installation pre-requisites

Review the [Planning Guide](https://docs.adaptiva.com/platform-install/planning-guides/onesite-platform-planning) prior to installation.

The OneSite Platform installation requires two files from the **Installer\Windows** folder:

`adaptiva-server-<version>-windows.exe`

`adaptiva-client-<version>-windows.exe`

The server needs to install the server and client files in order to communicate effectively with client devices. However, the client installed on the server does not operate in the same way as a client installer on a client device and does not participate in peer-to-peer sharing.

{% hint style="info" %}
The `<version>` placeholder refers to the downloaded version of the executable.

All components require local administrator privileges to install.
{% endhint %}

## Verify connectivity

Please refer to the [communication port requirements](/platform-install/additional-configuration/platform-communication-ports) and ensure your server has proper communication with cloud services.

In the case of a SQL Server Express Edition installation, your server will need to connect to **.adaptivacdn.cloud** to download SQL Express.

## Verify user permissions

When using an existing SQL Server installation, the user performing the server installation **MUST** have **sysadmin** permissions in the SQL Server that will host the Adaptiva database.

When integrating with Configuration Manager, the user must have permission to the Configuration Manager Site and file server, as well as sysadmin permissions in the SQL Server hosting the ConfigMgr database.

These permissions are only required for the setup and can be reduced after successful installation. You can review the [Account Permissions](/platform-install/planning-guides/onesite-platform-planning#account-permissions) section of the Planning guide for additional information.

## Database Reporting Account

Starting in Build 8.3, you will need to create a database reporting account to ensure that the Adaptiva Server is operating at the highest level of security for your SQL Server environment. All data providers in the Adaptiva Server will use this account to query the Adaptiva database. The account will only be granted `db_datareader` permissions, ensuring that the account cannot change any data in the Adaptiva database or any other database hosted on the database server.

> NOTE: A domain account is recommended for use as the database reporting account.

> IMPORTANT: When SQL Server is remote from the Adaptiva Server, the installation will only be able to use a domain account. If a SQL account is required, open a support ticket.

When you install Adaptiva Server, the install will automatically grant permissions to the specified account.

## SQL Express

If selecting SQL Express Edition during installation, see the following pre-requisites

### Internet Access

If selecting SQL Express Edition during installation, the server must be able to connect to the internet to download Microsoft SQL Server Express Edition. This is only required if Express Edition will be installed during the Adaptiva Server installation.

If using the Cloud Edition, the Adaptiva Server must also be able to reach `http(s)://services.adaptiva.cloud`.

### SQL Express pre-installed

If SQL Express has been installed beforehand, make sure the following configuration changes have been made.

#### TCP/IP connections must be enabled

1. Open SQL Server Configuration Manager.
2. Expand **SQL Server Network Configuration** (not 32-bit), and select **Protocols for MSSQLSERVER** or the Instance name used.
3. Enable **TCP/IP** if not already.
4. Enable **Shared Memory** but Named Pipes can stay Disabled.

#### Enable SQL Server Browser

1. Select **SQL Server Services**.
2. Right-click **SQL Server Browser** and select **Properties**.
3. Confirm the Log on as setting is for **Local Service**.
4. Click **Start**.

#### Grant Local System account Sysadmin role

You can reduce account permissions after installation.

1. Install SQL Server Management Studio.
2. If the account does not exist under **Security | Logins** run the following T-SQL command:

   ```sql
   CREATE LOGIN [NT AUTHORITY\SYSTEM] FROM WINDOWS WITH DEFAULT_DATABASE=[master], DEFAULT_LANGUAGE=[us_english];GO
   ALTER SERVER ROLE [sysadmin] ADD MEMBER [NT AUTHORITY\SYSTEM];GO
   ```

## SQL permissions

If SQL Express Edition will NOT be used, then prior to installing the Adaptiva Server, the installation account (and service account, if planned to use) and the Adaptiva Server SYSTEM account must be granted sysadmin permissions in SQL, to allow the creation of the Adaptiva database and the connections to the ConfigMgr database if that is being used. Once the installation is complete, these permissions can be reduced for day-to-day operations if required.

### Pre-Install Instructions

1. In **SQL Management Studio** object explorer, expand the **Security** folder, right-click the **Logins** folder and select **New Login...**
2. Click on **Search...**, then ensure the Location is set to the domain and enter the username of the account performing the installation or will be the service account, click on **Check Names**, then **OK**
3. Select the **Server Roles** page and check the box for the **sysadmin** role.

   ![](/files/KOvrMxWxRt4gH9qijKDY)
4. Click **OK** to add the login.

### Additional prerequisites for ConfigMgr

1. Using **SQL Management Studio**, expand the **Security** folder and select **Properties** for the installation and/or service account
2. Select the **User Mapping** page, in the **Users mapped to this login** section, check the box next to the name of the ConfigMgr database and in the Database role membership section, check the box for the **db\_owner** role

   ![](/files/tg1EciEqAK1YpWgxwvyY)
3. Click **OK**

## Workspace ONE

The following steps must be completed before starting the Adaptiva Server installation. There are also post-installation steps that will need to be completed.

### Install/Update the Cloud Connector

The AirWatch Cloud Connector (ACC) component must be installed before installing the Adaptiva Server. Make sure it is the proper version. For instructions on this, see the [omnissa Workspace ONE documentation library](https://docs.omnissa.com/bundle/AirWatchCloudConnectorVSaaS/page/EnableAirWatchCloudConnectorfromtheWorkspaceONEUEMconsole.html).

1. If the ACC is already installed, open the log file **CloudConnect.log** in *%InstallPath%\Airwatch\Logs\CloudConnector*.
2. Search for *Starting CloudConnector*. The version should be **19.7.0.0** or later.
3. If it is not 19.7.0.0 or later, open the Workspace ONE UEM console and navigate to: **Groups & Settings** | **All Settings** | **System** | **Enterprise Integration** | **Cloud Connector**. Select **Download AirWatch Cloud Connector Installer** and install.
4. Click on **Test Connection** and validate the **AirWatch Cloud Connector is active**.

### Download the Certificate

Download the vSEC certificate for the current instance of Workspace ONE.

1. Open the Workspace ONE UEM console and navigate to: **Groups & Settings** | **All Settings** | **System** | **Enterprise Integration** | **Peer Distribution** | **Adaptiva**

   ![](/files/yxZdntrmsKquRRSRutLn)
2. Click the link to **Download vSEC Certificate** and store it in a convenient location as it will be needed later. Return to this page after the installation of Adaptiva to upload the Adaptiva certificate and provide the name or IP address of the Adaptiva server.

### Installing the Adaptiva APIs

The ACC will require access to Adaptiva DLLs in order to call the APIs provided by Adaptiva. To install these on the server hosting the ACC follow these steps:

1. Navigate to the Adaptiva Installation source folder
2. Run the **AdaptivaWorkspaceONEACCInstaller.exe** as an administrator and click Yes if prompted

   ![](/files/rTk6qKR7slX3qYMmfZQj)
3. On the **End-User License Agreement** screen click **Accept**

   ![](/files/S12ABlEK5FkRDPohb7QQ)
4. The dialog will show current installation status, click **Install**

   ![A screenshot of a computer AI-generated content may be incorrect.](/files/HT279xSHhAQgXA0Vp59A)
5. When prompted: **Are You Sure you Wish To Install Adaptiva DLLs?**, click **Yes**
6. When prompted that the **Installation Was Successful**, click **OK**


# Platform install

Guidance on how to install the OneSite Platform.

These instructions are for On-Premises installations. Please see our [OneSite Cloud Portal](https://docs.adaptiva.com/cloud), for more information regarding our SaaS solution.

Adaptiva provides the installation files in a compressed (.zip) file. The latest version can be downloaded from the [Support Portal](https://support.adaptiva.com/hc/en-us).

![](/files/fuwUlFMpyluPgg0zQxVp)

The Zip file is password protected, please see instructions on the build page for more information.

The compressed file includes three folders.

* **Documentation** - Includes links to our docs site and a .pdf of Cumulative Release Notes.
* **Installers** - Server installer for the Platform in addition to client installers for both Windows and cross-platform.
* **Tools** - This folder contains tools used to troubleshoot issues under the advisement of our Support team.

## Installation Types

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-rocket">:rocket:</i></td><td><strong>Quick Install</strong></td><td>This is the best option for most environments. Quick Install will automatically download and configure SQL Server 2022 Express Edition and then install the Adaptiva Server with default options and a self-signed certificate.</td><td></td><td></td><td><a href="/pages/3dMQc0HSPRRspXrG8AvS">/pages/3dMQc0HSPRRspXrG8AvS</a></td></tr><tr><td><i class="fa-cubes">:cubes:</i></td><td><strong>Advanced Install</strong></td><td>If you are using an existing SQL Server Standard / Enterprise Edition or need to use a CA-based certificate, then perform an advanced install. This will allow you to customize all server installation settings.<br><br>You will also need to pre-create an account used for reporting access on the Adaptiva SQL database.</td><td></td><td></td><td><a href="/pages/aPLrZnBWhTUVeAE5bewl">/pages/aPLrZnBWhTUVeAE5bewl</a></td></tr><tr><td><i class="fa-plug">:plug:</i></td><td><strong>(Optional) Answer File</strong></td><td>An answer file can be created to automate the installation of the OneSite Platform server. The executable must be run with administrative privileges. The answer file can only be created when the Adaptiva Server has not been previously installed.</td><td></td><td></td><td><a href="/pages/EapUPcjCADcNKjH5HhFD">/pages/EapUPcjCADcNKjH5HhFD</a></td></tr></tbody></table>


# Quick Install

The Quick Install option will install the Adaptiva Server using default settings and *SQL Server Express Edition*. Configure your installation settings and add your license key to begin the OneSite Platform server installation.

{% hint style="warning" %}
Do not install Adaptiva Server on the Operating System (OS) C: drive. The OneSite product log files and the Adaptiva Content Library installed with the Adaptiva Server grow over time, which impacts storage and performance on the OS C: drive. The installer will prompt you to change the destination drive if you continue to install on the boot drive.
{% endhint %}

## Installation Wizard

1. Right click `adaptiva-server-<version>-windows.exe`, and then select **Run as administrator**.

   ![Server Install](/files/JxMG3zwQ0ckOSP5PskvC)
2. Click **Browse** to navigate to and select the installation folder to a drive other than the C drive.

   * If you continue with installation on the C: drive, you will see a warning dialog. Click **Yes** to ignore this warning if you still want to install on the C drive.

   ![Install Target Warning](/files/IluQi5am16e5QdeqrCrE)
3. Configure your **Superadmin Login ID and Password**.
   * **Use Windows Login**: This option will use either your current logged in account or one that you specify with your Windows credentials.
   * **Use Custom Login**: This option allows you to supply an email address and password to create a server login. The email address is a username and does not need to be a valid email address.
4. Enter one or more license keys, separated by semicolons.
5. The following items are checked by default:
   * **Create an Add/Remove Programs Entry**: The Adaptiva Server Installer will create an entry for OneSite Platform in **Windows Settings > Apps & Features**.

     ![](/files/QsEtTDsJDzLqptzixPGo)
   * **Add a Windows Firewall Exception for Server Application**: The Adaptiva Server Installer will add local exceptions in the Windows firewall for the default server ports (See [Communication Ports](https://adaptiva.com/hubfs/Docs/OneSite-Port-Detail.pdf)).
   * **IMPORTANT**: Review any existing domain-based group policies (GPO) that configure or restrict Windows firewall rules or rule creation as they can prevent or override these Adaptiva-created firewall exceptions.
6. Click **Quick Install**.

   ![Quick Install Dialog](/files/LFeZk4gt3jPrLLbZwfXQ)
7. Read the Quick Install Behavior prompt and click **Proceed**.
   * The wizard will download and install SQL Server 2022 Express Edition. SQL Express will be installed and configured to use a SQL native reporting account. The Adaptiva Server will then be installed with default options using port *443* and a self-signed certificate for access to the Admin Portal.

     ![Server Install Progress](/files/UFvLtIOtvo2yfaRsVeGX)
8. When the installation is completed, click **Next**.

   ![Post-Install Verification](/files/llPdlz1vaxeQmAkNVt7T)

   The wizard will perform a series of Post-Installation Verifications to validate the installation. The installation will skip some checks when not integrated with Microsoft Configuration Manager.
9. Click **Done**.

   After the installation of the OneSite Platform server, you must install the Adaptiva client on this machine as well. Continue with [Client Installation on the Server](/platform-install/server-install/install-platform/install-platform-server-client-install).


# Advanced Install

How to install the Adaptiva Server with Advanced Install settings.

The advanced install option will allow you to customize the installation options for OneSite Platform, including using an existing SQL Server instance.

{% hint style="warning" %}
Do not install Adaptiva Server on the Operating System (OS) C: drive. The OneSite product log files and the Adaptiva Content Library installed with the Adaptiva Server grow over time, which impacts storage and performance on the OS C: drive. The installer will prompt you to change the destination drive if you continue to install on the boot drive.

This also applies to the SQL Server 2022 Express Edition installation.
{% endhint %}

## Configure Installation settings

Configure your installation settings and add your license key to begin the Adaptiva Server setup process.

1. Right click `adaptiva-server-<version>-windows.exe`, and then select **Run as administrator**.

   ![Server Install](/files/t2gfyEd9JHnMBrtD9ITR)
2. Click **Browse** to navigate to and select the installation folder to a drive other than the C drive.

   * If you continue with installation on the C: drive, you will see a warning dialog. Click **Yes** to ignore this warning if you still want to install on the C drive.

   ![Target Disk Warning](/files/ycgr6SjQ6OzDBTF5bX7u)
3. Configure your **Superadmin Login ID and Password**.
   * **Use Windows Login**: This option will use either your current logged in account or one that you specify with your Windows credentials.
   * **Use Custom Login**: This option allows you to supply an email address and password to create a server login. The email address is a username and does not need to be a valid email address.
4. Enter one or more license keys, separated by semicolons.
5. The following items are checked by default:
   * **Create an Add/Remove Programs Entry**: The Adaptiva Server Installer will create an entry for OneSite Platform in **Windows Settings > Apps & Features**.

     ![](/files/QsEtTDsJDzLqptzixPGo)
   * **Add a Windows Firewall Exception for Server Application**: The Adaptiva Server Installer will add local exceptions in the Windows firewall for the default server ports (See [Communication Ports](https://adaptiva.com/hubfs/Docs/OneSite-Port-Detail.pdf)).
   * **IMPORTANT**: Review any existing domain-based group policies (GPO) that configure or restrict Windows firewall rules or rule creation as they can prevent or override these Adaptiva-created firewall exceptions.
6. Click **Advanced Install**.

### Configure TLS Security Settings

TLS Security Settings will be used to secure the Admin Portal. The [Deployment Planning Installation Guide](https://docs.adaptiva.com/platform-install/planning-guides/onesite-platform-planning#security-certificate-options) provides details about Certificates.

![TLS Security Settings](/files/j99Z3FDHH0Hixwuu0sT6)

1. Select one of the following **TLS security Settings**:
   * **TLS Using A Certificate Authority (CA)**: use a certificate you exported from a Certificate Authority:
     1. Click to select **Install A CA-Issued X.509 Certificate**.
     2. Click **Browse** and navigate to the location of the exported **Certificate PEM File**.
     3. Click **Browse** and navigate to the location of the exported **Private Key PEM File**.
   * **TLS Using Self-signed Certificate** (default): use a self-signed certificate.
     1. Click to select **Create A Self-signed X.509 Certificate**.
     2. Enter the **names or IP address** associated with the Adaptiva server that will host the Adaptiva Admin Portal. Include any server details for NETBIOS, FQDN, DNS Alias or IP Address. Separate each entry with a comma.
2. Set the **Web UI Port** used by the Admin Portal. This defaults to port *443*, but if other services are using that port, we suggest that you use port **9678**.
   * **IMPORTANT**: Be sure to share this port with all OneSite Administrators. It is required to access the Admin Portal.

#### Optional: Configure HTTP Proxy Configuration

If you are using an HTTP Proxy to route internet traffic, click **HTTP Proxy Configuration**.

1. Select your proxy configuration.

   ![HTTP Proxy Configuration](/files/X0O1fKQrsraOErhspyNA)

   * **Don't Use an HTTP Proxy**: no proxy settings will be configured.
   * **Prefer User Proxy Configured on the System**: a locally configured proxy will be configured.
   * **User a Proxy Auto-Configuration (PAC) File**: supply the URL to your PAC file.
   * **Use an HTTP Proxy Server**: supply the protocol, FQDN/IP of the proxy server, the port configured and a bypass list of semi-colon separated host names or IP addresses.
2. Click **OK**.

### Expected Client Count

1. Set the expected Adaptiva Client Count. Use the number determined from the Design Planning. The **Expected Total Number Of Adaptiva Clients** defaults to **5000**, which automatically sets the **Maximum Data Memory Buffer Size** to **2048 MB**.
2. Click **Next**.

### (Optional) Integrate 3rd party products

This installation dialog box provides third-party integration options for Microsoft ConfigMgr and Omnissa Workspace ONE.

* If you select **Integrate an Existing Microsoft ConfigMgr Site**, continue with [Integrate with ConfigMgr](/platform-install/server-install/install-platform/install-platform-advanced-install/install-platform-advanced-integrate-configmgr).
* If you select **Integrate With Workspace One**, continue with [Integrate with Workspace ONE](/platform-install/server-install/install-platform/install-platform-advanced-install/install-platform-advanced-integrate-workspaceone).

If you do **NOT** select an integration, continue with the Configure the SQL Database steps below.

### Configure the SQL Database

You can choose to install the SQL database on a new instance of SQL Express or an existing instance on a SQL 2017 or later server.

* If you select **Download and install free Microsoft SQL Express and auto-create database**, continue with [Option 1: SQL Express Installation](#option-1-sql-express-installation).
* If you select either **Create the database in ana existing SQL Server Instance** or **Create the database in the same SQL instance as ConfigMgr Site Database**, click [Option 2: Existing SQL Instance](#option-2-existing-sql-instance).

#### Option 1: SQL Express Installation

1. Select **Download And Install Free Microsoft SQL Express And Auto-create Database** and click **Next**.

   ![SQL Database Options](/files/fdzADbimJ476V4eOvGEI)
2. Click **Next**.
3. At the SQL Express Settings screen enter where the SQL Server Express installer should be downloaded to and where SQL Server Express will be installed

   ![SQL Express Settings](/files/HiEYuHavby138jup5uzY)

   * **Download Folder:** the folder where the SQLExpr\_x64\_ENU.exe will be downloaded.
     * You can pre-download SQLExpr\_x64\_ENU.exe. Click Browse and navigate to the executable.
   * **Installation Folder:** the folder where SQL Server 2022 Express Edition will be installed. Change the drive letter of the **Installation Folder** to a drive other than C.
4. Click **Next**.
5. Continue with [**Read-Only SQL Login For Reporting**](#read-only-sql-login-for-adaptiva-reporting).

#### Option 2: Existing SQL Instance

1. Select either **Create The Adaptiva Database In An Existing SQL Server Instance** or **Create the Database in the same SQL Instance as ConfigMgr Site Database** and click **Next**.

   ![SQL Database Options](/files/QdWbUiijWfHjNJyFE8DN)
2. You will be prompted to confirm that your system meets the SQL Server pre-requisites:

   ![SQL Prerequisites](/files/3TN2inemjADpwiDXfZE7)
3. Click **Continue**.
4. On the **Database Information** page, enter your SQL Server information.

   ![Database Information](/files/uN8BzhCLSUATkG93P3Ih)

#### Database Information

1. Select **SQL Instance Is Encrypted** if the SQL Server Instance is using encryption s.
2. If the **Default SQL Instance** is not used, uncheck the box and enter the **SQL Instance name**.
3. If the **Default SQL Port** is not used, uncheck the box and enter the **SQL Port**.

#### SQL Login

1. Enter the **SQL Server Machine Name** FQDN.
2. Select or enter a SQL account.
   * (Recommended) Select **Use Adaptiva Server's Local System Account**.
     * If you choose not to use the Local System Account, enter the NETBIOS Domain name, User Name and Password of the account with sysadmin permission in the SQL Server that will host the Adaptiva database.
   * If the account specified is a SQL account, uncheck **Use Windows Authentication**.
3. Click **Next**.
4. If the account specified is different from the login account used for the service SQL Server (*MSSQLSERVER | InstanceName*) a dialog box will prompt you to verify the account used by the SQL Service.

   ![Account Warning](/files/cGzYpKrDV1d6lbTOgkcy)
5. Click **Yes** if the settings are correct, otherwise, click **No** and update the settings.
6. At the Windows Authentication Protocol for SQL dialog, select the authentication method that will be used to connect to the SQL database.

   ![SQL Authentication Protocol](/files/7cMIZNO0qsFzFRJmfj7U)

   * **NTLM v2** is selected by default.
   * If you require extended protection with SQL, you can select **Kerberos (Requires SQL SPN)**. To support Kerberos authentication, Service Principal Names (SPNs) must be created and delegated properly in Active Directory. For more information, please see our [SPNs and delegation](https://docs.adaptiva.com/platform-install/additional-configuration/platform-spns-delegation) page on how to create SPNs and delegate Kerberos authentication.
7. Click **OK**.
8. When the SQL Server hosting the Adaptiva database is different from the SQL Server hosting the ConfigMgr database, a message will be displayed.

   ![Linked SQL Servers](/files/YRNMFhriRSm1oaWCOQqm)

   * Be sure the Linked Servers are created before continuing and then click **OK**. For more information see [Create the Linked Servers](/platform-install/additional-configuration/platform-spns-delegation#create-the-linked-servers).

### Read-Only SQL Login For Adaptiva Reporting

Provide a SQL login for reporting.

![SQL Reporting Login](/files/R4yKVTbVxoYxFlguOx9h)

1. Enter the account information to be used for reporting:
   * **Use Windows Authentication** -- This box will be checked and greyed out Windows Authentication mode has been specified in the local SQL Server.
   * **Domain Name** -- Enter the NETBIOS domain name used for the reporting account. Leave blank if *Use Windows Authentication* is unchecked and a SQL Login account is to be used.
   * **User Name** -- Enter the account name created for use as the reporting account.
   * **Password** -- Enter the password for the reporting account.
   * **Confirm Password** -- Confirm the password that you entered above.
     * **IMPORTANT**: When SQL Server is remote from the Adaptiva Server, the installation will only be able to use Windows authentication. New Installations using SQL Express that did not use Quick Install will also be required to create an account and use Windows Authentication.
2. Click **Next**.

### Completing the Installation

1. The installation will begin.

   ![Install Success](/files/LEAnYw0eO366fASE1WBA)
2. When the installation is complete, click **Next**.

   ![Post-Install Verification](/files/FojL9z8bvkzCPZrptcBN)

   * The wizard performs a series of Post-Installation Verifications to validate the installation. The installation will skip some checks when not integrated with Microsoft Configuration Manager.
   * **NOTE:** There is a known issue when the Kerberos authentication protocol is selected for the Adaptiva database: The **Read-Only Account Write Access Denied** will report **Failed**. This can be ignored.
3. Click **Done**.

After the installation of the OneSite Platform server, you must also install the Adaptiva client agent onto this machine.

For instructions on how to install the client on the sever machine, please see our [Client Installation on the Server](/platform-install/server-install/install-platform/install-platform-server-client-install) page.

### Server Installation Logs

In the case where an administrator needs to troubleshoot an Adaptiva Server installation, the following table contains the installation log locations. Other logs exist in the installation folder.

| Function                 | Log Location and Name                                                                                                            |
| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------- |
| Server Installation Logs | <p>%windir%\AdaptivaSetupLogs\Server\AdaptivaServerSetup.log<br>%install\_path%:\Adaptiva\AdaptivaServer\logs\Adaptiva\*.log</p> |
| Client Installation Log  | <p>%windir%\AdaptivaSetupLogs\Client\AdaptivaClientSetup.log<br>%install\_path%:\Adaptiva\AdaptivaClient\logs\*.log</p>          |

Access Server logs by navigating to **Settings** > **Logs** in the Admin Portal, or by navigating to the following location:

`<path>\Adaptiva\Adaptiva Server\Logs`

{% hint style="info" %}
OneSite Patch SaaS tenant logs can only be accessed by navigating to **Settings** > **Logs** in the Admin Portal.
{% endhint %}

The following options are available on the **Logs** page:

* **Download All Server Logs:** Downloads all Server logs, including component and workflow logs.
* **Download Server Error Logs:** Downloads Adaptiva Server error logs.
* **Clear Web Logs:** Clears all Admin Portal runtime information and errors recorded by the browser session.
* **Download Web Logs:** Downloads all Admin Portal runtime information and errors recorded by the browser session.


# Integrate Configuration Manager

(Optional)

On the Site Server Information screen, provide the information for the ConfigMgr Site Server that will integrate with the Adaptiva Server. This integration requires access to the SMS Provider, ConfigMgr database, Site Server inboxes, and the Content Library file system hosted by the Site Server.

1. Click to select **Integration with an existing Microsoft ConfigMgr Site** and click **Next**.
2. Enter the Site Server details using the information gathered during Deployment Planning:

   ![Site Server Info](/files/zE81FaINLzHigrgmL58E)
3. Enter the **Machine Name** (FQDN) and 3-character **Site Code** of the ConfigMgr site server.
4. Enter the ConfigMgr Site Login details gathered during Deployment Planning.

   We recommend using the default **Use Adaptiva Server's Local System Account** login. This is the simplest method of authentication of an Adaptiva Server connection with ConfigMgr.

   > **Note**: If the Adaptiva Server is not co-located with the ConfigMgr Site Server you must grant the Adaptiva Server's computer object the necessary permissions in Configuration Manager.

   If you choose not to use the Local System Account, enter the **Domain** (NETBIOS Domain name), **User Name** and **Password** for the domain account that has been granted the necessary permissions in Configuration Manager
5. Click **Next**.

**ConfigMgr Site Database Information**

On the Site Database information screen, provide the database information for the ConfigMgr Site Server that will integrate with the Adaptiva Server.

1. The Site Database fields will auto-populate from the settings obtained by the logged in user's permissions to the ConfigMgr Site Server. You can update the SQL Login information that you gathered during Deployment Planning.

   ![Site Database Info](/files/nvl4auVuEOklYMbaq6e3)
2. Review the Site Database details and configure any additional settings:

   **Machine Name:** the FQDN of the ConfigMgr SQL Server.

   **Database Name:** the ConfigMgr database name.

   If the SQL Server Instance is using encryption, click to select **SQL Instance Is Encrypted**.

   **SQL Instance Name**: the SQL instance name.

   **SQL Port**: the SQL port.
3. Review the SQL Login details and configure any additional settings:

   **Reuse Login Settings That Were Specified For Site Server Login** is selected by default.

   If you choose not to use the Local System Account, uncheck this box and uncheck **Use Adaptiva Server's Local System Account**.

   Enter the **Domain** (NETBIOS Domain name), **User Name** and **Password** for the domain account that has been granted the sysadmin permissions in SQL Server hosting the ConfigMgr database.

   If the account specified is a SQL account, uncheck **Use Windows Authentication**.
4. Click **Next**.

   If the account specified is different from the login account used for the service SQL Server (MSSQLSERVER | InstanceName) a warning will be displayed showing the account used by the SQL Service.

   ![Account Warning](/files/soARzo9n2sSeZzq2G4ld)
5. Review the warning and if the settings are correct, click **Yes**, otherwise, click No and update the settings.
6. At the SQL Authentication Protocols dialog, select the authentication method that will be used to connect to the ConfigMgr Site database.

   ![SQL Authentication Protocols](/files/3JTP5MI5G708z8BAQqqC)

   **NTLM v2** is selected by default when the ConfigMgr and Adaptiva databases are hosted on the same SQL server.

   Select **Kerberos (Requires SQL SPN)** when the ConfigMgr and Adaptiva databases are hosted on different SQL servers or additional security is required. To support Kerberos authentication, Service Principal Names (SPNs) must be created and delegated properly in Active Directory. See Appendix B in this document.
7. Click **OK**.

**Specify Login Information for Accessing Site Server Files**

The **Login Information For Access To the Site Server's File System** screen allows you to specify an account that has the necessary permissions to access the Site Server's file system. Specifically, this account must be able to access the inboxes and the Content Library. Review the table of permissions required in the Deployment Planning Guide for ConfigMgr for potential actions required for this account.

1. At the **Login Information** screen, enter information to access the ConfigMgr file system.

   ![Login Info](/files/cxiHzfwmr9aiCYpJEOYO)

   **Reuse Login Settings That Were Specified For Site Server Login** is the default. Uncheck this box to specify an account.

   If you choose not to use the Local System Account, enter the **Domain** (NETBIOS Domain name), **User Name** and **Password** for the domain account that has been granted the necessary permissions in Configuration Manager.
2. Click **Next**.
3. Continue with [Configure the SQL Database](/platform-install/server-install/install-platform/install-platform-advanced-install#configure-the-sql-database).


# Integrate Workspace ONE

1. Click to select **Integrate with Workspace ONE** and click **Next**.
2. At the **Please** **Specify Workspace ONE Settings** screen complete the following information:

   ![Workspace ONE Settings](/files/rHIybwEzAun46m14UGdD)

   **Certificate Location**: enter the path or browse to the location of the downloaded ACC certificate.
3. Record the location where the **Adaptiva Server Certificate For Workspace ONE** will be located after a successful installation: By default, this is **%*****InstallPath*****%\Adaptiva\AdaptivaServer\data\security**. The file will be called **AdaptivaServer.cer**.
4. Click **Next**.


# Install Client on Server

1. After the Adaptiva Server is installed, the Adaptiva Client must be installed on the server. At the **Launch Adaptiva Client Installer** dialog, the Client Installer Path will be displayed based on the relative path the server component was installed from.
2. Click **Launch** to begin the Client installation.

   ![Client Installer](/files/YjN9o9Fk4UxwO5Fqbxcz)
3. At the **Adaptiva Client Installer** dialog, complete the following

   ![Client Install](/files/xStCWDWAabdZ8P3wj1Xs)

   **Adaptiva Install Path:** Update the path as required. We recommend installing the Adaptiva client in the same parent folder as the Adaptiva Server (**%drive%:\Program Files\Adaptiva\AdaptivaClient**).

   The installer will auto-populate the **Server Host Name or IP Address** and **Server GUID** fields.
4. Click **Install**.
5. When the installation is completed, the Client Validation Checks application will confirm the connectivity requirements for the Adaptiva client.

   ![A screenshot of a computer error AI-generated content may be incorrect.](/files/Mw2xX5Wow1zfu2cLKjUq)

   The **Client to Client** and **Cloud Relay Connection** check is not applicable for a server installation.
6. Click **OK**.


# Add a License

Add A License Key

{% hint style="info" %}
During installation you have the option to add license keys from the installer wizard. However, if you skipped that step or want to add additional keys, you can follow the steps below to add them from the Adaptiva Admin Portal
{% endhint %}

After the Adaptiva Server setup is complete, enable one of the evaluation licenses or install your Adaptiva-provided license key to enable the product. This will activate the product and prepare to license clients. License keys can only be added via the Adaptiva Admin Portal.

1. In a web browser, enter the Adaptiva Server Admin Portal URL: `https://AdaptivaServerFQDN[:Port]`.
2. At the Adaptiva Web Portal, click **Log in with Active Directory**. If an Adaptiva login account was created, enter the email address and password created during installation and click **Log in**.

   * If you are using Mozilla Firefox, see Resolve the [Mozilla Firefox Active Directory Login Issue](https://support.adaptiva.com/hc/en-us/articles/37109022499341-Resolve-the-Mozilla-Firefox-Active-Directory-Login-Issue) KB article.

   ![Admin Portal Login](/files/rpYoJSpTM8NfIVQV5mO2)
3. After logging in, the Adaptiva Web Portal will be displayed. A license must be added to activate the features of that product in the Adaptiva Web Portal.

   ![Admin Portal](/files/hyvHlbIAi5oMTwhhd8KG)
4. Click **Manage Licenses**.

   ![Manage Licenses](/files/DGviMBoSVhYzeWRUsKid)
5. Click **Add Key**, enter your license key, and click **OK**.
6. Optionally, click **Start Free Trial**, select the product you wish to preview and click **OK**.
7. You will be prompted to Accept an End User License Agreement. Click **Accept**.
8. Your Adaptiva products will be listed on the left, with license details in the right pane.
9. Select an Adaptiva product to review the current license status.

   ![License Status](/files/u2FBg7mNWfSpQqkylbwm)

   * Notice the **License Count**, **Expiration Date** and specific **Licensed Collections** of devices targeted to receive the license.

## Target Clients for Licensing

1. In the Target Collections pane, target which clients will receive this license.
2. Toggle **Use All Clients**. In the confirmation window, click **OK**.
3. Optionally, click **Browse** and select a collection or group of clients, then click **OK**.

## Server Activation (OneSite Anywhere only)

Once you receive an activation code from Adaptiva continue with the next steps below. If you have not requested an activation code, see the section Server Activation in the [Installation Prerequisites](/platform-install/server-install/install-platform-prerequisites#server-activation-onesite-anywhere-only).

1. In a web browser connect to the Admin Portal -- `http://AdaptivaServerFQDN[:port]`.
2. Enter the appropriate credentials or click on **Login with Active Directory**.
3. Click on the ![gear](/files/3XkKUN49DPU4pPxBx7UG) with the drop-down on the far right and select **Settings | Server Activation**.

   ![Server Activation Settings](/files/Yq7SHGYHG03T92vU8rid)
4. On the Server Activation page, click **Activate Server**.
5. Enter the activation code provided by Adaptiva Support and click **OK**.

   ![Activation Code](/files/yLXgbJJ0C0NNYHi37WLt)
6. The Adaptiva Server Service will attempt to contact the Adaptiva Cloud Relay Server at [http://services.adaptiva.cloud](http://services.adaptiva.cloud/).
   * If it cannot reach the service using port 80 you will the following error:

     ![Activation Failed](/files/VUAOePiUcBreEP1POFAX)
   * If it successfully registers with the Adaptiva Cloud Relay Service, the Server activated slider will be slid to the right

     ![Server Activated](/files/SW0x7X9Xlahl006tj9EB)

Note the other information available in the Cloud Connect Adaptiva Server settings screen:

* **Customer name**: This is initially the FQDN of the Adaptiva server. After activation, it will display the name that was entered at the Cloud Relay Server.
* **Global ID**: Unique ID of the Adaptiva Server assigned at registration time
* **Tenant ID**: Unique ID of the Adaptiva Server. Also, part of the certificate issued to the server and make up the server's identity
* **Server GUID**: This uniquely identifies your Adaptiva Server and can be used for client installations. It is required if the client is being installed without connectivity to the Adaptiva Server, requiring the client to validate through the Adaptiva Cloud Relay Service.


# Optional - Answer File

Create a Silent Installation Answer file

An answer file can be created to automate the installation of the OneSite Platform server. The executable must be run with administrative privileges. The answer file can only be created when the Adaptiva Server has not been previously installed.

1. Right click `adaptiva-server-<version>-windows.exe`, and then select **Run as administrator**.
2. Configure your **Superadmin Login ID and Password**.
   * **Use Windows Login**: This option will use either your current logged in account or one that you specify with your Windows credentials.
   * **Use Custom Login**: This option allows you to supply an email address and password to create a server login. The email address is a username and does not need to be a valid email address.
3. Enter one or more license keys, separated by semicolons.
4. The following items are checked by default:
   * **Create an Add/Remove Programs Entry**: The Adaptiva Server Installer will create an entry for OneSite Platform in **Windows Settings > Apps & Features**.

     ![](/files/QsEtTDsJDzLqptzixPGo)
   * **Add a Windows Firewall Exception for Server Application**: The Adaptiva Server Installer will add local exceptions in the Windows firewall for the default server ports (See [Communication Ports](https://adaptiva.com/hubfs/Docs/OneSite-Port-Detail.pdf)).
   * \***IMPORTANT**: Review any existing domain-based group policies (GPO) that configure or restrict Windows firewall rules or rule creation as they can prevent or override these Adaptiva-created firewall exceptions.
5. Click **Answer File**.
6. At the Generate Installation Answer File dialog, enter or **Browse** to a location where the file will be created. Click **OK**. The answer file will be named *AdaptivaAnswerFile.txt* in the folder selected.

   ![Generate Answer File](/files/uORTIguBmHA5KlNeBlf5)

   * The installation screens will proceed as described in the Server Installation section. Each answer will be saved in the Answer file. The installation will NOT install the product. Use the Server Installation section below to learn about each screen during the installation process.
7. When all the prompting screens are complete the answer file is created. Click **OK**.

   ![File Creation](/files/Nj9OdMqjtWND30alG2ru)

   * **NOTE**: If passwords were entered for the SuperAdmin ID or Service accounts, these passwords will be stored in clear text in the Answer File. Delete or secure the answer file after the installation has been completed.

## Install using the Answer File

If you have created an answer file, follow these steps to use the answer file to install the Adaptiva OneSite Server.

1. Open a Command Prompt as Administrator.
2. Navigate to the installation source folder.
3. Enter the following command:

   `adaptiva-server-<version>-windows.exe -InstallOrUpgrade %path%:\\<AnswerFileName>`
4. There is no progress bar during the installation. The installation can be monitored using the Task Manager, monitoring the *adaptiva-server.exe* process and by monitoring the log file **C:\Windows\AdaptivaSetupLogs\Server\AdaptivaServerSetup.log**.
5. Upon successful installation the `adaptiva-server-<version>-windows.exe` process will be replaced with *AdaptivaServerService* and the *AdaptivaServerSetup.log* will show:

   `~performSilentServerInstall(): 2C58: Line: 160: Server installation was successful`

{% hint style="info" %}
The server installation normally launches **adaptiva-client-\<version>-windows.exe** to install the Adaptiva Client. The silent installation does not do this. Be sure to install the Adaptiva Client on the server as well.
{% endhint %}


# Post installation

Post-installation tasks for configuring the OneSite Platform.

## Add certificate to the root store

If a self-signed certificate was selected, you should import the certificate into the Trusted Root Certification Authorities container on every device where the Adaptiva Admin Portal will be accessed. Each OneSite Administrator who will use the Admin Portal from a remote device will need to import the certificate. Alternatively, the certificate can be deployed using a GPO or Intune policy.

### Download and install the certificate

1. In your browser, navigate to your Adaptiva Server name with optional *:port* - `https://<servername>[:port]`.

   Example: `https://adaptivaserver:9678`
2. You will see the message **Your connection isn't private**.
3. Click on the text **Not secure** next to the Address URL.
4. Click on **Your connection to this site isn't secure**.

   ![Connection Warning](/files/beAKZc3RudysCuw6LThC)
5. Click on the certificate icon to view the certificate.

   ![Certificate Details](/files/gXXLM5lVzwXm9muTqIs0)
6. Select the **Details** tab.
7. Click on **Export**.
8. Select a destination (your **Downloads** folder) - leave the default filename of `<servername>.crt`.
9. Close your browser.
10. In File Explorer, browse to the saved certificate and double-click it.
11. Select **Install Certificate...**.
12. Select **Local Machine (recommended)** and click **Next**.
13. Select **Place all certificates in the following store**.
14. Click **Browse**, select **Trusted Root Certification Authorities** and click **OK**.
15. Click **Next** and then click **Finish**.

#### Alternatively

1. The certificate is stored in the registry at `HKLM\SOFTWARE\Adaptiva\server\certificates.cloudui_public_cert`
2. The data can be saved into a UTF-8 formatted text file with a .crt extension.
3. You can then run the following command to import the certificate:

   `Certutil.exe -addstore root "<path>\<servername>.crt"`

#### Test the certificate

1. In your browser, enter the Adaptiva Server name with optional *:port* - `https://<servername>[:port]`.
2. You will now see the Admin Portal login page.
3. There will now be a lock icon next to the URL

   ![Secure Site Details](/files/NUwuhwsBCU3arWsv6V2r)

### Content Library Location

The Content Library will default to Adaptiva Server installation folder **%Path%\Adaptiva\AdaptivaServer\Data\ContentLibrary**.

Consider moving the Content Library to a dedicated drive that can be backed up or replicated. It is not supported to use a UNC path. Review this [How-To article](https://support.adaptiva.com/hc/en-us/articles/203736410-How-To-Change-the-location-of-the-content-library-) for instructions on moving the Content Library location.

> **IMPORTANT**: Ensure this drive is backed up or replicated.

### Configure SQL Database Best Practices

By default, the installation account is assigned as the owner of the Adaptiva database. SQL best practice is to set the SA account to the owner.

1. In **SQL Management Studio**, right-click on the **adaptiva** database and select **Properties**.
2. Select the **Files** page. Change the Owner to **SA**.
3. Select the **Options** page. Verify the Recovery model is set to **Simple**.

   > **NOTE**: If the Adaptiva database will be part of a SQL Always On Availability Group, the Recovery model should be set to Full.

### Finalize the Workspace ONE Integration

This is only applicable if the Workspace ONE integration was selected.

After a successful installation, return to the Workspace ONE UEM console to complete the integration of the two platforms.

1. Navigate to the Adaptiva settings page (**Groups & Settings | All Settings | System | Enterprise Integration | Peer Distribution | Adaptiva**) and enter either the name or the internal IP address of the Adaptiva server. This will allow the ACC to communicate with the Adaptiva server on the internal network.
2. Upload the Adaptiva Server certificate so the authentication between the ACC and Adaptiva services is secure. Recall the certificate was saved here: ***%InstallPath%*****\Program Files\Adaptiva\AdaptivaServer\data\security\AdaptivaServer.cer**.

   ![Certificate Upload](/files/RUX6f9mwiQlXuJ2E8oaB)
3. Click **Save**. The system will save the settings and immediately perform a health check to validate communications and then initiate publication of application metadata to the Adaptiva Server.

   ![Health Check](/files/ICEJ28caaUYZ9tGy17wE)

#### (Optional) Reduce SQL permissions

To remove SQL sysadmin access from the account

1. Stop the **AdaptivaServer** service.
2. In **SQL Management Studio**, select the ConfigMgr database and click **New Query**, enter the following command:

   ```sql
   CREATE ROLE db_executer\
   GRANT EXECUTE TO db_executer
   ```
3. Click **Execute**.
4. Repeat the above step against the Adaptiva database.
5. Expand **Security | Logins** folder, right-click the account used for installation and select **Properties**.
6. Select the **Server Roles** page and uncheck the server role: **sysadmin**.
7. Select **User Mapping**.
8. In the **Users mapped to this login** section, select the **adaptiva** database, and under the database role membership, select the following roles:

   ```sql
   db_datareader
   db_datawriter
   db_ddladmin
   db_executer
   ```
9. In the **Users mapped to this login** section, select the **ConfigMgr** database, and under the database role membership, de-select the `db_owner` role, and select the following roles:

   ```sql
   db_datareader
   db_datawriter
   db_ddladmin
   db_executer
   ```

   ![Login Properties](/files/k0ssXfBJCbTDOfLVgXl7)
10. Click **OK** when complete.
11. Start the **AdaptivaServer** service.

## Additional configuration

After you have completed the installation of the OneSite platform, you may choose to apply additional configurations to optimize your environment. These optional steps vary depending on the solution you’ve implemented and the size and complexity of your organization.

* [Create your network topology](https://docs.adaptiva.com/platform-guide/network-topology.md)
* [Configure security and access control](https://docs.adaptiva.com/platform-guide/security.md)
* [Configure SMTP settings](https://docs.adaptiva.com/platform-guide/additional-settings/smtp-settings.md)

## Administration and troubleshooting

* [Perform administrative tasks on Adaptiva clients with the Adaptiva Administration Tool (AAT)](https://support.adaptiva.com/hc/en-us/articles/360028239692-Administration-Adaptiva-Administration-Tool-AAT)
* [Troubleshoot client connectivity](https://docs.adaptiva.com/platform-guide/client-validator)


# Uninstall the Adaptiva Server

You can completely remove the Adaptiva Server by re-running the setup executable and select the **Uninstall** option. You should uninstall the OneSite Platform from the bottom-up, starting with the clients and then finishing with the Adaptiva Server.

To run the uninstallation silently, run the `adaptiva-server-<version>-windows.exe` executable fom the command line with the `-uninstall` switch.

We recommend opening a ticket with Adaptiva Support for assistance in removing the Adaptiva Server components. Uninstallation will delete the registry, the content library, and the Adaptiva Server folder contents. It will also delete the Adaptiva database and remove the Adaptiva tables, views, and triggers from the ConfigMgr database.

### Uninstall Adaptiva Workbench

Run the following command to uninstall the Adaptiva Workbench:

`adaptivaWorkbenchSetup.exe -uninstall`


# Platform upgrade

Instructions for upgrading OneSite Platform

When upgrading the Adaptiva infrastructure to a newer version it is important to follow a top-down upgrade model. The order of upgrade should be as follows:

1. Adaptiva Server component
2. Adaptiva Client on the Adaptiva Server
3. Adaptiva Workbench on the Adaptiva Server (if applicable)
4. Adaptiva Workbench on administrator systems
5. All Adaptiva Clients
6. OneSiteDownloader in Boot Images (if applicable)

> IMPORTANT: Elevated SQL permissions (sysadmin) is required to successfully complete the upgrade for both the account running the upgrade as well as the Adaptiva Server SYSTEM account.

## Platform Component Upgrade Options

The options for upgrading each individual component are below:

**Adaptiva Server**

* Manual - Manually execute the new version of `adaptiva-server-<version>-windows.exe` and select the **Upgrade** option. Select **Quick Upgrade** or select **Advanced Upgrade** and select **Next** through each screen. No changes are required. This will also automatically launch the Adaptiva client upgrade. Click **Launch**, then **Upgrade**.

**Adaptiva Workbench**

* Manual - Manually execute the new version of **AdaptivaWorkbenchSetup.exe** and select the **Upgrade** option.
* Unattended - `AdaptivaWorkBenchSetup.exe -installorupgrade`

**Adaptiva Client**

* Manual - Manually execute the new version of `adaptiva-client-<version>-windows.exe` and select the **Upgrade** option.
* Unattended - `adaptiva-client-<version>-windows.exe -installorupgrade -servername <serverFQDN>`

  When upgrading Adaptiva clients using the **-installorupgrade** option, the current configuration, content cache, and all settings will be preserved. The P2P Client MSI Installer can also be used to perform a client upgrade as described above.

  > IMPORTANT: When using Cloud functionality, be sure to include the appropriate command line parameters to enable this feature. I.e. -cloudrelay

**Boot Image**

* Manual - See the Adaptiva OneSite OSD User Guide to update the Boot image with the new **OneSiteDownloader.exe**. We recommend using the [OneSite Boot Image Powershell Script](https://support.adaptiva.com/hc/en-us/articles/115001545992-Create-OneSite-Boot-Image-PowerShell-Script-with-updated-read-Me). Alternatively you can use DISM or 7-Zip.

## Server Upgrade

Be sure to review the database permissions as documented in the Installation Prerequisites section here: [SQL permissions](/platform-install/server-install/install-platform-prerequisites#sql-permissions)

### New Antivirus Exclusions

For information about new required antivirus exclusions, see [Antivirus Exceptions](https://docs.adaptiva.com/platform-install/planning-guides/onesite-platform-planning#antivirus-exceptions).

### Server Upgrade Options

#### Quick Upgrade

Use this option to keep all the settings unchanged and begin the server upgrade.

* TLS Settings will default to self-signed with the server's FQDN and IP Address(es) in Subject Alternate Name list.
* A SQL login account will be created on the Adaptiva SQL Server. If the Adaptiva SQL Server is a remote server this will cause AdaptivaServerSetup to fail.
* If the TLS Settings and the Adaptiva Reporting Account have never been set, you must perform an Advanced Upgrade.

#### Advanced Upgrade

Use this option to customize each settings of the server upgrade.

1. Right click `adaptiva-server-<version>-windows.exe`, and then select **Run as administrator**.

![Server Installer](/files/35lmO85UFmu6ITYZdL3E)

1. Click **Advanced Upgrade**.
2. The following screen is used to provide the TLS Certificate configuration for use with the Admin Portal. Select which TLS Security Setting will be used to secure the Admin Portal.

![TLS Settings](/files/NaWTHGdHbVOBQyXP6ZZ2)

Select one of the following TLS security settings, based on the preferences of your organization. These settings allow secure access to the Adaptiva Admin Portal for devices with the certificate:

* Select **TLS Using A Certificate Authority (CA)** to use a certificate you exported from a Certificate Authority. If you choose this option, the CA-based certificate must be installed on the devices requiring access to the Adaptiva Admin portal. An auto-enrollment GPO can be configured and targeted to specific devices or a wild-card certificate can be used.
  * Click **Install A CA-Issued X.509 Certificate**.
  * Click **Browse**, and then navigate to the location of the Certificate PEM File.
  * Click **Browse**, and then navigate to the location of the Private Key PEM File.
* Select **TLS Using Self-signed Certificate** to use a self-signed certificate. If you choose this option, you must provide the certificate to every Adaptiva Administrator who must add it to the Certificate store on the device from which they access the Adaptiva Admin Portal. See [Add Certificate to the Root Store](/platform-install/server-install/install-platform#add-certificate-to-the-root-store)
  * Click **Create A Self-signed X.509 Certificate**.
  * Enter the names or IP addresses associated with the servers that host the Adaptiva Admin Portal. Be sure to include server details for NETBIOS, FQDN, DNS Alias or IP Address. Separate each entry by comma.

1. Click **Next**.
2. On the Integrations screen, you can optionally configure to integrate with Microsoft ConfigMgr or Workspace One. Click **Next**.
3. On the SQL Database screen, you will default to your exiting SQL configuration. Click **Next**.
4. On the SQL Login screen, you will need to provide a login account for reporting access. If you have previously configured these settings, leave the default values. Complete the fields as follows:

![SQL Login](/files/0ZZ7b53tnAh5WjIBHHeE)

**Use Windows Authentication** -- Check this if the reporting account has been created in the domain.

This box will be checked and greyed out when Windows Authentication mode has been specified in SQL Server.

**Domain Name** -- Enter the NETBIOS domain name used for the reporting account.

Leave blank if **Use Windows Authentication** is unchecked and a SQL Login account is to be used.

**User Name** -- Enter the account name to use for the reporting account.

**Password / Confirm Password** -- Enter and confirm the password for the reporting account.

1. Click **Next** and the upgrade will proceed.
2. When the installation is complete, the Post-Installation Verifications screen will run connection checks.

![Post-Install Checks](/files/9l6ufkslffKmnGcP2i41)

Some of these checks may be skipped based on the settings selected. Also, there is a known issue when the Kerberos authentication protocol is selected for the Adaptiva database: The Read-Only Account Write Access Denied will report Failed. This can be ignored.

## Client Upgrade on Server

You need to install the latest version of the Adaptiva Client the OneSite server.

![Client Upgrade](/files/JW1y7zaTWifmHYlaxWp2)

Leave the default settings and click **Upgrade**.

### Updated Admin Portal Build

When you open the Admin Portal you may a notification that an upgrade is available, click **OK.**

![](/files/LvXeAiEJbENzI6XUHv70)

At the top of the windows, click on **Dismiss** for any notifications.

![](/files/gGkHrWhVQNPD7AGBK4V4)

### (Optional) Add New License Keys

OneSite Patch and its add-on License keys should only be added AFTER upgrading to a version of the OneSite Platform that supports that product. Contact Adaptiva Support if you have questions.

License keys can only be added in the Adaptiva Admin Portal. See [License your Adaptiva solution](https://docs.adaptiva.com/platform-guide/license-solution)

### Automatic Client Upgrade

After you upgrade the Adaptiva Server, you can use the [Client Upgrade](https://docs.adaptiva.com/platform-guide/client-management/client-auto-upgrade) feature for clients on version 9.3 or later. To upgrade older client versions, use the Legacy Client Upgrade (Windows) feature.

#### Legacy Client Upgrade (Windows)

Before continuing, make sure the Adaptiva Server has been updated to the latest version of the Adaptiva Client. The Client installer will be obtained from the Adaptiva Server client install folder. This folder can be found by using the ADAPTIVACLIENT environment variable.

1. Connect to the Admin Portal using a web browser (except Internet Explorer) -- `<http://AdaptivaServerFQDN:[port]`
2. Enter the appropriate credentials or click on Login with Active Directory
3. Click the gear icon ![](/files/Oeef3EliJ3uDlaFXp3pQ) **| Settings | Legacy Client Upgrade (Windows)**.
4. At the top the dashboard will display the current coverage of the different versions in an overall chart and by location.

![](/files/H5TYgbwuhcPHdnCS6HeN)

1. The Client Auto Upgrade must be enabled before the settings can be changed. Once enabled, it will stay enabled.

![](/files/Htto2LYd5iglfSJcYHzY)

If it is already enabled, the last saved configurations will be set in each section below. Update as required and click on **Save and Deploy**.

> IMPORTANT: Clicking Save and Deploy, or Deploy, will immediately execute the workflow to perform the upgrade based on the settings in the form.

Click to enable **Enable Auto Client Upgrade**.

**Scheduling**

![](/files/3Gy7LPyApnMUbMvukfkt)

1. Next to **Schedule Start Time**, click on the calendar icon to select the date and time. This will be the day and time that the client upgrade should start.

![](/files/dThjWps7cxJwPmm7GCD0)

Clients that come online after the specified Start Time and have not yet received the policy will apply the policy immediately.

Click anywhere off the widget to close it. Notice the date and time has been entered into Schedule Start Time

1. Toggle **Use Server Time Zone** to have the specified start date and time refer to the time zone of the Adaptiva Server.

**Target Groups**

![](/files/Fs1CA8HSg13JdHLahLcU)

1. Toggle **Use All Adaptiva Clients** or click on **Browse** to select one or more Adaptiva Groups or ConfigMgr collections. When selecting a Group or collection, check the box next to the item. When finished selecting all groups/collections, click on Add to List.

**Load Balancing**

![](/files/mW2CZkvCmBSSpfYVS2Dz)

1. Toggle **Use Load Balancing** to enable load balancing. If not enabled, ALL targeted clients will execute the policy on the start date and time.
2. Set the Load Balance interval

The load balance interval can be between 0 and 100 Days, Hours or Minutes.

When Load Balancing is enabled, each client will be randomly divided across the load balance interval entered.

**Installation**

![](/files/08KO8Jm9jtYhB08FrKms)

Choose either Server FQDN or IP Address. The Adaptiva Client can be installed using either the `-servername` or `-serverip` switches. This option determines which option is used. Notice the command line will change based on the options selected, e.g. The FQDN or IP address of the Adaptiva Server has been automatically entered.

> IMPORTANT: Verify that automatic discovery found the correct Server Name or IP Address by reviewing the Command Line that was auto-generated.

To Override the FQDN or IP Address, toggle Override Server FQDN or IP Address and enter the Name or IP Address to use.

> IMPORTANT: If the Name or IP Address previously used is changed, it will cause the client to be inactivated and re-activated, which will then trigger a review of all content in the AdaptivaCache folder as well as new policy downloads. If the FQDN or IP Address needs to be changed to support a DNS CNAME Alias see the following article here. [How-To: Redirect OneSite client to a different Adaptiva server -- Adaptiva Support Portal](https://support.adaptiva.com/hc/en-us/articles/206503713-How-To-Redirect-OneSite-client-to-a-different-Adaptiva-server)

Choose any of the below options:

* **Use Cloud Relay**: Allows the Adaptiva client to communicate with `http://services.adaptiva.cloud` when unable to communicate via UDP to the on-premises Adaptiva Server.

> IMPORTANT: If any of the in-scope clients have been previously configured to use the Cloud Relay Service, be sure to enable this setting otherwise client communications will stop using the Adaptiva Cloud Relay server.

