Precision Desktop Management

Securing IT starts by managing IT

Network discovery

Criston Precision introduces an auto-discovery feature for each agent which enables the automatic creation of a network topology overview.

- Better control of assets
- Accurate tracking of unmanaged devices
- Possibility to push agent on unmanaged device
- Fast navigation and search
- Colored icons display device status
- Self-adapts to network infrastructure
- Queries/reports available

Operational inventories

Criston offers accurate IT inventory tracking functionality covering hardware, software and security configurations across Windows and Linux workstations, laptop, servers and mobile devices.

Multi-platform
- Intelligent hardware inventory correlates data from multiple OS
- Simplifies analysis through data correlation

WMI support
- On Windows platform, provides native access to WMI classes
- Accurate source of data for better decision support

Configurable
- Data to gather can be granularly selected
- Inventory can be scheduled
- Filters can be applied for tailored inventory reporting

Optimized
- Differential inventory upload (keeps history of changes)
- Bandwidth throttling for inventory uploads
- Scalable to manage tens of thousands of devices from one central server

Unconnected device inventory
- An executable can be run from a CD or USB key to gather hardware inventory on a device that is not networked
- Manages isolated sites

Security configuration inventories

Criston Precision includes a set of rules to create standard security configurations. For instance, administrators can create policies to lock/unlock USB storage devices and configure the Windows XP firewall.

- The software distribution and configuration capabilities allow Criston Precision users to package and deploy standard security configurations
- Speeds up security policy implementation
- Security configuration status (Installed /Enabled/ Disabled/Versions of Antivirus, Firewall, Automatic Update, Shared folders, weak passwords…)

Configuration Deployment

In addition to software distribution, Criston Precision includes a graphical policy editor that automates system configuration, allowing administrators to manage 10,000 desktops as easily as 10. Criston Precision includes a wide library of components that cover all aspects of desktop configuration – operating system, applications, shortcuts, drive mappings, printers, security policies, profiles, etc.

Through advanced scheduling, administrators granularly plan deployments, regular maintenance tasks, or monitoring operations.

- Automates IT management process for reduced operations costs and more efficient response to business changes

Streamlined systems configuration
- Wide range of configurable parameters including files, shortcuts, drive mapping, registry configuration, user profiles, USB device lock etc
- Standardizes configurations for higher quality

Automated maintenance tasks
- Wide range of actions that can be performed on a regular basis including file operations, backup, system shutdown/restart

Advanced scheduling
- Criston Precision includes a comprehensive scheduler that can be time or event-based

Dependency management
- A hierarchy of rules can be created so dependant rules are automatically executed if needed

Automatic rule Synchronization
- Clients automatically synchronize when they are plugged back into the network

Granular status
- Granular statuses and error messages are stored on the master server so the console can display precise installation log
- Keeps track of configuration deployment status

Software Deployment

To facilitate software deployment to large numbers of devices, Criston Precision integrates a software packaging module which can automatically provide ready-to-deploy packages.

MSI packager
- Leverages MSI technology investment
- Easy access to all MSI installation options
- Support for MST, network and administrative installations

Custom packager
- Collects any file into a package
- Can be configured to run command after installation
- Supports network installations

RPM packager
- Leverages RPM technology investment
- Native support for RPM packages
- Easy access to all RPM installation options

Snapshot packager
- Builds system snapshot before and after installation
- Customizable through scripts

Secure deployments
- Supports standard ZIP or proprietary package format
- Checksum verification prevents package corruption

Easy customization
- Can execute packages as logged on user or specific user
- Packages are easy to customize through library of configuration rules
- Access to scripting language before/after execution procedures
- Verification options prevent package download if pre-requisites not met (missing dependency, not enough disk space etc)

Package publication
- Packages can be published to master server (central repository) or directly stored on relay agents

Applications Management

Prohibited Applications

Criston Precision can prevent certain applications from running. Administrators define backlists or whitelists of applications by either selecting an application profile in the software inventory or manually entering application signature (name, version or other fields). Policies are then deployed automatically to devices or groups of devices and the agents will stop any process that is recognized as unauthorized.

