Upgrade
The information below will help you upgrade to the latest version of Specops Password Policy. For information on upgrading to the latest version of Specops Client, see Specops Client Installation.
Supported upgrade environments
It is strongly recommended to keep Specops Password Policy updated to the latest version. When upgrading, all components should be upgraded. It is best practice to upgrade the components in the following order:
- Specops Client (if applicable)
- Administration Tools
- Specops Password Arbiter (if applicable)
- Specops Password Policy Sentinel
Note
After upgrading Specops Password Policy Sentinel on a domain controller (DC), the DC should immediately be restarted. It is recommended to upgrade and restart one or a few, but not all, DCs at the time, to make sure there always is one or more DCs available to serve the Active Directory environment.
Planning an upgrade
Before upgrading, you should:
- Read the Specops Password Policy Release Notes. The Release Notes provide a summary of new features and changes since the last release. The Release Notes can help you evaluate whether an upgrade is necessary.
- Locate and read the Specops Password Policy Product Documentation.
- If you are upgrading to a new major version (for example, from version 5.xx to 6.xx), you will need a new license key before upgrading. Contact your sales representative for more information.
Requirements
To upgrade to the latest version, your organization’s environment must meet the system requirements.
Upgrading Specops Password Policy
Note
Upgrading Specops Password Policy requires domain administrator privileges.
The Setup Assistant will allow you to upgrade the required components. To start upgrading, follow the below tasks:
- Download the Setup Assistant.
-
Save and Run the Setup Assistant locally to a machine where you administer Group Policy.
Note
By default the file is extracted to
C:\temp\SpecopsPasswordPolicy_Setup_[VersionNumber] -
Double click SpecopsPasswordPolicy.Setup.exe to launch the Setup Assistant.
- To begin, click Start Installation in the Specops Setup Assistant dialog box.
Upgrading the Administration Tools
The Administration Tools are used to configure the central aspects of the solution and enable the creation of Specops Password Policy Settings in Group Policy Objects.
- From the Setup Assistant, select Administration Tools.
- Click Install.
The Domain Administration tool, Group Policy snap-in extension, and ADUC menu extensions will be updated.
Upgrading the Specops Password Policy Sentinel
Note
To upgrade the Specops Password Policy Sentinel, it is required to upgrade the MSI on all writable DCs. After upgrading, each DC needs to be rebooted.
It is not necessary to apply the MSI to all DCs at once, but once the MSI is deployed to a DC, it should be rebooted after the upgrade without delay.
One strategy is to upgrade and reboot all DCs at once.
However, in larger environments, it is unlikely that all DCs can be rebooted at the same time.
For such environments, upgrade a few DCs at a time; install and reboot so they eventually all have the latest Sentinel MSI.
Warning
Do NOT upgrade all DCs with the latest Sentinel MSI first, and wait with rebooting them. That could leave Specops Password Policy in a state where it is not functional.
New features in a policy should not be configured until all DCs have been upgraded and rebooted.
The Specops Sentinel ensures that password change requests comply with the Specops Password Policy assigned to the user object through Group Policy.
- From the Setup Assistant, select Domain Controller Sentinel to install the Sentinel.
- The grid will show all available DCs and the state for their Specops Password Policy Sentinel installation.
- Select one or more DCs that need upgrading (make sure to read the note and warning sections above first).
- Click Install.
- Reboot the upgraded DCs.
Upgrade the Specops Client
Specops Client displays the password policy rules when a user fails to meet the policy criteria when changing their password. The Client also notifies users when their passwords are about to expire.
You can automatically upgrade an existing Group Policy Object with Software Installation settings to deploy Specops Client in your domain.
- From the Setup Assistant, select Deploy Specops Password Client using GPSI.
- To select the Group Policy Object that will be used to deploy the Client, click Select GPO.
- Select an existing GPO from the list.
-
Click Download… to download the installation files for Specops Client.
- In the dialog box, click Download Files.
- When the dialog box is complete, click OK.
-
You can create a new share or select an existing share. To select an existing share you must copy the Specops Client MSI package into the appropriate share.
Note
The files can be copied from
C:\temp\SpecopsPasswordPolicy_Setup[VersionNumber]\products\specopspasswordpolicy -
Click Select Share.
-
Browse to the location of the network share, or enter the location of the share name.
Note
It is recommended that you use a Distributed File Share (DFS). If DFS is used with load balancing, verify that the setup files are copied to all servers before proceeding.
-
To upgrade the packages for x86 and x64 deployments in the selected GPO, click Add Settings.
Note
The Specops Client MSI will be deployed through a computer software installation and may not take effect until the computers have been restarted.