* **Bind to HTTP URL**: Allows the Adaptiva client to communicate with the on-premises Adaptiva Server via the defined HTTP Port. This adds the `-serverurl <url>` to the command line.

> When the Bind to HTTP URL is enabled, enter the URL of the on-premises Adaptiva server. For example: `http://adaptivaserver.mydomain.com:9679`.

* **No Add/Remove Programs Entry**: Enabling this setting will prevent Adaptive Client from being added to the Add & Remove Programs/Programs & Features list in Windows. Do not select this option if this information is required. Adds the `-noarp` switch to the command line.
* **No Firewall Entries**: Enabling this setting will prevent Windows Firewall entries from being created automatically. Adds the `-nofirewall` switch to the command line.
* **No WoL**: Enabling this setting will disable Wake on LAN. Do not select this option if it is desirable for machines to be woken using Wake on LAN magic packets in the event that content is available on the device, but the machine is offline. Adds the `-nowol` switch to the command line.
* **Memory Allocation (in MB)**: This setting configures the maximum JVM memory allocation for the client. As of Adaptiva Client version 9.1, the default memory allocation is 512MB. Do not set this number below 512. It is recommended to set this value in powers of 2 starting at 512.

> NOTE: The Memory value in the CLI Input shows the last value used and may differ from the Memory Allocation selection. Change the Memory Allocation to sync the CLI Input.

* Review the value of the Commandline to ensure that the servername | serverip is correct and that any required or desired command-line switches are present and displaying the correct values.

> NOTE: Commandline will always contain the -delay 30 switch on the end. This cannot be overridden.

* Once the command-line has been validated, click **Save and Deploy** to start the upgrade process.

  ![](/files/im0ADsXVPVxvq74NeFfX)

The command line must first be confirmed. Click **OK** after reviewing the Commandline.

These settings are saved in the database in the table `AUTOUPGRADESETTINGS`. Once you click Save and Deploy, the latest Adaptiva Client will be published as Adaptiva Content and a hidden schedule, group and content push policy will be created.

When the specified start date/time is reached, the clients will download the content. The content will get unpacked into a local folder on the client **%TEMP%\AdaptivaClientUpgrade** (normally **C:\Windows\TEMP**).

To review distribution status, scroll to the **Version Coverage** dashboard at the top of the page.


# Client install

Adaptiva Client installation guide for the OneSite Platform.

The Adaptiva Client must be installed on every device that will be managed. The Adaptiva Client supports a manual installation or a silent unattended installation. For complete coverage, the client agent setup can be added to a GPO-enforced startup script, the OS deployment process, and deployed using the peer-to-peer MSI.

Platform specific install guides:

* [Install Windows Client](/platform-install/client-install-and-uninstall/client-install/client-install-windows)
* [Install Linux and macOS Client](/platform-install/client-install-and-uninstall/client-install/client-install-linux-macos)
* [Install SaaS](/platform-install/client-install-and-uninstall/client-install/client-install-saas)
* [Uninstall Client](/platform-install/client-install-and-uninstall/client-uninstall)

## Client Installation Files

You can find the Adaptiva Client installation media in the *Installers* folder of the compressed build files. For more information on the supported operating systems, see [Supported Systems](/platform-install/overview/supported-systems).

{% hint style="info" %}
The `<version>` is a placeholder for the build version number, which changes with each release.
{% endhint %}

### Windows installers

| Package Name                                | Architecture | Descriptions                                                                                                                                                                |
| ------------------------------------------- | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `adaptiva-client-<version>-windows.exe`     | x64          | Windows client full installer                                                                                                                                               |
| `adaptiva-client-p2p-<version>-windows.msi` | x64          | Windows Installer-based application. The P2P Installer first attempts to find the Windows client installer on the local subnet, then downloads from the specified location. |

### Cross-platform installers

#### Linux

**Version 10.1.972 and later**

| Package Name                                   | Architecture | Distributions                                                                                             |
| ---------------------------------------------- | ------------ | --------------------------------------------------------------------------------------------------------- |
| `adaptiva-client-<version>-amd64.deb`          | x86\_64      | Debian & Ubuntu                                                                                           |
| `adaptiva-client-<version>-arm64.deb`          | ARM64        | Debian & Ubuntu                                                                                           |
| `adaptiva-client-<version>-1.x86_64.rpm`       | x86\_64      | AlmaLinux, Amazon Linux, CentOS Stream, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux |
| `adaptiva-client-<version>-1.aarch64.rpm`      | ARM64        | AlmaLinux, Amazon Linux, CentOS Stream, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux |
| `adaptiva-client-<version>-1.suse.x86_64.rpm`  | x86\_64      | openSUSE Leap, SUSE Linux Enterprise                                                                      |
| `adaptiva-client-<version>-1.suse.aarch64.rpm` | ARM64        | openSUSE Leap, SUSE Linux Enterprise                                                                      |

**Version 10.1.971 and below**

| Package Name                                  | Architecture | Distributions                                                                                    |
| --------------------------------------------- | ------------ | ------------------------------------------------------------------------------------------------ |
| `adaptiva-client-<version>-amd64.deb`         | x86\_64      | Debian and Ubuntu                                                                                |
| `adaptiva-client-<version>-1.el8.x86_64.rpm`  | x86\_64      | AlmaLinux 8, Oracle Linux 8, Red Hat Enterprise Linux 8 and Rocky Linux 8                        |
| `adaptiva-client-<version>-1.el9.x86_64.rpm`  | x86\_64      | AlmaLinux 9, CentOS Stream 9, Oracle Linux 9, Red Hat Enterprise Linux 9, and Rocky Linux 9      |
| `adaptiva-client-<version>-1.el10.x86_64.rpm` | x86\_64      | AlmaLinux 10, CentOS Stream 10, Oracle Linux 10, Red Hat Enterprise Linux 10, and Rocky Linux 10 |

#### macOS

| Package Name                          | Architecture | Versions                                                                               |
| ------------------------------------- | ------------ | -------------------------------------------------------------------------------------- |
| `adaptiva-client-<version>-macOS.pkg` | ARMx64       | Please see [Supported Systems macOS](/platform-install/overview/supported-systems#mac) |


# Install Windows Client

How to install Adaptiva Clients on Windows devices.

Windows clients can either by installed with the manual full installer, or with the peer-to-peer MSI installer.

## Manual full Windows client installation

Use this method on a one-off basis during testing, initial rollout or to supplement automatic deployment.

1. Run the `adaptiva-client-<version>-windows.exe` as Administrator, found in the installation source folder.
2. In the Adaptiva Client Installer dialog, verify or change the following installation options.

![Client installer dialog](/files/w2kWNzLvLiYfyYyXp2bi)

```
* **Client Install Path**

    * Directory where the client will be installed.

* **Server Host Name or IP Address**

    * The fully qualified domain name or IP address of the Adaptiva Server.

* **Use Cloud Relay Service to connect when off-premises**

    * Check this box if clients will be on the internet or split-tunnel networks

* **Use Password for installation (optional)**

    * Check this box and enter the password provided by your OneSite Administrator. You can find the password in the Admin Portal under **Settings > Client Authorization**.

* **Server’s GUID (optional)**

    * Enter the Server GUID provided by your OneSite Administrator. You can find the Server GUID in the Admin Portal under **Settings | Server Activation**.

* **Enable Wake On LAN**

    * Allows the client to be woken up using peer-to-peer WOL.

* **Add/Remove Programs Entry**

    * Adds an entry allowing for uninstallation of the client agent from the Control Panel.

* **Add Windows Firewall Exception**

    * Adds exceptions to the local Windows Firewall for the default client ports, see [Platform Communication Ports](platform-communication-ports.md) for a list of these ports.

* **Memory**

    * Sets the memory allowance for the client, in increments of 128 MB, with a minimum of 256 MB.

* **MSP Tenant Installation**

    * Only check this box if you are using a Managed Service Provider license and supply the Tenant GUID.
```

1. Click **Install**.

### Adaptiva Client Validator

The Adaptiva Client Validator verifies the connectivity requirements for the client and will run after installation.

![Client Validator](/files/bTB1j3lx21aBKqjyZHd9)

If all checks pass (or are not applicable), then the client is fully online and ready to be managed. If any of the checks fail, you can make the appropriate firewall or network configurations and then rerun the Client Validator tool from the Adaptiva client installation location (%ADAPTIVACLIENT%\bin\AdaptivaClientValidator.exe).

![Client Validator Results](/files/FK3nsyGSe17s965fZw3Z)

#### Validation check detail

The following describes the validation checks being performed:

* HTTP Connection - Verifies the client can connect with cloud services.
* Cloud Relay Connection - Verifies the client can connect to the cloud relay system. The Adaptiva Server must be activated for this check to pass.
* Client-Server Messaging - Verifies the client can send and receive messages to the Adaptiva Server.
* Client-Server Handshake - Verifies the client can successfully perform a handshake with the Adaptiva Server and has obtained a Client ID.
* Client to Client - Checks if the client has peers in the office and verifies connectivity with those clients.

Content Download - Verifies that the client can download a sample package of 8 bytes.

### Unattended Installation EXE Command Line Parameters

In some cases, an administrator may want to use an unattended method to install the Adaptiva Client. The table below describes the command line parameters available for the **Windows client installer**.

| Parameter                                             | Usage                                                                                                                                                                                                                                                     |
| ----------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Required**                                          |                                                                                                                                                                                                                                                           |
| -cleaninstall, -installorupgrade, or -uninstall       | <p><em>-cleaninstall</em> uninstalls the existing client installation and cleanly installs a new copy of the client.<br><em>-installorupgrade</em> installs the client or upgrades the existing client.<br><em>-uninstall</em> uninstalls the client.</p> |
| -upgrade                                              | All previously used settings will be retained; no other parameters should be entered.                                                                                                                                                                     |
| -servername `<servername>` or -serverIP `<server IP>` | FQDN or IP Address of the Adaptiva Server.                                                                                                                                                                                                                |
| -serverguid `<GUID>`                                  | The GUID of the Adaptiva Server can be provided by the OneSite administrator. This property is required when specifying the -cloudrelay.                                                                                                                  |
| -cloudrelay                                           | This property is required for Adaptiva Server installations. It enables the client to use the Cloud Relay Service to connect when off-premises.                                                                                                           |
| **Optional**                                          |                                                                                                                                                                                                                                                           |
| -custompacurl `<URL of PAC file>`                     | The installer will access the PAC file to gather the proxy information.                                                                                                                                                                                   |
| -customproxy `<server>:<port>:<scheme>`               | <p>The installer will use the information to access the proxy when trying to contact Cloud Services.<br>E.g. <code>-customproxy 10.10.10.1:9000:http</code></p>                                                                                           |
| -customproxybypass `<server1>;<server2>;<server3>`    | When -customproxy is used the servers included in the custom proxy bypass list will be excluded from using the proxy.                                                                                                                                     |
| -delay `<seconds>`                                    | Delays the starting of the installation executable. This is useful during a client self-upgrade using content push allowing workflows to complete before the Patch Client service is stopped.                                                             |
| -folder `<folder path>`                               | The desired installation path.By default, the Patch Client is installed under: `%ProgramFiles%\Adaptiva\AdaptivaClient`                                                                                                                                   |
| -mem `<memorysize>`                                   | Maximum Java heap size, in MB (defaults to 256).                                                                                                                                                                                                          |
| -noarp                                                | The installer will not create an entry in Add/Remove Programs.                                                                                                                                                                                            |
| -nocachedel                                           | This parameter can be used with the *-uninstall* or *-cleaninstall*. If this parameter is used the Adaptiva cache will not be deleted.                                                                                                                    |
| -nofirewall                                           | The installer will not create Windows Firewall rules for the Patch Client.                                                                                                                                                                                |
| -nomif                                                | The installer will not send ConfigMgr MIF status in the case of any errors found during installation.                                                                                                                                                     |
| -nowol                                                | Specify this option to disable Wake on LAN. By default, the Patch Client enables Windows Wake on LAN settings on all the network cards installed in the machine.                                                                                          |
| -password `<provided password>`                       | Provides additional security. Enter the password that was created on the Adaptiva Server.                                                                                                                                                                 |
| -preferuserproxy `true / false`                       | When *-preferuserproxy* is `true` the proxy settings will be obtained from the Internet Explorer settings. Defaults to `false`.                                                                                                                           |
| -serverurl `<server-url:port>`                        | Tells the client to communicate to the Adaptiva Server with HTTP instead of using UDP.                                                                                                                                                                    |
| -tenantguid `<GUID>`                                  | Use this to access the Managed Services Provider (MSP) functionality and create and maintain multi-tenant environments. The Tenant GUID can be provided by the OneSite Administrator.                                                                     |

## Peer-to-Peer (P2P) MSI

The Adaptiva Client P2P MSI installer reduces the bandwidth required for the distribution of the Adaptiva agent. Using the Adaptiva Client P2P MSI installer, the Adaptiva Client can be pushed using a group policy, a startup script, `SysInternals psexec`, or any other remote execution method available.

Once executed, the Adaptiva P2P Client MSI installs the full Adaptiva Client. The MSI does not contain the full client installation. Instead, the MSI -- which is specific to a particular version of the Adaptiva Client agent -- first looks for the Adaptiva Client on a peer system in the same subnet with the correct version. If a device is found with the correct version, it retrieves the setup executable `adaptiva-client-<version>-windows.exe` from that local client and installs the Adaptiva Client from that executable. If a peer is not found with the correct version, the MSI retrieves the executable `adaptiva-client-<version>-windows.exe` from a UNC or URL path specified on the command line. If multiple systems run the MSI simultaneously and none of them find the correct version of the client locally, an election takes place among those clients. Only the winner of the election downloads the executable from UNC or URL path, and it then makes the executable available to the other client systems.

{% hint style="info" %}
Ensure that the installation account executing the MSI has read and execute access at the destination UNC path.
{% endhint %}

The Adaptiva P2P Client MSI can be used interactively or as a silent installer with no user interaction.

The P2P installer is named `adaptiva-client-p2p-<version>-windows.msi` and is in the compressed `.zip` product download source.

{% hint style="info" %}
The SaaS tenant provides a pre-configured Windows installer script. This script contains the necessary information to connect to the Adaptiva Tenant. When using the p2p installer for a self-hosted environment, use one of the following methods.
{% endhint %}

### Manual Peer-to-Peer (P2P) client installation

1. Locate the `adaptiva-client-p2p-<version>-windows.msi` executable file on your machine and double-click it to execute.

   ![P2P installer welcome page](/files/Abgj0ymanGJlJo2ZWrIO)
2. Select **Next** to initiate the setup.

   ![P2P installer options page](/files/5yzkQo5C1sGOPPxaQeqY)
3. Select **Install or Upgrade**.

   ![P2P installer ready page](/files/QkCr4tR9p9fUHJjLcZtE)
4. Select **Install or Upgrade**, and then select **Finish** to exit the installer setup wizard.

The other options perform the following tasks:

* Update - Upgrades the existing client to the version of the p2p client installer.
* Clean - Uninstalls the existing client, and then installs the Windows client.
* Uninstall - Uninstalls the Windows client.

### Unattended Installation MSI Command Line Parameters

The table below contains the MSI properties valid for the P2P client installer.

{% hint style="info" %}
Be sure to enter these properties on the command line as `<PROPERTY>=<Value>`.
{% endhint %}

| Property                   | Value                                                                                                                                                                                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| -------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Required**               |                                                                                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| SERVERIP / SERVERNAME      | IP address of server or server name.                                                                                                                                                         | The Adaptiva Server to which this client will report. SERVERIP takes precedence over SERVERNAME if both are specified.                                                                                                                                                                                                                                                                                                                                                          |
| SOURCEUNCPATH / SOURCEURLS | `<UNC path of source>\adaptiva-client-<version>-windows.exe` or URL address of `adaptiva-client-<version>-windows.exe`                                                                       | <p>SOURCEUNCPATH: The location to download the client installer from if it cannot be found in the local office.<br>The account executing the installation must have at least read access to the UNC path.<br>SOURCEURLS: The list of Source CDN URLs (where each SOURCE URL is separated by '<' character) from where the P2P installer downloads the <code>adaptiva-client-\<version>-windows.exe</code> by HTTP protocol in case it is not available in the local office.</p> |
| CLOUDRELAY                 | <p><code>1</code>: Use the cloud relay feature<br><code>0</code>: Do not use the cloud relay feature (default)</p>                                                                           | When enabled, allows the client to communicate with the Adaptiva Cloud Relay server. Include the SERVERGUID property.                                                                                                                                                                                                                                                                                                                                                           |
| SERVERGUID                 | GUID of the Adaptiva Server                                                                                                                                                                  | The GUID of the Adaptiva can be provided by the Adaptiva Admin. Required when the client is on the internet. This property can only be used if CLOUDRELAY=1.                                                                                                                                                                                                                                                                                                                    |
| **Optional**               |                                                                                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ARPSYSTEMCOMPONENT         | <p><code>1</code>: suppresses creation<br><code>0</code>: does not suppress creation (default)</p>                                                                                           | Suppresses the creation of an Add/Remove Program entry for the actual Adaptiva Client. The P2P MSI creates a hidden Add/Remove Program entry for itself named Adaptiva Peer to Peer Client Installer.                                                                                                                                                                                                                                                                           |
| CLEANINSTALL               | <p><code>1</code>: performs a clean installation<br><code>0</code>: perform an <code>InstallOrUpgrade</code> installation (default)</p>                                                      | Uninstalls the existing client installation and cleanly installs a new copy of the client. If not specified, the `InstallorUpgrade` option is used by default.                                                                                                                                                                                                                                                                                                                  |
| MEM                        | `<memory in MB>`                                                                                                                                                                             | The amount of memory in MB to be used by the Adaptiva Client. Defaults to 256 MB.                                                                                                                                                                                                                                                                                                                                                                                               |
| CUSTOMPACURL               | `<URL of PAC file>`                                                                                                                                                                          | The installer will access the PAC file to gather the proxy information.                                                                                                                                                                                                                                                                                                                                                                                                         |
| CUSTOMPROXY                | `<server>:<port>:<scheme>`                                                                                                                                                                   | The installer will use the information to access the proxy when trying to contact Adaptiva Cloud Services.E.g. -customproxy 10.10.10.1:9000:http                                                                                                                                                                                                                                                                                                                                |
| CUSTOMPROXYBYPASS          | `<server1>;<server2>;<server3>`                                                                                                                                                              | When -customproxy is used the servers included in the custom proxy bypass list will be excluded from using the proxy.                                                                                                                                                                                                                                                                                                                                                           |
| NOCACHEDEL                 | <p><code>1</code>: cache is preserved<br><code>0</code>: cache is deleted during uninstallation (default)</p>                                                                                | Preserves the Adaptiva Client cache after uninstallation. This property is only valid when used in conjunction with the UNINSTALL property.                                                                                                                                                                                                                                                                                                                                     |
| NOFIREWALL                 | <p><code>1</code>: does not create any firewall exceptions<br><code>0</code>: creates firewall exception (default)</p>                                                                       | Disables creating exceptions in the Windows Firewall for the Adaptiva Client Installer.                                                                                                                                                                                                                                                                                                                                                                                         |
| NOLOGGING                  | <p><code>1</code>: only FATAL errors are logged, but no other logging is done<br><code>0</code>: normal INFO logging (default)</p>                                                           | Controls the logging level during the client install. Only logging fatal errors is helpful if the client system uses shared storage and to minimize logging.                                                                                                                                                                                                                                                                                                                    |
| NOWOL                      | <p><code>1</code>: disables WoL<br><code>0</code>: enables WoL (default)</p>                                                                                                                 | Disabled Wake-on-LAN                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| PASSWORD                   | Password provided by Adaptiva Admin                                                                                                                                                          | The password is entered by Adaptiva Admin in the workbench to ensure only authorized connections. This property can only be used if CLOUDRELAY=1.                                                                                                                                                                                                                                                                                                                               |
| PREFERUSERPROXY            | `true` / `false`                                                                                                                                                                             | When `preferuserproxy` is true the proxy settings will be obtained from the internet explorer settingsDefaults to false.                                                                                                                                                                                                                                                                                                                                                        |
| SERVERURL                  | Server FQDN URL:port                                                                                                                                                                         | Tells the client to communicate to the Adaptiva Server with HTTP, instead of using UDP.                                                                                                                                                                                                                                                                                                                                                                                         |
| TARGETDIR                  | `<path of desired install folder>`                                                                                                                                                           | The installation folder of the Adaptiva Client. Defaults to `%SystemDrive\Program Files\Adaptiva` or `%SystemDrive%\Program Files (x86)\Adaptiva`.                                                                                                                                                                                                                                                                                                                              |
| TENANTGUID                 | Tenant GUID provided by the Adaptiva administrator                                                                                                                                           | Use this to access the Managed Services Provider (MSP) functionality and create and maintain multi-tenant environments.                                                                                                                                                                                                                                                                                                                                                         |
| UNINSTALL                  | <p><code>1</code>: performs an uninstallation<br><code>0</code>: performs an installation (default)</p>                                                                                      | Ignores all other properties and performs an uninstallation of the Adaptiva Client.                                                                                                                                                                                                                                                                                                                                                                                             |
| WAITFORCOMPLETION          | <p><code>1</code>: the MSI installer waits for the client installation to finish<br><code>0</code>: the MSI will not wait for the Adaptiva Client installation to be completed (default)</p> | Specifies whether the AdaptivaP2P Client Installer MSI will wait until the installation completes.                                                                                                                                                                                                                                                                                                                                                                              |
| WANBYTESPERSECOND          | <p><code>X</code>: bytes per second<br><code>0</code>: Unlimited (default)</p>                                                                                                               | The maximum download speed that will be used while downloading the Adaptiva Client Installer exe over the WAN from the SOURCEUNCPATH.                                                                                                                                                                                                                                                                                                                                           |

### Installation command line examples

To deploy the Adaptiva P2P Client Installer, the only file needed for the package source is `adaptiva-client-p2p-<version>-windows.msi` which can be found in the Adaptiva installation source. The `adaptiva-client-<version>-windows.exe` must be accessible from a Share or a URL.

#### Silent Install UNC file share

This command silently installs the Adaptiva client on a Windows machine and tells it how to connect to your environment.

* Install with Server Share Source:

  ```cmd
  msiexec.exe /I adaptiva-client-p2p-<version>-windows.msi /qn SERVERNAME=AdaptivaServer.domain.com SOURCEUNCPATH=\\ServerFQDN\AdaptivaClient\adaptiva-client-<version>-windows.exe WAITFORCOMPLETION=1
  ```

#### Silent Install cloud/relay-based

Silently installs the Adaptive client, but is configured for a cloud/relay-based setup instead of UNC file share.

* Install with Cloud and Internet Source:

  ```cmd
  msiexec.exe /I Adaptiva-client-p2p-<version>-windows.msi /qn SERVERNAME=AdaptivaServer.domain.com SOURCEURLS=https://tiny.url/abcdefg CLOUDRELAY=1 SERVERGUID=abcdefgh-abcd-1234-efgh-abcdefghijkl WAITFORCOMPLETION=1
  ```

  Include the following switches as required if the Cloud Relay service or if HTTP client communications will be used:

  * Cloud Relay service: `CLOUDRELAY=1`, `SERVERGUID=<GUID>`, `PASSWORD=<auth. Secret>`
  * HTTP communications: `SERVERURL=<ServerURL:port>`

{% hint style="info" %}
You Server GUID can be found in the Admin Portal under **Settings | Server Activation**. You can also find it in the Adaptiva server registry, under `HKLM\Software\Adaptiva\server\client_data_manager.server_guid`
{% endhint %}

## Windows client setup logs

In the case where an administrator needs to troubleshoot an Adaptiva Client installation, the table below contains the installation log locations. Other logs exist in the installation folder.

* Standard client installation: **%windir%\AdaptivaSetupLogs\Client\AdaptivaClientSetup.log**
* P2P MSI client installation: **%windir%\AdaptivaSetupLogs\Client\AdaptivaP2PClientSetup.log**
* Client logs: `%ADAPTIVACLIENT\logs\*\*.log`


# Install Cross-Platform Client

How to install the Adaptiva Client on cross-platform devices.

You can install the Adaptiva Client on Linux and MacOS by installing the appropriate package and running the `adaptivactl` setup command. The setup command will install the OneSite client, configure firewall rules, and run post-installation checks to ensure functionality. The setup progress will print to the terminal and exit with a `0` exit-code if successful. If the client setup fails for any reason, it will exit with a non-zero exit-code.

The adaptivactl setup command checks for port availability before client setup. If a firewall is detected, setup will create firewall rules using the appropriate application: *ufw* with the DEB package, *firewalld* with the RPM package, and *socketfilterfw* with the MacOS package.

The client will now run post-setup checks to confirm connectivity with the server and other services. The setup will wait for these checks to be completed. You can skip these checks using the `--skip-connection-checks` flag.

There are several different installation packages provided for cross-platform device installations. Be sure to use the correct one for your operating system. Locate the installers\cross-platform folder in the downloaded .zip file.

{% hint style="info" %}
When installing the cross-platform client for the Adaptiva Cloud tenant, see [SaaS Client Installation](/platform-install/client-install-and-uninstall/client-install/client-install-saas) for more information.
{% endhint %}

## Linux Installation

### Adaptiva RPM signing key

With the inclusion of openSUSE and SUSE Linux support in version 10.1.972, you will need to import the Adaptiva RPM signing key on each SUSE-based Linux machine during prior to installation. This will allow these distributions to verify the signature of the RPM package.

The following distributions apply:

* Required
  * SUSE-based (openSUSE, SUSE Linux Enterprise)
* Optional - (Good practice to install the RPM signing key, but not necessary.)
  * Other RPM-based Linux distributions (Rocky Linux, Fedora, RHEL, etc.)
* Does not apply
  * DEB-based (Debian and Ubuntu)

1. Open a terminal window and run the following command to import the Adaptiva RPM signing key:

   ```bash
   sudo rpm --import https://adaptiva-releases.adaptivacdn.cloud/client/RPM-GPG-KEY-Adaptiva
   ```

{% hint style="info" %}
If you do not install the RPM signing key you will see the following message when trying to install the RPM:

*Signature verification failed \[4-Signatures public key is not available]*
{% endhint %}

### Install the package

* Run the following command to execute the package (replace `<version>` with the appropriate version of the Adaptiva client your are trying to install and `<arch>` with the specific architecture):
  * DNF package manager

    ```bash
    sudo dnf install ./adaptiva-client-<version>-1.<arch>.rpm
    ```
  * APT package manager

    ```bash
    sudo apt install ./adaptiva-client-<version>-1.<arch>.deb
    ```
  * Zypper package manager

    ```bash
    sudo zypper install adaptiva-client-<version>-1.suse.<arch>.rpm
    ```

{% hint style="info" %}
When running the apt install interactively, the following message may be returned: `N: Download is performed unsandboxed as root as file ‘/<path-to-install-package>’ couldn’t be accessed by user ‘_apt’. – pkgAcquire::Run (13: Permission denied) 109` You may ignore this error.
{% endhint %}

### Configure the client

1. Run the following `adaptivactl` command in setup mode to configure the client:

   ```bash
   sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl setup <flags>
   ```

   Only the `--server` flag is required. See the table below for the available parameters.

   **Example:**

   ```bash
   sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl setup --server adaptivaserver.corp.example
   ```
2. Once the client installation is completed, the client will perform a series of connection checks.

   ```bash
   [info] Running connection checks…
   [info] The connection check ‘HTTP Connection’ has started
   [info] The connection check ‘HTTP Connection’ has passed
   …
   ```

   * If installing a SUSE-based distribution, these checks will not be run.
3. When the connection checks are completed, the Patch Client is fully online and ready to be managed.

### Linux logs

Run the following command to view the client service log:

```bash
  sudo journalctl -u adaptivaclientd.service > .\AdaptivaClientdService.log
```

* Client logs: **/opt/adaptiva/adaptivaclient/logs**

## MacOS Installation

1. Open a Command terminal window, then run the following command to execute the package:

```zsh
sudo installer -tgt / -pkg ./adaptiva-client-<version>-macOS.pkg
```

1. Run the following `adaptivactl` command in setup mode to configure the client:

```zsh
sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl setup <flags>
```

Only the `--server` flag is required. See the table below for the available parameters.

1. Once the client installation is completed, the client will perform a series of connection checks.

```bash
[info] Running connection checks…
[info] The connection check ‘HTTP Connection’ has started
[info] The connection check ‘HTTP Connection’ has passed
…
```

## Mac adaptiva log

* Client installation log: **/opt/adaptivaclient/logs/adaptiva.log**
* Client logs: **/opt/adaptiva/adaptivaclient/logs**

### adaptivactl command line parameters

A list of the command line parameters for the adaptivactl, both required and optional. Known flags can also be printed by running:

```bash
/opt/adaptiva/adaptivaclient/bin/adaptivactl setup --help
```

| Flag                                            | Value                                                                                                                                    |
| ----------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| **Required**                                    |                                                                                                                                          |
| `--server <hostname> / <ip address> / url:port` | IP Address, hostname, or URL of the Patch Server to which the client reports to.                                                         |
| **Optional**                                    |                                                                                                                                          |
| `--auth-secret <secret>`                        | The client authentication secret to use to authenticate with the server. If absent, no authentication will be performed with the server. |
| `--proxy <scheme>://<host>:<port>`              | The HTTP proxy to use. Has the format `<scheme>://<host>:<port>`. If absent, the system-wide proxy will be used if configured.           |
| `--server-guid <guid>`                          | The Server GUID for your Adaptiva Server. You can find this in the Admin Portal under Settings, Server Activation.                       |
| `--tenant-guid <guid>`                          | The Tenant GUID used in multi-tenant environments.                                                                                       |
| `--cloud-tenant-id <tenant id>`                 | The ID of the cloud tenant in cloud-hosted environments.                                                                                 |
| `--system-config <property>=<value>`            | A system config value to set during setup, and has the following format: `<property>=<value>` This flag may be repeated multiple times.  |
| `--skip-firewall-rules`                         | Skip the creation of firewall rules.                                                                                                     |
| `--skip-connection-checks`                      | Skip the post-setup connection checks.                                                                                                   |

**Examples**:

Direct server using an IP address, an HTTP proxy, and a custom system config:

```bash
sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl setup --server 198.50.100.241 --server-guid 1cb07a9e-a88c-4db2-8fe3-2eb7748545d6 --proxy http://198.50.100.3:8080 --system-config onesite.server_message_retry_interval=60
```

Server using cloud relay, hostname, client authentication:

```bash
sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl setup --server adaptivaserver.corp.example --server-guid 1cb07a9e-a88c-4db2-8fe3-2eb7748545d6 --auth-secret 'P@ssw0rd123!'
```

### Restart the Adaptiva client

Use the following command to restart the Adaptiva Client Daemon.

Linux:

```bash
sudo systemctl restart adaptivaclientd
```

macOS:

```zsh
sudo launchctl kickstart -k system/com.adaptiva.clientd
```

### Modify system configuration on Linux or MacOS

The adaptivactl command can also be used to read and write system config values using the config operation.

The following command reads the value of a system config property:

```bash
sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl config get <property>
```

The following command sets the value of a system config property:

```bash
sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl config set <property> <value>
```

## Client upgrade

If you need to upgrade existing cross-platform clients to a newer version manually, perform package upgrades using the commands below. For more information on the supported operating systems, see [Supported Systems](/platform-install/overview/supported-systems). (Replace `<version>` with the appropriate version of the Adaptiva client your are trying to install and `<arch>` with the specific architecture)

### Version 10.1.972 and later

Debian / Ubuntu:

```bash
sudo apt install ./adaptiva-client-<version>-<arch>.deb
```

AlmaLinux, Amazon Linux, CentOS Stream, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux:

```bash
sudo dnf upgrade ./adaptiva-client-<version>-1.<arch>.rpm
```

SUSE-Based:

```bash
sudo zypper install ./adaptiva-client-<version>-1.suse.<arch>.rpm
```

macOS:

```zsh
sudo installer -tgt / -pkg ./adaptiva-client-<version>-macOS.pkg
```

* Use the following command in macOS to restart the Adaptiva Client Daemon:

  ```zsh
  sudo launchctl kickstart -k system/com.adaptiva.clientd
  ```

### Version 10.1.971 and below

Debian / Ubuntu:

```bash
sudo apt install ./adaptiva-client-<version>-1.<arch>.deb
```

AlmaLinux, CentOS Stream, Oracle, RHEL, Rocky:

```bash
sudo dnf upgrade ./adaptiva-client-<version>-1.el<#>.<arch>.rpm
```

macOS:

```zsh
sudo installer -tgt / -pkg ./adaptiva-client-<version>-macOS.pkg
```

* Use the following command in macOS to restart the Adaptiva Client Daemon:

  ```zsh
  sudo launchctl kickstart -k system/com.adaptiva.clientd
  ```

{% hint style="info" %}
Due to an issue in the 9.2.967 RPM packages, upgrading from 9.2.967 to 9.3.968 or later requires the following commands: `sudo dnf upgrade ./adaptiva-client-9.3.968.19-1.el9.x86_64.rpm` `sudo systemctl enable --now adaptivaclientd.service`
{% endhint %}


# Install SaaS Client

How to install Adaptiva SaaS Clients on Windows, macOS, and Linux devices.

## Download the SaaS Client

You'll want to first download the Adaptiva SaaS client from the Cloud Portal.

1. Log in to `https://<ServerName>.adaptiva.cloud` and click **Go to OneSite Patch**.
2. In the left-hand navigation, click **Asset Management > Client Installers**.
3. In the details pane, under **Client Installer Download Links**, click the download button (![Download button](/files/KKCVrLRC7jIrutP1Wz4a)) next to the desired OS option.

Follow the steps below to install SaaS clients on Windows, Linux, and macOS.

## Install the Windows SaaS Client

The Adaptiva Windows Client is installed using the P2P installer with all the needed configuration parameters in an `.msi` file.

1. Select the Windows Client from the dropdown menu.
2. Select ![Download button](/files/KKCVrLRC7jIrutP1Wz4a) to download the installer to your machine.
3. Run the downloaded `.msi` file, and then the client will be installed.

## Install the Cross Platform SaaS Client

The Cross Platform Adaptiva Client is installed using a shell script.

1. Select the appropriate Linux or macOS Client from the dropdown menus.
2. Select ![Download button](/files/KKCVrLRC7jIrutP1Wz4a) to download the `.sh shell script` to your machine.
3. Open a Command terminal window, then run the command below to execute the package. This command automatically downloads the appropriate package and installs the client.

```bash
sudo bash adaptiva-client-<version>-install-unix-<tenantObjectID>.sh
```

{% hint style="info" %}
When running the shell script interactively on systems that use apt, the system may return the following message: `N: Download is performed unsandboxed as root as file ‘/<path-to-install-package>’ couldn’t be accessed by user ‘_apt’. – pkgAcquire::Run (13: Permission denied) 109` You may ignore this error.
{% endhint %}


# Deploy clients

Learn how to deploy the Adaptiva client to your devices.

You can deploy the Adaptiva client to your devices using most application deployment methodologies. These articles walk you through how to install the client using:

* [Group Policy](/platform-install/client-install-and-uninstall/deploy-clients/deploy-clients-grouppolicy)
* [Microsoft Intune](/platform-install/client-install-and-uninstall/deploy-clients/deploy-clients-intune)
* [Microsoft Configuration Manager](/platform-install/client-install-and-uninstall/deploy-clients/deploy-clients-configmgr)

## General Deployment Guidance

You can use many methods to deploy the Adaptiva Client, but the same general process is used in each.

### 1. Access the Adaptiva Client

We recommend you deploy the Peer-to-Peer MSI `adaptiva-client-p2p-windows.msi` in order to minimize network utilization through peer-sharing.

* **On-premises**: You can access the Adaptiva Client installer from the **Installers** folder in the downloaded installation media.
* **SaaS**: You can access the Adaptiva Client installer from **Settings > Client Downloads** in the Admin Portal.

### 2. Share the full installer if necessary

{% hint style="info" icon="cloud" %}
Not required for SaaS.
{% endhint %}

If the client installer cannot access the full .exe client on the local subnet, it will default to the URL or UNC path defined in the installation command line.

### 3. Build your command line

{% hint style="info" icon="cloud" %}
For SaaS clients, all parameters are included in the msi.
{% endhint %}

* [EXE command line parameters](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-install/client-install-windows#unattended-installation-exe-command-line-parameters)
* [P2P command line parameters](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-install/client-install-windows#unattended-installation-msi-command-line-parameters)
* [adaptivactl command line parameters (Linux/MacOS installer package)](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-install/client-install-linux-macos#adaptivactl-command-line-parameters)

### 4. Deploy the client

* Choose your deployment tool
* Build you deployment package
  * Install using a System/sudo account
  * Add an uninstall command - [uninstall commands](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-uninstall)
* Target clients and monitor your deployment

### 5. Validate installation

* Navigate to the Adaptiva Admin Portal and go to **Assets > Devices** to confirm that devices appear in the dashboard.
* You can also confirm the functionality of the Adaptiva Client using the [Client Validator](https://docs.adaptiva.com/platform-guide/client-management/client-validator) tool when interactively installing.


# Deploy clients with Group Policy

Client Installation using ConfigMgr

Deploying software through Group Policy cannot use the standard command line syntax. The properties that are set via the command must be set in a Windows Installer transform file. A variety of tools are available that can be used for this task. [Orca](https://learn.microsoft.com/en-us/windows/win32/msi/orca-exe) is a free tool available from Microsoft and is part of the Windows SDK.

## Create a Transform File (MST)

Download and install the latest [Windows SDK](https://developer.microsoft.com/en-us/windows/downloads/windows-sdk/).

Follow these steps to create a Windows Installer transform file (MST) using Orca.

1. Open Orca, select **File > Open** and select the `adaptiva-client-p2p-<version>-windows.msi`.
2. In the menu bar, select **Transform > New Transform** to create a new transform file.
3. Select the Property table in the Tables list on the left.

   ![](/files/oXl5jHI33ejgyeDfVEHC)
4. In the Property table, modify the following values:

   * **SOURCEUNCPATH** = `<Path to the Adaptiva installer>`
   * **SERVERNAME** or **SERVERIP** = `<FQDN>` or `<IP Address>` of the Adaptiva Server

   If you are using the Cloud Relay service, set the following properties:

   * **CLOUDRELAY**=`1`
   * **SERVERGUID**=`<GUID>`
   * **PASSWORD**=`<password>`

   If you are using HTTP for client communications, set the following properties:

   * **SERVERURL**=`<ServerURL:port>`
5. Click **Transform > Generate Transform** and save the MST file.
6. Close the Orca tool.

## Create a File Share

1. Create a content source folder as follows:

   `<Drive>:<Path>\Adaptiva\Client`
2. Copy the Adaptiva Client MSI and MST files into the Client folder.
3. Share this folder on the server as **AdaptivaClient** with the following permissions:

   Share permissions: **Everyone: READ**

   NTFS permissions: **Domain Computers: Read and Execute, List, Read**

## Create a Group Policy Object

1. Open Group Policy Management and create a new or edit an existing GPO.

   ![New GPO](/files/j1won3m0zdzPleajO8Yj)
2. In the Group Policy Management Editor, expand **Computer Configuration > Policies > Software Settings**.
3. Right-click **Software installation** and select **New > Package**.

   ![Software installation](/files/mZOSIH7AxUWd4lsMW9oF)
4. In the **Open** dialog, navigate to the Adaptvia Client share location and select the `adaptiva-client-p2p-<version>-windows.msi`.
5. In the **Deploy Software** dialog, select **Advanced** and then click **OK**.

   ![](/files/mPJFJeV0dRLeHrxiYcBa)
6. In the Adaptiva Peer to Peer Client Installer Properties dialog, select the **Modifications** tab, and click **Add**.
7. Navigate to to the Adaptvia Client share location, select the MST file, and click **Open**.

   ![](/files/6eXgF9PxratG8uUesaZJ)
8. Click **OK** and close the policy.
9. Target the group policy appropriately. Devices will install the Adaptiva Client at the next system restart.


# Deploy clients with Intune

Deploy the Adaptiva client using Intune

You can create a Windows app (Win32) in Intune to install the Adaptiva Client using one or both of the methods below:

* (Recommended) [Distribute the Peer-to-Peer (P2P) installer](/platform-install/client-install-and-uninstall/deploy-clients/deploy-clients-intune/deploy-clients-intune-p2p) by publishing the `adaptiva-client-p2p-<version>-windows.msi` installer.
* [Distribute the full client installer](/platform-install/client-install-and-uninstall/deploy-clients/deploy-clients-intune/deploy-clients-intune-full) by publishing the `adaptiva-client-<version>-windows.exe` installer.

You can also create a [macOS app](/platform-install/client-install-and-uninstall/deploy-clients/deploy-clients-intune/deploy-clients-intune-macos) in Intune to install the Adaptiva Client to macOS machines in your company.

## Access the Adaptiva Client

The Adaptiva Client is available from the Installation folder of the installation media. You can download the latest release from the [Product Releases](https://support.adaptiva.com/hc/en-us/sections/201965326-Product-Releases) section of the Adaptiva Support Portal.

**For users of the SaaS platform**, you can access the P2P installer or cross-platform installation scripts from your tenant. Click the **settings gear > Settings > Client Downloads.**


# Distribute P2P installer

P2P Windows Client Installation using Intune (recommended)

## Overview

You can create a Windows app (Win32) in Intune to install the Adaptiva Client by publishing the `adaptiva-client-p2p-<version>-windows.msi` installer. Clients will download the 1MB P2P MSI and then use peer-based distribution to source the full installation files.

## Prerequisites

You will need to download and install the [Microsoft Win32 Content Prep Tool](https://github.com/microsoft/Microsoft-Win32-Content-Prep-Tool) to complete these steps.

## Access the Adaptiva Client

The Adaptiva Client is available from the Installation folder of the installation media. You can download the latest release from the [Product Releases](https://support.adaptiva.com/hc/en-us/sections/201965326-Product-Releases) section of the Adaptiva Support Portal.

**For users of OneSite Patch SaaS**, you can access the P2P installer or cross-platform installation scripts from the Cloud Admin Portal.

## Deploy the P2P Installer

You need to install the Adaptiva client using the SYSTEM account, so you need to use a Windows (Win32) App rather than a Line-of-Business app. To install the app in the Device content, you must create an `.intunewin` file and configure a Win32 App in Intune to install the app correctly.

When you distribute the Win32 App, devices will download and run the 1MB `adaptiva-client-p2p-<version>-windows.msi` from Intune. The device will then look for a peer on the local subnet to access the full client installer. If not found, the installer will download full installer either from a server share or an internet accessible location.

For any Intune clients on the internet, you need to host the full client install (`adaptiva-client-<version>-windows.exe`) in a cloud storage container or CDN accessible to clients over the internet. Clients that are on-premises will download the client from a peer.

### Share the Full Installer

* **Create a local network share**

  Create a network share for on-premises users to access the Adaptiva Client Installer.

  1. Create a content source folder as follows:

     `<Drive>:\<Path>\Adaptiva\FullClient`
  2. Copy the **adaptiva-client--windows.exe** from the Adaptiva installer files in \Adaptiva\AdaptivaClient\Bin.
  3. Share this folder on the server as **AdaptivaClient** with the following permissions:

     Share permissions: **Everyone: Read**

     NTFS permissions: **Domain Computers: Read & Execute, List folder contents, Read**
* **Create an internet-accessible share**

  Create an internet accessible share using any cloud storage or CDN provider. Copy the full `adaptiva-client-<version>-windows.exe` installer to this cloud storage container and ensure that you provide an appropriate access policy or token to allow clients to access it.

### Create Intunewin File for P2P Installer

Download and install the [Microsoft Win32 Content Prep Tool](https://github.com/microsoft/Microsoft-Win32-Content-Prep-Tool).

1. Create a content source folder as follows:

   `<Drive>:\\<Path>\Adaptiva\P2PClient`
2. Copy the `adaptiva-client-p2p-<version>-windows.msi` from the installation source into the P2PClient folder.
3. Open Notepad and create an install.cmd command for your appropriate installer:

   Choose the appropriate command for your environment.

   * For the OneSite Patch SaaS installer:

     `%windir%\system32\msiexec.exe /I adaptiva-client-p2p-<version>-windows.msi /qn WAITFORCOMPLETION=1`
   * On-premises with a share:

     `%windir%\system32\msiexec.exe /I adaptiva-client-p2p--windows.msi /qn WAITFORCOMPLETION=1 CLOUDRELAY=1 SERVERNAME=%1 SERVERGUID=%2 SOURCEUNCPATH=%3 %4 %5`
   * On-premises with a URL:

     `%windir%\system32\msiexec.exe /I adaptiva-client-p2p--windows.msi /qn WAITFORCOMPLETION=1 CLOUDRELAY=1 SERVERNAME=%1 SERVERGUID=%2 SOURCEURLS=%3 %4 %5`
   * Both with share and URL:

     `%windir%\system32\msiexec.exe /I adaptiva-client-p2p--windows.msi /qn WAITFORCOMPLETION=1 CLOUDRELAY=1 SERVERNAME=%1 SERVERGUID=%2 SOURCEUNCPATH=%3 SOURCEURLS=%4 %5 %6`
4. Save this file as **Install.cmd** in the P2PClient folder.
5. Open a command prompt at the intunewin tool folder and run the following command:

   `IntuneWinAppUtil.exe -c "<Drive>:\<Path>\Adaptiva\P2PClient" -s Install.cmd -o "<Drive>:\<Path>\Adaptiva\P2PClient"`

### Create Intune App for P2P Installer

Perform the following in Microsoft Intune.

{% hint style="info" %}
For more information on distributing line of business apps using Microsoft Intune, see <https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-win32-app-management>.
{% endhint %}

1. Log into the Microsoft Intune admin center (<https://intune.microsoft.com>) using the account with the appropriate role assignment.
2. In the left-hand navigation pane, click **Apps**, then click **All Apps**.

   ![](/files/TYuQuQHyMw9RsfyzI7kM)
3. Click **+ Create**.
4. In the right pane, select the **App type** drop-down.
5. Under **Other**, select **Windows app (Win32)**.

   ![](/files/oOzJwkaacYBeNYFtiGr9)
6. Click **Select**.
7. The **Add App** pane appears.

   ![](/files/hVm0XZ890KBlc2ISxXqK)
8. Click **Select app package file**.
9. In the right pane, click on the folder icon.

   ![](/files/wQzzwCbJ76zYK9MfTZRJ)
10. Browse to the path with your .intunewin file: `<Drive>:\<Path>\Adaptiva\P2PClient` and select the install.intunewin file. Click **Open**.
11. The right pane will be updated with the package file details. Click **OK**.
12. Under the **App Information** step, update the properties with these and any other values as appropriate. These are user facing values.

    ![](/files/VQDN1BfCrZD6Ve757bM7)

    * **Name** and **Description**: Update the name and description to user friendly values.
    * **Publisher**: Adaptiva
13. Update the other fields as necessary and click **Next**.
14. On the **Program** tab, enter the following:

    ![](/files/Xtwmz5os9uJKBKYzkZVe)

    * **Install command**:

      Choose the appropriate command for your environment.

      * For the OneSite Patch SaaS installer:

        `install.cmd`
      * On-premises with a share:

        `install.cmd [SERVERNAME] [SERVERGUID] [SOURCEUNCPATH] [optional parameters]`
      * On Prem with the URL

        `install.cmd [SERVERNAME] [SERVERGUID] [SOURCEURLS] [optional parameters]`
      * Both with share and URL:

        `install.cmd [SERVERNAME] [SERVERGUID] [SOURCEUNCPATH] [SOURCEURLS] [optional parameters]`

      Parameters need to be in the same order as defined in Install.cmd. Be sure to replace with the specific server information.
    * **Uninstall command**:

      `%windir%\system32\msiexec.exe /i adaptiva-client-p2p-<version>-windows.msi UNINSTALL=1`
    * **Install behavior**: System
    * **Device restart behavior**: No specific action
15. Click **Next**.
16. On the **Requirements** tab, click **Yes. Specify the systems the app can be installed on.**
17. Click to select the **Install on x86 system** and **Install on x64 system** checkboxes.
18. Select the **Minimum operating system**.
19. Complete any additional requirements as needed.

    ![](/files/4IYulSJRbSTlrDeACADr)
20. Click **Next**
21. On the **Detection Rules** tab, click the **Rules format** drop-down and select **Manually configure detection rules**.

    ![](/files/tRpQ5FBnZWpXSB70TkZw)
22. Click **+ Add**

    ![](/files/WafNv8TzHHUZl8srIPAR)
23. In the right-hand pane, click the **Rule type** dropdown and select **MSI**.

    ![](/files/YpY2g8cqAYB9QcwybrmK)
24. Create the following rule:

    ![](/files/u3gcpu3Ar7wgtmCtqjlV)

    * **Key path**: HKEY\_LOCAL\_MACHINE\Software\Adaptiva\Client
    * **Value name:** slm.version
    * **Detection method**: Value exists
    * **Associated with a 32-bit app on 64-bit clients**: No
25. Click **OK**.
26. Click **Next**.
27. On the **Dependencies** tab, click **Next**.

    ![](/files/mcakeLzLMCUeKqarKVeS)
28. On the **Supersedence** and **Scope tags** tabs, click **Next**.
29. On the **Assignments** tab, configure assignments for the following groups. Assignments do not need to be entered right now; they can be entered later.

    ![](/files/ZU6yLmfv5JZDnl7xLtKP)

    Add a group to **Required** to force the installation.

    Add a group to **Available** for enrolled devices to make the installation optional via the Company Portal app. When adding a group to Available, the group must contain Users, not Devices.

    Add a group to **Uninstall** for managed devices to have this app removed.
30. Click **Next**.
31. Review the App information and click **Create**.


# Distribute full installer

Full Windows Client Installation using Intune

{% hint style="info" %}
Adaptiva recommends [deploying the P2P installer](/platform-install/client-install-and-uninstall/deploy-clients/deploy-clients-intune/deploy-clients-intune-p2p) in order to simplify deployment. If you are using a SaaS environment, use the P2P installer.
{% endhint %}

## Overview

You can create a Windows app (Win32) in Intune to install the Adaptiva Client by publishing the `adaptiva-client-<version>-windows.exe` installer. This is the full Windows client installer for the Adaptiva Client available with your installation files.

## Prerequisites

You will need to download and install the [Microsoft Win32 Content Prep Tool](https://github.com/microsoft/Microsoft-Win32-Content-Prep-Tool) to complete these steps.

## Access the Adaptiva Client

The Adaptiva Client is available from the Installation folder of the installation media. You can download the latest release from the [Product Releases](https://support.adaptiva.com/hc/en-us/sections/201965326-Product-Releases) section of the Adaptiva Support Portal.

**For users of the SaaS platform**, you can access the P2P installer or cross-platform installation scripts from your tenant. Click the **settings gear > Settings > Client Downloads.**

However, to access the full client installer you will need to download and install the Adaptiva P2P client to gain access to the full Adaptiva client.

1. Follow these [steps to download and install](/platform-install/client-install-and-uninstall/client-install#saas-client-installation) the Adaptiva P2P Client on a device.
2. On the new device, navigate to `C:\` and show hidden folders.
3. Navigate to the hidden `C:\AdaptivaCache\Client` folder and copy `AdaptivaClientSetup.exe` to an accessible location.

## Deploy the Full Client Installer

Microsoft Intune does not support `.exe` distribution, so you must create an `.intunewin` file and configure a Win32 App in Intune.

This process will download the full Adaptiva client (approx. 92MB) using Intune. It is recommended to use the P2P Client Installer method as that will only download 1Mb using Intune.

### Create Intunewin File for Full Client Installation

Download and install the [Microsoft Win32 Content Prep Tool](https://github.com/microsoft/Microsoft-Win32-Content-Prep-Tool).

1. Create a content source folder as follows:

   `<Drive>:\<Path>\Adaptiva\FullClient`
2. Copy the `adaptiva-client-<version>-windows.exe` from the installation source into the FullClient folder.
3. Open a command prompt at the **intunewin** tool folder and run the following command:

   `Intunewinapputil -c "<Drive>:\<Path>\Adaptiva\FullClient\" -s adaptiva-client-<version>-windows.exe -o "<Drive>:\<Path>\Adaptiva\FullClient\"`

   * The installer name will be **AdaptivaClientSetup.exe** if you sourced it from a SaaS-based client.
4. The `<executable_name>.intunewin` will be created in the FullClient folder.

### Create Intune App for Full Installer

1. Log into the Microsoft Intune admin center (<https://intune.microsoft.com>) using the account with the appropriate role assignment.
2. In the left-hand navigation pane, click **Apps**, then click **All Apps**.

   ![](/files/TYuQuQHyMw9RsfyzI7kM)
3. Click **+ Create**.
4. In the right pane, select the **App type** drop-down.
5. Under **Other**, select **Windows app (Win32)**.

   ![](/files/oOzJwkaacYBeNYFtiGr9)
6. Click **Select**.
7. The **Add App** pane appears.

   ![](/files/hVm0XZ890KBlc2ISxXqK)
8. Click **Select app package file**.
9. In the right pane, click on the folder icon.

   ![](/files/wQzzwCbJ76zYK9MfTZRJ)
10. Browse to the path with the .intunewin file you created using the winapputil tool: `<Drive>:\<Path>\Adaptiva\FullClient` and select the `<executable_name>.intunewin` file. Click **Open**.
11. The right pane will be updated with the package file details. Click **OK**.
12. Under the **App Information** step, update the properties with these and any other values as appropriate. These are user facing values.

    ![](/files/dC3YAIaWpHFLaEbKCHSe)

    * **Name** and **Description**: Update the name and description to user friendly values.
    * **Publisher**: Adaptiva
13. Update the other fields as necessary and click **Next**.
14. On the **Program** tab, enter the following:

    ![](/files/Xtwmz5os9uJKBKYzkZVe)

    * **Install command**:

      Since you are installing from Intune, you should include the -CloudRelay and -ServerGUID parameters, which enables the client to use the Cloud Relay Service to connect when off-premises. **SaaS customers** will need the -Password parameter, but will not need the -CloudRelay parameter.

      `adaptiva-client-<version>-windows.exe -InstallorUpgrade -ServerName *AdaptivaServer.FQDN* -CloudRelay -ServerGUID <GUID> [-Password and other optional parameters]`
    * **Uninstall command**: `adaptiva-client-<version>-windows.exe -uninstall`
    * **Install behavior**: System
    * **Device restart behavior**: No specific action.
15. Click **Next**.
16. On the **Requirements** tab, click **Yes. Specify the systems the app can be installed on.**
17. Click to select the **Install on x86 system** and **Install on x64 system** checkboxes.
18. Select the **Minimum operating system** your organization supports.
19. Complete any additional requirements as needed.

    ![](/files/4IYulSJRbSTlrDeACADr)
20. Click **Next**
21. On the **Detection Rules** tab, click the **Rules format** drop-down and select **Manually configure detection rules**.

    ![](/files/tRpQ5FBnZWpXSB70TkZw)
22. Click **+ Add**
23. In the right-hand pane, click the **Rule type** dropdown and select **Registry**.

    ![](/files/YpY2g8cqAYB9QcwybrmK)
24. Create the following rule:

    ![](/files/u3gcpu3Ar7wgtmCtqjlV)

    * **Key path**: HKEY\_LOCAL\_MACHINE\Software\Adaptiva\Client
    * **Value name:** slm.version
    * **Detection method**: Value comparison
    * **Operator**: Less than
    * **Value**: 10.1.972.12
    * **Associated with a 32-bit app on 64-bit clients**: No
25. Click **OK**.
26. Click **Next**.
27. On the **Dependencies** tab, click **Next**.

    ![](/files/mcakeLzLMCUeKqarKVeS)
28. On the **Supersedence** and **Scope tags** tabs, click **Next**.
29. On the **Assignments** tab, configure assignments for the following groups. Assignments do not need to be entered right now; they can be entered later.

