Install remote Cayosoft Administrator console
Overview
You can connect to a local Cayosoft Administrator service, any Cayosoft Administrator Service running on another computer in the network, or a virtual Azure machine running Cayosoft Administrator using a remote console. This article describes the steps to prepare your environment, install and configure a remote Cayosoft Administrator console to connect to a Cayosoft Administrator service running remotely.
NOTE: Cayosoft Administrator documentation may reference the remote console as Cayosoft Administrator Client Tools. For the purposes of this article, the "remote console" name is used.
Prerequisites
Components
| Component | Notes |
|---|---|
Microsoft .NET Framework 4.7 or later |
The role is required. TIP: To determine the installed version of Microsoft .NET Framework, follow the instructions provided in the following article: Determine which versions and service pack levels of .NET Framework are installed. |
Microsoft Management Framework 5.1 or later |
See the Installing required Cayosoft Administrator components article for installation instructions. |
Remote Server Administration Tools (RSAT) |
See the Installing required Cayosoft Administrator components article for installation instructions. |
| Internet Information Services |
If you use the HTTP redirect feature in IIS, enable the following setting in HTTP Redirect settings of the PolicyManager application on the Cayosoft Administrator server:
|
Required ports
When installed and used remotely, the remote console requires an open 443 port on the target Cayosoft Administrator server. If the Cayosoft Administrator and remote console are installed on the same machine, and the console is used to connect to a different remote Cayosoft Administrator instance, the port 7800 is required. For more information, refer to the following article: Cayosoft Administrator URLs and IP address ranges.
Install remote Cayosoft Administrator console
On your existing Cayosoft Administrator server, navigate to the following link:
https://%AdministratorServerFQDN%/policymanager.Locate the Administrator Console section, and click Download to download the installer.
Send the installer to the intended remote server and double-click the installer to start the installation wizard.
-
Review the end-user license agreement, click I agree to the license terms and conditions, and click Install to proceed.
NOTE: You can change the target location for the remote console application by clicking Options. Define the target folder and click OK to return to the confirmation screen.
Wait for the wizard to complete. After the installation, the wizard will prompt you to reboot the server. Click Restart to restart immediately.
IMPORTANT: If the console version is older than the Cayosoft Administrator Service version, the connection window will prompt an error: Your version of Administration Console (%version%) is incompatible with version of Administration Service (%version). Click the link to download the latest Cayosoft Administrator console.
Connect to Cayosoft Administrator service remotely
When you launch a remote Cayosoft Administrator console, a connection wizard is prompted. Specify connection parameters to connect to the target Cayosoft Administrator server:
-
In the Server name or IP address field, define an IP address of the the Cayosoft Administrator server. You can then authenticate using either Active Directory credentials or a Microsoft 365/Azure AD account.
IMPORTANT: When you intend to use Kerberos authentication, you must define the server FQDN in the Server name field. If you have an IP address specified, the connection will fail.
Using the Use Kerberos authentication for remote connections setting, define the authentication protocol used when you connect to the remote Cayosoft Administrator service. When set to Yes, Cayosoft Administrator attempts to authenticate to the target server using Kerberos; if connection attempt fails, then Cayosoft Administrator falls back to NTLM authentication.
In the Name your connection field, define a name for the outbound connection.
-
Using the Connect as setting, define the credentials of the user connecting to the remote Cayosoft Administrator service.
When you log in as the current user or specify an Active Directory account, Kerberos/NTLM authentication is used.
When you use an Entra ID account, OAuth authentication is used.
NOTE: The specified account must have appropriate permissions delegated to access and manage items in the Cayosoft Administrator console. For more information, see the article Role-based delegation.
Review rule reports when using remote Administrator console
Reports for rules are stored on the server where Cayosoft Administrator is installed. To review rule reports in the remote Cayosoft Administrator console, you should share the folder for reports on the Cayosoft Administrator server and specify a new path in the remote Cayosoft Administrator console in the Reporting settings page; alternatively, you can use File Share (SMB).
IMPORTANT: If you configure automation rules using CSV files, the CSV files must be available on the server where the Cayosoft Administrator service is installed.
Troubleshooting
Clearing connection settings
To clear your Cayosoft Administrator console connection settings manually, follow the steps:
Close the Cayosoft Administrator console.
-
Open the following folder on your PC:C:\Users\<user name>\AppData\Local\Cayosoft.
Replace the
<user name>placeholder with your actual username. Delete all subfolders from the folder.
Start the Cayosoft Administrator console: The connecting dialog appears.
Related error messages
You may encounter one of the following errors:
-
When you attempt to connect to the Cayosoft Administrator service via remote console, the following error is prompted:
The server has rejected the client credentials. -
Alternatively, when you attempt to set up a Subscriber server, the following error is prompted:
A call to SSPI failed, see inner exception.
To resolve the error, specify the target server FQDN in the Server name or IP address field and set Use Kerberos authentication for remote connections to Yes.
Change history
| Version | Notes |
|---|---|
| 13.3 | The Use Kerberos authentication for remote connections setting has been added. |
Comments
0 comments
Please sign in to leave a comment.