Documentation Getting started Recommended deployments
GETTING STARTED

Recommended deployments

A small set of deployments covers most of what a managed computer needs from its first day. This page describes each kind, why it is worth having, and how to adapt it to a client.

A starting set

A deployment is a standing declaration that an item should be in a given state on the computers it targets. You can declare anything in the library, but the same few kinds of deployment do most of the work on almost every computer.

This page describes those kinds. Set them up to target every client, then adjust them for the clients that differ.

The Deployments screen.
The Deployments screen.

A profile for the primary user

This task creates the Windows user profile for the computer's primary user before that person has ever logged on.

It exists because of a timing problem. Settings such as the default web browser and the default PDF application belong to a user, and Windows stores them in that user's profile. On a new computer the person has not logged on yet, so there is no profile to hold the settings.

Overseer looks up the person's identifier in your directory or your identity provider and creates the profile from it. It does not need the person's password. User-level settings can then be applied during onboarding, and the person's first logon goes more smoothly because the profile is already there.

Keep this one in place wherever you assign a primary user.

Office applications by licence

A deployment for your office suite does not have to install it everywhere. Give it a condition that checks, through your identity provider, whether the computer's primary user holds a licence for that product.

Overseer then installs each application only for the people entitled to it. Use one deployment per product, including the specialist applications that only a few people have. Each person gets what their licence covers and nothing else.

Manufacturer updates

Computer manufacturers publish their own updates for the hardware they make:

  • driver updates
  • BIOS and firmware updates
  • hardware utilities

Create one task deployment for each manufacturer you support. Give each a filter script that reads the computer's make and model, so a manufacturer's updates apply only to that manufacturer's computers.

Everyday software

Some applications belong on nearly every computer. Others only need looking after where they happen to be. The four desired states cover both.

  • A web browser and a PDF reader. Set these to Installed for every client. Overseer installs them where they are missing and keeps them current.
  • Common utilities. For a tool you do not want on every computer, such as a file archiver, use Updated if Found. Overseer keeps it current where it exists and never installs it fresh.
  • Unwanted pre-installed software. For the extras a manufacturer ships that you do not want, use Uninstalled.
  • Your security software. Set it to Installed. If you resell it to some clients only, target the clients whose PSA agreement includes it.

Handling exceptions

Some clients standardise on a different PDF reader. Do not turn the default deployment off for everyone. Instead:

  1. 1Leave the default deployment in place for every client.
  2. 2Add a deployment for that client setting its own PDF reader to Installed.
  3. 3Add a second deployment for that client setting the default reader to Uninstalled.

The two narrower deployments override the default for that client, and every other client is unaffected. Deployment resolution explains how overlaps are settled.

Computer name and directory join

One task can name a computer according to your convention and join it to the client's directory. Onboarding enforcement suits it, because it is done once, when the computer is first set up.

Unlike the other kinds on this page, this one needs separate settings for each client. Create a deployment per client, each with that client's naming convention and directory details, instead of one deployment for all.

To join computers to a client's Active Directory, install the Overseer agent on one of that client's domain controllers, and preferably on more than one. Overseer uses that connection to prepare the join, so the new computer does not need to reach a domain controller itself.

Disk encryption with BitLocker

A BitLocker task keeps the disks on your computers encrypted. It:

  • checks that the computer's hardware and its version of Windows can support encryption
  • turns encryption on where they can
  • stores the recovery key in the client's directory or identity provider

It needs a connection to one of those two places, so that it has somewhere to store the key.

Making them your own

Treat these as a starting point, not a finished standard.

  • Review each one. Know what a deployment does and what it targets before you rely on it.
  • Leave out what you do not need. Skip the kinds that do not suit your clients.
  • Add exceptions. Use a narrower deployment for the client or computer that differs.
  • Copy and adjust. Where a deployment needs per-client settings, make a copy for each client.

A deployment takes effect only when a maintenance session runs, so you can set up and adjust deployments without changing any computer until you are ready.

Next steps

Creating and managing deploymentsDeclare what should be true, where, and how strictly it is enforced. Deployment resolutionHow Overseer picks the winner when several deployments apply. Best practicesHabits for schedules, deployments and naming that keep work predictable.
Was this article helpful?
← Best practices Dashboard →

In development. Launch inquiries welcome.

This documentation describes Overseer as it is being built. If you would like to hear when it launches, get in touch.

Ask about launch