    ![](/files/ZU6yLmfv5JZDnl7xLtKP)

    Add a group to **Required** to force the installation.

    Add a group to **Available** for enrolled devices to make the installation optional via the Company Portal app. When adding a group to Available, the group must contain Users, not Devices.

    Add a group to **Uninstall** for managed devices to have this app removed.
30. Click **Next**.
31. Review the App information and click **Create**.


# Distribute macOS installer

How to deploy the adaptiva macOS client with Microsoft Intune.

## Overview

You can easily add the Adaptiva macOS client installer as a macOS app (PKG) in Microsoft Intune. This will distribute the client to macOS devices and configure their connection to the Adaptiva server.

If you are using a SaaS instance, the installation configuration will differ. Skip to the instructions for a [SaaS client deployment using Intune](#saas-client-deployment-using-intune).

### Access the Adaptiva Client

The Adaptiva Client is available from the Installation folder of the installation media. You can download the latest release from the [Product Releases](https://support.adaptiva.com/hc/en-us/sections/201965326-Product-Releases) section of the Adaptiva Support Portal.

### Create macOS App

1. Log into the Microsoft Intune admin center (<https://intune.microsoft.com>) using the account with the appropriate role assignment.
2. In the left-hand navigation pane, click **Apps**, then click **All Apps**.

   ![](/files/TYuQuQHyMw9RsfyzI7kM)
3. Click **+ Add**.
4. In the Select app type pane, click the **App type** drop-down.
5. Under the Other app types, select **macOS app (PKG)**.

   ![](/files/LmVwUoF4ClHXZtAreUcc)
6. Click **Select** to open the Add App steps.

### Select the app package file

1. On the **App Information** pane, click **Select app package file**.

   ![](/files/dmRaBlCMV0TX1imL2boc)
2. In the App package file pane, select the **Browse** button. Browse to the path where the installation files were located and select the `adaptiva-client-<version>-macOS.pkg` file. Click **Open**. The app details are displayed.
3. Click **OK** on the App package file pane to add the app.
4. On the **App information** page, update the properties with these and any other values as appropriate. These are user facing values.

   ![](/files/LvO3yuf9bA4KHF9XQ2iT)

   * **Name** and **Description**: Update the name and description to user friendly values.
   * **Publisher**: Adaptiva
5. Complete any addition app information and click **Next**.
6. On the **Program** page, enter the following **Post-install script**:

   ```bash
   #! /bin/bash
   sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl setup -server <hostname> -server-guid <guid>
   ```

   * Update the configuration script with any valid parameters. See the [adaptivactl command line parameters](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-install/client-install-linux-macos#adaptivactl-command-line-parameters) reference for details.

   ![](/files/d4dxOKbkbRyYQYXCotJy)
7. Click **Next**.
8. Click the Minimum operating system drop-down and select **macOS Ventura 13.0**.

   ![](/files/JT1THWQdA5dYuMW6ZLu1)
9. Click **Next**.
10. On the **Detection Rules** tab, ensure **Yes** is selected for ignore app version. Update the **App Version** to the version listed in the name of the .pkg file.
11. Click **Next**.
12. On the **Supersedence** and **Scope tags** tabs, click **Next**.
13. On the **Assignments** tab, configure assignments for the following groups. Assignments do not need to be entered right now; they can be entered later.

    ![](/files/ZU6yLmfv5JZDnl7xLtKP)

    Add a group to **Required** to force the installation.

    Add a group to **Available** for enrolled devices to make the installation optional via the Company Portal app. When adding a group to Available, the group must contain Users, not Devices.

    Add a group to **Uninstall** for managed devices to have this app removed.
14. Click **Next**.
15. Review the App information and click **Create**.

## SaaS Client Deployment using Intune

If you are using a SaaS instance, you can access the macOS installation script (`adaptiva-client-<version>-install-unix.sh`) from the Cloud Admin Portal.

![](/files/a88l9mhdqyZbuJsqDLMs)

{% hint style="info" %}
If the Authorization token is updated, you must re-download the installation script and update your macOS script. See these instructions [if the authorization token is updated](#if-authorization-token-updated).
{% endhint %}

1. Log in to your cloud tenant and click the **settings gear > Settings > Client Downloads**. Download the macOS Client installation script to an accessible location.
2. Log into the Microsoft Intune admin center (<https://intune.microsoft.com>) using the account with the appropriate role assignment.
3. In the left-hand navigation pane, click **Devices**.
4. Under **By platform**, click **macOS**. Then under **Manage devices**, click **Scripts**.

   ![](/files/5eTItqp3UHbJfax1Qwwv)
5. Click **+ Add**.

   ![](/files/5I0wiRE71pmOKAVFhCmR)
6. On the **Basics** page, enter a **Name** and **Description** for the script policy, then select **Next**.
7. On the **Script settings** page, click the **Browse** button. Browse to the path where the macOS install script is located and select the `adaptiva-client-<version>-install-unix.sh` file. Click **Open**. The script details are displayed.
8. Configure the following script settings:

   * Run script as signed-in user: **No**
   * Hide script notifications on devices: **Not Configured**
   * Script frequency: **Not Configured**, this will run the script only 1 time.
   * Max number of times to retry if script fails: **Not Configured**.

   ![](/files/FKEhVQp7pyEjnKUYQZIf)
9. Select **Next**.
10. On the **Scope tags** tab, click **Next**.
11. On the **Assignments** tab, configure assignments for the following groups. Assignments do not need to be entered right now; they can be entered later.

    ![](/files/qlWOTwOY7zUU8PuxTQ90)

    Add a group to **Included groups** to install the client on these devices.

    Add a group to **Excluded groups** if necessary.
12. Click **Next**.
13. Review the script information and click **Add**.

### If authorization token updated

1. On the macOS | Scripts page, select the previously created script.
2. Under **Manage**, click **Properties**.
3. In the details pane, next to **Settings**, click **Edit**.
4. Click the **Browse** button, and browse to the updated .sh file. Click **Open**.
5. Click **Review + save**.
6. Review the script information and click **Save**.


# Deploy clients with ConfigMgr

Client Installation using ConfigMgr

You can use ConfigMgr to perform a large-scale, production deployment of the Adaptiva client. As with all Software Distribution in ConfigMgr, the first step is to create the package and program(s). If you are using Operating System Deployment, a package and program will be needed in the task sequence, do not use an application.

The application model can also be used for Adaptiva client deployment outside of a task sequence.

## (SaaS only) Access the Full Adaptiva Client

**For users of OneSite Patch SaaS**, you will need to download and install the Adaptiva P2P client to gain access to the full Adaptiva client.

1. Follow these [steps to download and install](/platform-install/client-install-and-uninstall/client-install#saas-client-installation) the Adaptiva P2P Client on a device.
2. On the new device, navigate to `C:\` and show hidden folders.
3. Navigate to the hidden `C:\AdaptivaCache\Client` folder and copy `AdaptivaClientSetup.exe` to an accessible location.

## Create a Package from the Package Definition File

To facilitate creating a pre-defined ConfigMgr package and program, the Adaptiva server provides a Package Definition File. You can find the **AdaptivaClientSetupSilent.sms** file on the Adaptiva server under `<InstallPath>\Program Files\Adaptiva\AdaptivaServer\config`.

1. Create a new folder called **Adaptiva** in the content source file repository.
2. Copy the `adaptiva-client-<version>-windows.exe` file from the installation source to the new folder.
3. Rename the client installer to **AdaptivaClientSetup.exe**. *This is an essential step to ensure a successful package configuration.*
4. In the ConfigMgr console, open the **Software Library** workspace.
5. In the navigation pane, expand **Application Management**, then right-click **Packages** and select **Create Package from Definition**.

   <img src="/files/PyRpdm5ouVaKf3KrLh25" alt="" width="50%">
6. On the **Package Definition** page, click **Browse** and navigate to `<InstallPath>\Program Files\Adaptiva\AdaptivaServer\config` folder on the Adaptiva server and select the **AdaptivaClientSetupSilent.SMS** file.
7. Click **Open**. The package name and version will be displayed. Select it and then click **Next**.

   <img src="/files/jESKty7CTHVYvDDGnFGP" alt="" width="50%">
8. At the **Source Files** page, select **Always obtain source files from a source folder** and click **Next**.

   <img src="/files/oG0A5ivNxSyWBY2mAGdM" alt="" width="50%">
9. At the **Source Folder** page, enter the UNC path to the **Adaptiva** folder created in step 1 and click **Next**.

   <img src="/files/p1pHod1E4x2e9h179yix" alt="" width="50%">
10. Complete the **Create Package from Definition Wizard**. This will create a new **AdaptivaClient** package.
11. Click the **Programs** tab under the package details.

The package includes 8 programs for the installation, upgrade, and uninstallation of the Adaptiva client.

| Name                              | Command Line                                                                                                                  | Description                                                                                                        |
| --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| CleanInstall                      | `AdaptivaClientSetup.exe -cleaninstall -servername <ServerFQDN>`                                                              | Uninstalls The Adaptiva Client Health And OneSite Client, And Installs It Again                                    |
| CleanInstallInternet              | `AdaptivaClientSetup.exe -cleaninstall -servername <ServerFQDN> -serverguid <ServerGUID> -cloudrelay`                         | Uninstalls The Adaptiva Client Health And OneSite Client, And Installs It Again - Supports Cloud Relay             |
| CleanInstallInternetNoCacheDelete | `AdaptivaClientSetup.exe -cleaninstall -servername <ServerFQDN> -nocachedel -serverguid <ServerGUID> -cloudrelay -nocachedel` | Uninstalls The Adaptiva Client Health And OneSite Client, And Installs It Again - Supports Cloud Relay             |
| CleanInstallNoCacheDelete         | `AdaptivaClientSetup.exe -cleaninstall -servername <ServerFQDN> -nocachedel`                                                  | Uninstalls The Adaptiva Client Health And OneSite Client, And Installs It Again                                    |
| InstallOrUpgrade                  | `AdaptivaClientSetup.exe -installorupgrade -servername <ServerFQDN>`                                                          | Installs The Adaptiva Client Health And OneSite Client, Or Upgrades It If Already Installed                        |
| InstallOrUpgradeInternet          | `AdaptivaClientSetup.exe -installorupgrade -servername <ServerFQDN> -serverguid <ServerGUID> -cloudrelay`                     | Installs The Adaptiva Client Health And OneSite Client, Or Upgrades It If Already Installed - Supports Cloud Relay |
| Uninstall                         | `AdaptivaClientSetup.exe -uninstall`                                                                                          | Uninstalls the Adaptiva Client Health And OneSite Client                                                           |
| UninstallNoCacheDelete            | `AdaptivaClientSetup.exe -uninstall -nocachedel`                                                                              | Uninstalls the Adaptiva Client Health And OneSite Client                                                           |

{% hint style="info" %}
You can find more information on the Adaptiva client installation switches in the [Client Install](/platform-install/client-install-and-uninstall/client-install) documentation.
{% endhint %}

By default, these programs will be set to display notifications to users when deployed unless notifications are suppressed via client policy.

12. To disable notifications, right-click the program and click **Properties**.
13. Click the **Advanced** tab.
14. Check the **Suppress program notifications** checkbox and click **OK**.

    <img src="/files/Ke8730jyv3JDzlj9BKjr" alt="" width="50%">

You can now deploy the program to collections of devices in your environment.

## Create an Application using the EXE

You can also deploy the Adaptiva client by creating a ConfigMgr application and deployment type using the `adaptiva-client-<version>-windows.exe`.

1. Create a new folder called **Adaptiva** in the content source file repository.
2. Copy the `adaptiva-client-<version>-windows.exe` file from the installation source to the new folder.
3. In the ConfigMgr console, open the **Software Library** workspace.
4. In the navigation pane, expand **Application Management**, then right-click **Applications** and click **Create Application**. The Create Application Wizard appears.
5. On the General page, select **Manually specify the application information** and click **Next**.

   <img src="/files/rSgxxQQ5JxZ9ARKR6hGz" alt="" width="50%">
6. On the General Information page, enter the information:

   Name: **Adaptiva Client Setup**

   Publisher: **Adaptiva**

   Software version: `<version>`

   Enter the other fields as required by your company's standards.
7. Click **Next**.
8. On the Software Center page enter the information as required by the company's standards and click **Next**.
9. On the Deployment Types page, click **Add...**. The Create Deployment Type Wizard appears.

   <img src="/files/89i2Kc51LMJfKPMvZaug" alt="" width="50%">
10. On the General page, click the **Type** drop-down and select **Script Installer**.
11. The **Manually specify the deployment type information** radion button will be automatically selected. Click **Next**.
12. On the General Information page, enter a Name of **Adaptiva Client Setup**, then click **Next**.
13. On the Content page, next to Content location, click **Browse**.
14. Select **Browse...** and enter the UNC path to where the Adaptiva client was copied.
15. Next to Installation program, click Browse and select the `adaptiva-client-<version>-windows.exe` file.
16. Add the following switches to the Installation program:

    `adaptiva-client-<version>-windows.exe -INSTALLORUPGRADE -SERVERNAME <serverfqdn> | -SERVERIP <serveripaddress> -CloudRelay`

    If you are using the Cloud Relay service or if HTTP client communications will be used, include the following switches:

    Cloud Relay service: `-CloudRelay`, `-ServerGUID <GUID>`, `-Password <Secret>` HTTP communications: `-ServerURL <ServerURL:port>`
17. Next to Uninstall program, click Browse and select select the `adaptiva-client-<version>-windows.exe` file.
18. Add the following switches to the Uninstall program:

    `adaptiva-client-<version>-windows.exe -UNINSTALL`

{% hint style="info" %}
You can find more information on the Adaptiva client installation switches in the [Client Install](/platform-install/client-install-and-uninstall/client-install) documentation.
{% endhint %}

19. Click **Next**.

#### Create Detection Method

1. On the Detection Method page, click **Add Clause...**.
2. From the Setting Type drop-down, select **Registry**.
3. Next to Hive, click **Browse...**.
4. Enter the Adaptiva Server computer name and click **Connect**.
5. Expand the Adaptiva server node and navigate to `HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\AdaptivaClient`.
6. In the Registry Value pane, select **DisplayName** and click **OK**.
7. Select the **This registry setting must satisfy the following rule to indicate the presence of this application** radio button. The current value will be automatically entered.
8. Click **OK**.

#### Complete the Wizard

1. Click **Next**.
2. On the User Experience page, next to Installation behavior, select **Install for system**.
3. Next to Logon requirement, select **Whether or not a user is logged on**.
4. Next to Installation program visibility, select **Hidden**.
5. Click **Next**.
6. On the **Requirements** page, click **Next**.
7. On the **Dependencies** page, click **Next**.
8. On the **Summary** page, click **Next** and then click **Close** when the wizard has completed successfully.
9. On the Deployment Types page, click **Next**.
10. Click **Next** on the Summary page and then click **Close** when the wizard has completed successfully.
11. Right-click the **Adaptiva Client Setup** application and click **Distribute Content**.
12. Complete the Distribute Content Wizard with the necessary Distribution Point or Distribution Point Group.

## Create an Application using the P2P MSI

You can distribute the Peer-to-peer (P2P) installer using a ConfigMgr application and deployment type.

1. Create a new folder called **Adaptiva** in the content source file repository.
2. Copy the `adaptiva-client-p2p-<version>-windows.msi` file from the installation source to the newly created folder.
3. In the ConfigMgr console, open the **Software Library** workspace.
4. In the navigation pane, expand **Application Management**, then right-click **Applications** and click **Create Application**. The Create Application Wizard appears.
5. On the General page, click **Browse...**, enter the UNC path to the content source and select the `adaptiva-client-p2p-<version>-windows.msi` file. Click **OK**.
6. Click **Next**.
7. On the **View imported information page**, verify that the application information was successfully imported from the Windows Installer (\*.msi file) and click **Next**.
8. On the **General Information** page, update any information as required. We recommended that you at least add the Publisher and Software version information.
9. Next to Installation program, update the command line using the following switches:

   ```cmd
   msiexec.exe /I adaptiva-client-p2p-<version>-windows.msi /qn SERVERNAME=<ServerFQDN> SOURCEUNCPATH=\\<ServerFQDN>\AdaptivaClient\AdaptivaClientSetup.exe WAITFORCOMPLETION=1
   ```

   If you are using the Cloud Relay service or if HTTP client communications will be used, include the following switches:

   Cloud Relay service: `-CloudRelay`, `-ServerGUID <GUID>`, `-Password <Secret>` HTTP communications: `-ServerURL <ServerURL:port>`
10. Click **Next**.
11. On the **Summary** page, click **Next** and then click **Close** when the wizard has completed successfully.
12. In the Applications details, select the **Adaptiva Peer To Peer Client Installer** application.
13. Select the **Deployment Types** tab in the application details.
14. Right-click the deployment type and click **Properties**.
15. Select the **Content** tab.
16. Check the **Allow clients to use distribution points from the default site boundary group** box.
17. Next to Deployment options, select **Download content from distribution point and run locally**.
18. Select the **Detection Method** tab.

    Notice the detection method. The MSI product code is specific to this version of the Adaptiva Client P2P Installer.
19. Click **OK**.
20. To make this visible in Software Center, right-click the application and click **Properties**.
21. On the General Information and Software Center tabs, update the information as required per the company's standards. Click **OK** when finished.
22. Right-click the application and click **Distribute Content**.
23. Complete the Distribute Content Wizard with the necessary Distribution Point or Distribution Point Group.


# Deploy clients with Jamf

Jamf instructions to deploy clients

You can use Jamf to perform a large-scale, production deployment of the Adaptiva client for macOS. The general shape of this process follows:

1. At the command line, install the package.
2. In Jamf, add a configuration script.
3. In Jamf, configure a policy.
4. At the command line, run the configuration script.

More detail for each of these steps is provided below.

## Install the Package File

The Adaptiva client for Mac is a package file (.pkg) found in the installer zip. You will need to know the version number, so you may want to extract files from the zip before you begin.

1. At the command line, type the following: `sudo installer -tgt / -pkg ./adaptiva-client-<version>-macOS.pkg`
2. Open Jamf.

{% hint style="info" %}
You can find more information on Adaptiva client installation and macOS in the [Client Installation on Linux or macOS](https://docs.adaptiva.com/platform-install/client-install/client-install#client-installation-on-linux-or-macos) documentation.
{% endhint %}

## Link the Package File to Jamf

When you get to the script stage of this process, Jamf will need to know how to find the package file. You can set those parameters in a New Package dialog.

1. In Jamf, go to **Settings > Computer Management > Packages**.
2. Click **New Package**.
3. Check to make sure you have selected the **General** tab.
4. In the **Filename** box, browse to the **adaptiva-client-\<version>-macOS.pkg** file or drag the file into the box.
5. In the **Display name** box, type **Adaptiva**.
6. In the **Category** dropdown, select **Utilities**.

   ![New package screen](/files/If7ZFfkimc2YRvBYx1kS)

## Add a Script to the New Package

For each device, a post-install script runs to configure the Adaptiva client with information like your server name and GUID. You can store the script in Jamf and link it to the package.

1. In Jamf, go to **Settings > Computer Management > Scripts**.
2. Click **New Script**.
3. Check to make sure you have selected the **General** tab.
4. In the **Display name** box, type **Adaptiva**.
5. In the **Category** dropdown, select **Utilities**.
6. Select the **Script** tab.
7. Customize and save the following script: `sudo /opt/adaptiva/adaptivaclient/bin/adaptivactl setup --server <server address> --server-guid <server GUID> --no-connection-checks`

   ![New Script screen](/files/Tc14oDydAzBQn7zUhQWC)

## Set a Policy for the Package

**Configure the Policy**

You'll want to configure a new policy that connects the Adaptiva script to policy options, such as triggers and execution frequency. By setting options at the policy level, you gain flexibility and easier management across different environments.

1. In Jamf, go to **Computers > Policies**.
2. Click **New Policy**.
3. Check to make sure you have selected the **Options** tab and **General** settings.
4. In the **Display Name** box, give the policy a meaningful name, such as **PRA install - Checkin with Limited Scope**.
5. In the **Trigger** section, select **Recurring Check-in**.
6. In the **Execution Frequency** dropdown, select **Once per computer**.
7. Set any other optional parameters.
8. When asked for details, add the Adaptiva package.

   ![New Policy screen](/files/05UenNp0SVpBl4XGT8jS)

**Set a Scope for the Initial Deployment**

For the initial deployment, you should limit the scope for a test run.

1. On the **New Policy** screen, check to make sure you have selected the **Scope** tab.
2. In the **Target Computers** dropdown, select **Specific Computers**.
3. In the **Target Users** dropdown, select **Specific Users**.

   ![Scope tab](/files/wegiB37W5Gg3AddQQUdl)

## Run the Configuration Script

**Prerequisites**

Before you run the configuration script, be sure to have the following pieces in place:

* Jamf policy
* Recurring check-in trigger
* Once-per-computer execution frequency
* Adaptiva package installed

**Run the Script**

1. At the Command Line, launch the policy by typing the following: `sudo jamf policy`
2. You may have to provide your credentials.
3. Jamf will check for policies triggered by **recurring check-in** for your user name.
4. You should see the text **Executing Policy Adaptiva** and a series of automated status reports.
5. A validator runs inside the script to make sure the connections are set up correctly.

## Validate the Deployment

In the Adaptiva Admin Portal, you can see whether Jamf and Adaptiva have communicated successfully with the devices in the Scope you set for this deployment.

1. In the Adaptiva Admin Portal, got to **Platform Features**, and then navigate to **Asset Devices**.
2. Confirm that the Adaptiva client is present.
3. You can also confirm any updates to the OS, client version, or product compliance.

{% hint style="info" %}
You can find more information about the various validation checks available in Adaptiva in the [Client Validator](https://docs.adaptiva.com/platform-guide/client-management/client-validator) documentation.
{% endhint %}


# Uninstall Client

How to uninstall Adaptiva clients on Windows, macOS, and Linux devices.

## Uninstall the Windows client

The experience to uninstall the Adaptiva Client changes slightly between the full Windows installer and the P2P installer.

### Full Windows Installer

Run the `adaptiva-client-<version>-windows.exe` and select the **Uninstall** button. To run the uninstallation silently, run the corresponding installation executable with a `-uninstall` switch on the command-line.

For example:

```shell
adaptiva-client-<version>-windows.exe -uninstall
```

### Windows P2P Installer

The Peer-to-Peer (P2P) client MSI installer can also be used to perform a client uninstallation. You can run the installer and select the **Uninstall** button or you can run a silent uninstallation from the command-line with the `-uninstall` switch.

For example:

```shell
msiexec.exe /i adaptiva-client-p2p-<version>-windows.msi /qn UNINSTALL=1
```

### Uninstall with cached data

This uninstall command removes any version of the Adaptiva Client, whereas the standard Windows Installer parameter (/x) only removes the specific version associated with the MSI, since each MSI is version-specific.

* Uninstall and leave the files in the AdaptivaCache folder:

  ```shell
  msiexec.exe /I adaptiva-client-p2p-<version>-windows.msi /q UNINSTALL=1 NOCACHEDEL=1
  ```

## Uninstall the Linux Client

Open a command shell and run the following command:

```bash
sudo apt remove adaptiva-client
```

or

```bash
sudo dnf remove adaptiva-client
```

or

```bash
sudo zypper remove adaptiva-client
```

## Uninstall the MacOS Client

Open a command shell and run the following command:

```zsh
sudo /opt/adaptiva/adaptivaclient/bin/uninstall
```


# Communication ports

## List of All Adaptiva Ports

[List of All Adaptiva Ports](https://adaptiva.com/hubfs/Docs/OneSite-Port-Detail.pdf).

## Communication Port and Flow Diagrams

[Communication Port and Flow Diagrams](https://adaptiva.com/hubfs/Docs/OneSite-Communications-Port-and-Flow-Diagram.pdf).

## Additional Firewall Rules

### Adaptiva Server Firewall Rule NETSH Commands

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Server -- 1\" action=allow dir=in enable=yes profile=domain localport=34545 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Server -- 2\" action=allow dir=in enable=yes profile=domain localport=34339 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Server -- 3\" action=allow dir=in enable=yes profile=domain localport=34341 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Server -- 4\" action=allow dir=in enable=yes profile=domain localport=34331 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Server -- 5\" action=allow dir=in enable=yes profile=domain localport=34333 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Server Service\" action=allow dir=in enable=yes profile=domain protocol=any edge=no program=\<AdaptivaServerInstallPath\>\\AdaptivaServer\\bin\\AdaptivaServerService.exe
```

### Adaptiva Client Firewall Rule NETSH Commands

Sometimes client VPN solutions or corporate Wi-Fi networks may show as Public or Private profile; therefore, it is often best to add the rule to all profiles for clients. To do this change the **profile=domain** values for each line to **profile=domain,private,public**

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client Service\" action=allow dir=in enable=yes profile=domain,private,public protocol=any edge=no program=\"\<path\>\\Adaptiva\\AdaptivaClient\\bin\\AdaptivaClientService.exe\"
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client\" action=allow dir=in enable=yes profile=domain,private,public localport=34760,34750,34546,34335,34337,34343,34345 protocol=udp edge=no
```

The following rules are deprecated:

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client -- 1\" action=allow dir=in enable=yes profile=domain localport=34760 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client -- 2\" action=allow dir=in enable=yes profile=domain localport=34750 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client -- 3\" action=allow dir=in enable=yes profile=domain localport=34546 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client -- 4\" action=allow dir=in enable=yes profile=domain localport=34335 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client -- 5\" action=allow dir=in enable=yes profile=domain localport=34337 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client -- 6\" action=allow dir=in enable=yes profile=domain localport=34343 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client -- 7\" action=allow dir=in enable=yes profile=domain localport=34345 protocol=udp edge=no
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client Service\" action=allow dir=in enable=yes profile=domain protocol=tcp edge=no program=\<*path*\>\\AdaptivaClient\\bin\\AdaptivaClientService.exe
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Client Service\" action=allow dir=in enable=yes profile=domain protocol=udp edge=no program=\<*path*\>\\AdaptivaClient\\bin\\AdaptivaClientService.exe
```

### Adaptiva Workbench Firewall Rule NETSH Commands

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Workbench\" action=allow dir=in enable=yes profile=domain protocol=udp edge=no program=\<*AdaptivaServerInstallPath*\>\\AdaptivaWorkbench\\AdaptivaWorkbench.exe
```

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva Workbench\" action=allow dir=in enable=yes profile=domain protocol=tcp edge=no program=\<*AdaptivaServerInstallPath*\>\\AdaptivaWorkbench\\AdaptivaWorkbench.exe
```

### Adaptiva Server to ACC Firewall Rule NETSH Commands

This should be run on the Adaptiva Server when outbound rules are restricted.

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva to ACC\" action=allow dir=out enable=yes profile=domain protocol=udp remoteport=34320 edge=no \[remoteip=\<ACC IP Address\>\]
```

This should be run on the Adaptiva Server when inbound rules are restricted

```netsh
netsh advfirewall firewall add rule name = \"ACC to Adaptiva UDP\" action=allow dir=in enable=yes profile=domain protocol=udp localport=34323 edge=no \[remoteip=\<ACC IP Address\>\]
```

```netsh
netsh advfirewall firewall add rule name = \"ACC to Adaptiva HTTPS\" action=allow dir=in enable=yes profile=domain protocol=tcp localport=54322 edge=no \[remoteip=\<ACC IP Address\>\]
```

### ACC to Adaptiva Server Firewall Rule NETSH Commands

This should be run on the ACC Server when inbound rules are restricted. The range 192.30.64.0-192.30.79.255 are public IP Addresses for AirWatch servers.

```netsh
netsh advfirewall firewall add rule name = \"Adaptiva to ACC\" action=allow dir=in enable=yes profile=domain protocol=udp localport=34320 edge=no \[remoteip=\<Adaptiva IP Address\>\]
```

```netsh
netsh advfirewall firewall add rule name = \"Airwatch\" action=allow dir=in enable=yes profile=domain protocol=tcp localport=443 edge=no \[remoteip=192.30.64.0-192.30.79.255\]
```

This should be run on the ACC Server when outbound rules are restricted.

```netsh
netsh advfirewall firewall add rule name = \"ACC to Adaptiva UDP\" action=allow dir=out enable=yes profile=domain protocol=udp remoteport=34323 edge=no \[remoteip=\<Adaptiva IP Address\>\]
```

```netsh
netsh advfirewall firewall add rule name = \"ACC to Adaptiva HTTPS\" action=allow dir=out enable=yes profile=domain protocol=tcp remoteport=54322 edge=no \[remoteip=\<Adaptiva IP Address\>\]
```

```netsh
netsh advfirewall firewall add rule name = \"Airwatch\" action=allow dir=out enable=yes profile=domain protocol=tcp remoteport=443 edge=no \[remoteip=192.30.64.0-192.30.79.255\]
```


# SPNs and delegation

In order to support moving to dedicated SQL Servers or SQL Always On Availability Groups, you will need to configure SPNs (Service Principle Name) and Kerberos delegations in your environment. This article is helpful to understand the principles of SQL Server connectivity: <http://support.microsoft.com/kb/2443457>.

## Create the SPNs

For Windows 2019 or earlier, we recommend using the Kerberos Configuration Manager utility, which can be downloaded from [Microsoft](https://www.microsoft.com/en-us/download/details.aspx?id=39046). This tools is not supported beyond Windows 2019 and SQL Server 2019.

{% hint style="info" %}
This utility may not work if the SQL Server is in a different domain than the SQL Service accounts or if there are many groups added to the local Administrators group.
{% endhint %}

### Use Kerberos Configuration Manager to set SPN's

*Only supported on Windows 2019 and SQL Server 2019 or earlier.*

Use the following steps in Kerberos Configuration Manager.

1. Log into the SQL Database server using an account in the local Administrators group.
2. Install the Kerberos Configuration Manager utility.
3. Navigate to **C:\Program Files\Microsoft\Kerberos Configuration Manager for SQL Server** and launch **KerberosConfigMgr.exe**.
4. Click **Connect** from the menu and then click **Connect** without entering any info.
5. Select the **SPN** tab.
6. Scroll all the way to the right and notice the Required SPN and Status columns.

{% hint style="info" %}
These next steps must be done with a Domain Admin account. They do not have to be executed on the database server.
{% endhint %}

1. If able to modify the service accounts, click on **Fix All** (or do them individually) otherwise, click **Generate All**, enter a file name and provide that script to an administrator with the appropriate permissions.
2. After the fix script(s) has been run, to confirm the SPNs have been created successfully, click on **Refresh**. Scroll to the right to confirm the status is **Good** for all rows.

### Use setspn command-line tool to set SPN's

Use the `setstpn` command line tool to create the SPN's.

1. Log into the SQL Database server using an account in the local Administrators group.
2. Open an administrative command prompt and type:

   ```shell
   setspn -L <domain>\<serviceaccount>
   ```

   For example, executing this command will return the following:

   ```shell
   C:\Users\administrator>setspn -L <domain>\sqlservice
   Registered ServicePrincipalNames for CN=SQLService,OU=Accounts,DC=<DOMAIN>,DC=lab:
   MSSQLSvc/SQLSERVER.<DOMAIN>.lab:1433
   MSSQLSvc/SQLSERVER.<DOMAIN>.lab
   ```

{% hint style="info" %}
These next steps must be done with a Domain Admin account. They do not have to be executed on the database server.
{% endhint %}

1. Create the SPNs:

   ```shell
   setspn -S MSSQLSvc/<NetBiosName> <domain>\<serviceaccount>

   setspn -S MSSQLSvc/<FQDN> <domain>\<serviceaccount>

   setspn -S MSSQLSvc/<FQDN>:<port> <domain>\<serviceaccount>
   ```
2. Rerun the following command and confirm the SPNs exist correctly:

   ```shell
   setspn -L <domain>\<serviceaccount>
   ```

   * If using with SQL Always On Availability Groups, then repeat the above steps on database server #2. This should ALSO be done with the AG Listener.

### Verify SPN setup

{% hint style="info" %}
Remote Server Administration Tools (RSAT) must be installed in order to use **Active Directory Users and Computers**. For more information, please see Microsoft's documentation guide: [Install and manage Remote Server Administration Tools in Windows](https://learn.microsoft.com/en-us/windows-server/administration/install-remote-server-administration-tools?tabs=server-manager%2Cdesktop-experience\&pivots=windows-server-2022).
{% endhint %}

After the SPNs have been setup:

1. Open Active Directory Users and Computers.
2. Click **View | Advanced Features**. This is required to see the Attribute Editor property of the service account object.
3. Select the **Accounts** folder.
4. Right-click the service account and select **Properties**.
5. Select the **Attribute Editor** tab. This is only visible with the Advanced Features view enabled.
6. Find the `servicePrincipalName` property and open it.

Confirm the SPNs are listed for the server(s) FQDN both with and without the port number.

You can also use the **setspn** command line tool to view these attributes by running the following command:

`setspn -L KAIBAB\AdaptivaSQLServer`

![](/files/tzAEnW2Lc2pVoeeXbEqZ)

## Delegate Kerberos authentication

Because the SQL Server is on a different server than the Adaptiva Server it is required to setup Kerberos trust delegation. The following steps cannot be done if the SPNs have not been setup correctly.

{% hint style="info" %}
These next steps must be done with a Domain Admin account.
{% endhint %}

1. Open **Active Directory Users and Computers**.
2. Select the **Accounts** folder.
3. Right-click the service account and select **Properties**.

   ![](/files/M3zPE7OdeABb0VwkcUwe)
4. Select the **Delegation** tab.
   * If SPNs have not been setup correctly, then this tab will not be available.
5. Select **Trust this user for delegation to specified services only** and select **Use Kerberos only**.
6. Click on **Add...**.
7. Click on **Users or Computers...**.
8. Enter the Service account name and click **Check Names** then click **OK**.
9. In the list of Available services, select all the entries with **MSSQLSvc** for the SQL Database server as appropriate and click **OK**.

   ![](/files/dDgCxBvK16G4B6Tf88dT)

   You must select the entries for them to be added.

   ![](/files/nePN4z6a1rvlct5YTULF)
10. Click **OK** to close the Properties box.
11. Log on to the SQL Server(s) and using SQL Server Configuration Manager, restart the SQL Server service (or Restart the server).

## Confirm the Configuration

Once the SPNs and the Kerberos delegations have been configured, use SQL Management Studio to confirm the connection properties (Kerberos Configuration Manager can also be used):

1. Click on the **Delegation** tab to confirm the delegations have been setup correctly
   * The details will state - *No obvious delegation issues*.
2. Log onto a different server than SQL database server that has SQL Management Studio installed.
3. Connect to the remote SQL Database server **Connect > Database Engine > enter the server name**.
4. Open a New Query Window on the remote database server and **Execute** the following query:

   `select auth_scheme from sys.dm_exec_connections where session_id=@@spid`
5. The result back should be **Kerberos**.

## Create the Linked Servers

Ensure that TCP/IP connections are enabled in SQL Configuration Manager.

When the Adaptiva database is on a different SQL Server then the ConfigMgr database, the Linked Servers must be manually created.

1. In **SQL Management Studio** with a connection to the ConfigMgr SQL database server, expand **Server Objects**, **Linked Servers**
2. Right-click on **Linked Servers** and click **New Linked Server**.
3. On the New Linked Server page, enter the following:

   Linked server: `<AdaptivaSQLServerFQDN>`

   Select **SQL Server**.
4. On the **Security** page, select **Be made using the login's current security context**.

   The account used must **NOT** have the setting enabled. Account is sensitive and cannot be delegated.
5. On the **Server Options** page, set the **Collation Compatible** field to **True**.

   ![](/files/eguO2aXua8FB5210j52A)
6. Click **OK**.
   * If SQL Always On Availability Groups are being used, repeat the above steps connected to database server #2 and connected to the Availability Group Listener.

Now repeat the above steps connecting to the Adaptiva SQL database server and creating a Linked Server to the ConfigMgr SQL Server FQDN.

## Test the Linked Servers

It is important to confirm the linked servers are able to access the data on the other server.

1. In SQL Server Management Studio, expand Server Objects, Linked Servers, FQDN of the other server, catalogs.
2. Notice the list of databases returned from the other server.
3. Expand the appropriate database and confirm that tables and views can be seen.


# Platform backup and recovery

OneSite Backup and Recovery

## Overview

This section outlines the steps required to provide Disaster Recovery (DR) capabilities for Adaptiva OneSite. In general, just like installation and operation, Adaptiva OneSite is very straight-forward to backup and restore. Guidance and examples are given as appropriate but many of these tasks can be performed in a variety of ways based upon the environment where OneSite is installed. Review this entire document before implementing a solution.

## Prerequisites (ConfigMgr)

Ensure there is a complete and successful backup of the ConfigMgr environment. Without this, OneSite can be restored and will function properly, but its main purpose to support, extend and supplement ConfigMgr, will not be satisfied.

The following Microsoft articles provide guidance on the backup and recovery for Configuration Manager.

Backup and Recovery for ConfigMgr Current Branch:

<https://docs.microsoft.com/en-us/sccm/core/servers/manage/backup-and-recovery>

Backup and Recovery for ConfigMgr 2012:

<https://docs.microsoft.com/en-us/previous-versions/system-center/system-center-2012-R2/gg712697(v=technet.10)>

## Scenarios

The following scenarios are supported for backup and recovery.

* **Disaster Recovery / Hardware Migration** - Adaptiva Server is restored on a server with the same name, SQL server, instance name, and database name.
* **Adaptiva or ConfigMgr Database Migration** - Adaptiva or ConfigMgr server name remains unchanged, but the SQL server name, instance name, (and/or) database name is changed.

## Backup

To recover an Adaptiva OneSite instance and associated data, a successful backup must be completed. It is best practice to backup OneSite data to an alternate location, and not on the system hosting OneSite itself. The exact procedure for doing this is dependent on the backup solution(s) in use. Similar to ConfigMgr, the files and data could be copied to a specific folder and configure the backup solution to backup that location.

The following table describes the components on the Adaptiva Server which should be backed up.

| Component                                                     | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ***Required***                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Adaptiva SQL Database                                         | Full SQL database backup.                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Adaptiva Install Folder                                       | `<AdaptivaServerInstallPath>`\AdaptivaServer                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Adaptiva Driver                                               | %systemroot%\system32\drivers\adaptivaservertransport\*.sys                                                                                                                                                                                                                                                                                                                                                                                                     |
| Adaptiva Server Registry Information                          | <p>HKLM\SOFTWARE\Adaptiva\server<br><em>Prior to version 5.5: HKLM\Software\javasoft\prefs\Adaptiva\server</em></p>                                                                                                                                                                                                                                                                                                                                             |
| Adaptiva Service Properties                                   | <p>Name: AdaptivaServer<br>Description: The Adaptiva Server service. Provides server side support for Adaptiva products.<br>DisplayName: Adaptiva<br>ServerName: AdaptivaServer<br>PathName: "<code>\<InstallPath></code>\Adaptiva\AdaptivaServer\bin\AdaptivaServerService.exe"<br>ServiceType: Own Process<br>StartName: LocalSystem<br>Caption: AdaptivaServer</p>                                                                                           |
| ***Optional***                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Custom Adaptiva Reports in ConfigMgr Reporting Services Point | In the case where any custom reports were created that are not included as part of the Adaptiva Server installation, those report RDL files should be downloaded. If there are subscriptions or schedules for those reports, the Reporting Services database should be backed up.                                                                                                                                                                               |
| Adaptiva Content Library                                      | <p>This is only applicable if the Content Library has been moved from the default location. The default location is:<br><code>\<InstallPath></code>\Adaptiva\AdaptivaServerInstallPath>\AdaptivaServer\data\ContentLibrary<br>If the above location is missing or there are no files within the ContentLibrary folder, check this registry key to determine if it has been moved:<br>HKLM\Software\Adaptiva\adaptiva\server\contentsystem.lib\_folder\_path</p> |

### Backup Procedure and Sample Commands

The following steps and commands can be used to complete the required set of backup steps listed in the table above. Replace all sections in <> brackets with correct entries for the environment.

> NOTE: The example command-lines referenced below assume the following:
>
> The Adaptiva Server and SQL Server are installed on the same machine.
>
> The Adaptiva database name is adaptiva.
>
> The account used to execute these commands has sufficient privileges to perform these actions.

1. Stop the AdaptivaServer Service.

```cmd
net stop AdaptivaServer
```

1. Setup some variable.

```cmd
REM Setup some Variables

set SERVERNAME=ENTER DB SERVER NAME

set DATABASENAME=adaptiva

set BACKUPLOC=DRIVE:\Backup\ServerBackup
```

1. Backup Adaptiva SQL Server database.

```cmd
REM Backup Adaptiva SQL Server database.

set DATESTAMP=%DATE:~-4%.%DATE:~7,2%.%DATE:~4,2%

set BACKUPFILENAME=%BACKUPLOC%\%DATABASENAME%-%DATESTAMP%.bak

REM May need to enter sqlcmd path. Default path to sqlcmd: C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\

REM Remove/Update Named Instance \ADAPTIVASQL

"[PATH TO\]sqlcmd" -E -S %SERVERNAME%[\ADAPTIVASQL] -d master -Q "BACKUP DATABASE %DATABASENAME% TO DISK = N'%BACKUPFILENAME%'"
```

1. Backup Adaptiva Install Folder using a command prompt.

```cmd
REM Backup Adaptiva Install Folder using a command prompt.

md %BACKUPLOC%\AdaptivaServer

xcopy.exe "%ADAPTIVASERVER%" %BACKUPLOC%\AdaptivaServer /v /e /r /k /h /o /x /y
```

1. Backup the Adaptive Protocol Driver using a command prompt.

```cmd
REM Backup the Adaptive Protocol Driver using a command prompt.

md %BACKUPLOC%\AdaptivaDriver

xcopy.exe %systemroot%\system32\drivers\adaptivaservertransport\*.sys %BACKUPLOC%\AdaptivaDriver /v /e /r /k /h /o /x /y
```

1. Backup the Adaptiva Server and driver registry keys.

```cmd
REM Backup the Adaptiva Server and driver registry keys.

REM --Version 5.5 and up

reg.exe export HKLM\SOFTWARE\Adaptiva\server %BACKUPLOC%\AdaptivaServer.reg /y

reg.exe export HKLM\\SYSTEM\CurrentControlSet\services\AdaptiveProtocolServer %BACKUPLOC%\AdaptivaDriver.reg /y

REM --Adaptiva Versions prior to 5.5

REM reg.exe export HKLM\SOFTWARE\javasoft\prefs\Adaptiva\server %BACKUPLOC%\AdaptivaServer.reg /y
```

1. Backup the Adaptiva Content Library folder if it has been moved to a non-default location.

```cmd
REM Backup the Adaptiva Content Library folder if it has been moved to a non-default location.

REM Remove the REM and enter the Content Library Location if it was moved from the default location

REM xcopy.exe <ContentLibraryLocation> %BACKUPLOC%\ContentLibrary /v /e /r /k /h /o /x /y
```

1. Record the configuration information for the AdaptivaServer service.

```cmd
REM Record the configuration information for the AdaptivaServer service.

wmic service where caption='AdaptivaServer' get caption, Description, DisplayName, Name, PathName, ServiceType, StartName /VALUE > %BACKUPLOC%\AdativaServerServiceInfo.txt
```

1. Restart the AdaptivaServer service.

```cmd
REM Restart the AdaptivaServer service.

REM DO NOT RESTART if moving Adaptiva to a new server

net start AdaptivaServer
```

The above commands can easily be customized for any environment and combined into a single batch file for scheduled execution. Using the built-in capabilities of ConfigMgr backup, these commands can be automatically triggered by ConfigMgr itself after the ConfigMgr Backup maintenance task runs. To do this, simply insert the customized form of the above commands into a batch file called AfterBackup.bat and place the batch file in the `<ConfigMgrInstallPath>`\inboxes\smsbkup.box folder. More details on this feature of ConfigMgr can be found at <https://docs.microsoft.com/en-us/configmgr/core/servers/manage/backup-and-recovery#using-the-afterbackupbat-file>.

## Restore

The following list of tasks outlines what must be done to restore OneSite. These tasks, similar to restoring ConfigMgr itself, assume a system with the same machine name, domain status, and drive letters as the original system and also depend on the complete and successful backup of a previously working OneSite installation using the steps outlined above. They also assume the existence of the files created by the backup tasks above.

### Restore Procedure and Sample Commands

Command-line examples are also given similar to those above in the Backup section; however, with restoration, these are typically not automated and thus using the Windows GUI to perform these processes may be easier.

1. Setup some variable.

```cmd
REM Setup some Variables

set SERVERNAME=ENTER DB SERVER NAME

set DATABASENAME=adaptiva

set BACKUPLOC=DRIVE:\Backup\ServerBackup

set ADAPTIVASERVER=<path to AdaptivaServer i.e. d:\program files\adaptiva\adaptivaserver>
```

1. Restore the Adaptiva SQL Server DB.

```cmd
REM Restore the Adaptiva SQL Server DB.

set BACKUPFILENAME=%BACKUPLOC%\adaptiva-yyyy.mm.dd.bak

set BACKUPLOC=c:\users\adaadmin\downloads\ServerBackup\ServerBackup

REM Default path to sqlcmd: C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\

REM Remove/Update Named Instance \ADAPTIVASQL

"[PATH TO\]sqlcmd" -E -S %SERVERNAME%\[\ADAPTIVASQL] -d master -Q "RESTORE DATABASE [%DATABASENAME%] FROM DISK = '%BACKUPFILENAME%'"
```

1. Restore the Adaptiva Server registry key.

```cmd
REM Restore the Adaptiva Server registry key.

reg.exe import %BACKUPLOC%\AdaptivaServer.reg
```

1. Restore the Adaptiva Server installation folder and Adaptive Protocol Driver file.

```cmd
REM Restore the Adaptiva Server installation folder and Adaptive Protocol Driver file.

xcopy.exe %BACKUPLOC%\AdaptivaServer "%ADAPTIVASERVER%" /v /e /r /k /h /o /x /y

xcopy.exe %BACKUPLOC%\AdaptivaDriver %systemroot%\system32\drivers /v /e /r /k /h /o /x /y
```

1. If the ContentLibrary folder had been moved to a non-default location, then it must also be restored.

```cmd
REM If the ContentLibrary folder had been moved to a non-default location, then it must also be restored.

REM Remove the REM and enter the Content Library Location if it was moved from the default location

REM xcopy.exe %BACKUPLOC%\ContentLibrary <ContentLibraryLocation> /v /e /r /k /h /o /x /y
```

1. Create the AdaptivaServer service using the service information recorded in AdaptivaServiceInfo.txt.

```cmd
REM Create the AdaptivaServer service using the service information recorded in AdaptivaServiceInfo.txt.

sc create AdaptivaServer type=own start=auto DisplayName=AdaptivaServer binPath="%ADAPTIVASERVER%\bin\AdaptivaServerService.exe"
```

1. Restore the Adaptive Protocol Driver registry information.

```cmd
REM Restore the Adaptive Protocol Driver registry information.

reg.exe import %BACKUPLOC%\AdaptivaDriver.reg
```

1. Create the AdaptiveProtocolServer service.

```cmd
REM Create the AdaptiveProtocolServer service.

>c create AdaptiveProtocolServer binPath=%systemroot%\system32\drivers type=kernel start=demand DisplayName=AdaptiveProtocolServer
```

1. If the Restore process was run on a different server with a different server name review the **Database Restoration Scenarios** below
2. At this point, in the process, the Adaptiva Server should be able to function, but in case there was something missed, the same version of **AdaptivaServerSetup.exe** as the restored Adaptiva Server should be run. When navigating through the installation wizard, no values should need to be modified as it will use the previous configuration as what is in the registry. See **Running Setup** below.

> IMPORTANT: If the Adaptiva database was moved to a database server different from the CM database, be sure to follow the steps in Appendix B before running AdaptivaServerSetup. Select Kerberos when prompted by AdaptivaServerSetup.

### Database Restoration Scenarios

If the Adaptiva or ConfigMgr databases need to be moved or restored to another SQL server, the Adaptiva Server Installer will allow for modifications of the SQL Server Machine Name, SQL encryption settings, and SQL Login information. If making changes to the Adaptiva / ConfigMgr database names, instance names, or ports, use the following table to modify the appropriate registry values before running **AdaptivaServerSetup.exe**.

**Registry Location:** 5.5 and Above: `HKLM\Software\Adaptiva\server` Prior to 5.5: `HKLM\Software\javasoft\prefs\Adaptiva\server`

Adaptiva Database Machine Name: `setup.adaptiva_db_machine_name` Adaptiva Database Name: `setup.adaptiva_db_name` Adaptiva Database SQL Port: `setup.adaptiva_db_port` Adaptiva Database SQL Instance: `setup.adaptiva_db_sql_named_instance` Adaptiva Server name: `setup.customer_name` ConfigMgr Database Machine Name: `setup.site_db_machine_name` ConfigMgr Database Name: `setup.site_db_name` ConfigMgr Database SQL Port: `setup.db_port` ConfigMgr Database SQL Instance: `setup.site_db_sql_named_instance` ConfigMgr Site Server Name: `setup.site_server_machine_name`

### Running Setup

1. Run **AdaptivaServerSetup.exe** and at the **License Agreement** screen, click **Accept**.
2. At the **Status** screen, the Adaptiva configuration will be listed which includes the Adaptiva Server version, installation folder, Adaptiva database server, database name, etc. Click **Upgrade** to start.
3. In the installer fields for the ConfigMgr server and database server can be changed/updated, but if the Adaptiva database names, instances, or ports were modified, they should be modified in the registry before running setup.
4. Once complete, verify the AdaptivaServer service started correctly by reviewing adaptiva.log in the `<AdaptivaServerInstallPath>`\AdaptivaServer\logs folder for errors or anomalies.
5. Reinstall the Adaptiva Client when prompted.
6. Reinstall the Adaptiva Workbench from the installation source (if desired). Ensure the same version of the workbench is being used as that of the AdaptivaServer that was just restored.

### Reporting

If the Adaptiva database was moved to a different SQL Server be sure to update the database connection in SQL Server Reporting Services for the ConfigMgr Reports

1. Browse to http\://`<ReportingServer>`/ConfigMgr\_`<sitecode>`/reports
2. Scroll to the bottom of the list and click on Adaptiva
3. Change the connection string to:
4. Datasource=new adaptivaserver fqdn;initial catalog=adaptiva
5. It should be using specific Credentials -- the CM Reporting Services Point account. Make sure this account has `db_datareader` permissions on the Adaptiva database on the new server


# Migrate Adaptiva SQL Database

This article provides an overview of the steps required to migrate the Adaptiva OneSite database to new hardware while keeping the Adaptiva server on the existing machine, thereby allowing you to reduce the load on the current server, improve performance, and centralize SQL management.

## Prerequisites

* Verify you have sysadmin permissons on the new SQL server to migrate the Adaptiva database to the new server.
* If your Adaptiva Server is integrated with ConfigMgr and the ConfigMgr database will be on a different SQL Server, you must ensure SPNs (Service Principle Name) are created and Kerberos delegations are set up. This will ensure communication between the Adaptiva SQL database and ConfigMgr SQL database.
  * For additional information please see [SPNs and delegation](/platform-install/additional-configuration/platform-spns-delegation)
* Download and install [SQL Server Management Studio](https://learn.microsoft.com/ssms/install/install).

## 1. Stop Adaptiva server services

*Perform the following on the origin Adaptiva Server.*

1. Open Windows Services and right-click on **AdaptivaServer** and select **Properties**.
2. Click the **Stop** button and select **Disabled** from the **Startup type** dropdown.
3. Click **OK**.
   * **Note**: Ensure there are no external systems that will change this setting. Scheduled Tasks, Service Monitoring utilities, etc. Temporarily disable those if they exist.

     ![](/files/xvbK4dYDI0CHV5t4CKKZ)

## 2. Backup the Adaptiva database

Follow these steps to back up your database via Server Management Studio (SSMS), [Create a Backup](https://learn.microsoft.com/en-us/sql/relational-databases/backup-restore/quickstart-backup-restore-database?view=sql-server-ver17\&tabs=ssms#create-a-backup)

## 3. Transfer database backup to new SQL server

1. Transfer the file to the new SQL Server (e.g., network share or file copy).
2. Confirm the file exists on the new SQL Server, is not corrupted, and is accessible locally.

## 4. Restore Adaptiva database on new SQL server

*Perform the following on the destination SQL Server*

Follow these steps to back up your database via Server Management Studio (SSMS), [Restore a database](https://learn.microsoft.com/en-us/sql/relational-databases/backup-restore/quickstart-backup-restore-database?view=sql-server-ver17\&tabs=ssms#restore-a-database).

## 5. Configure SQL server permissions

1. Update the following T-SQL script with the origin SQL Server `<DomainName>\<ComputerName>` and run it from SQL Management Studio:

   ```sql
   CREATE LOGIN [<DomainName>\<ComputerName>$] FROM WINDOWS;
   GO

   ALTER SERVER ROLE [sysadmin]
   ADD MEMBER [<DomainName>\<ComputerName>$];
   GO
   ```

* This will ensure that the permissions are retained after the database restoration.

## 6. Update Adaptiva database configuration

1. Open the Registry and navigate to `HKEY_LOCAL_MACHINE\SOFTWARE\Adaptiva\server\`.
2. Find `setup.adaptiva_db_option` and change the value to `3`.

   ![](/files/kES0LWGdOxW2gcqbCJYG)

This will update the **Specify Options For Creating The SQL Database** settings of the Adaptiva upgrade.

### OPTIONAL updates to database configuration

Configure the following settings if appropriate:

* If using a named SQL instance on a new SQL server machine, you must change the instance name on the `HKEY_LOCAL_MACHINE\SOFTWARE\Adaptiva\server\setup` `adaptiva_db_sql_named_instance` line in the registry.
* If using the default instance, you must leave the `HKEY_LOCAL_MACHINE\SOFTWARE\Adaptiva\server\setup`.`adaptiva_db_sql_named_instance` line blank in the registry.
* If not using the default SQL port 1433, you must set the port on the `HKEY_LOCAL_MACHINE\SOFTWARE\Adaptiva\server\setup` `adaptiva_db_port line in the registry`.
* If moving the database to a remote system not co-located with the Adaptiva Server service, the Adaptiva Server requires the `sysadmin` permissions to the new SQL server to change the database name in the registry.

## 7. Run Adaptiva server setup

1. Run `adaptiva-server-<version>-windows.exe` on the existing Adaptiva Server, and select **Advanced Upgrade**.

   ![](/files/dNvo67f9Q94KBfnFfma9)
2. Click **Next** until you reach the **Specify Options For Creating The SQL Database**.
3. Ensure **Create The Database In The Same SQL Instance As ConfigMgr Site Database** is selected.

   ![](/files/sv4BnwPzqxxPwVfqMsMl)
4. Click **Next** and at the Pre-requisites dialog click **Continue**.
5. On the Provide Information for the Database page, click to disable **Create the Database in the Site Database Server and Use Same SQL Login Settings**.
6. Under SQL Login, enter a **SQL Server Machine Name** of the FQDN of the destination SQL Server.
7. Leave **Use Adaptiva Server's Local System Account** checked.
8. Click **Next**. At the prompt, click **Yes** to confirm the account.
9. Click **OK**. Then click **OK** to confirm that the SQL Servers are linked.
10. Complete the install wizard and verify that the post install checks pass.

    ![](/files/QVhp1zGdynMUasom9ho3)

## 8. Validate migration

*Perform the following on the Adaptiva server.*

1. Ensure that the AdaptivaServer service is started.
2. Log in to the Adaptiva Admin Portal and ensure dashboards are visible.
3. Confirm clients are able to communicate with the server.
4. Monitor SQL activity to ensure the new database is being used.