Application blacklist and whitelist creation
- Multiple blacklists are possible
- Manual addition of software signature
- Direct addition of software signature from inventory
- Adapts to any type of application

Ability to assign different policies to different groups
- Forbidden or allowed applications are assigned to selected groups
- Provides the flexibility of assigning different policies to different devices

Active even if executable name changed
- Application monitoring is independent from executable filename so if the user renames a file, the software will still be forbidden

Statistical reports on forbidden application launch
- Reports can be used to analyze the history of forbidden applications launch (by user, device, application etc)
- Keeps track of suspect behaviour

Monitored Applications

Application monitoring provides Criston Precision administrators with direct visibility on installed applications and enables software inventory data correlation based on the following categories: purchased software/installed software/used software.

Statistical reports on application usage
- Reports can be used to analyze the history of applications usage (by user, device, application, time of day etc)
- Lowers cost of software licenses and maintenance

Protected Applications

Criston Precision’s self-healing technology proactively detects unintentional application, file and configuration changes and automatically corrects errors on client systems so that end-user service quality is maintained.

- Lowers maintenance costs
- Can repair applications even when the system is offline by using local backup
- Peer download: agents can search for other devices that have the same application installed, and automatically download non-corrupt file

System monitoring

Event Monitoring

Criston Precision integrates pre-defined event notification that will proactively prevent system failures.

- Real-time information-gathering and diagnostics using Windows events (application, system and security)
- Allows for proactive monitoring

Automatic corrective actions
- Prevents system failure and avoids downtime
- Criston agents can automatically launch corrective actions if certain Windows events occur

Performance Monitoring

Criston Precision can access performance counters on clients so administrators can monitor performance, request automatic event notification, execute automatic corrective actions.

- Real-time information-gathering and diagnostics
- Detailed system health and performance monitoring
- Event and report generation
- Allows for proactive monitoring

Automatic corrective actions
- Prevents system failure and avoids downtime
- Criston agents can automatically launch corrective actions if certain thresholds are reached

Resource Monitoring

Compliance requirements can be fulfilled by using Criston Precision to monitor file, internet and print-job monitoring at device level. Reports can be generated to analyze results by user, device, time of day etc.

File access monitoring
- Real-time information-gathering about file accesses in given monitored directories

Internet access monitoring
- Real-time information-gathering about browsed URLs

Printing monitoring
- Real-time information-gathering about print jobs

Monitoring reports
- Statistical and monitoring reports are available to display history of accesses

Remote Control

The Remote Control features in Criston Precision give IT administrators the capacity to remotely support and train end-users.

Secure
- Authenticated and encrypted communications
- User acknowledgement is configurable for each administrator profile
- If no user is connected, remote control can be forced
- Adapts to company policies

Logging
- Each remote control session is logged in a central audit file
- Client log file also locally records sessions

Helpdesk actions
- Allows for quick problem resolution
- Command execution in power user mode
- Restart target device
- File transfer
- Clipboard management

Portable
- Multi-platform console
- Video driver independent

Configurable
- Automatically adapts to available bandwidth
- Locks remote keyboard/mouse while connected
- Read-only (administrator cannot act on the target device)

Direct Access

Additional remote functions are directly integrated into the administration console to simplify and speed up helpdesk tasks, remote configurations operations, and support end-user, without work time interruption. Remote & silent access to:

- File system explorer
- Registry editor
- Windows service manager
- Windows task manager
- Windows event manager
- Agent configuration

Power Management

Criston Precision includes a set of configuration rules targeted at standardizing power settings on the different types of systems. Ensuring PCs can go into hibernation and yet restart quickly again will be vital in weaning users off an over-reliance upon stand-by where machines still use up to 96% of normal operating power.

Power management settings inventory
- Inventories power management profiles on each machine
- Tracks machines configuration to define best energy saving policy

Power management profile deployment
- Creates and deploys standard power management profiles
- Provides the flexibility of assigning different policies to different devices

Hibernation setup
- Activates hibernation even on desktops
- Allows energy savings without loss in productivity

Automatic wake-up
- Centrally managed wake-on-LAN to wake machines up before users come to work
- Allows energy savings without loss in productivity