Group Policy, Operations

Deploy single EXE applications without installers

Suppose we have the following requirement:

  • "DummyTest" application is a single EXE application with a configuration file
  • "DummyTest" application should be installed for all users in Group "Some Group 1", "Some Group 2" and "Some Group 3"
  • Group "Some Group 1", "Some Group 2" and "Some Group 3" have different configuration files
  • Users must have a desktop icon to access "DummyTest" application

Preperation

First thing is to copy the EXE file and config file to a network location.
In this article I use the domain Netlogon DFS share because the application is small and because the share is highly available and distributed.
After this duplicates are create for configuration file so that we have three, each with different configuration

EXE and config files on NETLOGON share

1) Deploying the EXE

a) Create a GPO Add the EXE into User Configuration > Preferences > Windows Settings > Files.
Note that when you specify the source file location, ensure you use the network location for the file

GPO file preference source path selection

b) Specify the destination file. This will be the location on the target user's profiles. You can press F3 to get a neat list of all the variables available.

GPO variable reference list for destination path

c) In this case the file will be deployed in %AppDataDir%\Dummy with name Dummy.exe.
Note this is the path that we need to point shortcut to in a later step

GPO file destination path configuration

d) Select the Common tab and tick "Remove this item when it is no longer applied" and "Item-level targeting". The EXE must be deployed when use is member of any of the three groups.
This is done by changing the item filtering to OR

GPO Common tab with item-level targeting and OR filter

2) Deploying the configuration file

The deploying of the configuration file is similar to the deploying of the EXE except that depending on the group membership, you will get one of three files and the destination file will always have the same name

Config file deployment for group 1
Config file deployment for group 2
Config file deployment for group 3

3) Deploying the shortcut

a) Add the shortcut into User Configuration > Preferences > Windows Settings > Shortcuts.
Note that the "Target Path" is the destination file from the EXE deploy task

GPO shortcut preference with target path

b) The shortcut should be deployed to users that are members of any of the three groups

Shortcut item-level targeting with security groups

The end result is that when a user is added to any of the three groups, they will get an EXE, configuration file and a shortcut. The configuration file is different for the three groups.

Also, if you remove user from group, the EXE, configuration file and shortcut will be removed

Posted on

Tagged Tools

No comments yet

Comments are moderated and appear once approved.