# Migrate Adaptiva Server

Migrate Adaptiva Server to new Server

This article details the steps to move the Adaptiva application server from one Windows server to another. This article assumes Adaptiva server is installed to the **E:\program files\adaptiva\adaptivaserver**. It is recommended to keep the same installation location on the new server. For instance, You may want to migrate your server for the following reasons:

* You want to move your server to the cloud.
* Your current hardware no longer supports a newer version of Windows Server.
* Your current hardware does not have enough disk space.

## Prerequisites

{% hint style="info" %}
We recommend running the custom client workflow and the initial robocopy at least 4 weeks prior to migrating the server. The robocopy process primarily applies to the Adaptiva content library, as it typically makes up the largest portion of the server’s data.
{% endhint %}

Before migrating to a new server, ensure the following steps have been completed:

1. Setup a DNS alias (CNAME) to point to the existing server.
2. Perform an initial robocopy of the Adaptiva Server installation directory to the new server.
3. Assign Adaptiva Clients to DNS alias. This will update the server name and server location values in the registry for each client.

### Initial Robocopy

This is to pre-stage the Adaptiva Server files on the new server. This reduces downtime during the final migration.

1. Enter the following command into a termnial:

   ```shell
   robocopy "E:\Program Files\Adaptiva\AdaptivaServer" "\\<NewServer>\E$\Program Files\Adaptiva\AdaptivaServer" /MIR /Z /R:2 /W:5 /LOG:precopy.log
   ```
2. Ensure the destination path matches the source path exactly.

If the Adaptiva content library is stored outside of the default installation path, perform a separate robocopy for that directory as well.

### Assign Clients to DNS Alias

Prior to migrating the Adaptiva server, you will first want to move clients by updating the new server name and location registry values. To do this, you will run the `AssignAdaptivaClientToDNSAlias` workflow by following the steps below.

1. Download the [AssignAdaptivaClientToDNSAlias workflow](https://adaptiva.com/hubfs/Docs/Workflow_Assign%20Adapitva%20Client%20To%20DNS%20Alias.obex) using this link.
2. Import the workflow by selecting **settings gear > Import** from the OneSite Platform and select the workflow .obex file.

   ![](/files/wmtrn9AC9jefEfDVBTUZ)
3. (Optional) Create a [Group](https://docs.adaptiva.com/platform-guide/platform-features/assets/groups) of devices for this workflow to target.
   * You can also just target **All Clients** or use an existing Group.
4. From the OneSite Admin Portal, select **OneSite Anywhere**.

   * If you do not have OneSite Anywhere enter `/content-push` at the end of your server URL:

   `https://<servername>:[port]/content-push`
5. Select **Content Push** from the side navigation.

   ![](/files/VZ2AW4ab1WvcxowCJ7uk)

   * The content-push URL will already display the Content Push pane.
6. Click on **+New** to create a new Content Push Policy and enter the following:
   * **Name** - Assign Adaptiva Clients To DNS Alias.
   * **(Optional) Description** - Add a description.
   * **Target Groups** - Click **Browse**, select the group or collection and click **OK**.
   * **Intellistage and Push Settings** - Toggle OFF **Enable IntelliStage**.
7. Click on **Advanced Settings** at the bottom of the pane.

   ![](/files/dhv2g2QlbfRlFQVQXpsc)
8. Click **Browse** next to **Client Policy Execution Workflow**, find the Workflow named **Assign Adaptiva Client To DNS Alias** and select it.

   ![](/files/eCSiJEiCzwN8y4FbrC0o)
9. Click **OK**, **Close**, then **Save**.
10. Click the **More** dropdown and select **Run Policy**.

    ![](/files/L8kG48W4Nist9Rhs9dqL)

This will trigger the clients to begin pointing to the DNS alias. Depending on how many clients you have, this can take a few weeks to get all of your clients redirected.

## Migrate Adaptiva server application

1. On the existing Adaptiva server, [uninstall the Adaptiva **client**](/platform-install/client-install-and-uninstall/client-uninstall).
2. Stop and disable the **AdaptivaServer** service.
3. Perform a final robocopy of the Adaptiva Server installation directory.
   * This ensures the new server has the most up-to-date files before proceeding with the remaining migration steps.
   * Since robocopy copies only the latest data, this second run of the robocopy will take less time than the initial robocopy from the Prerequisites above.
   * If the Adaptiva content library is not in default location in the server install path, copy it to same path on new server.
4. Copy *C:\windows\system32\drivers\AdaptivaServerTransport.sys*\* to the new server to the same location.
5. Backup server and driver registry keys, and copy to **E:\temp** directory on new server

   ```shell
   reg.exe export HKLM\SOFTWARE\Adaptiva\server <BackupLocation>\AdaptivaServer.reg /y
   reg.exe export HKLM\SYSTEM\CurrentControlSet\services\AdaptiveProtocolServer <BackupLocation>\AdaptivaDriver.reg /y
   ```
6. Run this command to backup the Adaptiva server service information and copy to E:\temp directory on the new server

   ```shell
   wmic service where (Name = 'AdaptivaServer') get caption, Description, DisplayName, Name, PathName, ServiceType, StartName ><BackupLocation>\AdaptivaServiceInfo.txt
   ```

From the new server follow the steps below:

1. Import registry keys:

   ```shell
   reg.exe import E:\temp\AdaptivaServer.reg
   reg.exe import E:\temp\AdaptivaDriver.reg
   ```
2. Create the AdaptivaServer service:

   ```shell
   sc create AdaptivaServer type=own start=auto DisplayName=AdaptivaServer binPath= E:\Program Files\Adaptiva\AdaptivaServer\bin\AdaptivaServerService.exe
   ```

   * If the path contains space, it is necessary to surround the path in quotes.
3. Create the AdaptivaProtocol service:

   ```shell
   sc create AdaptiveProtocolServer binPath="%systemroot%\system32\drivers" type=kernel start=demand DisplayName=AdaptiveProtocolServer
   ```
4. If you are using Kerberos authentication, be sure the [SPN is set correctly](/platform-install/additional-configuration/platform-spns-delegation) for the new server.
5. Copy the server and client setup executables to new server E:\temp.
6. Run AdaptivaServerSetup.exe as Administrator from E:\temp.
   * If any path or account is different on the new server, review the Adaptiva server registry **HKLM\SOFTWARE\Adaptiva\server** to find the old path and update to the new path prior to running setup.
7. Select **Quick Upgrade**.

{% hint style="warning" %}
If the install options show **Quick Install** the registry keys have not been properly updated, please do not proceed with an install and contact our [Support Team](https://adaptiva.com/support) to troubleshoot.
{% endhint %}

During the upgrade, all paths will exist and credentials used on previous setups will be populated in the wizard, so you should just need to select **Next** and **OK** throughout the wizard with the one exception of updating the Adaptiva Server name if this has changed.

1. Verify the paths and credential values are correct on each page of wizard.
2. Ensure all permissions required for the accounts are set correctly if using service accounts, such that they are in the local administrator group on the server.

After the upgrade completes, be sure all validation checks pass, then install the Adaptiva client.

1. Update the DNS alias so the new server and clients can establish communication.

{% hint style="info" %}
If the Server/Central Office is now in Azure or AWS this office needs to be set as WiFi type due to broadcast networking traffic not being allowed.
{% endhint %}

For confirmation the Adaptiva server is processing correctly, run the following SQL query on the Configuration Manager (ConfigMgr) database:

```sql
SELECT * FROM Adaptiva_notifications ORDER BY triggertime
```

This is the table the Adaptiva Server uses to process from Configuration Manager (ConfigMgr). With the Adaptiva Server service stopped, the rows will backlog, until the new server is up and available to process them. For the first few minutes the rows returned may continue to go up, but after 10 minutes, if the rows don't clear or at least start going down

Once SQL notification table has processed through, you are ready to change DNS alias to the new server IP.


# OneSite Platform User Guide

The Adaptiva OneSite Platform is an autonomous endpoint management and security platform with complete visibility and real-time control of your IT assets. The OneSite Platform hosts multiple Adaptiva products that support scalable endpoint management, autonomous patching, and integrations with key security partners.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-shield">:shield:</i></td><td><strong>Configure your security and access settings</strong></td><td>Grant access to administrators and define roles.</td><td></td><td></td><td><a href="/pages/kVmqGnnDOMdax8k2rEtF">/pages/kVmqGnnDOMdax8k2rEtF</a></td></tr><tr><td><i class="fa-chart-network">:chart-network:</i></td><td><strong>Implement your network topology</strong></td><td>Design and implement your network topology to take advantage of WAN optimization and Peer-to-Peer (P2P) capabilities.</td><td></td><td></td><td><a href="/pages/FN4CqIOl8sk78ip7I9tE">/pages/FN4CqIOl8sk78ip7I9tE</a></td></tr><tr><td><i class="fa-browser">:browser:</i></td><td><strong>Familiarize yourself with the Admin Portal</strong></td><td>Organize and manage your solution in the Admin Portal.</td><td></td><td></td><td><a href="/pages/b5lFK7gF8Ui0SHfW6na1">/pages/b5lFK7gF8Ui0SHfW6na1</a></td></tr></tbody></table>

![OneSite Platform](/files/z5u6UJ9UsIRcbOvFzGqt)

## Manage the OneSite Platform

In this guide, you can find information on managing the OneSite Platform.

{% columns %}
{% column %}
Keep the OneSite agent always up-to-date with automatic [client upgrades](/platform-guide/client-management/client-auto-upgrade).
{% endcolumn %}

{% column %}
[License your OneSite solution](/platform-guide/overview/license-solution) and assign licenses to clients.
{% endcolumn %}

{% column %}
Use [dashboards](/platform-guide/platform-features/dashboards) to manage your operations and monitor your endpoints.
{% endcolumn %}
{% endcolumns %}

## Customer Support

If you need information beyond what our documentation and [Knowledge Base](https://support.adaptiva.com/hc/en-us) provide, enter a support ticket and request help from [Adaptiva Customer Support](https://adaptiva.com/support).


# Navigating the Admin Portal

The Adaptiva Admin Portal is a unified console for you to create and manage all your Adaptiva products. You can manage security and user permissions, add new product licenses, and configure global client settings.

## Log in to the Admin Portal

In your web browser, navigate to `http[s]://AdaptivaServerFQDN[:port]`.

Note: Internet Explorer is no longer a supported browser.

The `:port` parameter is optional. If the server already uses port 80, the portal might use a different port like **9678**. Check with your Adaptiva administrator to confirm the correct port.

![Adaptiva admin portal login](/files/Xmok54LjDC4qRDw6BY6N)

## Sign in options

When the login screen appears, you’ll see two ways to sign in:

* Use Adaptiva credentials
  * Enter your **Email** and **Password**.
  * Click **Log in**.
  * Save your login for next time by checking **Remember my email**.
* Use Windows credentials
  * Click **Log in with Active Directory** to sign in with your current Windows login.
  * This doesn’t have to be an AD account, it just uses your current login token.

### Admin access

During installation the Administrator configures the Adaptiva Server to:

* Use a Windows Active Directory account as the Super Admin, or
* Creates an Adaptiva account as the Super Admin.

You can use this account for the first login. After that, the administrator can create new logins, assign roles, and manage permissions.

## License prompt

If you are starting the Admin Portal for the first time or your key has expired, you will be prompted for a key at login. See [License your Adaptiva solution](/platform-guide/overview/license-solution) for more details on licensing and key management.

## Navigate the Admin Portal

Use the Admin Portal to manage global settings and view dashboards for Adaptiva products like OneSite ConfigMgr, OneSite Intune, OneSite Workspace ONE, and Endpoint Health.

![Admin Portal Home](/files/1Cczsa98G7OnOdLwX3Tp)

## UI Elements

### Platform Features side navigation

Platform Features are located on the left side bar navigation. This displays features common to all Adaptiva solutions as well as solution-specific features, ie. OneSite Patch.

Platform Features include:

* **Actions** - Actions are objects that perform some task or activity on a device.
* **Assets** - Assets include management of Devices, Groups, and Locations.
* **Dashboards** - Includes management of Dashboards, Subscriptions, and Data Providers.
* **Forms** - Allow you to configure custom forms to use in conjunction with Workflows. These forms are attached to Workflows and pop up when the Workflow is launched, so you can enter the applicable information.
* **Schedules** - Allow you to configure schedules (e.g. patching schedules)
* **Tool Foundry** - Tool Foundry includes configuration of Custom Tools and Powershell Cmdlets which allow Administrators to convert workflows into standalone executables (.exe).
* **Workflows** - Workflows include Designer, Activities, Audit Policy, and Execution Policies which allow you to setup client & server automation actions.

![](/files/lTvxiao6gxrIchEQhsRt)

{% hint style="info" %}
Some Platform Features are not visible based on solution type (ex. OneSite Enterprise vs. OneSite Express), or user permissions (ex. Super Administrator vs. Administrator).
{% endhint %}

1. Each Platform Features is clickable if standalone.
2. Hover over an Activity with a **>** symbol to see the contents of the pull-out pane.

#### Tabs

For Platform Features that have dropdown panes, they also have corresponding tabs within the pull-out pane.

### Directories

File directories help keep things organized and work similar to other file directories you would find on your OS.

![](/files/LlHLclIh7cNsty11aZ97)

1. Selecting a folder will display the contents in a table in the right side pane.
2. The Search bar allows you to search for folders within the root folder.
3. Drag and drop folders to desired locations if you would like to nest or remove from a nested position. (A warning overlay will appear to confirm your change.)
4. Select the more options (![](/files/o7oZK8yljyNihkreC1cg)) button next to any folder for the following options:
   * **Create Folder**
   * **Expand All**
   * **Collapse All**
   * **Rename**
   * **Delete**
   * **Restore to Original**
   * **Export**
   * **Show References**
   * **Manage Permissions**
   * **Manage Class Permissions**

### Tables

Tables in Adaptiva solutions display objects like Devices, Locations, Products, etc. Each table has the ability to sort and customize column views. Below are some common features of Tables.

#### Search, sort. and views

![](/files/VosWZM7Xw5LKuyJAPyfQ)

#### Interaction

1. Many pages include built-in search with the ability to select filter criteria. Select the Search Columns… drop down for filter criteria. Typically, the left-most column is always the default column to search. Select Search or press Enter to complete the search.
2. Most columns are sortable in ascending or descending order, just click on the column name. Non-sortable columns will not change the pointer to and will remain the default pointer.
3. You can select the column view gear icon, if you would like to add or remove columns visible in the table
4. If table columns exceed the width of the browser window, you can use the bottom scroll to view additional columns.

#### Advanced search

With advanced search features you can add Boolean logic, or specific conditions.

1. By clicking and enabling the filter icon, this will expose the **Configure Search** button.

   ![](/files/kFzXIuGSdgWQ96zENwvx)
2. After clicking the **Configure Search** button, this will display an overlay where you can select Operator or Conditions in the **Creating Operating Condition** pane.

   ![](/files/C2PUEGS9RhfZpgMbAQtY)

   ![](/files/CzuEaZrDoU7t8YZeb0uw)

#### Object information

You can see detailed information on an object by clicking the carrot > to the left of the row.

![](/files/K3s1fIPbRiuex4062Zz8)

#### Reorganizing Objects

You can manually order some objects by clicking and dragging the six dots to the left of the row (![](/files/zbjr0OcrYyGNuIm8WB5i)). You can reorder objects within a folder or move objects to a different folder in this way. If reordering is not available, you will see the following:

#### Selecting Objects

When a row has on the far left, check one or more boxes to select the rows. Multi-select is not always available. At the top and bottom of the results will also be additional context panes. A check box to select All, if available, and ellipses for additional actions on the selected rows.

![](/files/GjwegaiG9DLaCuywvNH5)

#### Displaying All Rows

When results are returned, they will default to be displayed in 10 rows per page. This can be changed by select the drop down and select 10, 25, 50 or 100. Use the |<, <, >, or >| buttons to move forward and backward through the pages.

![](/files/VvlydYss2HciVxA0AH7l)

### Overlays

Overlays typically appear when configuring other selected objects (buttons, dropdown selections, etc.)

For example, if you wanted to create a new IP Range for your Location, you would navigate to the IP Range section and click **+ Create IP Range**. This would display the overlay for you to enter in your IP Range.

![](/files/ELzateZDJqrge9qJkqsl)

![](/files/JJvHEDWAhv2XmH9HKoiR)

### Errors

At the bottom of Editor pages will be a collapsed section named Error View. This may display errors found when saving a form. Clicking on Error View will expand the section and show any relevant errors for that Editor.

Errors can be resolved by selecting the **Resolve** button in the **Errors** tab.

Check the Resolution you wish to apply and click **OK**.


# License your OneSite solution

Adaptiva products require a license for each active client reporting to the site for which it is installed. The Adaptiva Server will periodically count all active, healthy, reporting clients as licensed clients. The license key will contain the licensed company name and client count.

If you are starting the Adaptiva Web Portal for the first time or your key has expired, you will be prompted for a key at login.

![License product prompt](/files/aDEStQMWvVH3DXO0h5jj)

You can view keys or add more by selecting the **gear icon | Product Licensing**.

![Product licensing page](/files/yepyrm2nII9p5oFAPxxA)

Products will function for a period of 30 days from the date of installation for evaluation purposes. If additional evaluation is required, please contact [Adaptiva Customer Support](https://adaptiva.com/support).

## Add a License

To license your Adaptiva solution, perform the following:

1. Select the settings **icon (gear) | Product Licensing**.

   ![](/files/C12v8u3SotaEJ7p8mVAu)
2. Click **Add Key**.

   ![](/files/qYx8PEcrjS6gKhb6UDY5)
3. Paste the license key for your Adaptiva solution in the text box and click **OK**.

   ![](/files/t2JCJnA3WEPN7Lp5nm2i)
4. The End User License Agreement: Adaptiva page appears. Read the license agreement and click **Accept**.
5. The notification banner displays the progress for the solution being enabled. When complete, click the product tab (ex. OneSite Patch).

## Start a Free Trial

To start a free trial of an Adaptiva solution, perform the following:

1. On the Product Licensing page, click **Start Free Trial**.
2. Click to select the solution(s) you wish to try and click **OK**.
3. The End User License Agreement: Adaptiva page appears. Read the license agreement and click **Accept**.
4. The notification banner displays the progress for the solution being enabled. When complete, click the product tab (ex. OneSite Patch).

## License Expiration

When your OneSite Patch license is about to expire, a top level banner will display notifying you of the expiration date. Clicking the license notification will take you to the licensing page in the Admin Portal.

![Expiration warning](/files/cvZrpVDWrXqoxKOU6nOg)

Once your product license expires, your product will no longer be accessible.

![Product disabled](/files/mk7mnAJ6NCuN965YjxC7)

In order to re-enable your product, you will need to enter a valid license key. Reach out to your sales representative to purchase or renew your license.


# OneSite Aida

Overview document for Aida

{% hint style="info" %}
Requires version 10.1 or higher.
{% endhint %}

<p align="center">Transform raw data into intelligent dashboards through generative AI prompts and monitor your environments in real time with OneSite Aida.</p>

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-download">:download:</i></td><td><strong>Install OneSite Products with Aida</strong><br><br>Install and license an OneSite product with the Aida add-on.</td><td></td><td></td></tr><tr><td><i class="fa-comment-dots">:comment-dots:</i></td><td><strong>Common Aida query examples</strong><br><br>See example prompts for ideas on creating your specific dashboards.</td><td></td><td></td></tr></tbody></table>

With OneSite Aida you can add AI chat capabilities to generate personalized dashboards so you can see your data the way you want to in real-time. OneSite Aida gives you the power to create queries with human-readable text, view chat History, and create Forks.

* **Chat** - Enter prompts into Aida's easy to use chat-style window in order to generate data virtualization. Each prompt will organize your data the way you want it so you can monitor what you need.

  ![](/files/wkwgmZfstT0i1HNP0YeQ)
* **Forks** - Forks allow you to branch off from a single query within your chat history so you can continue your queries without disrupting your main chat flow.

  ![](/files/sDmlnNq4BLaozuFn3hsi) ![](/files/BEhdEYfeeOUlMkXZ8foS)
* **History** - If you want to go back and see previous queries, you can click on the History tab to see a timeline view.

  ![](/files/LGh6DNJZ011jUY0c8f8M)


# Enable Aida

Installation guide for Aida

{% hint style="info" %}
Requires version 10.1 or higher.
{% endhint %}

In order to start using OneSite Aida with your OneSite product, you will first need to either purchase SaaS or install the on-premises version of OneSite Platform and then apply your desired Aida license.

{% hint style="info" %}
OneSite Aida will only see data from the product associated with the Aida license. For instance, if you have Aida for OneSite Patch it will only be available within OneSite Patch and will not interact with data from another product outside of OneSite Patch.
{% endhint %}

For instructions on how to install the OneSite Platform, please see our [Platform Installation Guide](https://docs.adaptiva.com/platform-install).

## Free Trial

If you have a **10.972.0.1+** version of **OneSite Device Inventory** or **OneSite Patch** license, a free trial of **Aida** is available from the Admin Portal. You can follow the steps below to activate your free trial from the OneSite Admin Portal.

1. Click the **Ask Aida** button next to the profile and settings icons to view the free trial pane.

   ![](/files/iQ8VZm1SVBBoiEQePxTM)
2. Toggle ON **Start Trial** for any available options.

   ![](/files/8AwO7AclASOmKjzPUHHA)
3. Click **Confirm** and you can now begin chatting with Aida.

   ![](/files/hI1L6C6IDBqUS59vbReh)

## License Aida

Once you have a paid version of Aida, you can add your license to the OneSite Platform to enable Aida. For more information regarding licensing, please see our [Add a License Key](https://docs.adaptiva.com/platform-install/server-install/install-platform#add-a-license-key) documentation.


# Getting Started with Aida

Getting Started guide for Aida

{% hint style="info" %}
Requires version 10.1 or higher.
{% endhint %}

OneSite Aida's main purpose is to take natural language queries and generate custom dashboards on the fly. Aida does this by accessing [Sensor](/platform-guide/platform-features/sensors) data relevant to the query. Aida, although not a general use chatbot, can respond to queries regarding its own scope, along with sensors and their definitions. For example you may want to ask Aida:

* "What kinds of data can I collect?"
* "What sensor(s) will capture patches with the highest risk scores?"

{% hint style="info" %}
OneSite Aida is limited to only work within the confines of OneSite tenants. Any on-premises database or SaaS tenant information is NOT shared externally. Therefore, querying in one tenant will not pull data from any other tenant. Additionally, Aida does not have direct access to data within the tenant. Aida only generates queries to gather data, but does not see any returned data.
{% endhint %}

## Create a dashboard with Aida

Once you query Aida it will display a button in the chat to open the dashboard preview. Once generated, you have the option of saving each dashboard to reference later. Newly generated dashboards will show live data, whereas saved dashboards will update on a schedule every 24 hours. If you do not decide to save, they will be saved temporarily. Each inactive temporary dashboard is auto-deleted after ten minutes after you leave a conversation and then restored when reopened.

For example, you could run the following query:

1. Click the **+** next to the **New Chat** dropdown menu to create a new chat, or start typing in the Aida chat field.
2. Enter a prompt like *Show me only non-compliant devices with a risk score above 75*.
3. Wait for your response and then click the generated dashboard button.

   ![](/files/n7GiKu0SYpPwmKPRpa9d)
4. This will open the Artifacts pane where you can view all of your recently generated dashboards.

   ![](/files/rX4enPvhmDgQRlYFsOTr)
5. Click **Save** if you would like to save your dashboard, otherwise you can either close the window, interact with your dashboard, or ask Aida to create additional dashboards.

## Fork an existing chat

Once you have started a chat with multiple queries, you can fork an existing chat query to continue queries from that point in the history. This is useful if you have dashboards created further in the history that may now be unrelated to a previous query node you wish to continue to explore.

To create a fork, please follow the steps below.

1. Click the **Forks** tab in an existing chat.
2. Click the ellipses (**...**) and select **Create Fork**.

   ![](/files/gVS2uBda1BLLJHirJXyk)
3. Enter a name for your new fork and click **OK**.

   ![](/files/YZiY4XeKDBZke4n2USc3)
4. Click the **Chat** tab and notice the **Building from:** status will now be building from your new fork.

   ![](/files/KmCoOx60ucXKoWEMPZoP)
5. Click the **History** tab to see a timeline view of your fork.

   ![](/files/WYAEYlKPwksH2obgZYRO)

## Chat History

You can see all of your selected chat's history from the **History** tab. This will give you a timeline view of your queries. Clicking on any node will open the response and generated dashboard and will allow you to show in the full chat window, create a fork, or delete the node.

![](/files/QvP5328MLfXY4KpsX1TZ)

## Sensors

To create query prompts that will better guide Aida responses, we recommend asking Aida about the sensor catalog. It can provide a reference for all of our available sensors with categories and descriptions for each sensor.

{% hint style="info" %}
Each OneSite product will have its own set of sensors that it exposes to Aida. For example, OneSite Patch will provide a set of Patch specific sensors, that would not be available if OneSite Patch was not licensed.
{% endhint %}

### Example queries

Below are some query examples with potential outputs for you to try when first interacting with Aida.

* "Which products or patches have active patching exceptions?"

  ![](/files/TXzQcBgkPtNHye7iL4jD)
* "Is global patching paused, and are there any specific products, patches, or clients with active pauses?"

  ![](/files/x80oMm8mycRapDGN5Scw)
* "Which non-compliant devices have a risk score above 50?"

  ![](/files/JnGGfb2MlEeHxRb2pKlW)
* "Which CVEs are present in my environment and what patches remediate them?"

  ![](/files/duubaznxpNF8idqQNw1j)


# Security and Access Control

## Security and Access Control

The Adaptiva Admin Portal supports several forms of user authentication:

* Active Directory
* Open ID Connect (OIDC)
* Security Asset Markup Language (SAML)
* Internal Adaptiva User ID

During the installation of the Adaptiva Server, the installer allows the administrator to create an Adaptiva User ID or specify an AD user account as SuperAdmin. The SuperAdmin account has the maximum permissions in the Adaptiva environment.

Integration with 3rd party identity providers must be performed after installation.

## Manage Administrators and Roles

1. Log in to the Admin Portal at `http[s]://AdaptivaServerFQDN[:port]`.
2. Click the gear icon ![gear icon](/files/WTzSkHtTiMjjbhpDKuea) **> Settings > Security > Administrators**. The Administrators view opens.

The Administrator account created during installation is displayed.

The default folders are **Administrators > Windows Administrators**. When you select a folder, the details pane will show the members of the selected folder.

Other folders may be exist depending on which products you have licensed, e.g. OneSite Admins, Advanced Endpoint Health Roles, Basic Endpoint Health Roles.

### Add a new Administrator

1. Click the **Administrators** tab.

   ![Administrators](/files/LmTp2dWigfsjygY59oTr)
2. Click **New**.
3. The Administrator editor will appear. Complete the following sections:

   **User Details**

   ![User Details](/files/ry6LeCeirpxnGkTr3oXk)

   **Admin Type**: Specify if this is an Adaptiva, Windows AD, OpenID Connect, or SAML login.

   * **Adaptiva**
     * **Email Address**: Specify email address of administrator. This is a required field. The email address does not have to be a real or valid email address. It will become the account's username and will be required when using the Adaptiva login
     * **Password**: Specify a password for the new account. The password must be at least 10 characters long and include at least one uppercase letter, one lowercase letter, and one numeric character. Enter the same password in the Confirm Password box.
     * **MFA Enabled**: Require multi-factor authentication when administrator logs in.
   * **Windows AD**
     * **Email Address**: Specify email address of administrator.
     * **Windows Domain**: Enter the NETBIOS domain name of the account domain
     * **Windows User Name**: Enter the SAMAccountName of the user's domain account that will be created as an Adaptiva Administrator
   * **OpenID Connect** or **SAML**
     * **Email Address**: Specify email address of administrator.
     * **Identity Provider**: Select your provider. Create new OIDC and SAML providers in the **Security > OIDC Providers** and **SAML Providers** menus.
     * **Subject ID**: Enter the unique identifier for the application user.

   **Administrator Details**

   ![Administrator details](/files/KeUSl53NVKxj2EAUxXJJ)

   Administrator Details require a valid First and Last name entry. Additional contact information is optional.

   **Direct Roles**

   ![](/files/IuXA6ldGQKP1qtf2CT6w)

   Click **Browse**, select a role like **All Admin Role**, and click **OK**. This list represents all roles to which the administrator has been added directly.
4. Once you've completed the required fields, click **Save**.

   ![](/files/nH0xnpDJ9n5mQsB2XDKH)
5. Click **Back to Administrators** button to navigate back to the Administrators page.  Here you can find your newly created login.

   ![](/files/lnfzcDKIzejMSFfjYOI7)

Adaptiva logins will be created in the root Administrators folder, while Windows AD Logins will be created in the Windows Administrators folder.

### Assigning Roles to Administrators

By default, all newly created users are added to the **All Admin** role. This role has limited access.

To manage roles for an Administrator account, follow these steps:

1. On the Administrators tab, click the administrator in the details pane to open the editor.

   ![](/files/grmls3qNwBODunug17an)
2. In the administrator editor, scroll down to the **Direct Roles** section. Displayed here are any roles already assigned to this login. Click **Browse** to add a new role.

   ![](/files/vGvdh7hnZYskWU385Nen)
3. The Manage Roles screen will display.  This view allows you to navigate the Roles folder structure and search for specific roles.  The Roles folder will contain roles that are universal to all Adaptiva products that are installed. Check the box next to one or more roles to assign to the Administrator account.
   * To remove a role, uncheck the box next to the role.
4. Click **OK**.
5. In the administrators editor, the new role assignment will appear in the *Direct Roles* section. You can also remove a role assignment by click the ellipsis (**...**) and then **Remove**.

For existing administrators, changes to this list will save immediately. When you add or remove a role on an existing Administrator, saving the Administrator object is not necessary.  The new role assignment is applied immediately.

### Manage Role Assignments

To add administrator accounts, including AD Groups, to a specific role, follow these steps:

1. Click the **Roles** tab.
2. In the details pane, click the **All Admin Role**.

   ![](/files/aNxPL0GFyRa6dqIv9JK8)
3. Scroll down to the Role Membership section and click **Browse**.

   ![](/files/TARhmzgPONWH6sGZzlV8)
4. In the Select Administrator dialog, select one or more administrator accounts and click on **OK**.
5. Click **+Add AD Group**.

   ![](/files/32gu2JQ2IacyF8mLikmQ)
6. In the Active Directory Group dialog, enter the following:
   * **Domain Name**: Enter the NETBIOS Domain name
   * **Group Name**: Enter the Domain Local or Domain Global Group name
7. Click **Check Group** to verify group membership.

   > NOTE: The group must have members. Also, nested group membership is not supported, only direct members will be returned. Universal Groups are not supported.
8. Click **Add AD Group**.
9. Click **Save**.

   Members of the AD Group will automatically be created as Adaptiva Administrators and added to the All Admins Role

### Creating New Roles

Some organizations may want to create custom roles to control access to what some administrators can view or change. Roles can be created in the Web Portal, but at this time, Folder-level and Class permissions can only be assigned using the Adaptiva Workbench. Follow the steps below to create a new role:

1. On the Roles tab, click **+ New**.
2. In the Role editor, complete the following sections:

   ![](/files/YN2lx1Zd3LFnpGd0mDK6)

   **Role Properties**

   * **Role Name**: Give the role a descriptive name.
   * **Role Description**: A detailed description of the purpose of the roles.
   * **MFA Required**: Require all administrators assigned to the role to use multi-factor authentication.

   **Role Membership**

   Add direct administrators or AD Groups to the role. See the section [Manage Role Assignments](#manage-role-assignments).
3. In Role editor, click **Save**.


# Generate Microsoft Teams Webhook URL

When adding a new Administrator or modifying Administrator details in OneSite Patch, you can add a Teams Webhook URL to post notices to a specified Teams channel. Administrators can check the Teams channel for patch notifications and take the necessary action.

## Prerequisites

You will first need to create a Teams Channel and incoming webhook from the following Microsoft documentation:

* [Create a Microsoft Teams Channel](https://support.microsoft.com/en-us/office/create-a-standard-private-or-shared-channel-in-microsoft-teams-fda0b75e-5b90-4fb8-8857-7e102b014525)
* [Create an Incoming Webhook](https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/add-incoming-webhook?tabs=newteams%2Cdotnet#create-an-incoming-webhook)

### Configure Administration Settings

{% hint style="info" %}
You must be signed in as a Super Administrator in order to add a Teams Webhook URL to another admin account.
{% endhint %}

1. Click **settings gear > Settings > Security > Administrators**.

   ![Navigation to admin settings](/files/AlVa7Ui0eaHsQKDB9xrZ)
2. Open an existing Administrator or click **+ New** to create a new Administrator.
3. Copy and paste the Teams Webhook URL under **Administrator Details**.

   * The URL was generated from the Create an Incoming Webhook guide above.

   ![Administrator Details with webhook](/files/B4l3Y0CbmJVGKizmK9cc)
4. Click **Save**.


# Role-based Access Control

Role-based access control (RBAC) allows your organization to manage who has access to resources in the OneSite Platform, what resources they have access to, and what they can do with these resources.

## Role-based Access Control (RBAC) in the OneSite Platform

You can use built-in roles and/or create custom roles to meet your organization’s needs.

RBAC allows you to:

* Assign permissions to specific job functions like operations
* Maintain data protection and regulatory compliance
* Protect sensitive data with the principle of least privilege
* Create branch office administrators for specific business units (Patch only)

## Explore the security roles

1. Log in to the Adaptiva Admin Portal.
2. Click the **gear icon > Settings > Security > Roles**.

The root roles for the OneSite platform are in the Roles folder, while folders will exist for product specific roles when licensed.

![Roles Panel](/files/vLwoxJEqLdOjJDtuTOh9)

## View a role and assign members to it

You can view the permissions and membership of a role in the role details.

1. Select a role to open the properties page. You can view the role assignments and permissions detail for the role.
2. Under Direct Administrators, click **Browse** and select a user to associate with this role and click **OK**.
3. Click **Save**.

## Create a custom role

You can create a custom role in the **Role** security settings.

1. On **Roles** panel, select the **Roles** folder.
2. Click **New**.
3. Enter a name and description for the role (ie. Security Analyst).
4. On the detail page for the role, scroll down to Permissions.
5. Click **Create New Permissions**.
6. Next to Class, click **Browse**.
7. On the Class Permission Definition page, search for OIDC, and select **OidcProvider**.
8. Click **OK**.
9. On the Class Level Permissions page, under Permissions, configure the following: a. Read: Allow b. Export: Allow
10. Click **Save**.

## Audit role permission with Permissions Viewer

You can use Permissions Viewer to see the permissions scope for any role or user you configure.

1. Click the **Permissions Viewer** navigation tab.
2. Next to Role, click **Browse**.
3. Select a role (ex. Security Analyst) and click **OK**.
4. Under Object Scope, type OIDC and then select **OIDCProvider**. In the Resultant Permissions pane, you can see the permissions this role has on the OidcProvider class.


# Create OIDC Provider

{% hint style="info" %}
You can only configure single sign-on (SSO) in an on-premises Adaptiva Server. This does not apply to our SaaS solution.
{% endhint %}

You can configure Single Sign-On (SSO) to the Adaptiva Admin Portal using OIDC (OpenID Connect). This allows you to federate users and assign them roles in the Adaptiva Server.

Below are some OIDC Provider specific guides:

* [Microsoft Entra](/platform-guide/security/configure-sso/configure-sso-entra#enable-entra-single-sign-on-using-oidc)
* [DUO Security](/platform-guide/security/configure-sso/configure-sso-duo)
* [Okta](/platform-guide/security/configure-sso/configure-sso-okta)

## Enable Single Sign-on using OIDC

Before enabling OIDC in the Admin Portal, verify that your IAM provider supports OpenID Connect and TLS is enabled (by default) on your Adaptiva server.

1. Log in to the Adaptiva Server as a Super Admin user.
2. Select the gear ![](/files/uQZrTL7g8eorsa1f6TwK) in the upper right, and then navigate to **Settings > Security > OIDC Providers**.

   ![](/files/e3GFsOZwsStiboOf7CD7)
3. Select **+New** to open a new **OIDC Providers** settings page, and then configure the following **General Settings**:
   1. Enter a **Name** (such as Entra ID or Okta ID) for the OIDC Provider, and then add a detailed **Description**.
   2. (Optional) Add a logo for the OIDC provider.
4. Scroll down to **OIDC Settings** and add the details provided by the OIDC Provider ([Entra](/platform-guide/security/configure-sso/configure-sso-entra#create-an-oidc-provider), [Okta](/platform-guide/security/configure-sso/configure-sso-okta#create-an-oidc-provider), [DUO](/platform-guide/security/configure-sso/configure-sso-duo#create-an-oidc-provider)):

   ![](/files/ZOXruqzwxXnaj0mkNzCz)

   * **Authority** - The base URI provided by the OIDC provider.
   * **Client ID** - The client ID given to the Adaptiva server when registered with the provider.
   * **Client Authentication Type** - The type of client authentication the Adaptiva server should send to the identity provider when requesting ID Tokens.

     * **None** - Select none if you are using build 9.2 or earlier.

     *If your Adaptiva Server is using build 9.3 or later*, add the Client Secret that you received from the Identity Management administrator:

     * **Private key (JWT)**

     * **Client Secret (JWT)**

     * **Client Secret (Post)**

   1. Enter the Client Secret into the respective field.
   2. **Client Secret** - The client secret used by Adaptiva server to authenticate with OIDC provider.
   3. Click **Save**.

## Create new Administrator account

After creating the OIDC Provider, register users as Administrators using the following steps:

1. Log in to the **Admin Portal** as a Super Admin.
2. Select the ![](/files/uQZrTL7g8eorsa1f6TwK) **> Settings > Security > Administrators**.
3. Click **+New** and create an Administrator account.
4. Select the **Admin Type** dropdown menu, and select **OpenID Connect**.
5. Enter the email address for the user you are creating. The system uses this address to send an email invitation to the user, and to match the user with their IAM service identity.
6. Click the **Identity Provider** drop-down and select the provider (Entra, Okta, DUO).
7. Enter the first and last name of the user in the **User Details** section and add any additional information as needed.
8. In the Direct Roles section, click **Browse**. Select the appropriate role(s) for the administrator and click **OK**.
9. Select **Save**.
10. Select the **More** dropdown and click **Invite** to send an invitation email to the user. Refer to the account activation for information on what the invite user will see. If they do not accept the invitation in 24 hours, you will need to send a new invite.

### Register new account

After receiving the invitation email, the user can complete the account registration using the following steps:

1. Select **Register Account** in the email. This takes the user to the IAM service login page.

   ![](/files/gS9fk25T4J0HSLjb4Dfc)

{% hint style="info" %}
If the user is not already logged in, the IAM prompts them to log in.
{% endhint %}

1. Open a new session of the Admin Portal. The login screen now lists the new OIDC Provider.

   ![](/files/c27HlFXTxZDXoRdQNIa6)
2. Select the new login selection to log into the portal using your IAM credentials.


# Create SAML Provider

{% hint style="info" %}
You can only configure single sign-on (SSO) in an on-premises Adaptiva Server. This does not apply to our SaaS solution.
{% endhint %}

SAML (Security Assertion Markup Language) on the OneSite platform allows you to configure a SAML provider in order for your users to login via SSO.

Below are some SAML Provider specific guides:

* [Microsoft Entra](/platform-guide/security/configure-sso/configure-sso-entra#enable-single-sign-on-using-saml)
* [PingIdentity](/platform-guide/security/configure-sso/configure-sso-pingidentity)

## Create the SAML Provider in the Admin Portal

1. Log in to the Admin Portal as a Super Admin.
2. Click the **gear icon > Settings > Security > SAML Providers**.
3. On the SAML Providers page, click **+ New**.
4. Enter a name and description. You can also add a logo (.png).
5. Under **SAML Settings**, configure the following values:
   * **Issuer ID** - The unique name this provider puts in it's `saml:Issuer` element. Used to look up the signing key when receiving a response.
   * **Authentication Request URI** - The URI to send a `saml:AuthnRequest`. If not set, can not request login using `saml:AuthnRequest`, but can still receive responses from the service provider.
   * **Attribute Consuming Service Index** - The index given to the Adaptiva client if registered with the provider. If not set, the Adaptiva Server will automatically set a `AsertionConsumerServiceURL` attribute any `saml:AuthnRequest` it builds.
   * **Name ID Format** - The **NameID** format to request from the provider. If blank, it is equivalent to `urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified`. At construction, it will be set to `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`.
   * **Public Key Info** - The signing key in PEM format used to verify the signature of a SAML response.
   * **Audience** - The audience the server will expect to be declared in the SAML response. If not set, the server's auto-detected URL will be used.
6. Click **Save**.

### Create the Administrator account

After creating the SAML Provider, register users as Administrators using the following steps:

1. Select **Settings > Security > Administrators**.
2. Click **+New** and create an Administrator account.
3. From the Admin Type dropdown, select **SAML**.
4. Enter the email address for the user you are creating.

   The system uses this address to send an email invitation to the user, and to match the user with their IAM service identity. This email address must have been granted permissions in the IAM’s SAML application.
5. Click the **Identity Provider** drop-down and select the provider you created earlier.
6. In the **Subject ID** field, enter the same email address used above.
7. Under **Administrator Details**, enter the first and last name of the user and add any additional information needed.
8. Under Direct Roles, click **Browse**. Select the appropriate role(s) for the administrator and click **OK**.
9. Select **Save**.

### Test the Login

1. Ask the user to test the login using SAML.
2. Navigate to the Admin Portal. The login screen now lists the new SAML Provider.
3. Select the new provider and log in to the portal using your IAM credentials.

{% hint style="info" %}
You may see the error `Error Message = Invalid Audience: https://ws25Tester:443, Error Code = 13 (0xd), Source Object = null propertyName[null]` In this example the server FQDN has a capital `T` in the server FQDN Entity ID. Make sure the Audience entry matches the case returned in the error.
{% endhint %}


# Configure SSO

The OneSite Platform can be integrated with OIDC and SAML providers to offer Single-Sign-On for added security.

We have several guides for providers along with how to set up both OIDC and SAML within the OneSite Platform.

Each guide will walk you through how to set up the 3rd-party provider configuration and the information needed to plug into the OneSite Platform OIDC and SAML settings. Once you have both sides set up, you can log into the OneSite Platform using your 3rd-party credentials.

## Adaptiva OneSite guides

* [Create OIDC Provider](/platform-guide/security/configure-oidc)
* [Create SAML Provider](/platform-guide/security/configure-saml)

## Provider specific guides

* [Configure SSO with Entra ID](/platform-guide/security/configure-sso/configure-sso-entra)
* [Configure SSO with DUO Security](/platform-guide/security/configure-sso/configure-sso-duo)
* [Configure SSO with Okta](/platform-guide/security/configure-sso/configure-sso-okta)
* [Configure SSO with PingIdentity](/platform-guide/security/configure-sso/configure-sso-pingidentity)


# Configure SSO with Entra ID

This guide outlines how to integrate the Adaptiva Server with Microsoft Entra ID. It provides configuration steps for both OpenID Connect (OIDC) and SAML (Security Assertion Markup Language), enabling secure single sign-on (SSO). With this integration your users can sign into the OneSite Platform using their Entra credentials adding a layer of security.

## Create an App Registration in Microsoft Entra

Create an App Registration for the Adaptiva Server to use for federation with Entra ID.

1. Log in to the Microsoft Entra admin center as a *Global Admin* or a delegate with *App Registration permissions*.
2. In the Search bar, enter **App Registrations**, and then select **App registrations** from results.
3. Select **New Registration**.

   ![](/files/rPUFuLIs6iPG0fx4hKPp)
4. Enter a **Name** for the application.

   ![](/files/YIAuxd2wyNlTTgUrIwm6)
5. Select the appropriate setting in the **Supported account types** section. Typically, you would select **Accounts in this organizational directory only**.
6. From the **Select a platform** drop-down, select either **Web** (build 9.3 or later) or **Single-page application (SPA)** (build 9.1 or 9.2).
7. Enter the URL as shown in the following example:

   `https://<AdaptivaServerFQDN>[:PORT]/login/oidc-redirect`.

   The `AdaptivaServerFQDN[:PORT]` is the name and port used to log in to the Adaptiva Server. For example, `https://cm.onelab.com:9678/login/oidc-redirect`.
8. Click **Register**.
9. *If your Adaptiva Server is using build 9.1 or 9.2*, add another URI:

   a. Select the **Redirect URIs** link from the Overview page.

   b. Click **Add URI**.

   c. Enter your URL into the respective field using the following format: `https://<AdaptivaServerFQDN>[:PORT]/login/oidc-redirect/registration`

   d. Select **Save**.
10. If the server is accessed using any other names besides the FQDN, create the necessary URIs for each name that you use.
11. Click **Register**.

### Create a Client Secret (build 9.3 or later)

*If your Adaptiva Server is using build 9.3 or later*, create a client secret for authentication to Entra ID.

1. Select **Certificates & Secrets** on the far-left action pane.
2. Select **+ New client secret**, under **Client secrets** on the **Clients & secrets** page:

   ![](/files/BnnIqq2MSKz4LT6dAq3k)
3. Enter a description in the **Description** field on the **Add a client secret** dialog, and then select the appropriate expiration timeframe based on the security guidelines of your company.

   ![](/files/I5r1MOBm7lqbDCnkzAw6)
4. Select **Add** to return to the **Clients & secrets** page.

   ![](/files/MAnMToAQBUX5CmNMRZDn)
5. Record the *value* of the secret to use in the Adaptiva Server. This secret value never displays again after you leave this page.

{% hint style="info" %}
Create a reminder on your calendar to create a new App secret before the secret expires.
{% endhint %}

6. Select **Overview** in the left-side pane.

   ![](/files/Yj8R1Z54fE1WLYuqsbV4)
7. Record the **Application (client) ID** and the **Directory (tenant) ID**.

## Create an OIDC Provider

Follow the steps on the [Configure OIDC](/platform-guide/security/configure-oidc) page, the one-to-one translation of information that is specific to DUO is below:

* **Authority** - This is the **Tenant URL** from Entra that you can copy and paste in the Authority field in the following format:

  `https://login.microsoftonline.com/<tenantID>/v2.0`

  The `<tenantID>` is the **Directory (tenant) ID** you recorded earlier.
* **Client ID** - This is the **Application (client) ID** from the Azure Global Admin.

*If using 9.3 or later:*

* **Client Secret** - This is the **Client secret (value)** from Entra.

### Updating your OIDC Configuration After Upgrading to Build 9.3

If you have upgraded to build 9.3 or later and have already configured OIDC, the following steps must be completed by the Azure Global Admin or a delegate to update your configuration.

#### Update the App Registration

1. Log in to the Microsoft Entra admin center as a *Global Admin* or a delegate with *App Registration permissions*.
2. Select **App registrations**.
3. Locate and select the App Registration created for the Adaptiva Server.
4. Select **Authentication**.
5. Click the trash can icon ![](/files/eiBVdYobaNWB3DdjQbwI) on the upper-right of the **Single-page application** section to delete all Redirect URIs.

   ![](/files/2Rn9qCr1vslFLUusWWWk)
6. Select **Delete** to confirm the deletion.

#### Create a Platform Configuration

1. Select **+ Add a platform**.
2. Select **Web**.
3. Enter the following URI in the **Redirect URI** field:

   `https://<AdaptivaServerFQDN>[:PORT]/login/oidc-redirect`
4. Select **Configure**.

#### Create a Client Secret

Follow the earlier steps to [create a client secret](#create-a-client-secret-build-93-or-later).

#### Update the OIDC Configuration

The following steps must be completed by the Adaptiva Administrator.

1. Log in to the Adaptiva Server as a Super Admin user.
2. Navigate to ![](/files/uQZrTL7g8eorsa1f6TwK) **> Security > OIDC Providers**.
3. Select the OIDC Provider that you created.
4. Select the **Client Authentication Type** in the **OIDC Settings** section, and then select **Client Secret (Post)**.
5. Enter the Secret you received from the Azure Global Admin into the **Client Secret** field. The **Show Secret** button appears after you enter the Secret into the **Client Secret** field.
6. Select **Save**.

## Enable Single Sign-on using SAML

### Create an Enterprise application in Azure

Create an Enterprise application for the Adaptiva Server to use for federation with Entra ID.

1. Log in to the Microsoft Entra admin center as a *Global Admin* or a delegate with *App Registration permissions*.
2. In the Search bar, enter **Enterprise applications** and then select **Enterprise applications**.
3. Click **New application** and then click **Create your own application**.
4. Enter a name and select the **Integrate any other application you don't find in the gallery (Non-gallery)** radio button.
5. Click **Create**. The application Overview page will appear.

### Assign Users

1. Click **Assign users and groups**.
2. Click **+ Add user/group**.
3. Under **Users and groups**, click the link and check the users or groups you want to grant access to the application.
4. Click **Assign**.
5. In the left-hand navigation, click **Single sign-on**.

#### Configure SAML single sign-on

1. On the application's overview page, in the left-hand navigation, select **Single sign-on**.
2. Click **SAML** as the single sign-on method.
3. On the Set up Single Sign-On with SAML page, under **1. Basic SAML Configuration**, click **Edit**.
4. Click **Add identifier**.
5. Enter the Identifier (Entity ID): `https://<AdaptivaServerFQDN>[:PORT]`.
6. Click **Add reply URL**.
7. Enter the Reply URL from your service provider's configuration: `https://<AdaptivaServerFQDN>[:PORT]/api/v1.0/authentication/saml-login`.
8. Click **Save**.
9. Under **3. SAML Certificates**, click the links to download the **Certificate** and **Federation Metadata XML** files.
10. Under **Step 4. Set up** , record the following links:
    1. Login URL: `https://login.microsoftonline.com/[GUID]/saml2`
    2. Microsoft Entra Identifier: `https://sts.windows.net/[GUID]/`
    3. Logout URL: `https://login.microsoftonline.com/[GUID]/saml2`

### Create the SAML Provider in the Admin Portal

Follow the steps on the [Configure SAML](/platform-guide/security/configure-saml) and enter the following information from Entra into the **SAML Settings** section below:

* **Issuer ID**: enter the **Microsoft Entra Identifier**
* **Authentication Request URI**: enter the **Login URL**
* **Attribute Consuming Service Index**: leave blank
* **Name ID Format**: Leave default
* **Public Key Info**: Open the certificate file (.cer) and copy and paste the contents into the window.
* **Audience**: Enter the same as the **Identifier Entity ID**. If you did not specify a port, include :443 to the server address.

## Log in page

After Microsoft Entra and the OneSite Platform have been federated using OIDC or SAML, an SSO button will appear on the login page. Once clicked, users will be redirected to a Entra login page and granted access to OneSite Platform.

![](/files/c27HlFXTxZDXoRdQNIa6)


# Configure SSO with DUO Security

Adaptiva integrates with DUO Security using the OpenID Connect (OIDC) protocol to provide single sign-on (SSO). In this setup, DUO acts as the identity provider (IdP) and manages user authentication, while Adaptiva relies on DUO to authenticate users and validate OIDC tokens. This allows your users to login with their DUO credentials adding an extra layer of security.

Below is a walkthrough on how to setup a relying party in DUO and then use the generated information to setup an OIDC provider in the OneSite Platform.

## Create a Generic OIDC Relying Party - SSO

First we'll begin by creating an application integration in the DUO security admin portal.

1. Select **Applications > Manage > Applications**, then click the **+ Add application** button.
2. Search for **Generic OIDC Relying Party** and click **+ Add**.

   ![](/files/YGzQJjxGFM2LJ5w3Xk0B)

### Basic Configuration

1. Change the **Application Name**.
   * e.g. Adaptiva SSO
2. Select either **Enable only for permitted groups** or **Enable for all users**.

### Metadata

Upon creation, DUO populates the following fields that you'll need to complete your OIDC setup in the Adaptiva Admin Portal.

* **Client ID**
* **Client Secret** - For versions 9.3 and above.
* **Issuer** - Base URL for every endpoint.

### Relying Party

1. If you are using versions 9.1 or 9.2, you will need to check the **Allow PKCE only authentication** box.
2. Add the redirect URL using the format below:
   * `https://<AdaptivaServerFQDN>:[PORT]/login/oidc-redirect`
3. Scroll the the very bottom and click **Save**.

### Add users on DUO

By default, admin users are not added to the **User** list, so you will need to add those manually for all users you wish to use the DUO SSO.

1. Select **Users > Users** from the side navigation.
2. Click the **Add User** button and enter the user information then click the **Add User** button.

   ![](/files/71wlOhmkuKcp2d2q3KEL)

   If **Enable for All users** was selected for the Application, this new user will be automatically added. However, if **Enable only for permitted groups** was selected these users will need to be added to specific groups to be included in the OIDC application.

## Create an OIDC Provider

Follow the steps on the [Configure OIDC](/platform-guide/security/configure-oidc) page, the one-to-one translation of information that is specific to DUO is below:

* **Authority** - This is the **Issuer** base URL from DUO that you can copy and paste in the Authority field.
* **Client ID** - This is the **Client ID** from DUO.

*If using 9.1-9.2:*

* **Client Authentication Type** - Select **Client Secret (Post)** from the dropdown.
* **Client Secret** - This is the **Client Secret** from DUO.

  View from DUO Application dashboard:

  ![](/files/gzNdKje9W4QWitJVzuYk)

  View from Adaptiva server settings:

  ![](/files/vLv5dCb4dv8MNauK8PDb)

## Log in page

After Duo Security and the OneSite Platform have been federated using OIDC, an SSO button will appear on the login page. Once clicked, users will be redirected to a Duo login page and granted access to OneSite Platform.

![](/files/bOEGCyTgevgnvjYJyCit)


# Configure SSO with Okta

Adaptiva integrates with Okta using the OpenID Connect (OIDC) protocol to provide single sign-on (SSO). In this setup, Okta acts as the identity provide (IdP) and manages user authentication, while Adaptiva relies on Okta to authenticate users and validate OIDC tokens. This allows your users to login with their Okta credentials adding an extra layer of security.

Below is a walkthrough on how to setup a relying party in Okta and then use the generated information to setup an OIDC provider in the OneSite Platform

## Create an OIDC App Integration

1. Log in to the Okta Admin Console.
2. Navigate to **Applications > Applications** and click **Create App Integration**.

   ![](/files/jLC0S04Z7Zebe29XMxfg)
3. Select **OIDC - OpenID Connect** as the sign-in method.
4. Choose the application type:

   If using 9.2 select **Single-Page Application (SPA)**

   If using 9.3 or later select **Web Application**

   ![](/files/39dWUbaXmxAiCoH3KwOu)
5. Click **Next**.

### Configure general settings

1. Provide an App Integration Name.
   * e.g., Adaptiva OIDC.
2. Configure **Demonstration of Proof-of-Possession (DPoP)** header if applicable.
3. Select the appropriate Grant Types:
   * **Authorization Code** (recommended for web apps)
   * **PKCE (Proof Key for Code Exchange)** for SPAs or native apps.

#### Sign-in Redirect URIs

1. Add the required **Sign-in Redirect URIs** where Okta will send authentication responses.

   `https://<AdaptivaServerFQDN>[:PORT]/login/oidc-redirect`

   Replacing AdaptivaServerFQDN and an optional PORT number with the specifics for your Adaptiva server.

   For example, `https://cm.onelab.com:9678/login/oidc-redirect`.

   For 9.2 only, add a second redirect URI.

   `https://<AdaptivaServerFQDN>[:PORT]/login/oidc-redirect/registration`
2. (Optional) Add a **Sign-out redirect URI**.

   ![](/files/tBctbdQPr95SVcmGPToE)

### Trusted Origins and Assignments

You can assign trusted origins for cross-origin requests if needed.

