Introduction
This document describes how to provision the Secure Client Umbrella Roaming Security Module using MS Intune.
Pre-requisites
- Access to Umbrella Dashboard
- Access to MS Intune Portal
- Secure Client Umbrella Module Profile
orginfo.json
- Secure Client Pre-deployment package for the required version
- Microsoft Win32 Content Prep Tool
This guide uses the Windows app (Win32) method. Convert both the cisco-secure-client-win-5.0.05040-core-vpn-predeploy-k9.msi
and cisco-secure-client-win-5.0.05040-umbrella-predeploy-k9.msi
files into .intunewin
format.
Caution: Windows Autopilot is not compatible with this process. Assign the VPN and Umbrella applications using standard Intune groups or devices.
Convert Secure Client MSI Files to .intunewin Format
- Access the Umbrella Dashboard and download the Secure Client Umbrella Module Profile
orginfo.json
fromDeployments > Roaming Clients > Download > Download Module Profile.
20109693592980
- After extracting the Secure Client pre-deployment package, place the Umbrella profile
orginfo.json
in the\cisco-secure-client-win-5.0.05040-predeploy-k9\Profiles\umbrella
directory.
20109945693716
- Download theMicrosoft Win32 Content Prep Tool.
- Create a folder and add theIntuneWinAppUtilapplication. Also, create Input and Output folders on your machine.
20115546066964
- In the
Intune_input
folder, add the Secure Client VPN Core and Umbrella MSI files. Also, copy the Profiles folder and its subfolders (including the Umbrella profile added in Step 2).
20110243105684
- Open theIntuneWinAppUtil.exeapplication and specify
Intune_input
as the source folder, the Secure Client Core VPN MSI as the source setup file, andIntune_output
as the output folder. This generates the Secure Client Core VPN.intunewin
file.
- Confirm the creation of the Secure Client Core VPN
.intunewin
file in theIntune_output
folder.
20110510904980
20110579164820
- Repeat Step 6 for the Secure Client Umbrella Module MSI file. The embedded Umbrella profile creates the Secure Client Umbrella
.intunewin
file.
20110729750676
- Confirm the creation of the Secure Client Umbrella
.intunewin
file in theIntune_output
folder.
20110832832020
Upload and Configure Secure Client Core VPN .intunewin in Intune Portal
- Access the MS Intune Portal underHome > Apps > Windows. For Select app type, chooseWindows app (Win32)and clickSelect.
20112513277204
- ClickSelect app package file, upload the Secure Client Core VPN
.intunewin
file, and clickOK.
20112597413396
- Specify required information such asPublisherandCategory, then clickNext.
20112682982036
- Enter the installation command parameters. Use the default or refer to the Secure Client Admin Guide for supported parameters. For example, to use passive mode and disable the VPN module (so only Umbrella module displays in the UI), and log to
vpninstall.log
:
msiexec /i "cisco-secure-client-win-5.0.05040-core-vpn-predeploy-k9.msi" /passive PRE_DEPLOY_DISABLE_VPN=1 /lvx* vpninstall.log
- Specify device restart behavior, then clickNext.
20112813814036
- Specify the OS architecture and minimum OS version for devices that require the Secure Client Core VPN. Additional requirements can also be set.
20112918066836
- Optionally, configure detection rules to check if the Secure Client Core VPN is present. In this example, set detection rule type as
.msi
for any Secure Client Core VPN version.
20113069368724
- Skip the Dependencies section for Secure Client Core VPN by clickingNext.
20113130954388
- Optionally, configure Supersedence to update or replace an existing application. This applies only to Win32 apps. For more information, refer to MS Intune documentation. In this example, do not specify any application to be replaced and clickNext.
20113224899220
- Specify assignments for groups or devices that require Secure Client VPN Core installation. ClickNextafter assignment.
20114450720404
- Review the configuration and clickCreate.
20113349733652
- After creation, return to the MS Intune Portal underHome > Apps > Windowsto view the newly created AnyConnect Core VPN Win32 app.
20113372533652
Upload and Configure Secure Client Umbrella Module .intunewin in Intune Portal
- Repeat the process for the Secure Client Umbrella Module. In the MS Intune Portal, go toHome > Apps > Windows. For Select app type, chooseWindows app (Win32)and clickSelect.
20113516023828
- ClickSelect app package file, upload the Secure Client Umbrella
.intunewin
file, and clickOK.
20113626878740
- Specify required information such asPublisherandCategory, then clickNext.
20113677228180
- Enter the installation command parameters. Use the default or refer to the Secure Client Admin Guide for supported parameters. For example, to use passive mode and log to
umbrellainstall.log
:
msiexec /i "cisco-secure-client-win-5.0.05040-umbrella-predeploy-k9.msi" /passive /lvx* umbrellainstall.log
- Specify device restart behavior, then clickNext.
20113856190740
- Specify the OS architecture and minimum OS version for devices that require the Secure Client Umbrella Module. Additional requirements can also be set.
20113968568980
- Optionally, configure detection rules to check if the Secure Client Umbrella Module is present. In this example, set detection rule type as
.msi
for any Secure Client Umbrella Module version.
20114138920724
- In the Dependencies section, specify the Secure Client Core VPN module and setAutomatically Installto Yes. If the Secure Client Core VPN is not installed, Intune installs it before the Secure Client Umbrella Module. ClickNext.
20114235246740
- Optionally, configure Supersedence to update or replace an existing application. This applies only to Win32 apps. For more information, refer to MS Intune documentation. In this example, do not specify any application to be replaced and clickNext.
20114285889044
- Specify assignments for groups or users requiring the Secure Client Umbrella Module. In this example, assign to a device group called "Intune Group". Additional parameters can also be set. ClickNext.
20114450720404
- Review the configuration and clickCreate.
20114540608916
- After creation, return to the MS Intune Portal underHome > Apps > Windowsto verify the Secure Client Umbrella Module Win32 app has been created and assigned. Wait for deployment to the selected devices or users.
20114630676244
Verification
- Review successful installations by navigating toHome > Apps > All Appsand clicking onCisco Secure Client - Umbrella.
20117335896980
20117374902676
- On the target PC, verify that both the Secure Client Core VPN and Umbrella modules are installed, with only the Umbrella module UI visible.
20117776753940