Assignments will be handled within the OneSite platform, so you can select **Skip group assignment for now**.

### Save and retrieve credentials

1. Save the configuration to generate a **Client ID** and a **Client Secret**.

You will use the following in OneSite when configuring your OIDC:

* **Authority** - Base URI of the Okta OIDC Provider.

  By default when creating an Application, the Issuer URL is set to **Dynamic**. To change this to the **Okta URL**:

  1. Select the **Sign On** tab.
  2. Click **Edit** in the **OpenID Connect ID Token**.
  3. Select **Okta URL** from the **Issuer** dropdown.

  You'll want to make sure this URL matches exactly what you have for **Authority** in the Adaptiva OIDC settings.

  ![](/files/DhHeMbx5KqySMO0LOMKl)
* **Client ID**
* **Client Secret** - OneSite version 9.3 or above.

### Assign User to Application

The OIDC Application is not assigned to the admin by default, so you will need to assign it to your user(s).

1. Select **Directory > People** from the side navigation.
2. Select **+ Add person** and create a user.
3. Select the new or existing user.
4. Select the **Assign Applications** button and assign Adaptiva Okta.
5. Click **Done**.

Additionally you can view assigned users in your Application settings from the **Assignments** tab.

![](/files/vc6roVVFdpjWYoRSoz57)

## Create an OIDC provider

Follow the steps on the [Configure OIDC](/platform-guide/security/configure-oidc) page on how to setup the OIDC provider within the Adaptiva Admin Portal. The one-to-one translation of information that is specific to Okta is below:

* **Authority** - This is the base URL from Okta that should be in the format:

  `https://<yourOktaDomain>`
* **Client ID** - This is the **Client ID** from Okta.

*If using 9.1-9.2:*

* **Client Authentication Type** - Select **Client Secret (Post)** from the dropdown.
* **Client Secret** - This is the **Client Secret** from Okta.

  View from DUO Application dashboard:

  ![](/files/OHvAT4q2AFvVroa0Bc1I)

  View from Adaptiva server settings:

  ![](/files/jsn0MdOxJ1oVIYXtwA5c)

## Log in page

After Okta and the OneSite Platform have been federated using OIDC, an SSO button will appear on the login page. Once clicked, users will be redirected to a Okta login page and granted access to OneSite Platform.

![](/files/8zdRzmZeBfqQVYu3r771)


# Configure SSO with PingIdentity

Adaptiva integrates with PingIdentity using the Security Assertion Markup Language (SAML) protocol to enable single sign-on (SSO). In this setup, OneSite acts as the SAML service provider (SP), while PingIdentity serves as the identity provider (IdP) and is responsible for authenticating users. This allows users to log in with their PingIdentity credentials to the OneSite Platform, adding an extra layer of security.

Below is a walkthrough on how to setup a relying party in PingIdentity and use the generated information to set up an OIDC provider in the OneSite Platform.

## Create Environment in PingIdentity

After you have logged into your PingIdentity dashboard, you'll need to create a new Environment.

1. Click **+** next to **Environments** from the admin dashboard.
2. Choose **Customer solution** and continue through the wizard and follow any additional setup instructions for PingOne SSO.

   ![](/files/gEyLZizR2kS3tRD9JTyN)
3. Click **Next**.
4. Enter a **Name** and **Description** and select desired configurations from the **Services** section.
5. Click **Finish**.

## Create an Application

Next you'll need to create the Adaptiva SSO application.

1. Click on the environment you just created and select **Manage Environment**

   ![](/files/GVXIEt8S4ulXQ0nuuj6W)
2. Select **Applications > Applications** from the side navigation.
3. Click the **+** button next to Applications.

   ![](/files/jRYTz8kGnkMc6CkfiqaM)
4. Enter a **Name** and a **Description**.
5. Select **SAML Application** under **Application Type**.
6. Select **Configure**.

   ![](/files/inGNIK4FiRUeGqu02vgg)
7. Select the **Manually Enter** radio button and enter the ACS URL in the following format:

   `https://<adaptiva-server-FDQN:PORT>//api/v1.0/authentication/saml-login`

   ![](/files/Z0yZmyufQUbybsdqwMZn)
8. Enter the **Entity ID**:

   `https://<adaptiva-server-fdqn:PORT>`
9. Click **Save**.
10. Select the **Download Signing Certificate** button under **Connection Details** and select the `.crt` format.
    * You will need this certificate later to complete the [Create the SAML Provider in the Admin Portal](#create-the-saml-provider-in-the-admin-portal) steps below.
11. Select the **Attribute Mappings** tab.
12. Select the pencil edit icon and change the PingOne map to **Email Address**.

    ![](/files/ZDGNFkPxjLl6gngDmhiE)

## Create a User

You will need to create users to add to your group. To create a new user, please follow the steps in the [PingOne - Adding a user](https://docs.pingidentity.com/pingone/directory/p1_adduser.html) documentation.

## Create a Group

Next you will need to create a Group to add your users to, then add the Group to the SAML application. Please follow the steps in this guide on how to create a group [PingOne - Create a group](https://docs.pingidentity.com/pingone/pingone_tutorials/p1_p1tutorial_create_a_group.html).

### Add a group to your application

1. Select the **Access** tab and select the pencil edit icon and select the group you'd like to add and configure any desired settings.

   ![](/files/3GYywKuPEJni4YO7NPst)

## Create the SAML Provider in the Admin Portal

Follow the steps on the [Configure SAML](/platform-guide/security/configure-saml) and enter the following information from PingOne into the **SAML Settings** section below:

* **Issuer ID** - Enter the **Issuer ID** from PingIdentity.
* **Authentication Request URI** - Enter the **Initiate Single Sign-on URL**
* **Attribute Consuming Service Index** - leave blank.
* **Name ID Format** - Leave default.
* **Public Key Info** - Open the Signing Certificate you downloaded in a previous step in Notepad and copy and paste in this text box.
* **Audience** - Enter the **Entity ID**

  Adaptiva SAML settings view:

  ![](/files/NvaUwI8kfUzr3dqR5JZS)

## Log in page

After PingIdentity and the OneSite Platform have been federated using SAML, an SSO button will appear on the login page. Once clicked, users will be redirected to a PingIdentity login page and granted access to OneSite Platform.

![](/files/LpHZI0sqjWpi8pOkFwHA)


# Server and Client Logs

Log information, what kinds of logs, where they are stored, etc

The Adaptiva server logs and client logs are available to monitor the solution and troubleshoot issues.

When working with [Adaptiva Support](https://adaptiva.com/support), please download or copy the logs out of their home folder and compress them before sharing with your support agent.

## Download or View Logs

1. Click the settings gear in the top right of the Admin Portal, and then click **Logs**.
2. Click the option that best fits your needs. Details are listed below.

If you want to see a specific log file or view real-time logs, you can navigate directly to the folder path provided.

### Download Server Logs

For server logs, you can **Download All Server Logs** or **Download Server Error Logs**. The latter option is a filter for when you only need to look for potential errors.

### Download Web Browser Logs

Web browser logs are helpful for troubleshooting if you are in a situation where the UI is not working properly, but nothing appears in back-end error logs, such as adaptiva.err. In this situation, it's possible that the web browser could be the problem.

Note: Clear Web Browser Logs is a troubleshooting solution that you should only click if directed to do so by a support agent. This sets a clear, restart-logging marker.

### View Audit Logs

Audit logs record changes to the objects stored in the Adaptiva Server. You can use these logs to create a record of action taken by administrators. With the on-prem version, you can [set up some auditing policies](https://support.adaptiva.com/hc/en-us/articles/4417395418509-Audit-Logging-in-Adaptiva-OneSite) to get specific about what you want to audit.

### View Client Logs

If you want to troubleshoot a specific client, you can use **View Client Logs** without having to physically go to each client machine. When you click this option, choose the specific client you want logs for, and then click **Download**. This command aggregates that client's logs into one \*.log file.

![View Client Logs menu option](/files/Airf4UVoZTlkUNJVHPi3)

## Server Logs

Location: `%ADAPTIVASERVER%\logs`

* `adaptiva.err`: Records any errors during the running of the AdaptivaServer service.
* `adaptiva.log`: Records almost all data regarding AdaptivaServer service.
* `AdaptivaNativeUtils.log`: AdaptivaServer to windows access logging.
* `AdaptivaNativeUtilX.log`: AdaptivaClient FIPS cryptography operations using OpenSSL.
* `AdaptivaServerNativeUtils.log`: Logs from native library such as addition and removal of SMB connections for networked filesystems.
* `AdaptivaService.log`: AdaptivaService service start/stop logging.
* `AdaptiveProtocolTransport.log`: AdaptivaServer data transfers using Adaptive Protocol.
* `messagingMonitor.log`: Logs all RVP advertisements.
* `ntlmauth.log`: Logs NTLM and Kerberos authentication for SQL Server from native library.
* `revision.properties`: Contains the timestamp, git commit id, and full version of the code for this install.
* `sqlMonitor.log`: Call to SQL logging.
* `VCDiff.log`: Logs generated by the native component responsible for creating diffs between two files. These files typically belong to different versions of application-level content for which differences (diffs) are computed.
* `VCDiffDecoder.log`: Logs generated by the native component responsible for applying a diff to a previous file version in order to reconstruct the updated content.

### Server Component Logs

Location: `%ADAPTIVASERVER%\logs\componentlogs`

* `Akka.log`: Logs from the server's REST API.
* `BlobServer.log`: Logs for internal system used for blob downloads.
* `BlobVersionAuditor.log`: Used for blob system auditing. Blob system is used when integrated with Microsoft Configuration Manager.
* `ByteLevelP2PPublisher.log`: Logs publication of content using the byte-range peer-to-peer protocol.
* `CdnService`: Catch-all log for anything to do with accessing the CDN service. Typically this covers service initialization, obtaining credentials from the operations manager, and upload and download of content.
* `ClientUpgrade.log`: Client auto upgrade system logs.
* `ContentSQLQuery.log`: Logs content receipts.
* `CrowdStrike.log`: Logs operations related to the vulnerability management integration with CrowdStrike.
* `DeltaSeries.log`: Tracks download and assembly of delta series content, i.e. content for which an earlier version may already exist locally. Typically useful when monitoring feeds, for which it handles content download before consumption. On customer servers, this log also covers distribution of delta series to client systems.
* `Feeds.log`: Tracks the receipt of feeds from the operations manager, and their subsequent consumption or distribution to client machines. Download of feed content is handled by the delta series system, which logs that part in more detail.
* `HTTP.log`: Used to monitor the health of the application's HTTP clients and connection managers.
* `IntentHistory.log`: Logs server-side changes made to Intent Schema objects.
* `License.log`: Records the status of the licenses enabled on the server.
* `MASFileActivity.log`: Covers direct content uploads from MAS to the public CDN. Note that this is distinct from feed publication, which also uploads content.
* `MemoryManager.log`: Current server memory usage and changes in memory usage.
* `MetadataCommon.log`: Logs CVE mapping updates for metadata objects.
* `MetadataOperations.log`: Logs patch blocklisting operations.
* `MultiTenancy.log`: Logs when tenants are created, updated and deleted on multi-tenant systems.
* `OperationsManagerRequests.log`: Logs requests sent to Operations Manager.
* `P2PRing.log`: Logs information about P2P ring system which is used for uploading the status messages from clients.
* `Patching.log`: Miscellaneous patching-related logs.
* `PatchingApprovals.log`: Logs when patch approvals are created or updated.
* `PatchingStatusCollection.log`: Logs receipt of patch statuses from clients and persistence to the database.
* `Provisioning.log`: Logs server activation via Operations Manager.
* `PayloadActivation.log`: Logs the arrival of new policy payloads from the server pending activation, including their policy ID, payload ID, and scheduled activation time.
* `RelayDetailed.log`: Detailed logging for Relay connectivity and Security protocols on HTTP. RelayDetailed are the previous HttpTransport, Security, and Relay logs combined into one file. This includes detailed error messages with stack traces as well as verbose logging for tracing requests end to end.
* `RelaySimple.log`: Provides an overview of handshakes and HTTP messaging from a more conceptual standpoint. Instead of logging through the train of classes and method executions involved in the process, it is intended simply to say the handshake completed successfully. It can be used to confirm that the system is working as intended, or that something broke and the detailed logs may need digging through.
* `RestApiFoundry.log`: Logs requests and authentication used by the API Foundry tool.
* `SensorOfflineCache.log`: This system does scheduled collection of data on clients and uploads diffs to the server.
* `SqlDataProvider.log`: Logs interactions with the system used to author and execute SQL for dashboards and analytics.
* `SQLUploader.log`: Logs when payloads of data are sent to the server to be inserted into the database in bulk.
* `ThreadInfo.log`: Output for logging current thread state information when slm.logthreadstates or slm.log\_thread\_cpu\_info is set to true.
* `TwilioSendGrid.log`: Logs interactions with third-party APIs for communication providers such as Twilio, SendGrid and Microsoft Teams.
* `UserDashboardSubscription.log`: Logs export of dashboards to Excel.
* `Utils.log`: Generic utility logs.
* `VulnerabilityManagement.log`: Logs receipt and processing of vulnerability data from vulnerability management integrations.
* `WebUINotifications.log`: Notifications delivered and received from the frontend Web UI.
* `WindowsPatching.log`: Progress and results of scans and patches for Windows Update and Office365.
* `WorkflowStatus.log`: Execution status, progress and errors related to workflow invocations.

### Server Workflow logs

Default Folder: `%ADAPTIVASERVER%\logs\workflowlogs`

* `<workflowname>-<workflowid>-<sequencenumber>.log`: All server and business workflows execution logging.

## Client Logs

Location: `%ADAPTIVACLIENT%\logs`

* `adaptiva.err`: Records any errors during the running of the AdaptivaClient service.
* `adaptiva.log`: Records almost all data regarding AdaptivaClient service which is not present in component logs.
* `AdaptivaClientValidator.log`: Adaptiva client setup validator tool logs.
* `AdaptivaNativeUtils.log`: AdaptivaClient to windows access logging.
* `AdaptivaNativeUtilX.log`: AdaptivaClient FIPS cryptography operations using OpenSSL.
* `AdaptivaRemoteInstallLog.log`: (Intune Edition only) Intune p2p content download initiation from IntuneManagementExtension.
* `AdaptivaService.log`: AdaptivaClient service start/stop logging.
* `AdaptivaServiceRestart.log`: AdaptivaServiceRestart.exe logging, used mostly by AdaptivaClient Setup during install or upgrades.
* `AdaptivaWindowsUpdateHelper.log`: Logs for a helper process which is used in Windows Update patching; includes the process ID and start time of the helper process.
* `AdaptiveProtocolTransport.log`: AdaptivaClient data transfers using Adaptive Protocol.
* `messagingMonitor.log`: Logs all message counts.
* `OneSiteProvider.log`: (OneSite Anywhere or ConfigMgr Edition Only) Logs activity of the ConfigMgr Client and the Adaptiva Client ACP and vice-versa for 32-bit OSes.
* `OneSiteProvider64.log`: (OneSite Anywhere or ConfigMgr Edition Only) Logs activity of the ConfigMgr Client and the Adaptiva Client ACP and vice-versa for 64-bit OSes.
* `revision.properties`: Contains the timestamp, git commit id, and full version of the code for this install.
* `sqlMonitor.log`: All SQL row counts.
* `VCDiff.log`: Logs about generating differentials between different versions of content.
* `VCDiffDecoder.log`: Logs about applying differentials between different versions of content.

### Client Component Logs

Location: `%ADAPTIVACLIENT%\logs\componentlogs`

* `_SDMErrors.log`: Errors related to deployment of patches.
* `ActionExec.log`: Logs activity for action executions.
* `BlobSystem.log`: Logs for internal system used for blob downloads.
* `BRP2PDownload.log`: Byte Range Peer-to-peer download for Windows Update and Microsoft 365 updates. Download related information on a client.
* `BRP2PDownloadTrace.log`: Specific information about where a byte range is downloaded from, it's either from CDN or from a peer.
* `BRP2PRvp.log`: Information about a client serving as an RVP in the Byte Range Peer-to-peer system.
* `BRP2PUpload.log`: Byte Range Peer-to-peer upload for Windows Update and Microsoft 365 updates. Upload related information on a client.
* `BRP2PUploadTrace.log`: Specific information about which peer a specific byte range block is sent to.
* `BulkMessaging.log`: Logs activity related to extremely fast new P2P messaging system.
* `CacheMigrationClient.log`: Records activity of the cache migration tool.
* `CHSClient.log`: Records activity of the Client health modules.
* `ClientInfo.log`: Client registration with server and Client IP address in use for communication logging.
* `ClientSetupChecks.log`: Client setup checks logs.
* `ClientUpgrade.log`: Client auto upgrade system logs.
* `Configuration.log`: Client system configurations changes logging.
* `ContentCache.log`: AdaptivaClient cache state logging.
* `ContentDeleter.log`: Logs activities of Adaptiva Client content deletion.
* `ContentDownload.log`: Logs all content downloads.
* `ContentLockManager.log`: Logs activity related to P2P locking done during content downloads.
* `ContentPush.log`: Content pre-staging/push logging.
* `ContentUnpack.log`: Content unpacking logging.
* `ContentUpload.log`: Content uploads from client to client.
* `DeltaSeries.log`: Logs download and assembly of delta series content, i.e. content for which an earlier version may already exist locally. Typically useful when monitoring feeds, for which it handles content download before consumption.
* `DownloadCompleted.log`: Logs all the content download completed details.
* `EPH.log`: (OneSite Health only) Contains information about the execution of OneSite Health policies on the client side. It logs the various health checks performed as part of the policy, along with the results that are sent back to the server.
* `Feeds.log`: Logs activity related to feeds. This includes initial receipt, dependency checks, consumption, and removal. Note that feed downloads are handled by the delta series system, and covered more extensively in that log.
* `FileDeletion.log`: Logs all Adaptiva file deletion requests (non-content).
* `GPClient.log`: (OneSite WakeUp only) Green Planet client logging.
* `HTTP.log`: Used to monitor the health of the application's HTTP clients and connection managers.
* `HttpTransport.log`: Client HTTP transport logs. HttpTransport is used when client binds to Adaptiva Server URL.
* `InternetPeer.log`: Contains details about communication for an internet client. It can be a pure internet or split internet client. This contains details about behaviors and protocols for internet client.
* `Inventory.log`: AdaptivaClient inventory collection and reporting logging.
* `IPC.log`: Logs inter-process communication between AdaptivaClient and other applications.
* `LargeMsgTransport.log`: Logs related to AdaptiveTransport for messages.
* `License.log`: Records the status of the client license.
* `LinuxPatching.log`: (OneSite Patch only) Tracks Linux package scanning, policy evaluation, deployment dependencies and patch pausing.
* `Locking.log`: General concurrent locking logs.
* `MemoryCache.log`: Logs related to CachedHashMap.
* `MemoryManager.log`: Current client memory state and changes logging.
* `Messaging.log`: Messaging ports start and stop logging.
* `MKDCHandler.log`: Logs the method in case Adaptiva client needs to stop because of some fatal error.
* `NatTraversal.log`: Logs details about NAT traversal used for internet peer to peer protocol.
* `NetworkLocation.log`: Contains details about current network location for this client. It can be one of these (ON\_PREMISES,ON\_PREMISES\_SPLIT,INTERNET,FORCED\_TUNNEL\_VPN,SPLIT\_TUNNEL\_VPN,UNKNOWN).
* `ObjectDeployment.log`: Adaptiva object deployment system logs.
* `OEMManager.log`: (OneSite WorkspaceONE Edition only) Logs related to 3rdParty OEM integrations.
* `Office365.log`: Logs Office 365 patch installations.
* `OfficeLockManager.log`: Logs related to Office level locking used in advanced functions. (e.g. in IntelliStage).
* `OneSiteDownload.log`: ConfigMgr client ACP invocation and downloads logging.
* `OneSitePreCache.log`: Content pre-caching logging.
* `OperationsManagerRequests.log`: Logs operations manager requests send from client.
* `P2PDiscovery.log`: Logs related to P2P discovery.
* `P2PDiscoveryCache.log`: Logs information about caching of results for P2P system.
* `P2PRing.log`: Logs information about P2P ring system which is used for sending status messages from client to server.
* `P2PStore.log`: Logs related to client’s local P2P store.
* `PatchContentDownloader.log`: Tracks the of non-Windows patch content, the order in which they are downloaded and the space requirement on disk for each update.
* `Patching.log`: Scan statuses for patches, metrics scans for patches, maintenance window openings.
* `PatchingAdmin.log`: Logs administrative actions for patching as observed by the client.
* `PatchingPolicyClient.log`: Logs the arrival of new or updated patching policies from the server, changes in business unit settings, patch prestaging requests, changes in patch desired states.
* `PatchNotifier.log`: Displaying and cancelling desktop notifications related to patching (such as reboot notifications).
* `PayloadActivation`: Logs the arrival of new policy payloads from the server pending activation, including their policy ID, payload ID and scheduled activation time.
* `PolicyManager.log`: Policy operations and processing logging.
* `PXE.log`: Records PXE service availability and communication.
* `RegIPC.log`: Logs activity related to IPC using windows registry.
* `RelayDetailed.log`: Detailed logging for Relay connectivity and Security protocols on HTTP. RelayDetailed are the previous HttpTransport, Security, and Relay logs combined into one file. This includes detailed error messages with stack traces as well as verbose logging for tracing requests end to end.
* `RelaySimple.log`: Provides an overview of handshakes and HTTP messaging from a more conceptual standpoint. Instead of logging through the train of classes and method executions involved in the process, it is intended simply to say the handshake completed successfully. It can be used to confirm that the system is working as intended, or that something broke and the detailed logs may need digging through.
* `RelayTrackingClient.log`: Logs messages requested to route through cloud relay servers for internet clients.
* `RelayTrackingServer.log`: Logs messages received from cloud relay servers for internet clients.
* `RemediationExec.log`: (OneSite Health only) Logs related to execution of remediation on the client.
* `RemoteWorkflowExecution.log`: Logging for remote workflow execution using tool foundry.
* `RVPOSDSupporter.log`: Records RVP content requests for clients executing OSD.
* `RVPState.log`: Displays RVP state for the local subnet.
* `SCCMClient.log`: (OneSite Anywhere or ConfigMgr Edition Only) Records interactions with the local ConfigMgr client.
* `SCCMDataUpload.log`: (OneSite Anywhere or ConfigMgr Edition Only) ConfigMgr client data upload management logging.
* `SCCMPolicyPolling.log`: (OneSite Anywhere or ConfigMgr Edition Only) ConfigMgr client policy polling management logging.
* `Scheduler.log`: AdaptivaClient scheduler.
* `Security.log`: Records the updating of ACLs.
* `SensorExec.log`: Execution of various sensors designed to query information about the system, such as installed applications.
* `SensorOfflineCache.log`: This system does scheduled collection of data on clients and uploads diffs to the server.
* `SentRecvMsg.log`: Logs all messaging between client-server and client-client.
* `ServerLocator.log`: Logs activity related to server binding, connectivity.
* `SmallMsgTransport.log`: Logs related to small UDP messages.
* `SoftwareDeploymentManager.log`: Logs related to patch deployment, including creation, progress, potential issues which may block the deployment of a patch and the success or failure stages of a patch deployment.
* `SoftwareInstaller.log`: Logs the status of software installation processes, including whether the installer is busy or its exit status.
* `SoftwareRelationshipManager.log`: Tracks the status of dependencies and relationships between software components being patched.
* `SparseFileSystem.log`: Data transferred by the Byte Range Peer-to-peer system is stored in sparse files on each participating clients. This file logs information about the reading and writing of these sparse files.
* `SQLAccess.log`: Logs local client database activity.
* `SQLUploader.log`: Logs information about uploading data to client SQL.
* `Startup.log`: Startup and shutdown logging for AdaptivaClient.
* `Telemetry.log`: This system handled running on demand queries for client data.
* `ThreadInfo.log`: Output for logging current thread state information when slm.logthreadstates or slm.log\_thread\_cpu\_info is set to true.
* `TFTP.log`: Records TFTP communications for boot image file delivery during PXE boot.
* `UserPortal.log`: Logs for the separate AdaptivaUserPortal Service, which performs user-specific actions such as displaying desktop notifications.
* `Utils.log`: Generic utility logs.
* `VirtualSMP.log`: Logs virtual state migration point activities.
* `WIFI.log`: WiFi office transition logging.
* `WindowsPatching.log`: Progress and results of scans and patches for Windows Update and Office365.
* `WOL.log`: Logs related to any Wake On LAN activity.
* `WorkflowStatus.log`: Execution status, progress and errors related to workflow invocations.
* `WorkflowSystem.log`: Any workflow related logs.

### Client MSI Installation Logs

Location: `%ADAPTIVACLIENT%\logs\msiLogs`

* `<productid>_<download identifier>.log`: MSI installation log for a given product and download.

### Client Workflow Logs

Location: `%ADAPTIVACLIENT%\logs\workflowlogs`

* `<workflowname>-<workflowid>-<sequencenumber>.log`: All client workflows execution logging.


# Assets


# Devices

The Devices pane allows you to view and manage all of your devices for each location and business unit.

In the Admin Portal, click **Assets > Devices**. This will display a table of all clients reporting into the server. You can view each device's full information by clicking the **>** dropdown.

![](/files/UsyjY0clRLWFLrH4Wlnu)

## Devices actions

There are two options for you to manage a device(s)

* **Remove Device**

  When a client is no longer valid, click the ellipses (**...**) next to the device entry and click **Remove Device**. This will remove the device from the service database. This can be useful when a machine is re-imaged and it's name has changed, but the record of the old client is still listed.

  When you remove the agent from the Device pane, it does not uninstall. It will trigger the agent to inactivate. The next time the client checks in it will ask for a new id.

{% hint style="info" %}
By default, inactive client records are purged after 21 days, but until the purge occurs the old record will still consume a license.

If the client does not check in for 21 days, the server will remove that client form the asset list, and the Client will mark itself as inactive. If it comes online again it will ask for a new ID and re-initiate communications.

You can change this duration in the Registry Editor from **HKLM\SOFTWARE\Adaptiva\client\client\_data\_manager.inactive\_client\_duration**. This value is in milliseconds by default (1814400000 = 21 days).

<img src="/files/9UbfPtg0FYIQgP2mO1Bn" alt="Image of registry key editor denoting the HKLM\SOFTWARE\Adaptiva\client\client_data_manager.inactive_client_duration value." data-size="original">
{% endhint %}

* **Sync Policies**

  When you click **Sync Policies** this will send a command to the selected device(s) to sync client policies. This is useful when client policies have changed and you want to manually sync these changes, or if a new device is added and you want to ensure the client policies are enacted.

  To verify if a device was properly synced, you can view the PolicyManager log via:

  `C:\Program Files\Adaptiva\AdaptivaClient\logs\componentlogs`

  ![](/files/CIklEREK3c4IyDN4Un6o)

  For more information, please see our [Client Settings Policies](/platform-guide/client-management/client-settings) page.


# Groups

Description of groups and how to work with them.

Groups allow you to target a set of devices based on a defined scope, such as location, client properties, or sensor data. Groups are commonly used for device targeting in both OneSite Anywhere and OneSite Health. In OneSite Patch, Business Units are the default as they have additional properties to standard Groups.

You can use Groups to select a set of machines to which you apply client settings, pre-stage content for content push policies, or apply targeted health policies and baselines.

![](/files/VhxCuAC255s2gbpIMQmq)

To access Groups, click **Assets > Groups** from the side bar navigation from the Admin Portal.

![](/files/JwtgE5m1bh0lZEDcO13k)

This will open the Groups page showing all groups and if integrated with Microsoft Configuration Manager (ConfigMgr), **ConfigMgr collections**. When integrated with ConfigMgr, the collections and Groups will display together. To only see the Adaptiva Groups, select the Groups folder on the left or to see only the ConfigMgr Collections, select that folder in the left pane.

## Group settings

When creating or modifying a Group, you will have multiple settings to configure. Below is a description of each setting and some possible use cases.

### General settings

![](/files/YEYDC1gljkxkBMN8wdaQ)

#### Name

* Choose a unique Name that helps identify your device group.
  * E.g. Adaptiva Developer Clients.

#### Description

* Optionally, you can add a description to add additional context.

#### Evaluation Schedules

* Membership Evaluation evaluates new client Devices to assess if they belong to a particular Group. By default, Membership Evaluation is triggered upon saving your Group and will only run once. You can periodically run Membership Evaluation again based on a chosen Schedule.
* Use case
  * You have a Group that is comprised of Linux devices. The schedule you have chosen runs Membership Evaluation daily at 4 AM. A new Linux device is added to your organization at 2 PM on Monday, but does not yet belong to a particular Group. At 4 AM Tuesday Membership Evaluation is run and thus your new Linux device is now added to your Linux Group.

### Group scopes

With **Group Scopes** you can scope devices by **Location**, **SQL query**, **Sensor**, and by directly selecting desired **Devices**.

{% hint style="info" %}
Multiple Group Scopes can be selected at a time, however, we recommended to primarily use **SQL queries** and **Sensors** for a more comprehensive approach. If multiple scopes make the most sense for your business needs, note that the combined scopes make a new, distinct group.
{% endhint %}

![](/files/DHEWD0bYfRW9muhDdUF9)

You can verify your scope by clicking **Save** to save the new Group and then **Show Members > Evaluate Memberships** in the Group Scopes section.

![](/files/4CvPgOQdcQVQG7sN5xc5)

#### Locations

* You can browse and choose a Location that will add all of the Location's Devices to this Group.
* Use case
  * You have created a new Location and want to create a new Group based off of this Location's Devices.

#### SQL Queries

{% hint style="info" %}
SQL Queries is an advanced setting, please reach our to our [Support team](https://www.adaptiva.com/support) for assistance. We recommend that you create, run, and debug any query in SQL Management Studio to ensure that it works as intended.

For all SaaS solutions, use PostgreSQL.
{% endhint %}

* For both on-premises and SaaS solutions, SQL Queries allow you to more granularly add Devices to a group based on specific queried Device properties.
  * This query returns the `adaptivaclientid` for all records where the `device_name` matches any name starting with "win" (case-insensitive). Then you can take the results and add to or create a **Business Unit**.

    **SQL:**

    ```sql
    SELECT device_id
    FROM a_AdaptivaClientDetails
    WHERE LOWER(device_name) LIKE 'win%'
    ```

    **PostgreSQL:**

    ```sql
    SELECT device_id
    FROM a_AdaptivaClientDetails
    WHERE device_name ILIKE 'win%'
    ```
  * This query finds all devices running a server OS in specified data centers and returns their device IDs. Be aware of case sensitivity, which may depend on the database collation setting.

    **SQL and PostgreSQL:**

    ```sql
    SELECT device_id 
    FROM a_AdaptivaClientDetails 
    WHERE operating_system LIKE '%server%' AND location IN (
      'datacenter1',
      'datacenter2',
      'datacenter3'
    );
    ```

#### Devices

{% hint style="warning" %}
Device scoping is sensitive to the Client ID. If an administrator reinstalls a Client, the Client receives a fresh ID, and the Business Unit no longer includes the new Client.
{% endhint %}

* By clicking **Browse** you can see all available Devices from every Location. You can select multiple Devices from this table or search and sort to find specific Devices.
* Use case
  * You know exactly which devices you'd like to add to a Group, so you select **Devices** > **Browse** and select multiple Devices from the table.

#### Sensors

* Sensors allow you to gather data from or perform tasks on multiple endpoints simultaneously at scale.
* Use case

  * You have created a Sensor that retrieves details about the currently installed Operating System. You create a Group called Windows and choose the OperatingSystem Sensor under **Group Scopes**. After saving your Group, the Membership Evaluation will run. All devices that are found with a Windows OS, will be added to this Group.

  ![](/files/7F5ifTadDhp5KAc5YJic)

{% hint style="warning" %}
Before inventory information can be used in a Group Scope, it must first be collected on the device. This inventory might take 24 hours or longer if devices are offline.
{% endhint %}

#### Base Scope

* Base scope allows you to create logic gates to include or exclude certain Devices from your Group.
* Use case
  * You have Wi-Fi and VPN devices and would like to exclude Default devices from your group. You can select the **OR** operator and add an existing group for All WiFi Clients and All VPN Clients. This will add in both WiFi and VPN clients and exclude Default devices.

After setting the initial Base Scope, you can add additional Groups to include in the Base Scope. You can add or exclude other Groups or change Operators to customize your Base Scope depending on your needs.

## Creating a Group

In the example below, we'll be creating a new Group that will include only Windows client Devices and exclude Linux devices and will run daily at 2 AM.

This example will take approximately 5-10 minutes to complete.

1. Click **+ New** to create a group and enter the following

   **General Settings**

   * **Name**
     * Enter **Clients - Windows ONLY**.
   * **Description**
     * For our example, we'll leave this blank since it is self-explanatory.
   * **Evaluation Schedules**
     1. Click **Browse** and select the **Schedules** folder then the select **Daily at 2 AM** schedule from the table.
     2. Click **OK**

        ![](/files/qdhGX0SubbwiSSiZfvXx)
2. Select **Base Scope** from the **Group Scopes** section.
3. Select **Add Operator > NOT** from the more options ellipses next to **Select Operator**.

   ![](/files/R6ILZSjGU3jQiW9ef0qj)
4. Select **Add Group** from the more options ellipses.
5. Select existing **Clients-Linux** from the table.
6. Click **OK**.

   ![](/files/ACyvjg7QiZBL10ffYSiT)
7. Click **Save**

   ![](/files/mqxnsEejx8d0fsIIqXTu)
8. Select **Show Members** > **Evaluate Membership** to verify the correct client Devices were added to your Group. Since we have a schedule, this would trigger daily at 2 AM, but we can select **Evaluate Membership** to trigger immediately.

   ![](/files/RPgXPuZtxH42zxjNol3X)

## More Options

You can perform additional operations on the Group by clicking the **More** dropdown.

![](/files/M5jzlTl4hwtAulRdoNDc)

* **New Group** - Create a new group.
* **Open Group** - Open a group in a separate tab.
* **Show Changes** - Show the changes from the previous version.
* **Save As** - Save the group with a new name.
* **Delete** - Permanently delete the group.
* **Export** - Export the group as an .obex or .json file.
* **Show References** - View and change the group hierarchy.
* **Manage Permissions** - Apply custom permissions to the group.
* **Sync Policies** - Force the immediate sync of group policies.


# Locations

Locations define client communication behavior in the OneSite platform

A Location is defined by one or more IP ranges intended to identify machines that are connected over a LAN. Setting up Locations is the first step in designing your network topology.

For more information regarding network topology, please see our [Network Topology](/platform-guide/platform-management/network-topology) page. This page covers additional information regarding:

* [Location hierarchy](/platform-guide/platform-management/network-topology#locations)
* [Content flow](/platform-guide/platform-management/network-topology#content-flow)
* [Transport protocols](/platform-guide/platform-management/network-topology#onesite-protocols)

## Location types

Location types affects the behavior of how the Adaptiva Client communicates within a Location. There are three Location types: Default, VPN, and WiFi. Each location type is defined below.

{% hint style="info" %}
It is important to define Locations by their Location types accurately to the physical network. If not properly added to a correct location type, you may run into issues like:

* If a Default location is created for devices connected to a wireless network, those devices will attempt to communicate by broadcast. The wireless Access Point, may block these transmissions preventing peers from communicating effectively within the Location.
* A VPN client added to a Default Location will pull content in two WAN hops—first to the VPN gateway, then through the tunnel to the client—slowing delivery and increasing network load.

When a physical location includes both a wired and a wireless subnet, create a separate Location for each. Set the wireless location to WiFi and assign it as a child of the wired location. This setup ensures the wireless Location retrieves content from its parent.
{% endhint %}

### Default

* Defines a standard wired Local Area Network (LAN).
* ALL subnets at this physical location should be combined into a single Location.
* Example: Central or regional headquarters office with wired connections.

### VPN

* Defines a Location and IP range allocated to clients connecting with a VPN.
* Does not use peer-to-peer communication and only pulls content from the Parent Location.
* It is recommended that **ALL** VPN subnets from a given concentrator be combined in a single Location.
* Example: Subnet devices are assigned addresses from when connected to the company VPN.

### WiFi

* Defines a Location and IP range or ranges allocated to clients connected over Wi-Fi.
* Uses unicast instead of broadcast to communicate between devices on the same subnet.
* Example: Wireless network at an Office which end-user devices will connect to. It is recommended that wireless networks be defined as a child Location to a wired network in the same physical location.

## Creating a new Location

This task will guide you on how to create a new Default Location. For a full comprehensive list of Location settings and actions, please see our [Locations Settings and Actions](/platform-guide/platform-features/locations/locations-settings-actions) page.

1. Hover over **Assets** and select **Locations** from the Platform Features side navigation.

   ![Locations button under Assets tab](/files/tr2QSfbL4K3JSr1ds2Au)
2. Click **+New** in the upper right corner of the Locations pane.

   ![](/files/vN2exOPDHAwKbMXEW0F8)
3. In the **General Settings** enter the following:

   * **Name** - "Seattle HQ"
   * **Description** - "Seattle Headquarters office"
   * **Location Type** - Default
   * **Metered Connection** - Toggle **OFF**.
   * **Allow Direct CDN Download** - Toggle **OFF**.

   ![](/files/j8q6YsMcaJG4HaWIdUiD)
4. In the **Address Range** settings enter an IP range that reflects your subnet of your location. For the purpose of this task we will enter the following:

   * Click **+Create IP Range**
   * **Starting** and **Ending IP** - `10.0.0.1` and `10.0.0.255`.
   * Click **+Create IP Range**

   ![](/files/PPlrNqoC7yBdVnFd4pok)
5. Click **Browse** from **Topology Settings** and select the **Central Office** from the table.

   ![](/files/WvL6rGMWQJp5sycU5GGF)
6. Click **OK**.

   ![](/files/YIO9aw44kcRYPbCt35ok)
7. Ignore the **Location Devices** section. This would only be applicable if you already had a location with associated devices.
8. Click **Save**.
9. Select **Tree** from the **Display As** dropdown.

   ![](/files/Cj4eU3JxBCbgWOi5P5YV)

You'll notice the Network Typology of your Locations will be stacked from Parent to Child accordingly.

## Delete a Location

You can delete a location(s) in two ways:

* Click the **ellipsis (...)** next to the location and click **Delete**. ![](/files/yZKXLIqkH3Y7Z06mwF4E)
* Click to select the checkbox next to one or more locations and then click the \*\*ellipsis (...)\*\*in the table header and click **Delete Selected**. ![](/files/uYHBXMYQ9PpH1qIYHY8N)


# Locations Settings and Actions

Comprehensive guide to locations and their available settings

Below is a comprehensive guide of Locations and their available settings, settings, and actions in the UI. This is intended for the more advanced user looking for additional features for their setup.

{% hint style="info" %}
If you'd like to learn more about how to use these, please contact our [Support team](https://adaptiva.com/support).
{% endhint %}

## Locations page layout

The Locations page offers two display modes, selectable from the Display As dropdown in the upper right of the Locations pane:

* Tree view — Displays Locations in a hierarchical parent–child structure. This is the recommended view for understanding your network topology and how Locations relate to one another.
* Table view — Displays Locations in a flat list. This is useful for quickly scanning or sorting all Locations regardless of hierarchy.

### Searching Locations

You can search for Locations using the search bar at the top of the Locations pane.

* By default, search matches against Location Name in both Tree and Table view.
* In Tree view only, you can also search by Display Name or IP Address.

{% hint style="info" %}
For more general information, see [Locations](/platform-guide/platform-features/locations).
{% endhint %}

## Location settings

When creating or editing a new Location, you will need to configure the following settings and settings:

### General Settings

* **Name**
  * This text field allows you to specify a name for the Location
* **Description**
  * This text field allows you to optionally add a description for the Location.
* **Location ID**
  * When creating a new Location, this shows as *0* until the Location is saved, then it is allocated a unique ID by the Adaptiva Server. The Location ID cannot be changed after creation.
* **Location Type**: This setting effects the behavior of how clients communicate within the Location. For more information regarding the Location Types, please see the **Location Types** section of our [Locations](/platform-guide/platform-features/locations#location-types) page.

  The options for this setting are:

  * **Default**
  * **VPN**
  * **WiFi**
* **Metered Connection**
  * Defines a Location and subnet range or ranges as metered.
  * This setting allows you to create policies that restrict WAN downloads from clients that are on metered connections. This policy setting can be configured within the System Configuration Perspective within the policy set: **Contentsystem / No WAN download on metered connection**.
* **Allow Direct CDN Download**
  * It allows an office to exit the hierarchy and go directly to the internet to download content. This may come from the Content Delivery Network (CDN) or from another client on the internet. Clients in this office will prefer content from an internet-based peer first. If no peers are available the content will be downloaded from the Adaptiva CDN. If that is also unavailable, the content will be download via the office hierarchy, going to the parent office and eventually to the Central office to get the content.
  * You'll want to use this when your VPN subnet is split-tunnel capable or if your remote office also has its own internet connection. This will help to reduce traffic on the corporate WAN network connection.

    ![](/files/4NjW8MHnV5WkIw2ZwYw0)

### Address Range

This is a table of IP address ranges, denoted by starting IP address and ending IP address. You'll want to set your address range for your Location's specific subnet.

{% hint style="info" %}
A subnet should be no larger than \24 (`255.255.255.0`).
{% endhint %}

### Topology settings

This setting allows you to browse and select a Parent Location. For more information regarding how to setup your network topology, please see our [Network topology](/platform-guide/platform-management/network-topology) page.

## Location actions

You can perform actions on a Location by clicking the ellipsis (**...**) under Actions, next to the Location in the results pane. These actions include:

![](/files/jy6JNWwgwaQ4Pecj0TBQ)

* **Edit**
  * This action allows you to edit an existing Location.
    1. Click **Edit** to open the Location context menu will let you change various settings for the Location. Please note that you cannot change the Location ID, which is the object ID in the database and was generated upon creation.
    2. The Location name can be renamed.
    3. The **Parent Location** can be changed to move the Location within the hierarchy.
    4. To move the Location, click on **Browse** and check the box next to the new parent Location and click on **OK**. Or, you can create a new Location by clicking on **+ Create new Location** to use as your Parent Location.
* **Rename**
  * Allows you to rename an existing Location's settings.
* **Save As**
  * Allows you to save a copy of an existing Location and its settings.
  * However, this is not recommended. If a Location is created with an IP range(s) and a copy is made, you'll receive an error for overlapping IP ranges.
* **Delete**
  * Click **Delete** to delete the selected Location.
  * ALL child Locations will be automatically deleted when deleting a Parent Location.
  * Once a Location is deleted, the IP range(s) defined within the Location are also deleted. Any clients which were reporting from the Location will become **NO OFFICE** clients if Auto-Location creation is turned off or a new Location will be auto-created the next time the client checks in if Auto-Location creation is turned on.
* **Export**
  * By default this is disabled and is only supported using the import/export Workflow. Please reach out to our [Support Team](https://adaptiva.com/support) for more information.
* **Show References**
  * This will open a Object References overlay and show you a tree hierarchy of where you Location is referenced in places like Parent Locations and Groups.
* **Manage Permissions**
  * Manage Permissions settings allow you to manage permissions for specific Locations. This will open an Location Permissions overlay where you can view, edit, and create new permissions based on Roles.

    ![](/files/Zpc8TiG2laJcsd0rmA3r)
  * Click **Create Permissions**.
  * **General Settings**
    * Browse and select a **Role**.
  * **Permissions**
    * Toggle ON/OFF permissions.
  * Click **Save**

    ![](/files/xLp3Ww9xWw9OHY4irZZY)
* **Create Child Office**
  * Allows you to create a new Location that will have the Parent Location setting prepopulated with the selected Parent Location.
* **View Clients**
  * Click **View Clients** to view all associated client devices for that location.
  * The Device overlay will open showing the list of machine names associated with the Location. The devices can be sorted by clicking the column headers (the Last Logged In and Public IP columns are not sortable). See also, [Devices](/platform-guide/platform-features/assets/devices)
  * One important reason to view the device list is to determine which client is functioning as the *RVP* on a given subnet.

    ![](/files/DwMrNiHstIOT182FWwCp)
* **Sync Policies**
  * This will immediately sync all Clients associated with a Location. This is useful after creating a new Location and wanting to manually sync instead of waiting for the Scheduling Settings sync timeframes.

## Multi-select Location actions

![](/files/Ed8kQZotiQ64NSSEtYjr)

* **Merge Offices**
  * To merge or move Locations, you must check the box next to the Location(s) and then click the ellipsis (**...**) below.
  * Click **Merge Offices** to select a target Location to merge the selected Location into. The **IP Address Range(s)** of the selected Location will be added to the target Location and then be deleted. The **Location Type**(Default, VPN, WiFi) of the target Location will remain unchanged.
* **Move Offices**
  * Click **Move Offices** to select a new **Parent Location** for the selected Location.
* **Sync Policies on Selected**
  * This will immediately sync all Clients in selected Locations.

## 'More' dropdown actions

![](/files/NvRqk3VSu5H6EjziVQo2)

* **Show No Office Clients**
  * This will display an overlay of clients that are not associated with any Location. This applies when a client device is removed from a Location or a Location is deleted.
* **Auto Location Creation**
  * Auto Location gets created when Adaptiva clients communicate with the server without belonging to any existing Location.
  * For more information regarding Auto Location, please see our [Enabling Auto Location](https://docs.adaptiva.com/platform-guide/platform-management/network-topology/on-premises-client-detection#enabling-auto-location-creation) page.
* **On-Premises Client Detection (SaaS Only)**
  * For more information regarding On-Premises Client Detection, please see our [On-Premises Client Detection](https://docs.adaptiva.com/platform-guide/platform-management/network-topology/on-premises-client-detection) page.


# Dashboards

## Overview

{% hint style="warning" %}
Creating custom Dashboards and Widgets is an advanced topic. If you are having issues with your Dashboards, please contact our [Support team](https://adaptiva.com/support).
{% endhint %}

The Adaptiva User Dashboard system can be used to author user Dashboards to display any dataset-based data in the form of tables, charts and other Widgets. Adaptiva offers many existing Dashboards to choose from, and for more advanced users you can create your own custom Dashboards.

![](/files/9SRmf2dCEqJCYqx3LEKQ)

## Prerequisites

You don't need anything prior to building a dashboard. However, it is recommended you first have an Adaptiva OneSite product license, and your server and clients are setup and running. Dashboards are intended to see real-time and historical data. If you proceed without first setting up your system, your dashboards will state "No data has been provided...".

## Custom Dashboard walkthrough

The user dashboard system is a platform level component and can found in the side bar navigation of Platform Features regardless of the currently selected product.

{% hint style="info" %}
For this example, we will be authoring a new user dashboard to show information of the number of released and available patches by year.
{% endhint %}

Each created Dashboard has various Widget types to choose from. These Widgets are the actual bits of data you can visualize on the Dashboard. For a full list of Widget types and their properties, please visit our [Widget types and properties](/platform-guide/platform-features/dashboards/widget-types-properties) page.

This walkthrough can be completed in approximately 30 minutes.

1. Select **Dashboards** > **Dashboards** from the side navigation from the Admin Portal.

   ![](/files/yDjCIhRYRuNwTHuBC4OI)
2. Select **+New** in the top-right corner

   This will open a dashboard layout browser window where you can select from one of three dashboard layouts. Selecting the desired dashboard layout brings up an empty dashboard designer.

   * **Default Dashboard:** Basic single-view dashboard where all Widgets are added to the same page.
   * **Drawer Dashboard:** Dashboard split in two, where the main dashboard content is on the right-hand side of the screen and the left side is reserved for drawer content, such as a description of the dashboard, supporting information or other data.
   * **Reverse-drawer Dashboard:** Similar to a Drawer dashboard, but mirrored so that the main dashboard content is on the left-hand side and the right side is for the supporting information.

     ![](/files/dsuTSeonn8UNnIMxaaOx)
3. For this example, select **Default Dashboard**.
4. Click the pencil icon (![](/files/MEqZYjNWyEfWi4UECBpn)) to give the dashboard an appropriate **Name**. For our example, we'll name our dashboard **Yearly Released and Available Patches**.

   ![](/files/kNOuK0OSUlIvgtkTmVYQ)
5. Hover over the first column with the default name **Row Title** to display the **Column** options.

   ![](/files/Misd4DxBF0lA9aPy2Ao9)

   * Plus (**+**) and minus (**-**) buttons will increase and decrease the column count respectively.

     ![](/files/z9K5uVX4gCRT1M1va5qB)
   * The 6-dot drag handle (![](/files/72PbL4IBwG5e403qExkh)) will allow you to move and organize rows.
   * The more options ellipses (**...**) button displays a dropdown of the following:
     * **Add Widget** - Adds a new Widget (table, chart, etc.) to the selected row.
     * **Add Row** - Adds another row either before or after the selected row.
     * **Spacing** - Defines the spacing between elements in the selected row: None, Small, Medium, or Large.
     * **Copy** - Copies the selected row.
     * **Paste** - Pastes a previously copied row.
     * **Remove Row** - Removes the selected row.
6. Select the **+** to increase our columns to two for this example.
7. Select **Add Widget** > **Chart** from the dropdown for our first column.
8. This will display the **Editing Chart Widget** overlay. Each Widget will have common properties along with type-specific properties. For a full list of Widget types and their properties, please visit our [Widget types and properties](/platform-guide/platform-features/dashboards/widget-types-properties) page.

   Enter the following for our Chart Widget:

   * **Card Title** - Available Patches in Previous Year by Month
   * **Info Text** - Chart to display all available patches by month in previous years.
   * **Exportable** - Leave toggled ON.
   * **Data Provider** - Click **Browse** and choose **Patching System Summary** from table and click **OK**.
   * **Data Set** - Select **CountPatchesInLastYear**.
   * **Linked Filters** and **Parameter Options** - Leave blank.
   * **Chart Type** - Select **Vertical Bar Chart**.
   * **Series Column**, **Value Column**, **Single Series Ordering** - Leave as defaults.

   ![](/files/7tjMC1xzj63PYv2vrrn0)
9. Click **OK** to save your edits.
10. Click the more options dropdown again from your column controls to create a second Chart widget with the following properties:

    * **Card Title** - Available Patches per Year.
    * **Info Text** - Chart to display number of available patches per Year.
    * **Exportable** - Leave toggled ON.
    * **Data Provider** - Click **Browse** and choose **Patching System Summary** from table.
    * **Data Set** - Select **CountPatchesPerYear**.
    * **Linked Filters** and **Parameter Options** - Leave blank.
    * **Chart Type** - Select **Vertical Bar Chart**.
    * **Series Column** - Change to **ReleaseYear**.
    * **Value Column**, **Single Series Ordering** - Leave as defaults.

    ![](/files/eaLNTj7iTx2H93DOyciE)
11. Click **OK** to save your edits.
12. Click the more options dropdown again from your column controls to create a Table widget with the following properties:
    * **Card Title** - Patches Released in the Last Year.
    * **Info Text** - Table to display number of patches released in previous years.
    * **Exportable** - Leave toggled ON.
    * **Data Provider** - Click **Browse** and choose **Patching System Summary** from table.
    * **Data Set** - Select **PatchesinLastYear**.
    * **Linked Filters** and **Parameter Options** - Leave blank.
    * **Rows per Page** - Select **25** from dropdown.
    * **Include Table Search** - Toggle **ON**.
    * **Default Sort Column** - Select **Patch Name Version** from dropdown.
    * **Default Sort Column** - Leave toggled **ON**.
    * **Row Menu**, **Header Menu** - Leave blank.
13. Click **OK** to save your edit.
14. Hover over your new Widget to display the **Width** options.

    ![](/files/jrbrZzOTfQztfbhv95vW)

    * Plus (**+**) and minus (**-**) buttons controls how many columns Widgets span. In a multi-column dashboard, this can be leveraged to place widgets next to each other, or have them occupy a certain proportion of the screen width.
      * e.g. if a dashboard has 4 columns and you wanted to have a table occupy 75% of the screen and a pie chart occupy the remaining 25%, you would set the table widget to have a width of 3, and the chart widget to have a width of 1.
    * The 6-dot drag handle will allow you to move and organize Widgets within their rows.
    * The more options ellipses (**...**) button displays a dropdown menu of the following:

      * **Edit Widget** - Opens the Edit Widget overlay.
      * **Copy** - Allows you to copy the Widget abd its set properties.
      * **Styling** - Defines the padding between Widgets in a row.
        * **Apply to All Sides** - Toggled **ON** by default. When toggled **OFF** will allow you to apply custom padding to Top, Right, Bottom, or Left sides individually.
        * **Spacing** - None, Small, Medium, or Large.
        * **Remove Column** - Removes the selected Widget.

      ![](/files/IkixfBI64WPDLjmbaRZo)
15. For our example, select the **+** of your Widget controls by hovering over your newly created table Widget. This will stretch the table to fit across both columns we created earlier.

    ![](/files/Dhj4AQ1Hxjzoq8IyZru6)

You should now have a fully created dashboard with multiple widgets.

![](/files/p96nnbj3XRlGiLcaK2eT)

### Saving and previewing

When the dashboard has been configured, you can Save the dashboard which makes it immediately available for viewing, or you can Preview the dashboard which shows what the dashboard would look like when a user navigates to it.

The save and preview buttons can be found at the top of the page.

![](/files/RqywFe0FXp0iYohCQqzN)

Here is a preview view of the dashboard we created above.

![](/files/aQOqzwCPFnsg8cQj3xTs)

Once saved, the dashboard can be found under the **Dashboards** > **Dashboards** section, and can be used in other areas of the product such as in Subscriptions.


# Common Dashboards

Below are examples of common custom dashboards so you can view specific data to make informed decisions regarding your environments. Each walkthrough will provide step-by-step instructions on how to create the dashboard and can be customized to fit your needs.

{% hint style="info" %}
Creating new Data Providers, or updating of existing Data Providers, can only be done in an on-premises environment. For security reasons, the SaaS environment required signed Data Providers. Please reach out to our [Support team](https://adaptiva.com/support) for assistance.
{% endhint %}

## Inactive Device Dashboard

After a device has been inactive for over 21 days, it is permanently removed from the OneSite platform and no longer visible in the Admin Portal. This dashboard and associated subscription allow you to receive a notification when a device has been inactive for over 15 days in order for you to take further action regarding the inactive devices. This could include troubleshooting a device that should be active, checking on a device that is no longer in use to ensure it is in compliance with your asset management policies.

{% hint style="info" %}
We recommend 15 days, however, you can modify this to suit your specific needs.
{% endhint %}

### Create Inactive Device dashboard

<details>

<summary>Step 1 - Create a new Data Provider</summary>

### Create a new Data Provider

For more information on how to create a Data Provider and Data Provider types, please see our [Data Providers](/platform-guide/platform-features/dashboards/data-providers) page.

1. Select **Dashboards > Data Providers** under **Platform Features** from the left side navigation.

   ![](/files/yhTAsxiZA0843gMe7Mka)
2. Click **+ New**.
3. Under **General** enter:
   * **Name** - Device Age
   * (Optional) **Description**
   * **Data Provider Type** - Adaptiva SQL
4. Under **Data Sets** click **+ Add Data Set** and enter the following:
   * **Name** - Device age greater than 15 days
   * (Optional) **Description**
5. Click **+ Add Column** and enter the following for **Column Name**, **Column Display**, **Column Type** for each of the associated columns that will be returned in the SQL query (see below):

   * **ComputerName** | Computer Name | Text
   * **OfficeName** | Office Name | Text
   * **AdaptivaClientVersion** | Adaptiva Client Version | Text
   * **OSName** | Operating System | Text
   * **LastMessageReceiveTime** | Last Message Received | Date-Time
   * **numberdays** | Number of Days Old | Whole Number
   * **IPAddress** | IP Address | Text

   ![](/files/hgCgG9T3SBV7mvT3epl8)
6. Click **Save** after each column information is entered.
7. Under **Data Set Queries** copy and paste the following SQL query into the **Data Query** tab field:

   ```sql
   SELECT * 
   FROM (
       SELECT 
       device_name AS ComputerName
       , location AS OfficeName
       , version AS AdaptivaClientVersion
       , device_type AS OSName
       , [last_check-in] AS LastMessageReceiveTime
       , DATEDIFF(dd, [last_check-in], GETDATE()) AS numberdays
       , ip_address AS IPAddress
       FROM a_AdaptivaClientDetails
       WHERE DATEDIFF(dd, [last_check-in], GETDATE()) > 15
       ) data
   ```

   ![](/files/MfNh72Tlm4TqTWgYtupY)
8. Copy and past the following SQL query into the **Count Query** tab field:

   ```sql
       SELECT COUNT(*) 
       FROM (
           SELECT 
           device_name AS ComputerName
           , location AS OfficeName
           , version AS AdaptivaClientVersion
           , device_type AS OSName
           , [last_check-in] AS LastMessageReceiveTime
           , datediff(dd, [last_check-in], getdate()) AS numberdays
           , ip_address AS IPAddress
           FROM a_AdaptivaClientDetails
           WHERE datediff(dd, [last_check-in], getdate()) > 15
           ) data
   ```
9. Click **Submit**.
10. Click **Save**.

</details>

<details>

<summary>Step 2 - Create a Dashboard</summary>

For more information on how to create a Dashboard, please see our [Dashboards](/platform-guide/platform-features/dashboards) and [Dashboard Widgets](/platform-guide/platform-features/dashboards/widget-types-properties) pages.

1. Select **Dashboards > Dashboards** from the left side navigation..
2. Click **+ New**.
3. Select **Default Dashboard**.

   ![](/files/6KpFqhhDz34L1sB4xjNb)
4. Click the pencil icon to change the **Name** to **Device Age**.

   ![](/files/YyBKcSzFhVFMOicYxtpK)
5. Click on the ellipses (**...**) from the column toolbar and select **Add Widget > Table**.

   ![](/files/iV7hqbOePT004Y61OHOl)
6. Enter the following:

   * **Card Title** - Device Age
   * **Data Provider** - Browse and select the data provider you created Device Age
   * **Default Sort Column** - NumDaysOld
   * **Default Sort Ascending** - Toggle **OFF**

   ![](/files/Er5MfB0e5pzTTxSrDYx0)
7. Click **OK**.
8. Click **Save**.

You can click **Preview** to see if any devices have been inactive for longer than 15 days. Any device that is less than 15 days, will not be displayed.

![](/files/pDF7fD1dhiCEmNoBm88h)

</details>

<details>

<summary>Step 3 - Create Dashboard Subscription</summary>

For more information, please see our [Subscriptions](/platform-guide/platform-features/dashboards/subscriptions) page.

{% hint style="info" %}
Subscriptions require SMTP to be configured in the settings. For more information, please see our [SMTP Settings](/platform-guide/additional-settings/smtp-settings) page.
{% endhint %}

The user Dashboard Subscription will send selected Roles an email notification with an Excel (.xlsx) file attached.

![](/files/PITnpHkeJJcfQc79AAKT)

![](/files/YYrEXrhrfuUtU3NL6g0d)

1. Select **Dashboards > Subscriptions** from the left side navigation.
2. Click **+ New**.
3. Under **Details** enter the following:
   * **Name** - Send Email for Devices Inactive More than 15 Days
   * (Optional) **Description**
4. Under **Email Settings** enter your desired **Email Subject Line** and **Email Body Text**.
5. Click **Browse** and select the Roles you wish to notify.

   ![](/files/Vm2s6ocLsKEbbgUKp4bU)
6. Click **Browse** under **Dashboard Settings** and select the Device Age dashboard you created above.
7. Click **OK**.
8. Click **Browse** under **Schedules** and select a schedule when you would like this subscription to be run, this will the schedule when your specified Roles will receive the email notification.
   * We recommend a daily schedule since this is a daily accrual of inactive days.
9. Click **Browse** Next to **Data Provider for Condition** and select **Device Age** data provider created above. This will autofill the **Data Set for condition** dropdown with the data set you created: Device age greater than 15 days.
10. Click **Save**.

If you would like to test your subscription before your specified schedule, you can click the **More** dropdown and select **Run Subscription**.

{% hint style="info" %}
If you do not have any devices that meet the specified criteria, you will NOT receive an email notification even after manually running a subscription.
{% endhint %}

</details>


# Widget Types and Properties

This page describes each Widget type and their corresponding properties.

## Widget Types

The following Widget types are available:

| Widget Types     | Description                                                                                   |
| ---------------- | --------------------------------------------------------------------------------------------- |
| **Text**         | Provides a data-bound text control that can used like a label to show dynamic data            |
| **List**         | Displays a list of data-bound values                                                          |
| **Rank**         | Provides a ranking of data-bound values and colors them appropriately                         |
| **Chart**        | Displays a chart for the specified dataset. Chart type is configurable                        |
| **Trends Chart** | Displays a chart for showing data over time from the specified dataset                        |
| **Counter**      | Provides a data-bound statistic-style Widget, generally used for showing counts               |
| **Table**        | Displays a table of raw data from the specified dataset                                       |
| **Button**       | Displays an button that you can write a JavaScript expression to execute on the button click. |
| **Progress Bar** |                                                                                               |
| **Timeline**     | Displays a milestone timeline of selected data.                                               |

## Widget Properties

The following Widget properties are available for all types of Widgets. These are the common properties. Each Widget has their own type-specific properties that we'll list further along this page.

| Widget Properties       | Description                                                                                                                                                                                 |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Card Title**          | This will be the main title for this particular Widget. It should be used to inform the viewer of the dashboard what data the Widget shows.                                                 |
| **Info Text**           | (Optional) When specified, this will show an information icon next to the card title that when clicked, will pop up with helper text that gives more of a detailed explanation of the data. |
| **Create Default Data** | (Optional) When specified, this will show an information icon next to the card title that when clicked, will pop up with helper text that gives more of a detailed explanation of the data. |
| **Exportable**          | When this is enable, the dashboard can be exported and imported into another environment.                                                                                                   |
| **Data Provider**       | This section allows you to browse for a specific data provider that contains the dataset that you wish to bind the respective Widget to.                                                    |
| **Linked Filters**      | Select which Dashboard Filters to link to the Widget. When filter data changes, the Widget will automatically refresh if linked.                                                            |
| **Parameter Options**   | This section allows the creation of parameters that may be passed to the dataset. See the Adding Parameters section below.                                                                  |

### Text Widget Properties

* **Text Content** - If the widget is not bound to a data provider, it will display this text.
* **Text Content Column** - If the widget is bound to a data provider, it will display the value of this field from the dataset.

![](/files/UzZYvdPg8S8QnIHupNuC)

### List Widget Properties

In addition to the common properties, Text Widgets have the following properties:

* **Displayed Properties** - This provides a list of the available properties from the selected dataset. You can select a property from the Displayed Properties list and then click +Add Property to add it to the list of Current Properties.

![](/files/tfxMJtD46EXz1sotifpn)

### Rank Widget Properties

* **Name Column** - This should be the column from the dataset to use as the display name for this ranking on the dashboard. This will be what actually gets shown.
* **Count Column** - This should be the column that is used to evaluate. This will not be shown on the dashboard and will only be used to determine the ranking. Different colors can be used for different rankings. The value of the column specified in the Name Column field will be evaluated against the Name Value to Match field, and if it matches, the dashboard will render that item in the selected color. Multiple criteria can be added for different colors.
* **Color Matches** - For each color match you wish to add, enter a Name Value to Match, choose the appropriate Value Type, choose a Color (either a Theme Color, or a Custom) and then click +Add Color. The new item will get added to the Current Color Matches section. Repeat for any other colors.

![](/files/1c0vbLSHKB59ltt4osan)

### Chart Widget Properties

* **Chart Type** - Choose the desired chart type that best fits the data.
* **Value Column** - Choose the numeric field that represents the value to render.
* **Single Series Ordering** - Choose the style of ordering for a single series dataset.

![](/files/QG7CBBFC0a79zsVozotp)

### Trends Chart Widget Properties

* **Value Column** - Select the column from the dataset that represents the value to be shown on the chart
* **Series Column** - Select the column from the dataset that represents the series data to be shown on the chart
* **X Axis Column** - Select the column from the dataset that represents the data to be shown on the X axis on the chart
* **Interval Parameter** - If the interval is being passed through as a parameter, select or add the parameter
* **Date Parameter** - If the data is being passed through as a parameter, select or add the parameter

![](/files/WyZ9T9Afc2ZYxreQSf07)

### Counter Widget Properties

* **Counter Configs** - This button will open a pop-out menu for the additional properties below.
* **Count Column** - This should be the dataset column containing the data to display as the primary text data on the widget.
* **Top Label** - This should be the text description for this counter.
* **Icon** - This should be the name of the icon to display to the left of the counter text

After entering these details click +Add Counter Config to add it to the Counter Configs section. Multiple counter configs can be added to a single counter widget.

![](/files/t4ld03fhCTBjlYDlQqkY)

### Table Widget Properties

* **Rows Per Page** - The default number of rows to show on each page of the table.
* **Include Table Search** - Toggle this ON if you would like to enable a search bar for your table.
* **Default Sort Column** - Choose from the dropdown your desired default column from which to sort.
* **Default Sort Ascending** - Toggle ON to sort columns by ascending values in the default column, toggle OFF to sort by descending values.
* **Row Menu** - Provides the ability to add Action items on a per row basis.
* **Header Menu** - Provides the ability to add Action items to the table header menu

![](/files/cY2tXV63GFh04D8aBAhq)

### Button

* **Button Text** - This will display the desired text for your button.
* **Button Look** - Choose between:
  * **Solid** - Display as a solid color button.
  * **Outline** - Display as a white button with a border color.
  * **Flat** - Will only display text without a border or solid color.
* **Button Type** - Choose between **Info**, **Error**, **Success**, **Warning**, and **Inverse**. Each will display a different color that corresponds to the button type.
* **Button Size** - Choose between **Normal** and **Small** for the desired button size.
* **Show as Full Width** - When toggled ON this will display the button to the full width of the Widget container on the Dashboard.
* **URL** - Enter a URL to apply to your button.
* **On Click** - JavaScript expression to execute on button click. Rows returned from the Data Provider are passed to the expression as data.

### Timeline

* **Content Column** - Select a column to populate the main content of each timeline entry.
* **Date Column** - Select a column to populate the date content of each timeline entry.
* (Optional) **Title Column** - Select a column to populate the title content of each timeline entry.
* **Include Pagination** - Determines whether the UI exposes previous/next controls on the timeline. If toggle OFF, all rows are rendered at once, which can affect UI runtime performance.
* **Rows Per Page** - Determines how many rows to display on each page if pagination is enabled.
* **Include Filtering** - When toggled ON, displays filter icon and search bar.
* **Route** - Define a route to navigate the user on timeline entry click.
  * Insert dynamic column names into the route with `{{...}}:/my-url/{{MyColumn}}?myParam={{MyColumn2}}`

## Adding Linked Filters and Parameter options

This section allows the creation of parameters that may be passed to the dataset. If the dataset SQL query requires parameters to be passed in, parameters can be defined using the dashboard designer.

![](/files/epQFPpU8e8UNDeF53a23)

1. Select the **+Create New Dashboard Filter** button to add a new Dashboard Filter.

   ![](/files/wJk0owqbOtnKVG0c4Zlw)
2. Start by specifying the Filter Name and optionally, a Filter Description.

The Filter name must match exactly with the Filter name in the SQL or PostgreSQL query.

1. Choose the desired Filter Type from one of the two options:
   * Route - Route Filters navigate the user to a different path respective to the specified Filter. There can only be one route-type Filter per dashboard.
   * Query - Query Filters append the Filter name and value to the URL and allow multiple Filters to be specified in a single dashboard. ***This is the recommended option.***
2. Select the Value Type from the list.
   * The value type must match **EXACTLY** with the data type of the Filter used in the SQL/PostgreSQL query.
3. (Optional) Specify a Default Value for this Filter.
4. Toggle **ON/OFF** whether this Filter should be Required (i.e. it must be specified and will not accept a NULL value)
5. Toggle **ON/OFF** whether it should be Read Only (i.e. it must have a default value and cannot be changed at runtime).
6. Choose the **Input Type** from one of the available options from the list:
   * **Server Object** - If the parameter is to be a server object ID then the Server Object input type can be selected which will prompt for the class name of the object to select from. At runtime this will prompt with an object browser of the specified type. This option is generally for advanced users.
   * **String**, **Integer**, **Float**, **Date** - These options provide a flat input box for the option to be entered.
   * **String Combo**, **Integer Combo**, **Float Combo** - These options provide a list of options to choose from in the respective data format.
7. Click **Save**.
8. Select your new **Dashboard Filter** from the **Parameter Options** dropdown.
9. Click **Save**.

## Related pages

### [Dashboards](/platform-guide/platform-features/dashboards)


# Data Providers

{% hint style="info" %}
Data Provider editing and creation is an advanced topic. It is recommended to use the existing Data Providers if you create your own Dashboards. Please reach out to our [Support Team](https://adaptiva.com/support) for assistance.

Additionally, editing and creating data providers is currently unavailable for SaaS implementations of the Platform.For security reasons, SaaS environment signed data providers are only permitted. Please reach out to our [Support team](https://adaptiva.com/support) for assistance.
{% endhint %}

A Dashboard uses results from queries to display data in meaningful ways. Data Providers are used to create the query. A Data Provider can include many data sets. It is recommended to create a single Data Provider for each Dashboard, but it is, of course, possible to use Data Sets from any Data Provider in a single Dashboard.

Data Providers are a platform-level component and can therefore be accessed when viewing any Adaptiva product from the side navigation. Navigate to **Dashboards > Data Providers**.

## Data provider types

There are currently two types of Data Providers:

* Adaptiva SQL - queries data from the Adaptiva SQL database
* Workflow - executes a workflow to return data

## Data Sets

Data sets include the data you want to extract to display depending on the chosen dashboard widget. For instance, you have the option to determine what data to include in a table widget column(s). This data is requested by either a SQL query or a Workflow depending on the data provider type chosen.

## Create a Data Provider

For this example, we will be querying from the SENSOR\_200000017\_DATA table (BIOS sensor). The columns we will be selecting will be the Client ID, the BIOS Name, the Manufacturer, the SerialNumber, and the SMBIOSBIOSVersion.

1. Select **Dashboards > Data Providers** from the side navigation under **Platform Features**.
2. Select **+ New**.
3. Enter a unique data provider **Name** and **Description** to help the user understand the result of the data provider.
4. Select **Adaptiva SQL** from the Data Provider Type dropdown.
5. Select **+ Add Data Set**.
6. Enter a unique data set **Name** and **Description**.
7. Select **+ Add Column** and create a column to match data in your SQL query.

   ![](/files/6AgStR2U1hpUFkjL6FeP)
8. Enter the **Data Query** in the code block field. For example:

   ```sql
   SELECT _SOC_ClientId, [Name], Manufacturer, SerialNumber, SMBIOSBIOSVersion 
   FROM SENSOR_200000017_DATA
   ```
9. Enter the **Count Query**.

   ```sql
   SELECT COUNT(*) FROM (
   SELECT _SOC_ClientId, [Name], Manufacturer, SerialNumber, SMBIOSBIOSVersion
   FROM SENSOR_200000017_DATA
   ) X
   ```
10. (Optional) Select desired options for **Default Sort Configuration**.
11. (Optional) If the SQL query takes input parameters, select **+ Add Properties**.
12. Click **Submit**.
13. Click **Save**

### Workflow Data Sets

Workflow data sets can be used to query data outside of the Adaptiva database, this is an advanced use case and we recommend reaching out to our [Support team](https://adaptiva.com/support) for assistance.

If you choose to use a Workflow data set, you will still follow the majority of the steps above except:

1. Select **Workflow** from the Data Provider Type dropdown.
2. When adding a data set, select **Browse** to choose a workflow you'd like to use.


# Subscriptions

The OneSite User Dashboard Subscriptions system provides the ability to subscribe users and groups to specific user dashboards. A user dashboard subscription policy will E-Mail the data within a user dashboard to the subscribed users and groups according to the desired schedule.

In addition, administrators can assign a conditional dataset to the subscription policy so that the dashboard data will only be sent if the condition is met.

{% hint style="info" %}
Dashboard subscriptions can only be used with SMTP and cannot be used with `twilio@adaptiva.com` notifications. For more information on how to set up SMTP, please see [SMTP Settings](/platform-guide/additional-settings/smtp-settings).
{% endhint %}

User Dashboard Subscriptions are a platform-level component and can therefore be accessed when viewing any Adaptiva product from the left-hand menu **Dashboards > Subscriptions**.

## Subscription settings

### Details

| Setting     | Description                                           |
| ----------- | ----------------------------------------------------- |
| Name        | Enter a unique name for your Subscription.            |
| Description | Enter a description that describes your Subscription. |

### Email Settings

| Setting                         | Description                                                                                                                                                                         |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Email subject line              | What will be displayed as your subject line.                                                                                                                                        |
| Email Body Text                 | What will the text will be for your email body.                                                                                                                                     |
| Email Significance              | Scale of 1-5 of the email significance flag.                                                                                                                                        |
| Email only Once a Day           | When toggled **ON**, you will receive a single email per day at the scheduled time. By default this will send an email each time the data provider is updated with new information. |
| Roles to receieve notifications | Select the Roles you wish to receive the email notifications                                                                                                                        |

### Dashboard Settings

| Setting        | Description                                                               |
| -------------- | ------------------------------------------------------------------------- |
| User Dashboard | Click **Browse** and select the dashboard you would like to subscribe to. |

### Schedules

| Setting   | Description                                                                                                     |
| --------- | --------------------------------------------------------------------------------------------------------------- |
| Schedules | Click **Browse** and select the schedule or create a new schedule for when you would like to receive the email. |

{% hint style="info" %}
If a Condition Data Provider is later added, this schedule will be the schedule on which the data provider and dataset get evaluated to determine whether or not to send the E-Mail. If no data provider and dataset are added, then the E-Mail will be sent according to this schedule.
{% endhint %}

### Data Provider for Condition

Conditions are optional. By adding a condition, the E-Mail will only get sent if the data provider and dataset for the condition return at least 1 row at the time the schedule executes. If the data provider and dataset do not return any rows, the E-Mail will not get sent.

| Setting                     | Description                                                                                                                                   |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| Data Provider for condition | Click **Browse** and select desired Data Provider. This will determine the options you can select for the **Data Set for condition** dropdown |
| Data Set for condition      | Select the data set from the dropdown that you wish to receive notifications about.                                                           |

![](/files/NNA9qV6U0zC56y81Fc9l)


# Schedules

Describes how to use and configure schedules in OneSite Platform

Schedules automate the delivery of content, the execution of Workflows, updating Groups, and the delivery of some notifications. There are several default Schedules you can choose from or modify, or you can create your own custom schedule.

![](/files/YTR3pOkt5jzv8Ztr32QK)

{% hint style="info" %}
We recommend that you open one of our default Schedules, select **More > Save As**, then modify the copy rather than creating a brand new Schedule.
{% endhint %}

## Schedule settings

When creating or modifying a schedule, you will have multiple settings to configure. Below is a description of each setting and some possible use cases.

### General settings

![](/files/fRS7zsyNYHPKy30LWXZY)

#### Name

* You'll want a unique name of your schedule that describes when it runs.
* E.g. - Every Thursday at 9 AM.

#### Description

* You can optionally add a description that will add more context especially for similar schedules.
* E.g. - This schedule is set to Every Thursday at 9 AM and uses the Server timezone.

### Schedule settings

![](/files/BY1Ln9EoP7VCnPGzRRjM)

#### Use Server TimeZone

* This setting is disabled by default and will use the local time zone. If you enable this setting, the schedule will be based off the timezone set in the server settings.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Make sure that you are aware of what time zone the server is using.</p><p>For SaaS installations, if the server time zone has not explicitly been set then its value will be <strong>Default Time Zone</strong>, which is <strong>UTC+0</strong>.</p><p>On premises installations use the local time zone of the device it is installed on.</p><p>You can check the server time zone setting by clicking on the gear icon in the upper right and selecting <strong>settings > about</strong>.</p></div>
* Use case of Local Timezone
  * You set the schedule to run at 6 AM local machine time for your Seattle Location (PST) clients to receive content. New York clients have a separate schedule to also run at 6 AM EST local machine time. This ensures that the New York Location's working hours are unaffected by a PST schedule.
* Use case of Server Timezone
  * You toggle on **Use Server Timezone** (CST) and set the schedule to 4 AM. New York and Seattle clients receive their content at 5 AM and 3 AM respectively. This ensures both Locations receive content at the same time in their different timezones.

#### Start/End Time

* You must specify at least a **Start time** and an optional **End time** that requires **Enable End Time** to be enabled.
* Use case of end time
  * You set your Schedule to run every hour between 11/01 7 AM and 11/01 11:59 PM to receive Dashboard Subscription notifications to monitor Deployment Status for new Tucson location clients.

#### Schedule Repeat

* By default this is set to ASAP. You can select recurring times or **Not Recurring** so it only runs a single time once deployed and added to an object.

### Additional Time Constraints

When enabled, you can more granularly configure time slots to ensure the object is scheduled around any time constraints like working hours or business events.

![](/files/Bd5NI9TXF14L7VXA54Mx)

#### Time slots

* You can add time slots to define when you don't want your Schedule to run.
* Use case

  * Your business has regular server maintenance on Tuesdays. You want to create a schedule that runs every hour of each day, except during working hours on Tuesdays. You can create a Schedule with Recurring Interval set to 1 hour, and add a time slot for Tuesdays between 7 AM and 7 PM.

  ![](/files/lX6JNkSuKPOFuIdoGuSJ)

#### Load Leveling Duration

* Adaptiva balances the load so clients are targeted in smaller subsets within a set **Load Leveling Duration** duration instead of all clients targeted at the same time.
* Use case
  * You have 100 clients set to receive some content via a custom Schedule. The custom Schedule is configured to run every Sunday at 2 a.m and has a load leveling Duration of two hours. This will assign to each device a random time within the load level window to receive content. If the devices are not available during this window they will wait until the next Sunday at 2 a.m.

#### Set Override Duration

{% hint style="info" %}
We recommend you work with our [Adaptiva Support Team](https://adaptiva.com/support) before you enable Override Duration.
{% endhint %}

* Override Duration sets a timer at the end of the specified time slots. When the Override Duration has expired, Schedules will run ASAP.
* Use case
  * You have 100 clients who are scheduled to receive a patch every Sunday between the hours of 2 AM and 4 AM. Of the 100 clients, only 96 clients receive the patch during that load leveling duration. The last four clients were not powered on and therefore will have to wait until the following Sunday when the schedule runs again. However, you have set your Override Duration to 8 hours. So, once the 8 hours has passed, the schedule will run again at 10 a.m. (8 hours from the start time) on Monday for those remaining clients.

## Create a custom Schedule

In the example below, we'll be creating a new Schedule and applying it to Dashboard Subscription.

This example will take you less than 10 minutes to complete.

1. Click **Schedules** from the side bar navigation in the Admin Portal.

   ![](/files/4KvuEbfcDmG8nu6V3kNp)
2. Click the **Schedules** folder and click the existing **Daily at 2 AM** schedule in the **Schedule Name** column.

   ![](/files/bXTl2xGw8LqLP90KfSar)
3. Click **More** > **Save As** and change the name to Every 108 Minutes.

   ![](/files/JcAZRULM4BBCYqQJ2XHl)
4. In the Schedule editor, configure the following settings:

   **General Settings**

   ![](/files/fRS7zsyNYHPKy30LWXZY)

   * **Name** - The name will already be displayed from the **Save As** step.
   * **Description** - Enter a description.

   **Schedule Settings**

   ![](/files/vwLbVL6eoqwrI0heRObK)

   * **Use Server TimeZone** - Toggle **ON**.
   * **Start/End Time** - We'll set the **Start Time** to our current date at 7 AM, and our **End Time** to September 22 at 7 AM.
   * **Schedule Repeat** - Keep **Recurring Interval** selected from the Daily at 2 AM schedule we copied. Change the **Recurring Interval** to 1 Hours and 48 minutes (108 minutes) in the respective fields.

   **Additional Time Constraints** - We'll leave this disabled for simplicity.
5. Click **Save and Deploy**.
6. Navigate to **Dashboards** > **Subscriptions** from the side navigation bar.

   ![](/files/1SNmDZTQBFEP6YehHNQo)
7. Create a new **Subscription** or modify an existing and add the **Every 108 minutes** Schedule.

   ![](/files/bbOErONpCjWPzwb8wXoS)

You have now set up a Dashboard Subscription to send a notification every 108 minutes.


# Sensors

Understand how Sensors gather data and perform tasks on clients.

Sensors in the OneSite Platform can be deployed to endpoints to gather data from, or perform tasks on, multiple endpoints simultaneously at scale. There are a variety of built-in sensors or you can create your own to retrieve almost any kind of data.

Most sensors return data that doesn't change very often (hardware information, BIOS version etc.), however some sensor data can have frequent changes, such as running processes or system uptime.

Sensors are primarily used to evaluate membership to Business Units or Groups based on custom criteria. Membership can be dynamically based on Sensor scopes, where a device could move based on Sensor results. For example, you can apply [Windows Feature Updates](https://docs.adaptiva.com/patch/scenarios/feature-updates) based on the version number reported by the Windows operating system.

![Sensors Overview](/files/sQTrb8CAM0YOiOMNVlNf)

## Sensor Types

* **Java** - These sensors are built-in and cannot be authored manually. They perform activities that interact directly with the Adaptiva Client on the device.
* **PowerShell** - These sensors will run a specified PowerShell script on the device and output data using return parameters that are specified within the script itself.
* **Visual Basic Script(VBS)** - These sensors will execute a specified Visual Basic Script (vbs) on the device and output data using WScript.Echo commands specified within the script itself.
* **WMI** - These sensors allow you to specify either a WMI query or class to pull data from. The specified query or class will be interrogated from the Windows Management Instrumentation on the device and the respective rows will be returned.
* **Workflow** - These sensors allow you to specify an Adaptiva Workflow to execute to return data. The Sensor system will leverage the ResultArrayOfRows property on the End node of the workflow to collect data. Workflows used as Sensors must add any return data as Row objects to the ResultArrayOfRows property. To do this, workflows must use the RowOperations workflow activity.

## Logs

Logs for the Sensors feature are available on the server and client.

* Server logs: **SensorOfflineCache.log**
* Client Logs: **SensorExec.log**, **SensorOfflineCache.log**

For detailed information on these logs, see [Server and Client Logs](/platform-guide/platform-features/logs).

## Create a custom Sensor

{% hint style="info" %}
Creating a custom sensor is an advanced topic. If you have an idea for a sensor you'd like to create, please reach out to our [Support Team](mailto:support@adaptiva.com?subject=Custom%20Sensor%20Request\&body=Please%20select%20the%20type%20of%20custom%20sensor%20you%20would%20like%20to%20request:%0D%0A%0D%0A%5B%20%5D%20Java%0D%0A%5B%20%5D%20PowerShell%0D%0A%5B%20%5D%20Visual%20Basic%20Script%20\(VBS\)%0D%0A%5B%20%5D%20WMI%0D%0A%5B%20%5D%20Workflow%0D%0A%0D%0APlease%20describe%20your%20custom%20sensor%20requirements%20below:%0D%0A%0D%0A)
{% endhint %}

The following example creates a sensor that queries a client and returns the current state of Microsoft Defender Antivirus. In particular, we want to know how Defender is running and whether it's the active antivirus and if real-time protection is currently enabled. This is useful to troubleshoot if you have

For additional information regarding the commands used in this guide, please see [Microsoft Defender Antivirus in Windows Overview](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-windows#check-the-state-of-microsoft-defender-antivirus-on-your-device).

1. Select **+** to expand **Platform Features > Sensors** from the side navigation.
2. Click **+ New**.
3. Enter the following under the **General Info** section:
   * **Name** - *DefenderStatus*.
   * **Description** - *Displays whether Microsoft Defender Antivirus is active and whether real-time protection is currently enabled on the device.*
   * **Sensor Type** - Select **PowerShell**, this will only select **Windows** as the **Supported Platform**.
4. Enter the following script under **Sensor Settings**:

   ```shell
   Get-MpComputerStatus | select AMRunningMode, RealTimeProtectionEnabled
   ```

   ![](/files/Dk1PPBQNwkjWuq3DfLju)
5. Create a **Sensor Output Schema** by adding the two columns of the data you'd like to have returned when the sensor executes.

   * **AMRunningMode** - Text
   * **RealTimeProtectionEnabled** - Boolean

   ![](/files/OJ8h8Nm5bG2xKoTLkb9H)
6. (Optional) If you'd like to create custom column names, you can map them to the default column names created in the Sensor Output Schema section.

{% hint style="info" %}
Only two sensor types allow you to autogenerate input parameters or output schemas. These buttons will become active if the following are selected:

* **Workflow** - Autogenerate Input Parameters
* **WMI** - Autogenerate Output Schema

Once these buttons are clicked, it will run the WMI query or Workflow script and populate the respective table.
{% endhint %}

## Add custom sensor to Group or Business Unit

Please see [Groups](https://docs.adaptiva.com/platform-guide/platform-features/assets/groups#creating-a-group) or [Business Units](https://docs.adaptiva.com/patch/patching-fundamentals/business-units-rollout-processes#create-a-business-unit) for full instructions on how to create a Group or Business Unit.

1. Create a new **Group**.
2. Click **Sensors > + Add Sensor Scope** under the **Scopes** section.
3. Enter the **Scope Name** and enter a description (optional).
4. Click **Browse** next to **Sensor** and select the sensor you created in steps above.

   ![](/files/05l6RDW5nmfdM8BKUvhP)
5. Click **OK**.
6. Click the ellipses (**...**) next to **Filter Condition** and select **Add Operating Condition** and choose:
   * **Data Column** - AMRunningMode.
   * **Operating Condition** - Any.
   * **Value** - *Not Running*.
7. Click **OK > OK**.
8. Add an additional sensor scope:
   * **Data Column** - RealTimeProtectionEnabled.
   * **Operating Condition** - Any.
   * **Value** - *True*.
9. Click **OK > OK**.

   ![](/files/SGZ2aXlesSXEPJn0qTG1)

## Reset Sensor

If sensors are not reporting accurately, you can reset the sensor for a specific group or device. You can trigger the reset immediately or it will reset the next time sensors are run on the client.

1. In the Sensors pane, find the sensor you wish to reset and click the **ellipsis (...) > Reset Sensors**. The Reset Sensors pane appears.

   ![Reset Sensors](/files/gN4swrNzhXCIbTtQaYv3)
2. If you want to trigger the reset immediately, toggle ON **Send Immediately**.
3. You can add additional sensors by clicking **Browse** next to Sensors, selecting a new sensor, and clicking **OK**.
4. You can target specific devices by clicking **Browse** next to Target Devices, selecting a device(s), and clicking **OK**.
5. You can target groups of devices by clicking **Browse** next to Target Groups, select a group(s), and clicking **OK**.
6. Click OK to reset the sensors. A pop-up dialog will confirm the sensor reset.


# Understand Content Cache

Learn about the Adaptiva Client Cache, a local repository for sharing content with peers.

The Adaptiva Client Cache is a local content repository used by the Adaptiva Client to store patch content on managed devices. The Adaptiva Client downloads patch content into the cache to share with peers, keeping content local in order to maintain availability and reduce repeated network transfers. The client can download content from either peers within the subnet or the parent office.

## What Is the Adaptiva Client Cache

* Windows: `[drive:]\AdaptivaCache`
* Linux / Mac: `/opt/adaptiva/adaptivacache`

The **AdaptivaCache** is a hidden folder used by the Adaptiva Client to store content on endpoint devices. The **AdaptivaCache** folder is created at the root of every physical (non-removable) drive on a client device. For Linux and MacOS devices, the cache folder is created in **/opt/adaptiva/adaptivacache**. On computers with more than one writable drive, the Adaptiva Client will create an **AdaptivaCache** folder on each writable drive. Content will be stored on the disk with the most space at the time of download.

Administrators can override the default configuration of the Adaptiva Client Cache to define a custom cache location.

## How the Cache Functions

The Adaptiva Client Cache retain content on the device for reuse and sharing. Content is not normally removed unless a defined condition occurs, such as low disk space, client uninstall, un-publishing content in Adaptiva, corruption detection, or manual deletion. We recommend not removing content from the cache as it will become inconsistent with the client state.

During content transfer, secure hash validation is used to confirm content integrity. If content fails validation, it is removed from the receiving client cache. A notification is also sent to the machine that provided the content so that the corrupt copy can be removed there as well.

## When Content Is Deleted from the Cache

Content is rarely removed from the Adaptiva Client Cache, but it may be deleted under the following circumstances:

* *If the disk drive becomes full.*

  By default, the deletion threshold is 2% or 1GB remaining free disk space. When met, content in the cache is removed to make space for the operating system, applications, or end-user activity.
* *If the Adaptiva Client is uninstalled without preserving the cache.*

  You can explicitly choose to preserve the content cache when uninstalling, either by selecting the option in the wizard or using the `-nocachedel` command-line switch.
* *If the content is deleted from Configuration Manager.*

  When content is deleted from Configuration Manager, the Adaptiva Server notifies all devices with that content in the cache to delete it. If content is only removed from a Distribution Point, it will remain in the cache until it is fully deleted from ConfigMgr.
* *If the content is unpublished in Adaptiva.*

  When content is un-published from the Adaptiva Server, clients are notified to to remove that content from the cache.
* *If the content is detected as corrupt.*

  If the secure hash validation fails, the client deletes the content and notifies the sender to remove their copy.
* *If the content is manually deleted by someone with the required NTFS permissions.*


# Network topology

Overview of the network topology

Proper implementation of your network topology in the OneSite platform is a crucial part of the operation of any OneSite solution like Patch or Anywhere. To get the most our of OneSite's peer-to-peer content sharing, you will need to group clients into accurate Locations based on their network and IP ranges. Clients in the same Location will discover and download content from their peers in the local network rather than individually downloading content from the Internet.

The goal of an optimized topology is:

* Minimize WAN usage
* Maximize local, LAN-based peer-to-peer sharing.
* Ensure fast, reliable content delivery.
* Reflect your physical network topology of your environment.

This guide explains the key concepts, how topology influences content flow, and the built in features used by Location types.

If you would like to import your network topology from a spreadsheet, please see our [Import your network topology](/platform-guide/platform-management/network-topology/network-topology-import) page.

## Locations

Locations are the building blocks of defining your network topology. A Location is defined by one or more IP ranges intended to identify machines that are connected over a LAN. Locations should be defined for any IP ranges that are separated by a WAN link to ensure accurate content routing and optimal peer-to-peer behavior.

There are three distinct Location types:

* Default
* WiFi
* VPN

For more information regarding Locations and their types, please see our [Locations](https://docs.adaptiva.com/platform-guide/platform-features/locations) page.

### Central location

After installing your Adaptiva server, a Central Office will be automatically generated. This is the top-level Location and contains the Content Library, ensuring content is always available here.

All devices ultimately fall back to the Central Office for content if no other peer or parent Location has it, which we'll discuss more in the [Content flow](#content-flow) section below.

### Auto locations

When a client registers with the server for the first time, it is going to send its IP address and subnet mask. The server will then determine if it is a known IP range and add it to the appropriate Location. If the client IP is in an unknown IP range, Adaptiva automatically generates an Auto-Location named `Auto<networkID>`. By default, these Auto locations will be under the Central Office.

For more information regarding Auto Location setup please see our [Auto-Location](https://docs.adaptiva.com/platform-guide/platform-management/network-topology/on-premises-client-detection#enabling-auto-location-creation) page.

![](/files/h1jez0aZipLJGE9UW0D3)

While functional, Auto-Locations often produce:

* Too many small Locations that may actually be in the same physical location or LAN.
* Inefficient content routing since it will always route back to the Central Office, even though another Location may be physically closer.

To fix this we want to set up our network typology from both a physical network standpoint as well as a logical network standpoint. To do so, we can [create our own custom Locations](https://docs.adaptiva.com/platform-guide/platform-features/locations#creating-a-new-location) which should look more akin to the image below depending on your own physical network of each Location that you may have.

![](/files/2oS2T2JL2gOmA0wwqDZM)

{% hint style="info" %}
For SaaS customers, the network topology will be set up in much of the same way, however, you'll be able to access the Admin Portal from any device anywhere, as the Central Office and server will be located in the cloud.
{% endhint %}

## Content flow

The main goal of the network topology is to minimize WAN usage and maximize LAN-based peer-to-peer sharing.

At each Location, elections are automatically held to choose a designated device per location that communicates and controls the flow of content. This ensures:

* Content is only transferred once from a parent to a child office, reducing WAN traffic.
* Clients detect and send content locally whenever possible.

### Rendezvous Points (RVPs) and elections

During elections each client device self-evaluates things like:

* CPU utilization
* RAM
* Operating system
* Whether it is a desktop, laptop, or tablet

The client then volunteers itself as the RVP (Rendezvous Point), and then all client devices are evaluated and the best candidate is chosen as the RVP.

This entire process is automated and you can see which devices are RVPs from the Devices tab from **Assets** > **Devices** on the OneSite Admin Portal.

![](/files/xOUs73gN3xS9SVL3HAa9)

RVPs are responsible for:

* Managing content flow - essentially a traffic cop that dictates which clients can proceed with content downloads based on priority.
* Communicating with RVPs in parent and child Locations - content discovery if content is not located in the RVP's subnet.
* Coordinating peer discovery - finds new peers and adds to a table in memory.

### Content search

Once the RVP is established and a client's policy requests content, the client will proceeds to search in a particular order. Below is a content search from the network topology diagram example above.

1. Local
   * The Client device checks itself to see if it has the specific content already.
   * Houston WiFi Location client.
2. Subnet
   * The Client then asks other peers on the same subnet to find the specific content.
   * Houston WiFi Location client.
3. Location
   * The client asks the RVP of its subnet to reach out to the other RVPs at the same Location.
   * RVP from Houston WiFi Location asks RVP from Houston Location.
4. Parent
   * The RVP then asks the Parent RVP to find the specific content.
   * RVP from Houston WiFi Location asks RVP from America DC.
5. Central Location

   * If it still not found, the RVP will ask the Central Office.
   * RVP fro Houston WiFi asks RVP from Central Office.

   ![](/files/6OGBo7KfY7Mw9SM297bV)

{% hint style="info" %}
Locations can be configured to download directly from the internet-based Content Delivery Network (CDN) if desired. This can be done during the creation or modification of a Location by toggling on **Allow Direct CDN Download**. Please see our [Location settings and actions](https://github.com/AdaptivaDocs/docs/tree/main/platform/user-guide/location-settings-actions.md) page.

<img src="/files/zVA16mpiK5Sng56NUZO5" alt="" data-size="original">
{% endhint %}

## OneSite protocols

Adaptiva offers two proprietary protocols that optimize the delivery of content between Locations:

* **Adaptive Background Transport** - Used **between** Locations
* **Adaptive Foreground Transport protocol** - Used **within** Locations

{% hint style="warning" %}
Misconfigured offices can lead to:

* Foreground protocol used over WAN which will result in WAN saturation.
* Background protocol used over LAN which will cause slower distribution of content.
  {% endhint %}

### Background Adaptive Transport

The Background Adaptive Transport protocol is going to ensure that we can get our content across quickly without impacting other business traffic. This protocol is going to be used every time you are transferring over a WAN link ***between*** Locations, both on-premises as well as over the internet. This mechanism is one of the core advantages of the OneSite Platform, enabling efficient and non-disruptive data transfers even on congested networks.

#### Quality of Service (QoS) Considerations

When using the OneSite platform, you'll want to optimize how the Background Adaptive Transport operates on your network. If QoS artificially prioritizes OneSite traffic (e.g., assigning it a high-priority or reserved class), it can interfere with the optimal functionality of this protocol. The following issues can occur:

* Unintended congestion or latency for other critical applications.
* Reduced performance of OneSite, as the protocol cannot respond accurately to network conditions.
* Intelligent bandwidth control does not function properly.

**Implementation best practices**

If your organization mandates QoS controls across all network traffic, implement the following best practices:

* Identify OneSite traffic via ports. The bandwidth harvesting and background protocol uses UDP port 34750, and the foreground protocol uses UDP port 34760.
* Assign OneSite traffic to the lowest priority class (scavenger or default).
* Ensure it is not marked with high-priority or reserved-bandwidth tags.

This ensures that OneSite operates as expected, intelligently yielding more critical traffic while optimizing OneSite transfer rates in real time.

### Background Adaptive Transport Features

Below are the features that are included with this protocol.

#### Predictive Bandwidth Harvesting

The Predictive Bandwidth Harvesting feature, predicts future network conditions to optimize software delivery without throttling the bandwidth. This speeds up or slows down the content delivery where appropriate to not interfere with normal business traffic.

#### NetBoost

NetBoost helps us guarantee network responsiveness when the cause for slowdowns is not related to bandwidth.

#### Flow Equalizer

This feature protects the WAN by proactively leveling out traffic when multiple downloads occur at once.

### Foreground Adaptive Transport

The Foreground Adaptive Transport protocol is used whenever we are communicating ***within*** a Location of one or more subnets. It effectively transports data across the network in the fastest and most effective manner possible.

### Foreground Adaptive Transport Features

Below are the features that are included with this protocol.

#### Memory pipeline architecture

This feature delivers data quickly to peer systems on the LAN without impacting the end users.

## Summary

A well-designed network topology in the OneSite Platform ensures efficient, reliable, and LAN-optimized content delivery. By defining accurate Locations, establishing clear parent–child hierarchies, and relying on RVP-driven content flow supported by Adaptiva’s Adaptive Transport protocols, these components work together to significantly reduce WAN utilization and streamline high-performance, LAN-based peer-to-peer content delivery.

### Key takeaways

* Build accurate Locations that reflect real network boundaries and consolidate unnecessary Auto-Locations
* Define a logical parent–child hierarchy so content flows from the Central Office downward efficiently
* RVPs coordinate peer discovery and content searches across subnet, Location, parent, and Central Office layers
* Background and Foreground Adaptive Transport protocols optimize performance while protecting WAN and LAN traffic

## Related pages

[Devices](/platform-guide/platform-features/assets/devices)

[Locations](/platform-guide/platform-features/locations)

[Groups](/platform-guide/platform-features/assets/groups)


# Import your network topology

For on-premises customers, OneSite allows you to import your complete topology—including Locations, IP ranges, hierarchy, and types—using an Excel file.

You can download our sample files to use as templates for your topology import:

* [Sample-Input-Network-Topology-Import-Workflow.xlsx](https://adaptiva.com/hubfs/Docs/Sample-Input-Network-Topology-Import-Workflow.xlsx)
* [Sample-Input-Network-Topology-Import-Workflow-CIDR.xlsx](https://adaptiva.com/hubfs/Docs/Sample-Input-Network-Topology-Import-Workflow-CIDR.xlsx)

Modify the sample spreadsheet and store it on the Adaptiva server. In this example, the file name will be `C:\Adaptiva\NetworkTopology.xlsx`.

1. Navigate to **Workflows > Workflow Designer** in the Admin portal.
2. Select the **Utility Workflows** folder.
3. Right-click the **Import Network Topology From Spreadsheet** workflow and select **Launch**.

   ![](/files/8szLr6reHG6Z5hEy6dYW)
4. Enter the following values:

   **Excel File Location**

   ![](/files/agP9t5EGAY51SZSh6zHv)

   * **File path** -- Enter the path and filename for the .XLSX file which contains the network topology.
   * **Number Of Initial Header Rows To Be Ignored** - Enter the number of rows which should be ignored. Typically, this in only the first row that is used for column headers in the Excel file.
   * **Default Input**

   **Office Name and Description**

   ![](/files/KBeZyC8EW2KvrBnAGKhs)

   * **Column Number Which Contains Office Names** - Enter the column number that contains the office name and description that will be populated for each office in the Network Topology Perspective.
   * (Optional) **Add all the IP Address Ranges to the Description Field of Each Office** - Toggle **ON** to include the IP address range for each office in the office description.

   **Office Hierarchy**

   ![](/files/U7MPZkeK6Jlp1oLOvNqh)

   * **Column number which contains name of the parent office** - Enter the column number.
     * The row in the spreadsheet which represents the name of the Parent office should **match exactly** what is in the Network Topology Perspective, or a child office will be created.
   * **Automatically Delete Empty Offices Which Don't Have Child Offices** - Toggle **ON** if it is possible that the import results in empty offices.

   **IP Address Information**

   ![](/files/VqwQHO9nW6TuBKYir2Jl)

   * Select one of the following options:
     * **Spreadsheet contains IP Address Ranges**
     * **Spreadsheet contains Subnet Addresses and subnet masks**
     * **Spreadsheet contains CIDR**
   * Next, enter the column numbers which contain the information for each of the items.

   **Office Type Settings**

   ![](/files/e6KKsdbr5x4ugTzCirMI)

   * Enter the column numbers which contain VPN, WiFi, and Metered information.
5. Click **OK** to begin the import. Depending on the amount of data, the import may take time. Open the Network Topology Perspective to view your changes.

After importing a Network Topology from a spreadsheet, it is recommended that you review the logs for overlapping ranges. Some may have been removed from an office in favor of another due to the same range being incorrectly identified in the spreadsheet or associated with more than one office.

The log can be found in `<AdaptivaServerInstallPath>\Logs\Workflowlogs`. The log file name will start with Import Network Topology From Spreadsheet. When you open the log, simply search for `Removed Overlapping Range` to identify which offices and ranges require follow up.


# On-Premises Client Detection in SaaS

Advanced setup for on-prem client detection in SaaS

{% hint style="warning" %}
This is an advanced setup guide. If you would like assistance setting up On-Premises Client Detection, please contact our [Support Team](https://adaptiva.com/support).
{% endhint %}

**Auto Location Creation** and **On-Premises Client Detection** once enabled and configured, will allow you to group subnets into a single Location and optimize WAN downloads and better control LAN content sharing, or to enable the creation of Business Units or Groups based on a Location.

OneSite Patch - Self-hosted automatically creates a Location when the Adaptiva Client directly communicates with the Adaptiva Server, across the company network. If the Adaptiva Client cannot communicate directly, it sends messages to Adaptiva Cloud Services to relay them to the Adaptiva Server, and then the Adaptiva Client is placed in an Internet Location based on its public IP address.

In the SaaS environment by default, the Adaptiva Client communicates directly with the SaaS tenant using HTTPS and automatically creates an Internet Location based on the Public IP Address of the client. The system does not display Internet Locations in Assets > Locations. It always configures Internet Locations as Wi-Fi and uses unicast to communicate with all devices on the subnet. As a result, you cannot define Business Units and Groups using Locations. Additionally, you cannot group subnets together to reduce the number of downloads to a given Location.

![](/files/ahr0Kkmwo6YL5lZtkHlI)

![](/files/W87kLWuNDVoPu2THdFxD)

Below will guide you through how to setup client detection on OneSite Patch - Saas.

{% hint style="info" %}
Internet Locations are not available on the Locations page.
{% endhint %}

## Enabling Auto Location Creation

When an Adaptiva Client registers with the server for the first time, the server checks for an existing location with an IP range that matches the client. If it does not find an existing location, the server automatically creates a location using the IP address associated with the client and subnet mask. The Auto Location Creation feature on the Locations page controls this behavior. Follow the steps below to toggle ON Auto Location.

By default the Auto-Location will be set to the Central office.

{% hint style="info" %}
Auto Location Creation is disabled by default.
{% endhint %}

1. Select **Assets** > **Locations** from the side bar navigation.

   ![](/files/CoTgqztRWZgnzlRwsVSQ)
2. Select **Auto Location Creation** from the **More** dropdown.

   ![](/files/W5LRI6c7dBeVAtYL3pDS)
3. Toggle ON **Auto Location Creation Enabled**.

   ![](/files/FRxyey36LKravuJregXU)

### Allowed Auto Location IP Ranges

When you enable Auto Location Creation, you can specify which IP ranges are allowed to create an auto location.

1. Toggle ON **Restrict IP Ranges**.

   ![](/files/6z6leleA8orSP3gauXOU)
2. Then, select **+Create IP Range** to enter the subnet ranges and click **Create IP Range**.

   ![](/files/c2rbLF63UvEA3NuCXnUI)
3. Click **Save**.

## Setting up On-Premises Client Detection

1. Select **On-Premises Client Detection** from the **More** dropdown.

   ![](/files/76G2c2qZNW9o9vHbp844)
2. Configure one or more of the following Client Detection Settings:

   **ICMP Target**

   1. Select either Hostname or IP address.
   2. Enter the information for a device on the company network that the Adaptiva Client can ping using ICMP.

   ![](/files/DolLoE0guIMm33Y1MxTD)

   **DNS Targets**

   1. Enter a DNS Target and click **Save DNS Target**.

   ![](/files/BIOiSSbkhj4nQfMqyNFR)

   **Public IP Ranges**

   1. Then, select **+Create IP Range** to enter the Public IP ranges and click **Create IP Range**.

      ![](/files/c2rbLF63UvEA3NuCXnUI)
   2. Click **Save**.

## Adding IP range(s) to the Central Office Location

After completing the preceding steps, you must add an IP range to the Central Office Location, or a desired Location.

1. Select **Edit** from the more options dropdown next to the Location in the Locations tab.

   ![](/files/EMw6ngswYwSPjbW0B09p)
2. Click **+Create IP Range**.
3. Add in the IP Range(s) of the Internet clients created in the On-Premises Client Detection steps above.

   ![](/files/c2rbLF63UvEA3NuCXnUI)
4. Click **Create IP Range**.
5. Click **Save**.

The system adds clients that match the defined options to auto-created Locations based on their internal IP addresses. You can then manage these Locations as needed.

## Viewing internet clients

Clients that connect from the internet are not assigned to a standard Location and will not appear in the Locations pane. Instead, they are placed into a hidden system Location called *InternetLocation*.

To view these clients:

1. In the Admin Portal, hover over **Assets** and select **Devices**.
2. In the **Devices** table, search or sort by the **Public IP** column to identify clients connecting from internet IP addresses.

For more information on managing devices, see [Devices](/platform-guide/platform-features/assets/devices).

## Related Pages

[Client Upgrade](https://docs.adaptiva.com/platform-guide/client-management/client-auto-upgrade)

[Client Validator](https://docs.adaptiva.com/platform-guide/client-validator)


# Client Trusted Certificates

Provision trusted certificates to clients

The Adaptiva client can leverage trusted certificates for secure client communication with network security applications or appliances. In the Admin Portal, you can issue trusted certificates to a PKI store on managed Adaptiva client groups or Business Units.

This enables scenarios such as SSL inspection, where the Adaptiva Client establishes trust with a security application (such as Zscaler) using the certificate provisioned to the pki store on the device. This feature supports Windows, MacOS, and Linux devices.

## Add Client Trusted Certificates

1. Navigate to **Settings > Client Trusted Certificates > Certificates**. The uploaded certificate must be a PEM-encoded X.509 certificate.

   ![Certificate Settings Menu](/files/qm1cpDWvLaQW9yAFwYr3)
2. Click **+ New**.
3. Enter a **Name**.
4. Open your .pem and copy the public key into the **Certificate** text box.
5. Click **Save**. The identity will be parsed from the certificate and displayed.

   ![Create New Certificate](/files/VU0IBNJWaTXz1Ujdib4i)

## Add Certificates with Policies

1. On the top level navigation of the certificates page, click **Policies**.
2. Click **+ New**.
3. Under General Settings, enter a **Name** and **Description** of the policy.
4. Under Certificate Settings, next to Certificates, click **Browse**.
5. On the Select Client Trusted Certificate page, click to select the certificate(s). You can multi-select if there are multiple certificates to deploy using a single policy.
6. Click **OK**.
7. Next to Target Groups, click **Browse**.
8. On the Select Group page, click to select the Group(s) or Business Unit(s) you wish to apply the policy to. You can define policies to target different groups of devices with different certificates.
9. Click **OK**.
10. Click **Save**.

    ![Certificate Policy Provisioning](/files/dcok0psCayoyPTvqIa69)

### Client Certificate Store

The Adaptiva Client by default looks in multiple certificate stores: the data/pki directory, the system trusted certificate store, and the JVM cacerts file. When changes are made to the certificate store, the Client will restart within 60 seconds to ensure that only up-to-date certificates are being used.

You can view the certificate store on a client machine by navigating to **%AdaptivaClient%\data\pki**. All certificates assigned to the client by a certificate policy will be stored as .crt files in this directory.


# Import a Workflow

Instructions on importing workflows

Workflows are a useful tool to help you automate a myriad of processes across the OneSite Platform - including OneSite Patch - to solve a specific problem or enhance a specific feature.

Adaptiva offers many built-in Workflows to choose from, as well as the ability to create your own custom Workflows. For example, you may want to create a Workflow called "Inventory specific system properties for device targeting" which will target clients with specialized property checks.

Below is a guide on how to import and deploy your custom Workflows.

{% hint style="info" %}
OBEX and JSON files are supported for both exporting and importing.
{% endhint %}

## Importing your custom Workflow

1. Select the **Home** screen settings cog dropdown (![](/files/IEIEAgwVtxbQN7rIGOVK)), and select the **Import** button.

   ![](/files/bwfm623SSwPoRWECYAXb)
2. This will open the Import pane and Windows File Explorer.

   ![](/files/HG6ShdZSZ11uW130bU0t)
3. Select a file to import and click **Open**.
4. The Import pane will display.

   ![](/files/57xyyERLsz2BRSaSpJbx)

   Exporting Organization, Description, and Import Folder Settings information will populate if it exists in the OBEX or JSON file prior to importing. Otherwise this will be blank.
5. If an OBEX or JSON file denotes a file directory, this Workflow will be saved there.

   * However, if you would like to override where the file will be saved in the Workflow directory, toggle **Override Automatic Import Folder** and **Browse** to choose a different folder.

   ![](/files/m6fiRSy4nMNwM2EdcLlW) ![](/files/ZvtCvLIK0pWLLwonqlPX)
6. Select **Import**, and the file should now successfully be imported into the Workflows Designer Dashboard.

   ![](/files/5Ri9eiOS8hKvRrjAZV55)

## Deploy your custom Workflow

1. Hover over the **Workflows** dropdown and select **Designer** in the left navigation menu.

   ![](/files/sbCHwWWE2Y22kLHpy5O3)
2. Select the folder containing the imported Workflow from the Workflow Designer directory.
3. The folder contents will be displayed in the pane on the right.
4. Select the more options dropdown next to the Workflow and select **Deployment Settings**.

   ![](/files/75SBkWs0SNpK41Y16HpC)
5. Select **Deploy**.
6. Review the Deployment, Execute, and Logging settings and then select **OK**.

   ![](/files/R52G3eHeh5O7X2SX4A4J)
7. A pop up will appear at the bottom of the window if the deployment was successful.

   ![](/files/HQWajnbWyS2SfsLy32YB)

## Resolving errors during import

When importing a new file, errors may be present in the Import pane. Common errors include objects with the same name or type, or built in objects that already exist, etc. We have resolution options to choose from for each type of error you may encounter. All errors must be resolved prior to importing a Workflow.

1. Errors can be resolved by selecting the hammer icon to the right of the error in the **Errors** tab.

   ![Error hammer](/files/Deu2MuR9UHynf7aaghBg)
2. Check the Resolution you wish to apply. Depending on the resolution, you may have additional options to consider before you click **OK**.
3. Once all Errors are resolved, select **Import**.


# Client Authorization

How to setup Client Authorization in the OneSite Platform.

{% hint style="info" %}
Client Authorization is only used for the on-premises version of the OneSite Platform. For more information on Client Tokens for SaaS, please visit our [Client Install](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-install/client-install-saas) page.
{% endhint %}

Client Authorization can be used to additionally protect Adaptiva client installations that are completed over the internet. This is important when the client cannot communicate with the Adaptiva Server, but can communicate with the Adaptiva Cloud Relay Services at `http://services.adaptiva.cloud`.

When an Authorization Secret is created, a new client installation must include that Authorization Secret. A secret is entered during the Adaptiva Client installation that ensures only clients with valid secrets can be registered with the Adaptiva Server.

Multiple secrets can be created, and either secret can be entered when prompted. For instance, you may want to give one Admin group a particular secret that differs from another group based on location. Both secrets will grant Client Authorization regardless of which secret is entered.

Authorization Secrets can be created and removed at any time. When removed, be sure to update any command lines that included the secret.

{% hint style="info" %}
Authorization secrets are essentially passwords and are recommended to follow the same guidelines: minimum 10 characters in length, contains 1 or more digits, an uppercase letter, and a lowercase letter.
{% endhint %}

## Setting up client authorization

1. Select **Settings** > **Client Authorization** from the Admin Portal settings gear (![](/files/3TIyhkfCAp2B83XW32xP)).
2. Select from the following radio buttons to choose which client installations will require a password:

   * **No Authorization** - Does not require a password.
   * **Enable Internet Clients** - Only Internet Clients will require a password.
   * **Enable All Clients** - All Clients will require a password.

   ![](/files/fS2bUZFRnjlppHUeesGQ)
3. Click **+Add Secret**
4. Enter an **Auth Secret**.

   ![](/files/yRnlQgtmvY6nLfYoiMCd)
5. Click **OK**.
6. Click **Save**.


# Client Upgrade

*Applies to version 9.3, 10.0, and above*

## Automatically upgrade Adaptiva clients

After version 9.3, Adaptiva clients will automatically upgrade to the matching version deployed on their Adaptiva server. Anytime you upgrade your Adaptiva server, devices will begin to upgrade to the new Adaptiva client version in waves. The Client Upgrade settings in the Adaptiva Admin Portal control the configuration of client upgrades in your organization.

![Client upgrade settings dashboard](/files/myLp3msX8NSgt6UFifbe)

Clients are upgraded across four deployment waves, each wave targeting a group of devices. The default upgrade settings will stagger deployment waves every 7 days with a deployment window of 7 days for each wave, completing after 35 days.

### Wave deployment groups

The default deployment groups for each wave will select a percentage of the devices in your organization and map those to a deployment wave.

| Group name                          |      Devices targeted |
| ----------------------------------- | --------------------: |
| Client Upgrade Default Wave 1 Group |                    1% |
| Client Upgrade Default Wave 2 Group |                   10% |
| Client Upgrade Default Wave 3 Group |                   25% |
| Client Upgrade Default Wave 4 Group | All remaining devices |

Clients are selected for membership in each group randomly. The membership for the client in these default groups cannot be modified, but you can remove these default groups from the deployment waves and replace them with ones you have configured.

### Planning deployment groups

You can select your own device groups to customize the deployment of client upgrades. For example, you can target pre-production devices in Wave 1 for testing. After your initial testing, you can configure the remaining waves to deploy to production. You can also pause deployments if you discover unwanted client behavior after an upgrade.

## Configure client upgrade settings

In the Adaptiva Admin Portal, in the upper-right corner, click the **gear icon | Settings | Client Upgrade**.

Client Upgrade is enabled by default. You will see the default waves configured and reporting dashboards displaying deployment progress.

Each deployment wave is displayed with a deployment status, scheduled start time and deployment progress.

![Client upgrade dashboard](/files/Zcp1n2s4ET4uJOoYyu8P)

*Deployment Status* -- the overall status of the deployment wave: *Completed*, *In Progress*, or *Not Scheduled*.

*Scheduled Start Time* -- the start time of wave 1 is based on the time of the client version update plus the Time to Wait value. Proceeding waves will begin to deploy based on the previous wave’s start time plus the Time to Wait value.

*Deployment Progress* -- number and percentage of clients that have successfully upgraded.

### Create a custom deployment schedule

You can configure a custom deployment schedule by selecting the **Deploy in a schedule wave** radio button under **Deployment Schedule**.

Click **Settings**.

![Wait time and load leveling](/files/Ex0vED0nFXxu7WYZxQZi)

You can configure both the **Time to Wait** and **Load Leveling Window** times to customize your deployment for clients across waves.

* *Time to Wait* - defines the time a wave waits before beginning its deployment, measured from the start of the previous wave.
* *Load Leveling Window* - defines a window of time when clients are upgraded. If the window expires and clients remain, those clients are moved into the next wave.

You can configure the start time of each wave by setting a *Time to Wait*. You configure the deployment window for all clients in that wave by setting a *Load Leveling Window*. The default time for these settings is 7 days, but you can configure it for as low as 1 hour.

{% hint style="info" %}
The Load Leveling Window of a wave cannot exceed the Time to Wait in the next wave. For example, if you set the Load Leveling Window to 2 hours in Wave 1 and then try to set the Time to Wait to 1 hour in Wave 2, the following error appears: `Load Leveling Window cannot exceed the start time of the next wave.`
{% endhint %}

After configuring the Deployment Schedule, click **Save**.

You can start the deployment of a wave by selecting the **Deploy immediately** radio button. This will ignore the Time to Wait and Load Leveling Window values and upgrade all clients in the wave immediately.

The next time a new client version is available, the Deployment Schedule will revert to **Deploy in Scheduled Wave**. The client upgrade cycle will reset and initiate a new schedule for each wave based on the **Time to Wait** and **Load Leveling** settings.

### Select custom deployment groups

You can select custom deployment groups to align client upgrades to your organizational structure. For example, you can target clients in a lab environment for faster deployment in wave 1.

To configure custom groups for your deployment, perform the following:

1. On a wave card, click **Configure Groups** to select a custom deployment group.
2. In the Select Group pane, under Target Groups, click **Browse** and select one or more groups. Click **OK**.
3. Click the **Affected Devices** tab to show the devices targeted by the selected groups.
4. Click **Set** to confirm your selection.
5. On the Client Upgrade Settings page, click **Save**.

### Monitor deployment progress

You can monitor the deployment progress of your devices using the built-in dashboards on the Client Upgrade Settings page.

![Monitor deployment progress](/files/HmeKzzddJSTvWpuX3JQ9)

In the **Devices by Version** panel, you can view all device version for client reporting to the Adaptiva server. When you select a section of the donut chart, it filters the *All Devices Table* to your selection. You can use this report to evaluate devices not upgraded to the latest version and diagnose any blockers to your upgrade rollout.

In the **Deployment Progress by Wave** panel, you can view the deployment progress for each wave. When you select a section of the bar chart, it filters the *All Devices Table* to show the devices in that deployment wave.

### Pause client upgrade

You can pause the automatic rollout of the Adaptiva client by clicking the **Pause Deployment** button and then clicking **Save**.

![Pause deployment button](/files/uqVEQwwqQbA2C9c2KuOW)

When you pause the client upgrade, all deployments immediately stop. The pause time and date will display to the left of the button. The button will update to **Resume Deployment**.

![Resume deployment button](/files/XcxWXKVUBJbG8kNm9iyJ)

Once you resume automatic upgrades, each deployment wave will resume based on the initial scheduled execution time. For example, if each wave is scheduled to start every five days, and the deployment is then paused for one month, all waves will immediately start upgrading.

## Troubleshoot deployment issues

In the **Devices by Version** panel, select the devices reporting an older version to filter the *All Devices Table*.

You can then review the last check in time for each device in **Assets | Devices** to determine client connectivity. Contact [Adaptiva Support](https://adaptiva.com/support) for assistance troubleshooting device connectivity and upgrade.

## Additional Considerations

The Client Upgrade feature is only applicable to clients on version 9.3 or later. To upgrade older client versions, use the [Legacy Client Upgrade (Windows)](/platform-guide/client-management/legacy-client-upgrade) feature and then transition to automatic client upgrades when all clients are up to date.


# Legacy Client Upgrade (Windows)

How to update devices with the Legacy Client Upgrade (Windows) feature.

*Applies to version 9.2 or earlier*

The Legacy Client Upgrade (Windows) feature is available to upgrade devices using Adaptiva client versions 9.2, 9.1, or earlier. If you have devices using the 9.3 or later version of the Adaptiva Client, use the new [Client Upgrade](/platform-guide/client-management/client-auto-upgrade) feature to automatically upgrade Adaptiva client versions.

Since the Legacy Client Upgrade (Windows) feature only supports Windows devices, any Linux or macOS devices will need to be upgraded manually or an unattended installation using a software distribution tool. See the [Client Installation on Linux or MacOS](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-install/client-install-linux-macos) section of the OneSite Platform Installation Guide.

Once you have upgraded all devices to the 9.3 Adaptiva client, you can [disable the Legacy Client Upgrade (Windows) feature](#disable-legacy-client-upgrade-windows). This will allow you to use the automatic Client Upgrade feature moving forward.

## Enable legacy client upgrade

1. Connect to the Admin Portal using a web browser (except Internet Explorer) -- `http://AdaptivaServerFQDN[:port]`.
2. Enter the appropriate credentials or click on **Login with Active Directory**.
3. Click on the gear icon ![](/files/IZ1YqeJ3mXKyyrvGw3C6) **> Settings > Legacy Client Upgrade (Windows)**.
4. The dashboard will show the current coverage for different client versions and the upgrade status by location.

   ![](/files/YhIQunXWMxp9HHmD40Tf)

   ![](/files/04d4p1wPiVcOjB4wTr7r)
5. Toggle ON **Enable Client Auto Upgrade**. The settings below can now be configured.

   ![](/files/Ua199Q63QgxLHJtkqFuX)

   If it is already enabled, the last saved settings will be set in each section below.

### Scheduling

The Schedule settings configure when clients begin upgrading to the client version of the server.

![](/files/edEJUX49oiAdfuDfvlmT)

Click the calendar icon ![](/files/VaXcqUNEF6CGgQp8xr8E) to open a calendar widget and select a start date and time.

![](/files/QmUcL7xCPNsO5NNRcum3)

Click anywhere off the widget to close it. The date and time has been entered into Schedule Start Time. You can toggle **Use Server Time Zone** to have this start time use the time zone of the Adaptiva Server.

Once the upgrade policy is saved and deployed, clients that come online after this start time will apply the policy immediately.

### Target Groups

You can target clients for upgrade by group or simply target all clients registered with the Adaptiva server.

![](/files/WvGmHRPfSNr2J9kih1GM)

To target all Adaptiva clients for upgrade, toggle **Use All Adaptiva Clients**.

To target a collection of clients for upgrade, click **Browse**.

In the Select Group pane, check the box next one or more Adaptiva Groups or ConfigMgr collections, then click **OK**.

### Load Balancing

By default, all targeted clients will begin to upgrade on the start date and time. If you want to balance the rollout of client upgrades over a period of time, configure the load balancing settings.

![](/files/C1vMpV2TU2oH417zAwwS)

Toggle **Use Load Balancing**.

You can set a load balance interval between 0 and 100 Days, Hours or Minutes. Once enabled, each client will be randomly divided across the load balance interval for their upgrade schedule.

### Installation

You can configure all of the upgrade settings for your clients. Any setting configured on the page will update the command line reference below.

![](/files/0MClWNtUOcD8clP0GvZ0)

* **Use Server FQDN** or **Use Server IP Address**

  You can choose either **Use Server FQDN** or **Use Server IP Address**. The Adaptiva Client can only be installed using either the `-servername` or `-serverip` switches.

  You can verify the Server Name or IP Address is correct by reviewing the command line below.
* **Override Server FQDN**

  To override the Server FQDN or IP Address, toggle **Override Server FQDN** and enter the new Name or IP Address to use.

  When you override the Name or IP Address, it will cause the client to be inactivated and re-activated. This will trigger a review of all content in the AdaptivaCache folder as well as new policy downloads.

  If the FQDN or IP Address needs to be changed to support a DNS CNAME Alias see [How-To: Redirect OneSite client to a different Adaptiva server](https://support.adaptiva.com/hc/en-us/articles/206503713-How-To-Redirect-OneSite-client-to-a-different-Adaptiva-server)

Choose any of the below options:

* **Use Cloud Relay**: Allows the Adaptiva client to communicate with `http://services.adaptiva.cloud` when unable to communicate via UDP to the on-premises Adaptiva Server.

{% hint style="info" %}
If any of the in-scope clients have been previously configured to use the Cloud Relay Service, be sure to enable this setting otherwise client communications will stop using the Adaptiva Cloud Relay server.
{% endhint %}

* **Bind to HTTP URL**: Allows the Adaptiva client to communicate with the on-premises Adaptiva Server via the defined HTTP Port. This adds the `-serverurl <url>` to the command line.

  When the Bind to HTTP URL is enabled, enter the URL of the on-premises Adaptiva server. For example: `http://adaptivaserver.mydomain.com:9678`
* **No Add/Remove Programs Entry**: Enabling this setting will prevent Adaptive Client from being added to the Add & Remove Programs/Programs & Features list in Windows. Do not select this option if this information is required. Adds the `-noarp` switch to the command line.
* **No Firewall Entries**: Enabling this setting will prevent Windows Firewall entries from being created automatically. Adds the `-nofirewall` switch to the command line.
* **No WoL**: Enabling this setting will disable Wake on LAN. Do not select this option if it is desirable for machines to be woken using Wake on LAN magic packets in the event that content is available on the device, but the machine is offline. Adds the `-nowol` switch to the command line.
* **Memory Allocation (in MB)**: This setting configures the maximum JVM memory allocation for the client. As of Adaptiva Client version 9.1, the default memory allocation is 512MB. Do not set this number below 512. It is recommended to set this value in powers of 2 starting at 512.

  The Memory value in the CLI Input shows the last value used and may differ from the Memory Allocation selection. Change the Memory Allocation to sync the CLI Input.

Review the value of the command line to ensure that the `servername | serverip` is correct and that any required or desired command-line switches are present and displaying the correct values.

> NOTE: The command line will always contain the `-delay 30` switch on the end. This cannot be overridden.

### Save and Deploy

Once you have configured the client upgrade settings, click **Save and Deploy** to start the upgrade process.

You will be prompted to validate the command line.

![](/files/MBRcAuNczNb9uc3gyggF)

Click **OK** after reviewing the installation command line.

These settings are saved in the database in the table `AUTOUPGRADESETTINGS`. When Save is clicked, the latest Adaptiva Client will be published as Adaptiva Content, a hidden schedule, group and content push policy will be created.

When the specified start date/time is reached, the clients will download the content. The content will get unpacked into a local folder on the client `%TEMP%\AdaptivaClientUpgrade` (normally `C:\Windows\TEMP`).

The client upgrade status will update at the top of the window.

### Disable Legacy Client Upgrade (Windows)

Once you have upgraded all devices to the 9.3 Adaptiva client, disable the Legacy Client Upgrade (Windows) feature and use the automatic [Client Upgrade](/platform-guide/client-management/client-auto-upgrade) feature moving forward.

1. Toggle OFF Enable Auto Client Upgrade.
2. Click **Save and Deploy**.


# Client Settings Policy

Learn how to create configuration changes on devices using client settings policies.

Client Settings can be used to create configuration changes for a Device Group or globally for all client devices.

An example of a common client setting is enabling driver patching:

* **Patching Client System > Enable Driver Updates** - Enable driver patching for BIOS and firmware. If set to **true** this will enable a client to perform driver updates.

## Configure a Client Settings Policy

1. Connect and log into to the Admin Portal.
2. Click **the gear icon > Settings > Client Settings Policies**.
3. To create a new policy, click **+ New**.

   In the **General Settings**, complete the following:

   * **Name** - Enter a unique name. For this example, *Enable driver patching*.
   * **Description** - Enter a description. For this example, *Enable driver updates on clients to allow patching*.
   * **Priority** - To ensure these settings apply to the target groups, set this value greater than 1.
   * **Target Groups** - Click **Browse** and select one or more Groups. In this example, we chose *All Clients*.

   ![](/files/GwP4bHzB2NA8fhkul4GJ)
4. Click **OK**.
5. In the **Client Settings** section, click **Add Settings**.

   ![Client settings](/files/fB0K3OUtwST7Nv4xG6gt)
6. Find and expand **Patching Client System**.
7. Check **Enable Driver Updates**.
8. Click **OK**.
9. Select **Enable Driver Updates** from the **Client Settings to Override** table.

   ![](/files/9ti97bTFkozCfauUwKWZ)
10. In the Settings Details, in the *New Value* field, enter **true**.
11. Click **Save** to create the policy. This will immediately distribute the policy to all target clients.


# Client Validator

The Adaptiva Client Validator is installed by the Adaptiva Client setup. It runs automatically after the Adaptiva Client is installed and can be run anytime to troubleshoot client connectivity. The Validator verifies all connectivity requirements for the client to be fully online and managed. All results are logged in the client registry.

You can run the Client Validator tool from the Adaptiva Client installation location: `%ADAPTIVACLIENT%\bin\AdaptivaClientValidator.exe`.

## Validation check detail

The following describes the validation checks being performed:

* HTTP Connection: Verifies the client can connect with cloud services.
* Cloud Relay Connection: Verifies the client can connect to the cloud relay system. The Adaptiva Server must be activated for this check to pass.
* Client-Server Messaging: Verifies the client can send and receive messages to the Adaptiva Server.
* Client-Server Handshake: Verifies the client can successfully perform a handshake with the Adaptiva Server and has obtained a client id.
* Client to Client: Checks if the client has peers in the office and verifies connectivity with those clients. Content Download: Verifies that the client can download a sample package of 8 bytes.

## Client Validator registry settings

You can view the status and results of the client validator in the registry, under `HKEY_LOCAL_MACHINE\Software\Adaptiva\client`.

### HTTP connection

**Key**: `check.http_connection`

**Values**: Passed / In Progress / Failed

**Details**:

This check confirms connectivity to:

* `http(s)://services.adaptiva.cloud`
* `https://adaptiva-releases.adaptivacdn.cloud/client/ClientSetupTest`
* `https://adaptiva-opr-content.adaptivacdn.cloud/ClientSetupTest`
* The URL of the cloud tenant if specified in the install: `https://[tenant name].adaptiva.cloud/`.

### Cloud relay connection

**Keys**: `check.cloud_relay_connection`, `check. cloud_relay_connection_detail`

**Values**: Passed / In Progress / Failed / Not Applicable

**Details**:

This check is only performed if the client is configured to use a cloud relay. If the client is not configured to use a cloud relay or is using a cloud server, the test completes with a “Not Applicable”. The \_detail key records the check result.

### Client-server messaging

**Keys**: `check.client_server_messaging`, `check.client_server_messaging_detail`

**Values**: Passed / In Progress / Failed

**Details**:

This check determines if the client can send a message to the server and gets a reply. A new client will always do a full handshake protocol and receive a NewClientConnection reply from the server. Established clients send a ping message and receive an “ack” reply from the server. The `_detail` key records the details of the server reply.

### Client-server handshake

**Keys**: `check.client_server_handshake`, `check.client_server_handshake_detail`

**Values**: Passed / In Progress / Failed

**Details**:

This check determines if the client has successfully performed a handshake with the server and obtained a client id. The `_detail` key will record the client id.

### Client-to-client messaging

**Keys**: `check.client_to_client_messaging`, `check.client_to_client_messaging`

**Values**: Passed / In Progress / Failed / Not Applicable

**Details**:

The client will request a list of local clients, to which the server will respond with a list of up to 32 client IDs and IP addresses that are in the same location as the client. The client sends a ping message to each of these clients and wait for a reply. If the client receives any reply for a local client the check passes, otherwise it fails.

If no other clients share that location, the server sends an empty client list and the check completes with a "Not Applicable" status.

### Content download

**Key**: `check.content_download`

**Values**: Passed / In Progress / Failed

**Details**:

This check determines if a client can download a built-in content package of 8 bytes in size using any method (P2P or CDN).

### Stop Checks

**Key**: `check.stop_checks`

**Values**: true / false

**Details**:

This check determines if the client validator checks have completed. The client validator will set this value to `true` if the user has accepted the current state of tests and decided to proceed.

### Check timeout

**Key**: `check.timeout`

**Values**: seconds

**Details**:

This key configures timeout in seconds for the tests run by the client. The default value is `300` (5 minutes).


# SMTP Settings

Comprehensive guide to SMTP settings

The SMTP Settings feature allows you to configure the settings for a SMTP Provider. By default email notifications are sent from `twilio@adaptiva.com`. However, by setting up your SMTP Provider, notifications can be sent from a specified email address in your environment.

For example, you could have email notifications sent from `PatchAdmin@<yourcompany>.com` with your company's logo and signature.

SMTP Settings can be used in conjunction with the following:

* **Communication Providers** - You have the choice of two types of SMTP: HTML or Simple Text. This is determined by the **Communication Provider** you select in your Approval Chain or Notification Settings. For more information regarding Communication Providers within OneSite Patch, please see our [Communication Providers](https://docs.adaptiva.com/patch/advanced-settings/communication-providers) page.
* **Approval and Notification chains** - By default Approval Chains are set to `HTMLEmailCommunicationProvider` for the auto-created Super Admins. You can change this to either `HtmlSmtpServerCommunicationProvider` or `SimpleSmtpServerCommunicationProvider` in order to use the SMTP you set up in SMTP Settings.
* **Dashboard Subscriptions** - Dashboard Subscriptions allow you to send the results of a specific dashboard via email to Administrators defined in a specific Role on a specified schedule. Dashboard Subscriptions can only use SMTP so it is required to setup SMTP Settings prior to creating your first Subscription.

{% hint style="info" %}
Each user must have an email associated with their account in order to receive any email notifications. By default, if the Super Admin was selected during installation to be the logged on **Active Directory** account, that account will not have an email address. Remember to update the Administrator account to include an email address.

Additionally, if Active Directory users are added via group membership, they will not have an email address and each must be updated to include the appropriate email address.
{% endhint %}

## Set up SMTP Settings

SMTP Settings can be accessed in the OneSite Platform and will be applied to all Adaptiva solutions. Below are steps to configure your SMTP Settings.

### Email Notification Settings

1. Click the settings gear in the top right of the Admin Portal.
2. Select **Settings** > **SMTP Settings**.

   ![](/files/JwBJC2vhAwM7K0oXK4ni)
3. Toggle ON **Use Email Notifications**.
4. Enter the following into each field:

   ![](/files/6sLBEOWKOm5B8IE4KMCj)

   * **Mail Sever** - Enter the FQDN or URL of the SMTP mail server.
   * **Mail Server Port** - Enter the port.
   * (Optional) **Email Address** and **Email Password** - Enter the email address and password. This email address is for the server itself for authentication. You will not need to enter either if **Use Unauthenticated SMTP** is toggled ON.
   * **From Email Address** - Enter the email address you'd like email notifications to be sent from.
   * **Use TLS** or **Use SSL** - Toggle ON either TLS or SSL.
   * **Use Unauthenticated SMTP** - Toggle ON if your SMTP server does not require authentication. If enabled, the SMTP emails will explicitly not send the username and password. Some environments like Azure’s SMTP relay require this.

### Email Customization Settings

These settings are customization options that are only applied to the HtmlSmtpCommunicationProvider Communication Provider.

![](/files/IFpTjoCXu4YmaIq0q8CI)

1. **Logo URL** - Enter the URL of your Logo image file. By default this will be the Adaptiva logo. The logo must be in a PNG file format.
2. **Support Contact** - Enter instructions on how your users can contact your support team.
3. **Email Support** - Enter a personalized email signature.

## Related pages

[Communication Providers](https://docs.adaptiva.com/patch/advanced-settings/communication-providers)


# Manual Policy Sync

Manual Policy Sync is a OneSite Patch setting that will manually dispatch select policies. This can help you troubleshoot to ensure existing policies that run automatically, do not have an issue.

This setting is found from the **Settings** dropdown on the top right on either the OneSite Platform or Patch Home page.

Syncing a Policy dispatches its latest version to all target clients.

{% hint style="info" %}
Only Super Administrators may sync Policies.
{% endhint %}

![](/files/RWCkuSXZQjB7ZiurGWyp)

If you're noticing some devices are not receiving the same policy as other devices in the same Business Unit. You can then make incremental changes and run Manual Policy Sync to verify your changes without having to wait for the Policy to run on its own designated schedule. Once you have found the issue, you can keep your updated changes and ensure that the policy will run as expected during its scheduled sync.

## Dispatching selected policies

1. Select one or more **Policies** from the table.
2. Click **Dispatch Selected**.

   ![](/files/NXZaHM5t9Nbfdlg4cn8f)
3. A pop-up will appear at the bottom of the pane notifying you of a successful dispatch.

   ![](/files/nr93jlU0GxiwxifaVz2V)
4. Verify the target clients of the selected Policies were updated to the latest version of that Policy.


# Server Activation and About

{% hint style="info" %}
Below are some advanced settings and should be used with caution. However, these two settings display useful information for our [Support Team](https://adaptiva.com/support) to help you troubleshoot any issues you may have, so they are noted here.
{% endhint %}

## Server Activation

Server Activation details your server information and for Anywhere clients the place to activate your server. For more information regarding activating your server, please see our [Platform Install - Server Activation](https://docs.adaptiva.com/platform-install/server-install/install-platform#server-activation-onesite-anywhere-only) page.

Select the Settings cog in the top left and then select Settings > Server Activation.

![](/files/VlR66JWLVNfnA2GhxybE)

This will display the Server Activation pane.

![](/files/fiDzh1WQ5gqYyDx5uQNH)

The following fields will be available to view:

* **Server Activated** - This will automatically be toggled ON and greyed out unless you are an **OneSite Anywhere** customer.
* **Customer Name** - The customer name is a unique name. In most cases for on-premises customers, this will be your server name. If you are a SaaS customer, this will likely be an auto-generated ID.
* **Global ID** - For SaaS solutions, this is the unique auto-generated GUID used by both the server and clients. When messages are sent through Adaptiva cloud relays, the relay uses the GUID to identify which server the messages should be forwarded to, so they are forwarded to the appropriate clients.
* **Tenant ID** - In SaaS, this is the unique ID of your Tenants.
* **Server GUID** - Similar to Global IDs, but for on-premises customers, server GUIDs handles messaging between on-premises Adaptiva servers and clients.

## About

The About section displays information about your server and allows you to set a specific time zone.

![](/files/smsB3e7JUHTPvNfheETK)

### Server Info

The following information will be displayed under Server Info:

* **Server Name** - Name of your server. This is the name you created during installation.
* **Server FQDN** - Unique FQDN for your server. E.g. `server1.adaptiva.cloud` or `server1` depending on if you are a SaaS or on-premises customer.
* **Version** - Displays the version of your Adaptiva platform.
* **Cloud Relay Server Global ID** - The unique GUID for the cloud relay server.
* **Cloud Relay Server FQDN or IP** - Unique FQDN or IP address for the cloud relay server.
* **Server Time Zone** - This will allow you to set a desired time zone to be used for scheduling server jobs and tasks.

### UI Settings

The UI Settings are advanced settings that should be approached with caution.

![](/files/IHzSS1A6ju6EknejlGe9)

Under UI settings, you will find the following options:

* **UI State Caching** - This allows you to control how Widget state persists for complex, stateful Widgets like Tables.
  * **None** - Widget states will not persist if the tabbed is closed or browser is refreshed.
  * **Session** - Persists states on a per-tab basis until the tab is closed or executes a browser refresh.
    * For instance, if you have a Table sorted by Operating System, this will continue to be sorted by OS even after navigating away from the pane in the same session.
  * **Storage** - Writes state to `LocalStorage` and persists upon closing a tab or refreshing the browser.
    * In the same scenario as **Session**, if you have a Table sorted by Operating System, this will continue to be sorted by OS even after closing and reopening a tab or refreshing the browser.

<details>

<summary>Advanced Options - Developer Mode</summary>

{% hint style="danger" %}
Do NOT enable Developer Mode without instruction from our [Support Team](https://adaptiva.com/support).
{% endhint %}

Developer Mode enables the Memory Pipeline in the sidebar view. This allows you to upload custom content via a local source, network source, or CDN. To reiterate, uploading custom content should be avoided unless with explicit instruction from Support.

</details>


# Sensor Offline Cache

Sensor Offline Cache collects endpoint sensor data, stores it on the server, marks outdated data as historical, and controls how long that data is retained for monitoring and troubleshooting purposes.

The Sensor Offline Cache stores device data with settings controlling when historical data is removed. New data is saved indefinitely unless it is updated by a newer record, whereby it is marked for deletion and appends a delete by date. This ensures that historical data about a device is available for an administrator to monitor, but is removed by a set date to free up space for newer records.

For example, a device returns that it has Windows 10 installed. This record will be stored in the database with a creation date and the deletion date set to `NULL`. A few months later, the device data is updated to Windows 11 and a new record is created. The existing Windows 10 record will now populate with a deletion date and will be purged from the database at set date/time while the Windows 11 record will remain.

{% hint style="info" %}
As of version 10.1.972.8, Sensor Offline Cache now defaults to 365 days for deletion and is enabled by default. If the setting was previous configured in a later version, this will NOT be overwritten.

In older versions, this data is saved indefinitely by default.
{% endhint %}

## Sensor Offline Cache Purger Settings

The time until deletion duration is determined by the Sensor Offline Cache Purger Settings.

![](/files/NbHhvCo6shFz5LHh3Zfk)

These settings can by found by navigating to **settings gear > Settings > Sensor Offline Cache**.

![](/files/2qGetnVNSvNRquCpGFgV)

Each of the following settings can be modified to suit your specific needs:

* **Purger Enabled** - When enabled (default), the purger clears sensor data at regular, user defined intervals.
* **Default Retention Period** - Determines how long stale sensor rows remain in the database before deletion.
* **Time Between Purge Starts** - Determines how often we kick off the process which deletes overly stale data.


# OneSite Cloud Portal

Overview page for OneSite Cloud Portal

The OneSite Cloud Portal provides IT professionals with high-level management of their Companies and Tenants to support the SaaS deployment of OneSite Patch. This deployment of OneSite Patch is supported in the cloud and does not require on-premises equipment or hardware, but uses the same OneSite Patch dashboard. The SaaS deployment process is the same for supported Adaptiva products, because they are all built on the OneSite Platform.

For additional documentation regarding the use of OneSite Patch, please visit our [OneSite Patch](https://docs.adaptiva.com/patch) documentation.

This guide explains how to use the OneSite Cloud Portal for setting up Companies, Tenants, Users, and how to navigate the Cloud Portal pages.

![](/files/y4PmpNf6Yo1MYjj9Qq7J)

## Site Map

| Page                                                                 | Description                                                                             |
| -------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| [Sign Up](/cloud/getting-started/signup)                             | How to create a new sign up account.                                                    |
| [Log In to Cloud Portal](/cloud/getting-started/log-in-cloud-portal) | How to login after being signed out while optionally using Multi-Factor Authentication. |
| [Set Up Company](/cloud/configuration/create-company)                | How to create and manage new Companies.                                                 |
| [Set up Tenant](/cloud/configuration/create-tenant)                  | How to create, configure, and manage Tenants.                                           |
| [Manage Account](/cloud/user-management/manage-account)              | How to change your account password, set up MFA, or delete your account.                |
| [Administrator Roles](/cloud/user-management/roles-responsibilities) | Description of Administrator types and corresponding roles and responsibilities.        |
| [Invite Users](/cloud/user-management/invite-users)                  | How to invite users to a Company or a Tenant and assign User Role.                      |

## Customer Support

If you need information beyond what our Documentation and [Knowledge Base](https://support.adaptiva.com/hc/en-us) provide, enter a support ticket and request help from [Adaptiva Customer Support](https://adaptiva.com/support).


# Sign up

Signing Up as a User in the OneSite Cloud Portal

Sign up as a user to access the OneSite Cloud Portal. After you register and log in, create your first Company and Tenant. The system assigns you the Super Administrator role for the Company you created. Next, invite users so they can access the tenant and/or help manage the Company.

## Sign Up for the OneSite Cloud Portal

1. Start by opening up the [Adaptiva Cloud Portal homepage](https://console.adaptiva.cloud/) in your preferred browser.

   ![](/files/i174wFf0wrPI8dMqoyXG)
2. Select **Sign Up** to create a request for your account. The **New User Request** dialog appears.

   ![](/files/gyGWNZ1meHf6KVylWpHb)
3. Enter your email address into the **Email** field, and then select **Sign Up** to create the request for your account. You will shortly receive an email from `twilio@adaptiva.com`, allowing you to register and activate your account to use on the OneSite Cloud Portal.

   You must use a corporate email account. No public domains are allowed (such as, gmail.com, hotmail.com, outlook.com, etc.).

## Register Your OneSite Cloud Portal User Account

Twilio sends an email to users who either self-register or receive an invitation from an Administrator. The email contains a link to the **Register New User** dialog, where users complete their registration. For invited users, the email also includes a second link to activate the registered account with the company.

{% hint style="info" %}
You can use the invite for 24 hours after we send this email.
{% endhint %}

1. Navigate to your inbox, locate the email `twilio@adaptiva.com`, and then select the first link in the email to register your user account.
2. The **Register New User** dialog appears.

   ![](/files/zoTURtWqRYtD9NFfnLvC)
3. Select the **Admin Type** login from the list. You can choose from the following login options:
   * **Adaptiva:**
     * Enter an email address, and password (password parameters can be found by clicking the information tooltip). Enter password again to confirm.
   * **OIDC Provider:**
     * Select the provider as directed by your Company Administrator. If you are currently not logged in with that provider you will be prompted to log in.
4. Enter your **First Name** and **Last Name** in the respective fields.
5. Enter the following contact details (optional) into the respective fields:
   * Daytime phone number
   * After-hours phone number
   * Text Message phone number
   * WhatsApp phone number
   * Teams Webhook URL

{% hint style="info" %}
For more information on the Teams Webhook URL, review the [Generating a Microsoft Teams Webhook URL](https://support.adaptiva.com/hc/en-us/articles/36076277883149-Generating-a-Microsoft-Teams-Webhook-URL) KB article.
{% endhint %}

1. Select **Register** to create your account.
2. You will now be directed to the Adaptiva Cloud Portal to continue setup.

   ![](/files/fC6UeEeQVnSM7nyiILjF)


# Log in to Cloud Portal

Log in to the OneSite Cloud Portal using a native-login or OIDC-enabled account. You may also set up MFA with an authenticator app on your mobile device to add an extra authentication layer. This is setup after the initial login.

## Log in to the OneSite Cloud Portal

1. Log in to the OneSite Cloud Portal using one of the following options depending on your account type:

   ![](/files/OcLD2GhQly4yVnTSBZRe)

   a. Log in with your email using the following steps:

   1. Enter your Email address and Password to login using your activated Adaptiva account.

      You can check the box to remember the email address when you return to this web page.
   2. If your account is configured to use MFA the **Multi-Factor Authentication** dialog will appear.

   ![](/files/PRDeObC4bd6Dj7n3N1f6)

   1. Enter the code provided by the authenticator app on your mobile device into the field.
   2. After the authentication process completes, the system logs you into the OneSite Cloud Portal.

   b. Select **Log in with \<Provider>** if your account has been set up using an OIDC Admin type.

   If you have not signed into your provider yet, the system will prompt you to complete the authentication.


# Companies

After signing into your Cloud Portal account, you can create a Company on the **Welcome to the Adaptiva Cloud** page to get started.

A company can manage their own Adaptiva products, or may have a Managed Service Provider (MSP) managing multiple companies. In either scenario, a new Super Administrator can create a unique Company on Adaptiva Cloud that can have up to three [Tenants](/cloud/configuration/create-tenant) per Company. There is not a limit on the amount of Companies you can create.

The My Companies section of the main dashboard upon initial sign-in, allow Super Administrators to manage Company associated Super Administrators and Administrators along with associated Tenants.

## Create a Company

1. Select **Go to Cloud Portal**.

   ![Go to Cloud Portal button.](/files/3VvYThCZpGcQmMEl5WIX)

   The **OneSite Cloud Portal Home** page will appear.
2. Select **Create Company** to create your first Company or select **+ New Company** to create additional Companies.

   The **Create Company** dialog appears.

   ![Create company overlay highlighting Company Metadata settings.](/files/3yTmKScAmHDNwNqCI06j)
3. Enter the following company details into the respective fields under **Company Metadata** on the **Create Company** dialog:
   * **Company Name:** The name of the Company.
   * **Subdomain:** Constructs the company URL and appends .adaptiva.cloud to the subdomain entered. The subdomain cannot be changed after you save.

     The subdomain must follow these specific requirements:

     * Starts with a letter
     * Lowercase alphanumeric
     * Between 1-30 characters
   * **Description:** Describes the Company.
   * **Employee Count:** The number of employees associated with the Company.
   * **Postal Code:** The five-digit numeric code associated with the postal delivery area where the Company is located.
   * **State / Region / Province:** The administrative division within a Country where the Company is located.
   * **Country:** The self-governing territory where the Company is located.
4. Select **Save** to create the company. You will then be directed to the Manage Company screen.

   ![Company details and administrators on the manage company page.](/files/T0FyAoVPyUJl6MGceYro)

   After creating your Company, you will receive a confirmation email from `twilio@adaptiva.com`. You can now continue steps for [creating Tenants](/cloud/configuration/create-tenant).

   ![Company creation email notification example.](/files/siFAB5G6Ti7wVHMIsJY0)

## My Companies section

Create, Manage, or delete companies under **My Companies** on the **Home** page, depending on the permissions assigned to you.

![My companies section example.](/files/fpggSwGmZiPRUtEUyQCO)

To manage a Company, select **Manage** on the appropriate Company.

### Edit the Company Details

![](/files/LJPcfk1HLITDKQ8cv31f)

1. Select ![Pencil icon for editing company details.](/files/IDDg4JjhoHOcRnlKqXeI) next to the field to make the necessary edits to the following Company information on the **Company** page:

   * Company name
   * Company description

   **Company Details**:

   * Employee count
   * Postal code
   * State, region, or province
   * Country

### Delete a Company

1. Select **Delete Company** under **Company Details** on the **Company** page.

   ![Delete company button.](/files/rzeM5y2LXDkZGNTVdWJR)
2. Select **OK** on the **Schedule deletion for...** dialog to schedule the deletion of the Company.
3. (Optional) Select the **Export Logs** button in the top right of the Schedule deletion window. This will automatically download an `adaptiva_web_logs` file and save it to your Downloads folder by default.

   * This log file documents actions performed and errors for your company.

   ![Export logs button](/files/J6iPftH87pSrTwBjQTKN)
4. The Company will be deleted 90 days from the date and time the deletion was requested.

After deleting your Company, you will receive an email from `twilio@adaptiva.com` confirming the deletion request. You will also receive periodic reminder emails that your company will be deleted in case you would like to cancel your deletion request.

#### Cancel Deletion Request

* Select **Cancel Deletion Request** under **Company Details** on the **Company** page.

  ![Cancel deletion button.](/files/arEFcxaO9TwNnuWKhwqW)
* The **Cancel Deletion Request** option no longer appears on the **Company Details** section.

After canceling the deletion of your Company, you will receive an email from `twilio@adaptiva.com` confirming the cancellation request.


# Tenants

Create and manage new SaaS tenants in the Cloud Portal.

Each Company will have at least one Tenant, up to three total. A Tenant is the instance of your Adaptiva Cloud product. After setting up and connecting a Tenant, an Admin can download client installers, view and interact with real-time dashboards, create workflows, etc.

Create a new Tenant within the Company you created, either under **My Tenants** on the **OneSite Cloud Portal Home** page or the **Tenants** tab of the **Company** page.

## Create a Tenant

1. Select **+ New Tenant** on the **Tenants** tab on the **Company** page.

   ![](/files/GkjRTIZnKQfTWHAYP6qx)
2. Enter the desired **Name** and **Description** in the respective fields under **General Settings** on the **Create Company Tenant Configuration** dialog.

   ![](/files/4jCM5gPImmbzyZfQXSFB)
3. Enter the desired **Subdomain** in the respective field. For example, `cloudpatch` creates the URL `cloudpatch-company.adaptiva.cloud`.

   The system combines the Tenant subdomain with the Company subdomain to create the Tenant portal URL. The subdomain must follow specific requirements:

   * Starts with a letter
   * Lowercase alphanumeric
   * Between 1-30 characters
4. Configure the **Creation Settings** using the following steps:

   ![](/files/p7vPNtvLAdXw3dn1vEDM)

   a. Select **Browse** next to **Initial Administrators**.

   b. Select the desired **Administrator** from the **All Administrators** list.

   c. Select **OK** to return to the **Create Company Tenant Configuration** dialog.

   ![](/files/gUxrHjiebFWuNGuI6mrn)

   The administrator appears in the **Initial Administrators** list under **Creation Settings**.

   d. (Optional) Enter a product license key into the **Initial License** field, and then select **+Save License Key** to add it to the Tenant. Add additional license keys, as necessary.
5. Select the desired region from the **Tenant Region** dropdown list under **Regioning**.

   ![](/files/NcM6HwOtM3Qi4WoKv221)
6. Configure the settings under **Scheduling Settings**:

   ![](/files/ULQnoQggM3akdgKqxRJV)

   a. Set the Maintenance Schedule for when the Tenant may be taken offline for maintenance. A one-hour window is assigned to your Tenant. Set the schedule using the following steps:

   1. Select the day from the dropdown menu.
   2. Select ![](/files/IQCuDugwV8tHvhAq1GWP), and then select the desired time from the dialog.
   3. Select the desired time zone from the dropdown menu.

   b. Set the Backup Schedule time using the following steps:

   1. Select ![](/files/IQCuDugwV8tHvhAq1GWP), and then select the desired time from the dialog.
   2. Select the desired time zone from the dropdown menu.

{% hint style="info" %}
The time you select for the Maintenance Schedule must fall between 9:00 AM - 9:00 PM US/Pacific time.
{% endhint %}

1. Select **Save** at the upper-left of the **Create Company Tenant Configuration** dialog.

   ![](/files/PNvDMGWFotYFoOb27z8t)

   The system may take several minutes to create your Tenant. When it is ready, you will receive an email from `twilio@adaptiva.com` confirming that the Tenant is available for use.

   ![](/files/9CUP7qoKcXaccsJ9CJV8)

### Provisioning States

A Tenant appears under **My Tenants** with a Provisioning State icon. The following icons indicate the provisioning state of the Tenant:

* **Setup**: This icon (![](/files/9KvS4Gcnow0WK5NBNZgl)) indicates that the system is setting up the new Tenant.
* **Active**: This icon ( ![](/files/Gk6CSZqQFax3kf2vvOHx)) indicates that the Tenant is active.
* **Disabled**: This icon (![](/files/FyR2pZgZZdg65CMcEDPE)) indicates that the Tenant is disabled.

## Manage your Tenant

Once you have created your Tenant, you can manage your Tenant settings from the Cloud Portal at any time.

1. Click **Manage** under your Tenant from the Home page on the Cloud Portal.

   ![](/files/X6TugTM3GqUZNyi8jBeO)
2. This will display your configurations made during creating a new Tenant. You can alter the following settings:

   * Tenant Name
   * Tenant Description
   * Tenant Region
   * Scheduling Settings

   ![](/files/ZlMKUM255HXrMVkfhXie)

Super Administrators and Administrators can be managed in their respective tabs. You can add or remove users from either user type. For more information about user roles, please see our [Administrator Roles](/cloud/user-management/roles-responsibilities) page.

### Client Authorization

Additionally, you can download cross-platform Tenant client files and **Reset Client Authorization Tokens**.

{% hint style="danger" %}
Resetting Client Authorization Tokens will require ALL existing clients to redownload their client files.
{% endhint %}

## Connect to Your Tenant

Connect to your Tenant using the following steps:

1. Select ![Connect button](/files/5yDKZcjIcY15orDKygZT) **Connect** on the **Company** page. You can also connect via the **Tenant** page at the upper-right corner, or on the main landing page when first signing in.

   ![](/files/SzNZ8Vg7YQqeXxtNtGyw)
2. The **Adaptiva Admin Portal** will appear indicating your Tenant has successfully been connected. For further instructions on how to

   ![](/files/cf1vWbyHsKpelaW2zd18)

{% hint style="warning" %}
After seven days of inactivity, you will receive an email from `twilio@adaptiva.com` notifying you of the inactivity. The Tenant will be disabled after being inactive for 30 days. At 90 days of inactivity, the Tenant is automatically deleted.

Open a ticket with [Adaptiva Support](https://github.com/AdaptivaDocs/docs/tree/main/cloud/support.adaptiva.com) for help with enabling the Tenant before it is deleted.
{% endhint %}

## Downloading the Adaptiva Client

Download the installation file (![Download](/files/PYWAFlx56WnvIn1d9pLB)) next to the desired OS option under **Tenant Client Downloads**. For more information on downloading and installing the Adaptiva Client for Linux, macOS, or Windows, see [SaaS Client Installation](https://docs.adaptiva.com/platform-install/client-install-and-uninstall/client-install/client-install-saas).

### Reset the Client Authorization Token

You can reset the Client Authorization Token in the cloud portal.

1. Select **Reset Client Authorization Token** under **Tenant Client Downloads** on the **Tenants** page.

   ![](/files/VCWcAS0oIjDFQr3zhROz)

   The new token appears on the **Reset Client Authorization Token** dialog:

   ![](/files/sccngyLAuGUWq8GD75qb)
2. (Optional) Select **Regenerate Token** to create a different token or enter your own token.
3. The token must be an alphanumeric string between 8-64 characters.
4. Select **OK** to return to the **Tenant** page.

{% hint style="warning" %}
Client authorization tokens are now replaced in the client installers. Existing clients will continue working. However, new installations require the updated installer to facilitate handshaking with the Tenant server. Download new installers after changing the Authorization token and delete any previously downloaded files.
{% endhint %}

## My Tenants Section

Create, connect, manage, or delete tenants under **My Tenants** on the **Home** page, depending on the permissions assigned to you.

![](/files/CppT1UsczlnRwig5SV3k)

To manage a tenant, select **Manage** on the appropriate tenant.

### Scheduling Settings

Set the maintenance schedule for upgrading the Tenant, and the backup schedule under **Scheduling Settings** on the **Tenant** page.

![](/files/dHUIV4mw6MKbKAaN4h57)

### Delete a Tenant

1. Select ![](/files/EjMUFnCqwz1vi2hwDFRo) **Delete Tenant** on the upper-right of the **Tenant** page or on the **Home** page under **My Tenants**.

   ![](/files/ibwnoATmMTl0Y6oyyKtO)

   ![](/files/pEVfQKSWjvojDm3CQzJe)

   The **Schedule deletion for <...>** dialog appears:

   ![](/files/44dbAaqBCEjkmL7UDnXw)
2. (Optional) Select the Export Logs button in the top right of the Schedule deletion window. This will automatically download a .log file to your Downloads folder by default.

   ![](/files/qvQ22bmKdEC1B67yR4N5)
3. Select **OK** to schedule the deletion of the Tenant.

   Tenants will automatically be deleted 90 days after the request. You will receive an email from `twilio@adaptiva.com` confirming that the Tenant was deleted.

#### Cancel Tenant Deletion

Select ![](/files/EjMUFnCqwz1vi2hwDFRo) **Cancel Deletion Request** on the upper-right of the **Tenants** page to cancel the Tenant deletion request or from the **My Tenants** section of the **Home** page.

![](/files/cHuwWATsWTVRqTyAZyB0)

![](/files/9b7eYWplAOLanRAwqK8H)

You will receive an email from `twilio@adaptiva.com` acknowledging the cancellation of the Tenant deletion request.

## Update Tenants to latest version

By default, updates are sent from Adaptiva automatically to the your Cloud Portal Tenants. Your Tenant will update to the latest version during your defined Maintenance Schedule. If you are in an active session, you will see a banner request to refresh the page so you can view the latest released version. This will also automatically trigger the new version to be deployed to your clients.

### Pause Upgrades

You can toggle the **Upgrades Paused** setting to pause automatic upgrades on the tenant for cases such as change freezes. When toggled ON, the tenant will not be upgraded automatically when Adaptiva releases a new software version. When toggled OFF, automatic upgrades of the tenant will occur during the Maintenance Schedule set in **Scheduling Settings**. This setting is off by default.

It is important to understand that NO updates will happen during a pause, including any bug resolution or platform fixes. Client versioning will also be paused.

### Client Upgrades

If your Client Upgrade settings are set to **Deploy Immediately**, tenant updates will reset to the default **Deploy in scheduled wave (default)** of 7 days.

![](/files/cx28D9BQbdY1ZtHtBN1U)

You can choose to update the Client Upgrade settings to more aggressively rollout new client versions.


# Manage Account

How to manage your Cloud Portal account.

Manage your user account details, change your password, or delete your account by navigating to ![](/files/aIeyrz1FbdT6k80WNMQZ) **| Manage Account** page.

## Update User Information

1. Select ![](/files/aIeyrz1FbdT6k80WNMQZ) on the upper-right of the **Home** page, and then select **Manage Account** on the dialog that appears.

   ![](/files/0wbI2knOGytW16DQipFJ)
2. Make the desired updates to the fields below, and then select **OK** to save your changes.

   ![](/files/ZoweywAmmYc6g389N1vN)

* **First Name**
* **Last Name**
* *(Optional)* **Voice Phone Number** - How to contact your Administrator during business hours.
* *(Optional)* **After Office Phone Number** - How to contact your Administrator after hours.
* *(Optional)* **Text Message Phone Number** - Receive text message notifications based on Communication Provider settings.
* *(Optional)* **WhatsApp Phone Number** - Receive WhatsApp message notifications based on Communication Provider settings.
* *(Optional)* **Teams Webhook URL** - Receive Teams message notifications based on Communication Provider settings.

For more information regarding notifications, please see our [Communication Providers](https://docs.adaptiva.com/patch/advanced-settings/communication-providers) page.

## Change Your Password

1. Select ![](/files/s4BSVfXUkyu86lffzESY) **Change Password** on the **Manage Account** page. The **Change Password** dialog appears.

   ![](/files/AQPnPhIBuYIo5C2byFRR)
2. Enter the new password in the **Enter New Password** field.
3. Re-enter the new password into the **Confirm Password** field.
4. Select **OK** to return to the **Manage Account** dialog.

## Set up MFA

1. Select ![](/files/WRuCsr5usQ2NH7Mo1sHl) **Set up MFA** on the **Manage Account** dialog. The **Multi-factor Authentication Setup** dialog appears. MFA is only available with native-logins.
2. Set up MFA using one of the following options:

   a. Scan the QR code with the authenticator app on your mobile device on the **QR Code** tab.

   ![](/files/AGcrEnZUg2zFvVnCxNUl)

   * Enter the authentication code from your authenticator app into the field to complete setup.

   b. Copy the authentication secret on the **Authentication Secret** tab.

   1. Use the authentication secret to register a new account with your authentication app.
   2. Enter the authentication code from your authenticator app into the field to complete setup.

   ![](/files/ya1TAw1eCAJg4RUVZEBd)

## Delete Your Account

1. Select ![](/files/C3bZ61DINkSXrqVV62ve) **Delete Account** on the **Manage Account** dialog to delete your account. The **Are you sure?** dialog appears.

   ![](/files/2SDFggpXfXVsH24og3Rg)
2. (Optional) Select the Export Logs button, this will automatically save a .log file to your Downloads folder by default.

   ![](/files/tiOiM5QSu6TEf290rk8Y)
3. Select **OK** to confirm the account deletion.

## Related pages

### [Communication Providers](https://docs.adaptiva.com/patch/advanced-settings/communication-providers)

### [Configure SMTP Settings](https://docs.adaptiva.com/platform-guide/additional-settings/smtp-settings)


# Administrator Roles

Administrator Roles and Responsibilities

Review the user roles and responsibilities in this section to understand each role before assigning it to users.

## Cloud User Role

Each user who signs up for the OneSite Cloud Portal is automatically assigned this role along with any invited users.

{% hint style="info" %}
Invited Users to a Company or Tenant also have the ability to create their own Companies and Tenants exclusive to the Company or Tenants they were invited to.
{% endhint %}

### User Permissions

The User role allows the user to do the following tasks:

* Sign in to the OneSite Cloud Portal
* Create a company

## Users

To see list of Users in your Company or Tenants:

1. Select the cog icon in the upper right corner of the top navigation bar and select Settings > Security > Administrators.

   ![](/files/7GFcqptOLJ7BnGL4JY2h)
2. From here you can make edits to your own account and see References of other Users.

   ![](/files/JskX9xyqN4gtZjpMjcYE)

### References

The References dialog will display Company or its Tenants to which the User has been assigned.

1. To see References of other users select References from the more option drop down.

   ![](/files/FxqSDhph8H5vw4ad7HJY)
2. The References dialog will be displayed.

   ![](/files/wEULq8aP75IMAMew9PiV)

## Administrator Roles

The following roles and permissions are available in the OneSite Cloud Portal:

* **Company Super Administrator:** The Super Admin for the Company to which they are assigned.
* **Company Administrator:** The Administrator for the Company to which they are assigned.
* **Tenant Super Administrator:** The Super Admin for the Tenant to which they are assigned.
* **Tenant Administrator:** The Administrator for the Tenant to which they are assigned.

### Company Super Administrator Role

The Company Super Administrator role is automatically assigned to the user who creates the company. Invited users can also be added to this role.

#### Company Super Administrator Permissions

The Company Super Administrator role allows the user to do the following tasks within their assigned Company:

* Create multiple Companies
* Create up to 3 Tenants per Company.
* Edit Company details
* Delete the Company
* Invite users to the Company or any of its Tenants.
* Assign or remove the Company Super Admin role for other users
* Assign or remove the Company Admin role
* Assign or remove the Tenant Super Admin role or the Tenant Admin role
* Delete any Tenant

### Company Administrator Role

Users can be assigned or invited to a Company Administrator role.

#### Company Administrator Permissions

The Company Administrator role allows the user to do the following tasks within their assigned company:

* Manage the Company.
* [Invite users to the Company](/cloud/user-management/invite-users#invite-users-to-a-company).
* [Invite users to a Tenant](/cloud/user-management/invite-users#invite-users-to-a-tenant).
* Create, modify, or delete Tenants.

### Tenant Super Administrator Role

Users can be assigned or invited to the Tenant Super Administrator role.

#### Tenant Super Administrator Permissions

The Tenant Super Administrator role allows the user to do the following tasks within their assigned Tenant:

* Access the Tenant.
* Invite users to a Tenant and assign either the Tenant Super Admin role or the Tenant Admin role.
* Invite users to a Tenant and assign either the Tenant Super Admin role or the Tenant Admin role.

### Tenant Administrator Role

The Tenant Super Administrator assigns or invites user to this role within the Tenant to which they are assigned.

#### Tenant Administrator Permissions

The Tenant Administrators are added to the All Admin role on the tenant. The Tenant Super Administrator can add the user to additional roles on the Tenant. The Tenant Administrator role allows the user to do the following tasks within their assigned Tenant:

* Access the Tenant
* [Download clients](/cloud/configuration/create-tenant#downloading-the-adaptiva-client)


# Invite Users

How to invite and register users on the OneSite Cloud Portal.

Any Company Administrator or Tenant Super Administrator can invite users to a company or tenant, and assign the appropriate role.

After a User has been invited they will receive an email from `twilio@adaptiva.com` with two links. The first link allows users to register to the OneSite Cloud Portal. Once the user creates their account, they can return to the invite email and select the second link, which presents the login page, allowing the user to log in to the OneSite Cloud Portal and activate their account with the Tenant.

![](/files/tcVTofsvb4IiTmmtVF0U)

Follow the steps below for the Administrator or for the invited user to complete this process.

## Invite Users to a Company or Tenant

1. Select **Invite User** on the upper-right of the **Company** or **Tenant** page.

   ![](/files/QpElfA0kf1XPRL3nFPUB)
2. Enter the **User email**.
   * You must use a corporate email account. No public domains are allowed (such as gmail.com, hotmail.com, outlook.com, etc.).
3. Select the **User Role** dropdown menu, and then select either the Company Administrator role or the Company Super Administrator role to assign to the invited user.

   ![](/files/3ZQppBPdzVffGXjA0GdN)
4. Select **OK** to send the invite.

## Register New User

Once a user has received a invite notification email and clicked the register link they will need to fill out the **Register New User** form with their credentials.

![](/files/qXIKqWTcCGIln7x8nTCr)

By default, your account is created as an Adaptiva account type, which uses a separate password and does not support Single Sign-On (SSO).

1. As a new user, select the first link from the Twilio invite email to open the **Register New User** page.
2. Select **Adaptiva** from the **Admin Type** dropdown and enter:

   * **Email Address** - You must use a corporate email account. No public domains are allowed (such as, gmail.com, hotmail.com, outlook.com, etc.).
   * **Password** - Strong passwords are enforced for Adaptiva accounts; the password must be at least 10 characters long and contain at least one digit, an uppercase letter, and a lowercase letter.
   * **First Name** and **Last Name**

   ![](/files/tD4Kkd9siXmPgcOsxbH8)
3. Fill out any optional information and click **Register**.
4. Go back to the email notification and select the second link to gain access to the Company or Tenant you were invited to.

## Invite Users with Entra ID

The Admin Portal is intended for administrator use and may require a separate account from your regular company credentials. If your organization uses Microsoft Entra ID and you want to enable SSO, follow the steps below.

### Registering as a brand new user

Once you have received an invite link for a Company or Tenant, you can register in the same way as you would with your Adaptiva credentials above, but will need to change the following options.

1. Change **Admin Type** to **OpenID Connect** from the dropdown and click on the **Sign up with Microsoft** button.

   ![](/files/tD4Kkd9siXmPgcOsxbH8)
2. Fill out the remaining required information along with any optional information and click **Register**.
3. Go back to the email notification and select the second link to gain access to the Company or Tenant you were invited to.

### Change an existing user to use their Entra ID

If you previously registered your account with Adaptiva credentials, you can switch to use your Entra login by changing the **Admin Type** from **Adaptiva** to **OpenID Connect** **Admin Type** and this will prompt you to register again.

{% hint style="info" %}
You can only change your own account, any other admin does not have write access to your account.
{% endhint %}

1. Log into the Cloud Portal with your Adaptiva credentials.
2. Click the **settings gear > Settings > Security > Administrators** from the top right of the Cloud Portal pane.

   ![](/files/p2GsKCo5eKgcC5PAKp3J)
3. Select the existing registered Admin.
4. Change the **Admin Type** to **OpenID Connect** from the **Admin Type** dropdown and select **Microsoft** from the **Identity Provider** dropdown.
5. Click **Save**.
6. Click the **More** dropdown and select **Invite**.

   ![](/files/mkLMYBLwHF0K6nCjwqMk)

   * This will send an invite to your email. You will then need to accept this invitation to register a unique Subject ID with your User Account.
7. Log yourself out the Cloud Portal, then log back in by clicking **Log in with Microsoft**. This will open the **Register New User** pane where you will need to register again.

   ![](/files/CV6PHUTVnwWQLx25sAJQ)
8. Select **OpenID Connect** from the **Admin Type** dropdown and click on the **Sign up with Microsoft** button.
9. Click **Register**.

Once you have logged out again, your previous Adaptiva password will no longer work and you will be required to always sign in with Microsoft Entra.

### Switching back to Adaptiva credentials

{% hint style="info" %}
If using a SaaS version older than 10.1.972.x please reach out to our [Support Team](https://adaptiva.com/support) for assistance.
{% endhint %}

If you no longer wish to sign in via Entra, please walkthrough the steps below:

1. Click the **settings gear > Settings > Security > Administrators** from the top right of the Cloud Portal pane.

   ![](/files/p2GsKCo5eKgcC5PAKp3J)
2. Select you name from the table.
3. Select **Adaptiva** from the **Admin Type** dropdown.
4. Enter a password into the **Password** and **Confirm Password** fields.

   ![](/files/LKbci8uUwu6rwqa74F8Z)
5. Click **Save**.

Now you should be able to login with Adaptiva credentials the next time you log in.


# OneSite Patch overview

Configure your autonomous patch management solution

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-rocket">:rocket:</i></td><td><strong>Get started with autonomous patch management</strong></td><td>Use our guided walkthrough to get patching quickly.</td><td></td><td></td><td><a href="/pages/jFf1U6pWzXKYYuHq0hQa">/pages/jFf1U6pWzXKYYuHq0hQa</a></td></tr><tr><td><i class="fa-cubes">:cubes:</i></td><td><strong>Build Strategies for policy-driven automation</strong></td><td>Customize your patch strategy with deployment waves and approval workflows.</td><td></td><td></td><td><a href="/pages/bgxKLrPXEVrvd7GccIGW">/pages/bgxKLrPXEVrvd7GccIGW</a></td></tr><tr><td><i class="fa-plug">:plug:</i></td><td><strong>Manage your patch health in the operations dashboard</strong></td><td>Manage and operate your autonomous patching infrastructure.</td><td></td><td></td><td><a href="/pages/Q2xwwZUgI7Ao3scyyIpU">/pages/Q2xwwZUgI7Ao3scyyIpU</a></td></tr></tbody></table>

OneSite Patch by Adaptiva is an enterprise-grade, autonomous patch management solution designed to streamline and secure endpoint update processes across diverse environments. It enables IT and security teams to automate patching workflows; reducing manual effort and maintaining compliance with minimal intervention.

![Patch Home Dashboard](/files/9hDWqcZFVMIDRhRyH8Va)

## Learn more about OneSite Patch

{% columns %}
{% column %}
Model your [Business Units](/patch/patching-fundamentals/business-units) with department-specific patching strategies, ensuring granular control and flexibility.
{% endcolumn %}

{% column %}
Configure [Communication Providers](/patch/advanced-settings/communication-providers) to notify your patch and security administrators of approvals and visibility, or escalate issues to the right people.
{% endcolumn %}

{% column %}
Seamlessly [integrate](/patch/integrations/integration-partners) with leading vulnerability management platforms for real-time threat detection and remediation.
{% endcolumn %}

{% column %}
Use fine-grained [Flex Controls](/patch/patching-fundamentals/flex-controls) of the autonomous patching process to block and rollback patch, or even pause all patching in your business.
{% endcolumn %}
{% endcolumns %}

### Learn more about the OneSite platform

{% columns %}
{% column %}
**Cross-Platform**: [Supports](https://docs.adaptiva.com/platform-install/overview/supported-systems) Windows, macOS, and Linux endpoints, ensuring comprehensive coverage across heterogeneous environments.
{% endcolumn %}

{% column %}
**Peer-to-Peer Content Distribution**: Utilizes Adaptiva’s proprietary [P2P](https://adaptiva.com/products/onesite-platform/features/p2p-architecture) algorithm to optimize bandwidth usage and accelerate delivery across distributed networks.
{% endcolumn %}

{% column %}
**Extensive Catalog**: Maintains an up-to-date [Patch Library](https://adaptiva.com/patch-library) covering over 20,000 products, including OS updates, third-party applications, drivers, BIOS, and firmware.
{% endcolumn %}

{% column %}
**Automated Testing and Publishing**: Adaptiva handles validation and packaging of all content, eliminating the need for manual patch preparation.
{% endcolumn %}
{% endcolumns %}


# OneSite Patch SaaS comparison

Guide to comparing OneSite Patch SaaS vs. OneSite Patch On-premises solutions.

Adaptiva offers both a self-hosted and a cloud-hosted (SaaS) model for OneSite Patch. This guide outlines key differences between the SaaS deployment and self-hosted versions.

## Advantages of SaaS deployment

* Fully managed SaaS deployment of OneSite Patch.
* Offloads infrastructure, updates, and database management to Adaptiva to manage.
* Does not require any additional hardware.
* Platform automatically scales.
* Deployments receive the latest features, security patches, and improvements automatically, with no manual intervention.
* Built-in redundancy and failover.

## Key Differences

| Topic                                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Object Handling and Workflow Execution      | <p>In OneSite Patch SaaS, server and business workflows are restricted to prevent changes to the shared environment.<br><br>These workflows must use already signed activities that Adaptiva has approved as secure.</p>                                                                                                                                                                                                                                                                                                                                                                                        |
| Custom Data Providers for Custom Dashboards | <p>Custom Data Providers cannot be created in the cloud environment.<br><br>Custom Dashboards can use existing Data Providers.<br><br>Subscriptions can be set up using existing Data Providers.</p>                                                                                                                                                                                                                                                                                                                                                                                                            |
| Content Distribution and Publication        | <p>Content distribution and publication is restricted to OneSite Patch content only.<br><br>All content required by the server is stored and managed on a secure storage container in the Adaptiva CDN.<br><br>Content distribution works the same in both cloud and self-hosted models.  Content is delivered through P2P methods, with fallback to the built-in CDN for Adaptiva. <br><br>Customers migrating to OneSite Patch SaaS will not be able to leverage Adaptiva content or ConfigMgr, Intune, or Workspace One content distribution and publication.<br><br>Adaptiva content cannot be created.</p> |
| Client Communication and Authentication     | <p>To ensure successful communication between clients and OneSite Patch SaaS, customers must enable outbound traffic to Adaptiva cloud URL's.<br><br>HTTP Proxy Configuration Allow outbound traffic to Adaptiva cloud URLs through any HTTPS proxies in your environment.<br><br>Firewall Settings: Open the necessary UDP ports in your firewalls to enable peer-to-peer content distribution between client devices. See Adaptiva Port Detail.</p>                                                                                                                                                           |
| Admin and Identity Management               | <p>SaaS customers manage all administrator accounts and usage of identity providers (OIDC, SAML ) through the OneSite Cloud Portal.<br><br>Administrator accounts can be assigned to roles within the tenant server.</p>                                                                                                                                                                                                                                                                                                                                                                                        |
| Support and Troubleshooting                 | <p>Customers cannot directly manage the tenant infrastructure in the OneSite Cloud Portal.<br><br>Common requests that require redirection or escalation include unsigned workflows, admin or identity configuration changes, missing content due to Adaptiva CDN publishing errors, or integration issues caused by restricted APIs.<br><br><strong>Note</strong>: Customers with complex RBAC setups may need specific adjustments.</p>                                                                                                                                                                       |
| Migrating to SaaS                           | <p>Migration from self-hosted to OneSite Patch SaaS requires coordination across teams to assess workflows, scripts, RBAC roles, and content delivery configurations.<br><br>Customers should consider the following when migrating to OneSite Patch SaaS: Intent objects will not be lost, but historical data will be lost.<br><br><strong>Note</strong>: The SaaS deployment automatically re-acquires the current state, and all dashboards will populate quickly with current data during the migration from Self-hosted to SaaS.</p>                                                                      |
| Locations in OneSite Patch Saas             | <p>OneSite Patch SaaS changes the way you create and manage Locations compared to a self-hosted environment.<br><br>For more information, see On-Premises Client Detection in OneSite Patch SaaS.</p>                                                                                                                                                                                                                                                                                                                                                                                                           |

## Settings in OneSite Patch SaaS

OneSite Patch SaaS has some removed settings along with new additions compared to OneSite Patch On-Premises. Please see our [Platform User Guide](https://docs.adaptiva.com/platform-guide) for more information regarding available settings.

![](/files/Axai6PdEuFaAZ1WdnV1j)

The following settings have been removed from OneSite Patch SaaS:

| Setting                                                                                    | Reason                                                                                                                                                                                                                                                                        |
| ------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Adaptiva Content Publication</strong><br><br><strong>Cloud Storage</strong></p> | Custom content is not supported in the SaaS environment.                                                                                                                                                                                                                      |
| **Client Authorization**                                                                   | <p>This is now managed by the Tenant.<br><br>For more information about managing Tenants, please see our <a href="https://docs.adaptiva.com/cloud/create-tenant">Set up Tenant</a> page.</p>                                                                                  |
| **Legacy Client Upgrade (Windows)**                                                        | <p>The Adaptiva Client Upgrade is now released automatically after the Tenant is upgraded.<br><br>For more information see: <a href="https://docs.adaptiva.com/platform-install/platform-upgrade/upgrade-platform#automatic-client-upgrade">Automatic Client Upgrade</a>.</p> |


# OneSite Patch SaaS FAQ

Frequently asked questions regarding OneSite Patch - SaaS.

## Overview

If you would like to know additional information about our SaaS solution please visit the following pages or contact our [Support team](https://github.com/AdaptivaDocs/docs/tree/main/patch/adaptiva.com/support/README.md):

<details>

<summary>Are all Adaptiva products available with a SaaS Deployment?</summary>

At this time, only OneSite Patch is available with a SaaS Deployment. Additional Adaptiva solutions may be added over time, based on demand and customer feedback.

</details>

<details>

<summary>How is content distributed in the cloud?</summary>

Content distribution works the same in both SaaS and self-hosted models. Content is delivered using Adaptiva’s unique peer-to-peer protocols with a backup to Adaptiva’s built-in CDN, which is automatically set up to ensure fast, reliable, and efficient delivery across your environment.

</details>

<details>

<summary>How do I manage my on-premises network topology with SaaS?</summary>

You can configure on-premises detection policies using criteria such as IP address ranges, DNS resolution, or ping response. This enables the platform to automatically differentiate between internal and external clients and adjust its behavior accordingly. The rest of the network topology remains the same, whether you're using a self-hosted or SaaS deployment. Even with the SaaS option, local peer-to-peer (P2P) content distribution is still fully supported— ensuring efficient delivery within your internal network.

</details>

<details>

<summary>How are administrator and user access managed?</summary>

In OneSite Patch - SaaS Deployment, all administrative accounts and identity providers (e.g., SAML, OIDC) are managed through the OneSite Cloud Portal. This centralized approach provides enhanced security and streamlines access control.

</details>

<details>

<summary>Can I use the same workflows or integrations from my self-hosted environment in a SaaS deployment?</summary>

Both versions contain the same workflow engine and activities. However, some server-side workflows may require updates to run in SaaS, especially if they rely on unsigned activities that aren't safe in shared SaaS environments.

</details>

<details>

<summary>What if I want to move from self-hosted to SaaS?</summary>

We’re here to help make the transition smooth and straightforward. Moving to the SaaS deployment involves reviewing your existing workflows, integrations, and configurations to ensure full compatibility. Our Solutions team will support you through every step of the process.

Here’s what to expect:

1. Start by contacting [Support](https://github.com/AdaptivaDocs/docs/tree/main/patch/adaptiva.com/support/README.md) – Our team will work with you to plan and execute the migration with minimal disruption.
2. Objects will not be lost.
3. Historical data will not migrate – However, your SaaS deployment will automatically re-acquire the current state, and all dashboards will quickly repopulate with up-to-date information.

</details>

<details>

<summary>Do all the vulnerability management integrations work with OneSite Patch - SaaS?</summary>

Yes, integrations with CrowdStrike Exposure Management, Tenable Patch Management, SentinelOne Singularity Platform and Windows Defender for Endpoint work with both SaaS and Self-Hosted deployments.

</details>

<details>

<summary>How is the SaaS environment secured?</summary>

Adaptiva OneSite Patch - SaaS is designed with robust security measures to protect customer data and operations. It is hosted in a secure, cloud-native environment. Adaptiva

is certified under **ISO/IEC 27001:2022**, an internationally recognized standard for information security management systems (ISMS). This certification ensures that Adaptiva has implemented rigorous controls for data confidentiality, integrity, and availability. Additionally, all communication between clients and the cloud server is encrypted via HTTPS, and only signed, Adaptiva-approved workflows are executed on the server to maintain trusted operations.

</details>

## Related pages

### [OneSite Patch SaaS comparison](/patch/overview/saas-comparison)


# Role-based Access Control

Role-based access control (RBAC) allows your organization to manage who has access to resources in OneSite Patch, what resources they have access to, and what they can do with these resources.

## Role-based Access Control (RBAC) in OneSite Patch

OneSite Patch has built-in roles you can use to provide permissions to your patching solution. For more information on the RBAC capabilities of the OneSite Platform see [RBAC](https://github.com/AdaptivaDocs/docs/tree/main/platform/user-guide/rbac.md)

RBAC allows you to:

* Assign permissions to specific job functions like operations
* Maintain data protection and regulatory compliance
* Protect sensitive data with the principle of least privilege
* Create branch office administrators for specific business units

## Explore the security roles

1. Log in to the Adaptiva Admin Portal.
2. Click the **gear icon > Settings > Security > Roles**.
3. On the Roles page, select the **Patch Roles** folder.

### Built-in roles for Patch

There are 4 built-in roles for OneSite Patch. These roles cover the most common use cases, though custom roles can be added as needed. These roles will be automatically created when you add a OneSite Patch license.

**Patch Super Administrator**: This role gives users full permission to OneSite Patch. This role is typically your IT solutions administrator.

**Patch Architect**: This role is focused on design, architecture, and implementation of the patching solution. For example, the architect can configure custom integrations but can't submit patches to a strategy.

* Full permission on all intent schema objects
* Read permission on all Flex Controls
* Full permission on Integrations
* Read permission on all dashboards

**Patch Operator**: This role is focused on the day to day running of the patching solution. For example, the operator can submit patches to a patching strategy. This role is typically your day-to-day IT Operations staff.

* Read permission for all intent schema objects
* Full permissions for Flex Controls
* Read permissions to all patching dashboards
* Additional permissions:
  * Submit patches to strategy
  * Submit patches to deployment channel
  * Submit patches to business unit

**Patch Reviewer**: This role is focused on observing the patching solution without access to any controls. For example, the reviewer can view patching strategies but can’t submit patches to a strategy.

* Read permission to all intent schema objects
* Read permission to Flex Controls
* Permission for all patching dashboards

### Branch administrator role

OneSite Patch allows you to create a branch administrator role that has full permission to OneSite Patch, but scoped to a specific Business Unit(s). The branch administrator has full control on all components within the scope of their business unit, but no class level permissions to objects outside of their scope. This branch administrator role is created dynamically in the Business Unit settings.

**Patch Branch Administrator**: this role gives users full permission to all OneSite Patch components, scoped to one or more business units. For example, a Seattle HQ branch administrator can create a patching strategy for the Seattle HQ business unit, but not for any other business unit.

## View a role and assign members to it

You can view the permissions and membership of a role in the role details.

1. Select a Patch role to open the properties page. You can view the role assignments and permissions detail for the role.
2. Under Direct Administrators, click **Browse** and select a user to associate with this role and click **OK**.
3. Click **Save**.

## Role permission details

The following specialty permissions and flex control permissions were created to enable role-based access control.

**Specialty permissions**

To enable role-based access control, new specialty permissions were created for the highest-level components in OneSite Patch:

* **Strategy**: submit patches to a strategy, view/manage pause/resume operations, view/manage patching cycles, add/remove patches to cycle, scan for patches, reset deployment failures.
* **Deployment Channel**: pause/resume operations, view/manage cycles, add/remove patches to cycle.
* **Business Unit**: add to deployment waves, add to bot runtime, view dashboards, pause/resume operations, view/manage rollback, view/manage patch exceptions, view/manage rollout cycles, add/remove patches to cycle, scan for patches, reset deployment failures.
* **Deployment Waves**: add to patching strategy, add to deployment channel

**Flex control permissions**

* **Pause/resume**: View pause/resume operations, Manage pause/resume operations
* **Rollback**: view and manage rollback operations
* **Patching exceptions**: View and manage patching exception operations
* **Patching cycles**: View and manage patching cycles, add/remove patches to/form patching cycles
* **Deployment channel cycles**: View and manage deployment channel cycles, add/remove patches to/from deployment channel cycles
* **Business unit rollout cycles**: View and manage business unit rollout cycles, add/remove patches to/form business unit rollout cycles
* **Patches**: scan for patches, reset deployment failures for patches

If an administrator has been granted any of these permission, they can perform these operations anywhere they want unless they are scoped to a specific object.

## Next steps

* [Create a branch office administrator](/patch/security-and-access-control/branch-admin)


# Create Branch Office Admin

How to create a Branch Administrator role for specified Business Units within OneSite Patch.

You can create a branch administrator role that has permissions scoped to a specific Business Unit(s). A user with this role has full control over components within the scope of their Business Unit, but no class level permissions to objects outside of their scope. The Branch Administrator role is created dynamically from a Business Unit by an administrator.

* **Patch Enterprise Branch Administrator**: this role gives users full permission to OneSite Patch, scoped to one or more Business Units. For example, a Seattle HQ branch administrator can create a patching strategy for the Seattle HQ Business Unit, but not for any other Business Unit.

## Create a branch administrator role

Complete to following to create a new branch administrator role.

1. In the left-hand navigation pane, click **Asset Management > Business Units**.
2. Next to your Business Unit, click the **ellipsis (...)** and then click **Create Branch Administrator**.

   ![Create Branch Administrator](/files/4Z3cgW0LalmEFDdnGhdK)
3. On the Create Branch Administrator page, give the account a name.

   ![Configure Branch Administrator](/files/pkzfTSWMaeS8HAj3solh)
4. The Business Unit is scoped to your previous selection.
5. Click **OK**.
6. Click **Settings > Security > Roles**, and in the page click the **Branch Administrator Roles** folder.

   The new branch administrator role is created in the Branch Administrator Roles folder, under Patch Enterprise Roles.

   The role has no class level permissions for features in OneSite Patch. All permissions for the role are scoped to a folder under the intent objects. ![Roles](/files/0OJRH7s6cP9v3kTsyLeE)
7. Select the new branch administrator role to open the properties page.
8. Under Direct Administrators, click **Browse**, select a user to associate with this role, and click **OK**.

   ![Add User to Role](/files/RSIqeQbpeNlXiHzWwCbu)
9. Click **Save**.

## View components scoped to the branch administrator

Administrators with the branch administrator role will have full access only to objects scoped to their role. These objects are all organized in a folder for each Patch feature. For example, view the dedicated folder for the branch admin role in Patching Strategies.

1. In the left-hand navigation pane, click **Strategies**.
2. Under Patching Strategies is a new folder named **Branch : %role name% : PatchingStrategy**.

   ![View objects](/files/yMFU4j31InqkrttUQtfD)

The branch administrator will only have full access to the patching strategies in this folder.

## View the branch admin permissions in Permissions Viewer

You can view the limited scope of a branch administrator's permissions using the Permissions Viewer.

1. Click **Settings > Security > Permissions Viewer**.
2. Next to Role, click **Browse**.
3. Select the branch administrator role and click **OK**.
4. Under Object Scope, type and then select **PatchingStrategy**.

   In the Resultant Permissions pane, you can see that the branch administrator role does not have permissions on the **PatchingStrategy** class.
5. Next to Folder, click **Browse**.
6. Select the folder named **Branch : %role name% : PatchingStrategy** and click **OK**.

In the Resultant Permissions pane, you can see that the branch administrator has full permissions on the **PatchingStrategy** class within the scope of the folder.

![View Role Permissions](/files/46D32DMCdeWfPLOsr6yG)

In the Resultant Permissions pane, you can see that the branch administrator has full permissions on the **PatchingStrategy** class within the scope of the folder.


# Getting Started

OneSite Patch allows you to configure the distribution of your patches via Strategies, Business Units, and Deployments.

Business Units are specific groups of devices you wish to apply patches, and Deployments manage the process of actually applying patches.

Beginning with version `10.0`, there is a guided walkthrough to get you started creating Strategies and managing your Business Units. This walkthrough is intended to get you up and running in the least amount of time with a 'set-it-and-forget-it' approach.

![](/files/3RHWMNVsrNICTDzGYHXf)

## Walkthrough tasks

The walkthrough will guide you through specific step-by-step tasks in order for you to:

* Add Devices
  * Add devices by installing the Adaptiva client.
* Verify Your Devices
  * Verify your devices have successfully communicated with your server and have been added to either your Central Location or an Auto-generated Location.
* Manage Business Units
  * Group your devices into separate Business Units within your Locations.
* Create and Run a Strategy
  * Create a new Strategy to fit your patching needs.
* Deployments Dashboard
  * Monitor and manage the progress of your patch deployments.

### Re-enabling the walkthrough

When you have completed all of the tasks, you can either close the walkthrough, or select **Dismiss Forever**. If you select **Dismiss Forever**, this will also remove the **Get Started** button from the side navigation.

If, however, you want to revisit the **Get Started** walkthrough you can re-enable it with the following steps:

1. Select the profile icon from the top right of the pane and **Manage Account**.
2. Toggle **ON** the **OneSite Patch: General** in the **Onboarding section**.

   ![](/files/gQi4IKPLs4QTcBoeZCo3)

## Related pages

[Dashboards](/patch/get-started/dashboards)


# Strategies

How to create, edit, run, and monitor Strategies in OneSite Patch.

Strategies are a critical step in designing your system that defines *What*, *When*, and *How* to implement your patching.

## Create a Strategy in v10.0+

In OneSite Patch, creating new patching strategies is comprised of four simple steps:

1. **Overview** - Enter a **Name**, **Description**, and **Enable** the Strategy.
2. **What to Patch** - Include all the Products you'd like to patch and filter patches as necessary.
3. **When to Patch** - Set a schedule for when you'd like your Strategy to run. Strategies are run on the server, and use the timezone that is set in the server settings.
4. **How to Patch** - Set up how you'd like to patch to specific Business Units and add Transitions that let you control the behavior of how the strategy is executed and how patches are deployed.

{% hint style="info" %}
Since Strategies run on the server, make sure that you are aware of what time zone the server is using.

For SaaS installations, if the server time zone has not explicitly been set then its value will be **Default Time Zone**, which is **UTC+0**.

On premises installations use the local time zone of the device it is installed on.

You can check the server time zone setting by clicking on the gear icon in the upper right and selecting **settings > about**.
{% endhint %}

Below is an example that incorporates several features of the new Strategy configuration with a staged approach to ensure successful deployment for pilot to production devices. This is a common use case that you will likely want to implement in your own environment. For descriptions of each section, please see our [Deployment Plan Details](#deployment-plan-details) section below.

### Navigation

1. Click **Strategies** from the side bar navigation.
2. Click **New Strategy**.

### Overview

1. Enter a **Name** and an optional **Description**.
2. Toggle **ON** Strategy Enabled.

   ![](/files/ACPrJY4FtJVjK7cpDVLB)

### What to patch

1. Toggle **ON** Include All Products or choose individual products.
2. Click **OK**.

   ![](/files/nsnytHaON2wPoErb00Dm)
3. Click **Next**.

### When to patch

1. Select **Browse** next to **Schedule**.
2. Click the **Schedule** folder and select **2nd Tuesday of Month (00hrs)** from the table.
3. Click **OK**.

   ![](/files/jDmjBKbyfdcnv9C0H46T)
4. Click **Next**.

### How to patch

The How to Patch section allows you to select Deployment Rings and add Transitions to customize deployment actions. It also allows you to set up auto approvals.

1. Click **Next** then select **+ Add Deployment Ring**.
2. Click **Browse** and select the built-in **1% of All Devices (Built-in Pilot)** business unit.
   * 1% of All Devices (Built-in Pilot) selects devices at random. If you want a more specific pilot group that represents all aspects of your environment (OS, device type, etc.), please see our [Create Business Unit](/patch/patching-fundamentals/business-units#create-a-business-unit) page.

     ![](/files/zLEzh1RS8pwHujwYofJ6)
3. Click **+ Add Transition > Delay Transition** and enter 3 days.
   * This will allow your admin time to test and verify these devices before deploying to production devices.
4. Click **+ Add Transition > Approval Transition**.

   1. Click **Browse** to select the Roles you wish to notify for approval.
   2. Set the **Minimum Approvals Needed** to 1 and **Reminder Interval** to 2 hours.

   ![](/files/2JPe6jUQHQZEnAuNcJtE)
5. Add a pre-production Deployment Ring that has a larger subset of devices than your Pilot Business Unit.
6. Select **+ Add Transition > Success gate**.
   1. **Minimum Success Threshold** set to 80% and **Maximum Failure Threshold** to 5%.
      * This will ensure that at least 80% of devices must succeed AND no more than 5% can fail deployment.
   2. **Failure Action**
      * Set to **Roll back, remove from next ring, and continue**.
      * This failure action will roll back any patches that may have been installed on successful devices, then the patch will be removed from the deployment, and then the deployment will continue from here.
   3. **Send Failure Notification**
      * Toggle ON, this will expose additional notification settings.
   4. **Roles to Notify**
      * Set to desired Roles.
   5. **Communication Provider**
      * Set to desired provider.
   6. **Notification Message**

      * Write a descriptive message. e.g. Patch failed to install on greater than 5% of targets. Failing patch was {PatchName}.

      ![](/files/9oVHamHXqDl6heCM87UQ)
7. Click **+ Add Deployment Ring** and select **All devices**.

   ![](/files/yP80Thhx5tWKHKeZANQQ)
8. If you want to set auto-approvals, switch the **Auto Approve** toggle to on.
9. Under **Approval Timeout Duration**, set the amount of time you want to give the approver before the strategy is automatically approved.

   ![Set timeouts for auto approvals](/files/HjEbnYvyv3yqDx1B9eTo)

You have now created a new Strategy that:

* Deploys to a **pilot** business unit for initial testing.
* Deploys to a **pre-production** business unit with a success gate to a larger subset of devices for further validation.
* Deploys to a **production** business unit to deploy to all remaining devices.
* Has a timed auto-approval window.

If you would like to run your Strategy immediately instead of waiting for the selected scheduled time, you can select the ellipses **(...)** next to your Strategy name in the table and the select **Run Strategy**.

![](/files/s06rrQhGzA4yxHhjMop8)

## Deployment plan details

Below is some additional information regarding the Transition settings in the **How to Patch** section of the Strategy walkthrough.

### Add deployment ring

Adding a **Deployment Ring** will allow you to choose which Business Units you'd like the **Strategy** to target for deployment.

{% hint style="info" %}
For more information regarding creating Business Units to add to your Deployment Rings, please see our [Business Units](/patch/patching-fundamentals/business-units) page.
{% endhint %}

![](/files/7n5mPadq7kyBh1f5P7Jj)

### Add a transition

Transitions give you the ability to create objects that dictate the behavior of how a patch should be deployed.

#### Approval

You can add an **Approval Transition** that will require a patch to get an approval prior to deployment. With an Approval Transition, you can specify:

* Which Role will be the approval body
* Whether or not you need unanimous approvals or a minimum number of approvals needed
* When to send reminders to approvers after an approval request has been sent

  ![](/files/DKewXKjGcL5AeCtpv2G5)

{% hint style="info" %}
Approval request notifications will list all patches included in the approval request for your strategy.

<img src="/files/HlIjN6vrrGgRl1EJ9Cjj" alt="" data-size="original">
{% endhint %}

#### Delay

**Delay Transition** allows you to delay the deployment of a patch by a specified time after it is received.

* Enter Delay Duration in Days, Hours, Minutes.

  ![](/files/MHau6DUiBi2UEGmF5AMA)

#### Success gates

You can create **Success Gate Transitions** to test on a smaller Business Unit before deploying out to a broader scope of devices. After creating your **Strategy** with a **Success Gate**, a [Deployment wave](/patch/advanced-settings/deployment-waves) will be automatically generated.

With a **Success Gate** you can define things like:

* A **Minimum Success Threshold** sets how many deployments must succeed by percentage of devices before continuing. For example, if you have 2 devices and you set Minimum Success Threshold to 50%, at least 1 device must be successful before continuing the **Patching Proccess** pipeline.
* Similar to **Minimum Success Threshold**, you can set a **Maximum Failure Threshold** that will fail a **Patching Process** if the percentage of unsuccessful deployments is exceeded. In the same scenario of 2 devices, if you set the maximum to 50% and 1 device failed, it will trigger the **Failure Action**.
* If a particular patch deployment fails, you can specify whether or not to send a **Failure Notification** and if you want it to:
  * Abort
  * Continue
  * Remove from next wave and continue
  * Roll back, remove from next wave, and continue

![](/files/rYPaBUqE3baLsePMCFwk)

## Patch filters

Patch filters allow you to set constraints on which patches will be applied to your strategy when they meet the desired conditions set by your admin. Each patch filter allows you to set an operating condition and enter the value by which to filter. For a full list of patch filters, please see our [Patch Filters](/patch/advanced-settings/patch-filters-categorized-q1) page.

You can include/exclude patches or add multiple patch filters by selecting Operators (AND, OR, NOT).

* **AND**
  * If AND is the first selected operator it will need to meet both the conditions of the products include/exclude and the additional patch filter.
  * For example, if 7-Zip and Adobe Acrobat are the only products selected AND `General.IsMajorFeature == true`, the patch will need to meet both conditions before being added to the strategy. If a patch is for 7-Zip, but it is not a major feature, it will not be added to the strategy.
  * Additional AND operators for additional patch filters follow this same pattern.
* **OR**
  * When using the OR operator first, it will act as an AND since we still require a product selection. If you use additional OR operators, the patch will need to meet at least one condition.
  * For example, if you have the condition `General.IsMajorFeature == true`and then an OR operator for `Risk.KnownExploitExists == true` only one of these conditions needs to be true for it to be included in the targeted patch list.
* **NOT**
  * When NOT is selected as the initial operator, you may only select a single patch filter and cannot add additional operators or filters. This operator will exclude patches based on a selected condition.
  * For example, if you have NOT `General.IsMinorFeature == true`, this will select only the patches that are not minor features (i.e. major features, bug fixes, updates, etc.).

Below is an example of how to add a patch filter.

1. Toggle **ON** **Include All Products** or select **Browse** to select desired individual products.
2. Select the ellipses next to **Patch Filter** and select **Add Operator > OR**.
3. Select the ellipses again and select **Add Operating Condition**.
4. Select `Risk.KnownExploitExists` from the **Data Column** dropdown.

   ![](/files/f56iJf8Wlx7oUNyEq6JD)
5. Use the default for **Operating Condition** (Equals).
6. Set the **Value** to **Medium**
7. Click **OK**.
8. Add another `Risk.KnownExploitExists` and set the value to **High**.

   ![](/files/IqGstwKwqpDcrbFz1laa)
9. Click **Preview Targeted Patches**.

If a product doesn't have any major feature patches, they will not be displayed.

If a product has major features, it will only display major feature patches that have are either a bug fix, or a have a known exploit that exists. ![](/files/rYPaBUqE3baLsePMCFwk)

* Which roles and by which communication provider to send notifications.
* Add a custom **Notification Message**.
  * If you hover over the Notification Message tooltip, you can see the available dynamic variables. You can add these variables to your message and it will populate the appropriate data. Dynamic variables include:
    * {FirstName} - First name of the administrator that will be notified.
    * {LastName} - Last name of the administrator that will be notified.
    * {PatchStrategyName} - Name of the patching strategy that has failed.
    * {PatchName} - Name of patch(es) that has failed.
    * {ProductName} - Name of patch(es) that has failed.
    * {Publisher} - Name of the patch publisher.
    * {Version} - Version of the patch.
    * {TargetCount} - Count of targeted devices.
    * {FailureCount} - Count of failed targeted devices.
    * {CompliantCount} - Count of targeted devices that are compliant.
    * {NonCompliantCount} - Count of targeted devices that are non-compliant.
    * {FailureP} - Percentage of target devices that have failed.
    * {CompliantP} - Percentage of target devices that are compliant.

**Notification Message/ Dynamic Variable example**

Hello {FirstName} {LastName}, Your patch deployment strategy "{PatchStrategyName}" has completed and had failures.

Patch Details: Patch: {PatchName} Product: {ProductName} Publisher: {Publisher} Version: {Version}

Deployment Results:

Total Devices: {TargetCount} Compliant: {CompliantCount} ({CompliantP}%) Non-Compliant: {NonCompliantCount} Failed: {FailureCount} ({FailureP}%)

Please review the {FailureCount} failed installation(s) in the OneSite console.

Best regards, OneSite Patch Management System

## Monitor patch activity

To monitor patch activity, there are a variety of dashboards you can explore that provide details, such as the date a patch was deployed or whether a patch is pending an approval. Learn more about [Dashboards](https://docs.adaptiva.com/platform-guide/platform-features/dashboards).

However, you may prefer an email summary that you can include in roll-up reports to management or the rest of your team.

### Pre-notifications

If you want to see a list of patches before they are deployed, Approval Requests send out an email notice that there are patches waiting for approval. The link in the email takes you to a dashboard showing all pending approval requests, so you will get an email if you are in the appropriate Approval Chain.

![Pending patch list](/files/QIG5PZFQA14cMrN5mjzq)

You could also use role-based access control to notify your team, but limit who on that notification list can approve the request. For instance, if you are a Super Admin in the approval chain, but you want a coworker to only have read permissions, then you could set that person's access to Reviewer.

* Learn more about [Approval Requests](https://docs.adaptiva.com/patch/patching-fundamentals/approval-requests)
* Learn more about [Role-based Access Control](https://docs.adaptiva.com/patch/security-and-access-control/rbac)

### Post-notifications

If you want a list of patches that have been deployed in a given week, subscribe to a dashboard that gives you the data you want to see and set it to send out a weekly summary email. For a notification email, **Patch Status - Summary** might be a good candidate.

Note that a patch might not have made it through all the deployment rings before the end of a given week, in which case, the status might show as pending.

Learn more about [Dashboard Subscriptions](https://docs.adaptiva.com/platform-guide/platform-features/dashboards/subscriptions)


# Common patch configurations

Common Patching Strategy configurations.

The following patching strategies are the most commonly used in any environment, large or small. These strategies ensure patching is handled not only as a response to high-priority security risks, but also as a routine maintenance that helps preserve system reliability, performance, and compliance.

Oftentimes, these are used in conjunction with more complex and custom patching strategies. However, they also provide a recommended starting point and can be used exclusively depending on the size of your environment and specific organizational needs.

## Best overall practices

| Practice Area              | Recommendation                                                    | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| -------------------------- | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Pilot Deployments**      | Always implement a pilot phase, regardless of environment size.   | <p>Without pilot testing, you risk troubleshooting issues simultaneously across all devices.<br><br>Recommended pilot size: 12-25 devices, preferably lab machines.</p>                                                                                                                                                                                                                                                                                      |
| **Ring-Based Deployment**  | Mature from small-scale lab pilots to ring-based deployment model | <p>Use P-rings to expand testing beyond lab environments.<br><br>Create separate business units with divergent maintenance windows.<br><br>Progressively expand deployment scope across rings.</p>                                                                                                                                                                                                                                                           |
| **Pilot Device Selection** | Select devices representing full production environment           | <p><strong>Operating Systems:</strong> Windows 10, Windows 11, macOS, Linux<br><br><strong>Device Types:</strong> Workstations and servers<br><br><strong>Use Cases:</strong> High-performance machines (development, analysis) and lightweight devices (kiosks)<br><br>The built-in Business Units are not always ideal as these are randomly chosen devices (1% of All Workstations etc.), so it's best to strategically create custom business units.</p> |
| **Pilot User Selection**   | Choose users who provide actionable feedback                      | <p>IT staff and IT-friendly users who provide detailed feedback, non-IT staff for real-world validation, and users who reliably communicate issues.<br><br>Avoid choosing mission critical devices (revenue generators, CEO's, etc.)</p>                                                                                                                                                                                                                     |
| **Approval Timing**        | Schedule during business hours for timely response                | Configure approval requests to generate mid-morning (\~10:00 AM) when an admin is most likely to view it during work hours.                                                                                                                                                                                                                                                                                                                                  |

## Daily critical patching

This patching strategy deploys daily patching based on criticality scores provided by a vulnerability management integration partner. Each patch that is marked *Critical* is deployed to all clients daily at a desired time.

Please see our list of [Integration Partners](/patch/integrations/integration-partners) that support criticality scores.

<details>

<summary>Create strategy</summary>

#### Navigation

1. Select **Strategies** from the side navigation.

   ![](/files/64JfaeMvRqeIzK77AECO)
2. Click **New Strategy**.

#### Overview

1. Enter a **Name** and **Description**.
2. Toggle **ON** **Strategy Enabled**.
3. Click **Next**.

#### What to Patch

1. Either toggle **ON** **Include All Products** or select desired individual products/patches.
2. Select the ellipses (**...**) next to **Patch Filter**.
3. Select **Add Operating Condition**.

   ![](/files/6UZQZ9A4eJadTl0mryQz)
4. Select one of the following from the **Data Column** dropdown:
   * For Adaptiva - **Risk.SecurityExposureLevel**.
   * For Microsoft Defender - **Defender.SeverityLevel**.
   * For CrowdStrike - **Falcon.ExPRT**.
   * For SentinelOne - **SentinelOne.RiskSeverity**.
5. Set the **Operating Condition** to **Equals**.
6. Set the **Value** to **Critical**.

   ![](/files/IxdXVnECgM8t4ma2p2I9)
7. Click **OK**.
8. Click **Next**.

#### When to Patch

1. Click **+ Browse** next to **Schedule**.
2. Click the **Schedules** folder and select a desired schedule that will run in the AM.

   ![](/files/890ujoSFXYJSyL8mwk6i)
3. Click **OK**.
4. Click **Next**.

#### How to Patch

1. Click **+ Add Deployment Ring**.
2. Click **+ Browse** and select your pilot devices business unit.

   ![](/files/qXe6AlOZKLM3L7JNLC7h)
3. Click **+ Add Transition > Delay Transition** and enter 8-12 hours.

   * This is to determine your PM production deployment. This will be the delay from your chosen schedule from the **When to patch** pane.

   ![](/files/wKCYpoaDZy0uZMYVy4Cv)
4. Click **OK**.
5. Click **+ Add Deployment Ring** and select your production devices.
6. Click **Save**.

</details>

## Accelerated browser patching

Browsers are highly susceptible to vulnerabilities and it is good practice to prioritize patching for these products. This patch strategy is run on browser products twice a week -- once in the morning for a pilot group and once in the evening for the remainder of devices on Tuesdays and Thursdays.

<details>

<summary>Create strategy</summary>

#### Navigation

1. Select **Strategies** from the side navigation.

   ![](/files/64JfaeMvRqeIzK77AECO)
2. Click **New Strategy**.

#### Overview

1. Enter a **Name** and **Description**.
2. Toggle **ON** **Strategy Enabled**.
3. Click **Next**.

#### What to Patch

1. Either toggle **ON** **Include All Products** or select individual products/patches.
2. Select **Browse** next to **Included Products**.
3. Select all of your browser products from the table.

   ![](/files/nmTjlroIyi8Ffr27RHOT)
4. Click **Next**.

#### When to Patch

1. Click **Browse** next to schedule.
2. Select the **Schedules** folder and select **Weekly (Tuesday, 10hrs)** and **Weekly (Thursday, 10hrs)**.

   ![](/files/AV7jQH9YXISgrOkICKbA)
3. Click **OK**.
4. Click **Next**.

#### How to Patch

1. Click **+ Add Deployment Ring**.
2. Click **Browse** and select your preferred pilot **Business Unit**.
3. Click **OK**.
4. Click **+ Add Transition > Delay Transition** and enter *12 hours*.

   ![](/files/HcfNDpim4a8NG42WngPQ)
5. Add an additional Deployment ring for the remaining production devices.

   ![](/files/Y1jc5eSIEzWhsoYIvEUv)
6. Click **Save**.

</details>

## Weekly Pilot / Production patching (Pilot Monday / Patch Friday)

This patch strategy covers weekly patching for all products for pilot business unit devices on every Monday and the remaining production business unit devices every Friday. Weekly patching ensures general upkeep of all products.

<details>

<summary>Create strategy</summary>

#### Navigation

1. Select **Strategies** from the side navigation.

   ![](/files/64JfaeMvRqeIzK77AECO)
2. Click **New Strategy**.

#### Overview

1. Enter a **Name** and **Description**.
2. Toggle **ON** **Strategy Enabled**.
3. Click **Next**.

#### What to Patch

1. Either toggle **ON** **Include All Products** or select individual products/patches.
2. Click **Next**.

#### When to Patch

1. Click **Browse** next to schedule.
2. Select the **Schedules** folder and select **Weekly (Monday, 10hrs)**.
3. Click **Next**.

#### How to Patch

1. Click **+ Add Deployment Ring**.
2. Click **Browse** and select your preferred pilot (P0) **Business Unit**.

   ![](/files/C5dnJsHnXoVUk7PQY3o9)
3. Click **OK**.
4. Click **+ Add Transition > Delay Transition** and enter 2 days.

   ![](/files/3nsOuWglYkKhXIy4hJUM)
5. Create an additional pilot (P1) deployment ring and another delay of 2 days.
6. Click **+ Add Transition > Approval Transition**.
7. Select **Browse** and click **Create new Role** and add your desired admins to be notified for approval requests.
8. Click **OK** and add a **Reminder Interval** of 2 hours.

   ![](/files/bKEU4Dyvw0NocKSAi79e)
9. Add another deployment ring for your production devices.
10. Add a delay transition of 8hrs.
    * By default after an approval request is approved, it will run the patch strategy ASAP. Adding a delay here will ensure that after the approval, production devices will install patches outside of business hours.
11. Click **Save**.

</details>

## Monthly multi-phase patching

The goal of the monthly multi-phase patching is to introduce predictability so users can always anticipate when patches happen on a monthly-basis. Additionally, the pilot/production structure ensures that multiple device groups are tested prior to a full deployment.

<details>

<summary>Create strategy</summary>

#### Navigation

1. Select **Strategies** from the side navigation.

   ![](/files/64JfaeMvRqeIzK77AECO)
2. Click **New Strategy**.

#### Overview

1. Enter a **Name** and **Description**.
2. Toggle **ON** **Strategy Enabled**.
3. Click **Next**.

#### What to Patch

1. Either toggle **ON** **Include All Products** or select individual products/patches.
2. Click **Next**.

#### When to Patch

1. Click **Browse** next to **Schedule** and select **2nd Tuesday of the Month (10hrs)**.
2. CLick **OK**.
3. Click **Next**.

#### How to Patch

1. Click **+ Add Deployment Ring**.
2. Click **Browse** and select your preferred pilot (P0) **Business Unit**.

   ![](/files/C5dnJsHnXoVUk7PQY3o9)
3. Click **OK**.
4. Click **+ Add Transition > Delay Transition** and enter 7 days.

   ![](/files/cvKugIpYBCKKGIpBSEcW)
5. Repeat for P1, P2.
6. After the delay transition for week three, click **+ Add Transition > Approval Transition**.
7. Select **Browse** and click **Create new Role** and add your desired admins to be notified for approval requests.
8. Click **OK** and add a **Reminder Interval** of 2 hours.

   ![](/files/VONhJm7lS38wyIMlcaOZ)
9. Create a final deployment ring for your production devices.
10. Your plan outline should look like the following:

    ![](/files/RvQnKJOJV1ftTAhxaGb8)

</details>

## Clustered services patching

The goal of clustered services patching is to maintain service availability by patching nodes in a controlled sequence. This includes patching passive nodes first, validating their success, and sending an approval request before advancing to active nodes, to ensure zero-downtime deployments.

<details>

<summary>Create strategy</summary>

#### Navigation

1. Select **Strategies** from the side navigation.

   ![](/files/64JfaeMvRqeIzK77AECO)
2. Click **New Strategy**.

#### Overview

1. Enter a **Name** and **Description**.
2. Toggle **ON** **Strategy Enabled**.
3. Click **Next**.

#### What to Patch

1. Either toggle **ON** **Include All Products** or select individual products/patches.
2. Click **Next**.

#### When to Patch primary secondary , patch secondary

1. Click **+ Browse** next to **Schedule**.
2. Click the **Schedules** folder and select a desired schedule that will run in the AM.

   ![](/files/890ujoSFXYJSyL8mwk6i)
3. Click **OK**.
4. Click **Next**.

#### How to Patch

1. Click **+ Add Deployment Ring**.
2. Click **+ Browse** and select your secondary servers business unit.

   ![](/files/sP2vOqBdXlT1BrgKY3ot)
3. Click **+ Add Transition > Success Gate Transition**.
4. Set the **Minimum Success Threshold** to 100. This will ensure that 100% of all of your devices must be patched successfully before continuing.
5. Set the Failure Action to **Abort**.
6. (Optional) Toggle **ON** **Send Failure Notification**, select the roles to notify, communication provider, and enter a notification message.

   * If you hover over the **Notification Message** tooltip to view the available dynamic variables. For more information regarding dynamic variables, please see our [Success Gates - Notification Message](/patch/get-started/strategies-v2#success-gates) section.

   ![](/files/woiJCjDqqo6hkfgX5F3P)
7. Click **+ Add Approval Transition**, select the roles you'd like to be notified and designated approvers, and then configure the desired approval settings.

   ![](/files/Di3RSaSzCV3YJoP13ECT)
8. Click **+ Add Deployment Ring** and select your primary server business unit.

   ![](/files/F0xmTueX0jaLFMVZardQ)
9. Click **Save**.

</details>


# Dashboards

Dashboards offer real-time information about the status of objects within OneSite Patch.

Some Dashboards are useful for a quick glance to confirm everything is running smoothly, or you can drill down deeper into specific widgets to see where you might need to take action. For instance, you can:

* View the overall compliance of all devices
* Select a Device from a table widget of patches to see further details about the Device
* Perform a Flex Control action from a Flex Control widget

There are several pre-built Dashboards for you to explore. If you're interested in creating your own dashboard, please see our [Advanced: Dashboard Management](https://docs.adaptiva.com/platform-guide/dashboards) page.

## Home

The **Home** dashboard displays the more relevant information for keeping you updated on the overall status of your patching environments. All text in these widgets are links that allow you to drill deeper into the related content.

### Insights

![](/files/UGZfLhYpb4sUI84lluLw)

* **Overview** - The Overview dashboard gives a general count of each object. You can select either the green or red button to open a table that displays each associated object where you can apply actions if necessary.
* **Blind spots** - The **Blind Spots** widget details areas that may have been missed during daily activities.
* **Patching overrides** - Patching Overrides details exceptions, blocked patches by the user, blocked patches by Adaptiva, and rollbacks.
  * Useful for reviewing patches you may want to actually deploy.
* **Patching Metadata** - Summarizes the status of the latest endpoint scans and client product inventory updates. Metadata includes details about the products, patches, and updates approved for installation.
  * Tells the administrator when the AdaptivaServer and AdaptivaClient last synchronized with the Metadata Server and when the last sync resulted in an update to the clients.

### Patch Metrics

![](/files/pSXlIPAucuvCribXTK52)

The Patch Metric section details:

* **Status** - The status of the Patch may change dynamically as new statues are updated and will be reflected in the chart in real-time, and the graph over time. Some statues present in the graph may not actively appear in the real-time chart data. You can also click on each bar of the bar graph to open a fly-out and view those associated patches.

  ![](/files/tTkjt0ZWgcpvAlTCXlHx)
* **Overall Compliance** - Graphs the overall compliance of devices in the environment with the patch requirements.
* **Risk Score** - For more information regarding Risk Score, please see our [Risk Assessment Settings](https://docs.adaptiva.com/patch/advanced-settings/risk-assessment) page.

### Actions

![](/files/WiCEEuUMnXTQXqaYm83s)

* **Quick Actions** - Quick Actions allow you to create higher level tasks on the fly without having to find it deeper in the UI.
* **Emergency Kit** - Use the Emergency Kit to quickly apply Patch actions or navigate to **Flex Controls** for more granular controls.

## Patches and Products dashboard

Both of these dashboards can be found from the **Software** dropdown from the side navigation.

![](/files/jOheas4UOrqNJshaRoyv)

### Patches

The Patches dashboard details metrics, trends, top 10 most critical patches, and status of Patches. This is a useful view to monitor Patches and determine which Patches may need additional attention.

* **Patching Metrics** - Shows basic patch related information specific to your environment based on scanning requirements.
* **Patch Trends**
  * **Patching Status** - Shows the status of all patches, the number of machines tracked in the environment, and the number of patches in each status by percentage.
  * **Risk Contribution** - Shows the number of patches in the environment and the risk rates by percentage.
* **Top 10 Most Critical Patches** - This table view organizes the patches by their [Risk Contribution](https://docs.adaptiva.com/patch/advanced-settings/risk-assessment#risk-score-settings).
* **Active Product Deployments** - Quick glance view if there are any deployments running and its progress.
* **Patch Status** - Shows the total number of Patches required in your environment and the installation/applicability of the aggregate total. Additionally you can select the ellipses more context menu to perform the following: Rollback, Submit Patch to Strategy, Scan Patch, Block Patch, and Reset Deployment Failures for Patch.

  ![](/files/AAjunEx4QqhzqF5bODnK)

### Products

The Products dashboard details metrics, compliance rates, risk contribution, and status of Products. This is a useful view to monitor Products and determine which Products may need additional attention.

* **Product Metrics** - Tracks supported products, detected products, and patching requirements, and provides a visual indication of product patching over time.
* **Product Compliance Rates** and **Products by Risk Contribution** - Graph of the compliance of products and their risk contributions.
* **Product Status** - A table that lists each product that OneSite Patch looks for during a scan, the installation/applicability status of each, and the status, compliance, and Risk Score for each.

**Product Compliance** - This metric is calculated based on how many devices a product is installed and how many devices still need an update. The following equation is used to calcualte the product compliance percentage:

```shell
# of Machines installed with product - Devices requring an update / # of Machines installed with product

Example:

15 - 4 / 15 = 73% compliant
```

## Devices

The **Devices** dashboard can be found from the **Asset Management** dropdown from the side navigation.

![](/files/sjq7j5kxDdpljTRO6DWy)

* **Device Metrics** - Tracks Device patching status over time.
* **Product Compliance Rates** - Graph of the compliance of products and their risk contributions.
* **Devices by Risk Contribution** - Displays which devices contribute to the most risk.
* **Device Status** - Overview of each Devices status with all elements.

**Device Compliance** - This metric is calculated based on how many products a device has installed and how many are updated with latest patches (product compliat). The following equation is used to calcualte the product compliance percentage:

```shell
Compliant Products / Product Count

Example:

30/32 = 94% compliant
```

{% hint style="info" %}
Device Compliance is rounded to the nearest percent.

Products that are **Compliant by Exclusion** due to a rollback or exception are not included in the total compliant products.
{% endhint %}

## Deployments

The **Deployments** dashboard can be accessed by clicking **Deployments** in the side navigation.

![](/files/fw49iiZgVD2n8rLjyGvY)

* **Deployment Metrics** - Tracks rollouts, patches in progress, and provides a visual indication of patches installed over time.
* **Patch Deployment Status** and **Schedule Patch Deployments** - Graphs deployment status and upcoming deployments.
* **Patch Deployments** - Lists either **In-Progress** and **Completed** individual patches that have been deployed. If you click on the number of **Cycles**, you can see the deployment cycle information for that patch. You can then click on these cycles which will open up the flex controls for this patching strategy cycle.

  ![](/files/Iavm7bbxVcpnSxX7bBd6) ![](/files/h4xQRa7FJa93ptEWepaS)

## Flex controls cycle operations

The **Flex Control Cycle Operations** has its own set of interactable dashboards. For more information regarding these, see our [Flex Controls](https://docs.adaptiva.com/patch/patching-fundamentals/flex-controls/flex-controls-cycle-operations) page.

## Additional dashboards

There is a table of additional dashboards you can access by clicking **Dashboards > Dashboards** under the **Platform Features** side navigation dropdown.

You can view each dashboard, but selecting their **name** in the table.

![](/files/qtL54hJwv8jWA0w1HrUr)




---

[Next Page](/llms-full.txt/1)

