AI Preview
Is this content worth your time? Use the quick preview to decide.
Welcome to Techaptic!
In today’s guide, we dive deep into ManageEngine Endpoint Central, a unified endpoint management solution that simplifies controlling servers, laptops, desktops, and mobile devices from a single location.
While the “Next-Next-Finish” installation might seem straightforward, a robust production environment requires detailed attention to prerequisites and post-installation configurations. In this post, we cover the entire process: from setting up NAT and SSL certificates to ensure secure agent communication, to configuring Active Directory integration and Database Backups for operational continuity. Follow along to ensure your Endpoint Central server is optimized for performance and security from day one.
🔗 Helpful Links
ManageEngine Endpoint Central Free Trial: https://www.manageengine.com/products/desktop-central/download.html
Video Tutorial


You need to accept cookies to watch this video.
Quiz
Downloadable Resources
To download the exclusive resource prepared for this content, you need to subscribe to our free email newsletter. Please fill out the form below; the download link will be sent to your email address. You can unsubscribe at any time.
Endpoint Central Installation Checklist For Best Practices (.pdf)
Full Transcript
INTRODUCTION
Hello and welcome to Techaptic.
Today, we are going to install ManageEngine Endpoint Central. However, we will not simply install the software and leave it with its default settings. We will also configure the most important options so that the server is prepared for reliable and secure use in a production environment.
Although the Endpoint Central installation wizard may look straightforward, overlooking hardware, software, database, or network prerequisites can cause performance problems and technical issues later.
In this video, we will first review the essential prerequisites and then proceed with the ManageEngine Endpoint Central installation. After the installation is complete, we will become familiar with the web console and configure the core server settings according to practical best practices.
By the end of this video, you will not only know how to install ManageEngine Endpoint Central, but you will also understand how to configure its most critical initial settings.
If you are ready, let’s get started.
𝗪𝗛𝗔𝗧 𝗜𝗦 𝗠𝗔𝗡𝗔𝗚𝗘𝗘𝗡𝗚𝗜𝗡𝗘 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟?
ManageEngine Endpoint Central is a Unified Endpoint Management, or UEM, solution.
A Unified Endpoint Management platform allows IT administrators and technicians to manage different operating systems and endpoint technologies from a single centralized console. Depending on the selected edition, license, and add-ons, Endpoint Central can manage Windows, macOS, Linux, and mobile devices.
The product includes several endpoint administration capabilities, such as patch management, software deployment, configuration management, asset and inventory management, remote control, operating system deployment, application control, vulnerability management, browser security, mobile device management, and many other functions.
The exact modules available in your environment depend on the edition, license, and optional security add-ons that you use.
Like other enterprise UEM platforms, Endpoint Central also has specific hardware, software, database, and network requirements that should be reviewed before installation.
𝗥𝗘𝗩𝗜𝗘𝗪𝗜𝗡𝗚 𝗧𝗛𝗘 𝗛𝗔𝗥𝗗𝗪𝗔𝗥𝗘 𝗔𝗡𝗗 𝗦𝗢𝗙𝗧𝗪𝗔𝗥𝗘 𝗥𝗘𝗤𝗨𝗜𝗥𝗘𝗠𝗘𝗡𝗧𝗦
On the product requirements page, you can review the hardware requirements and the supported software requirements.
The published hardware values should be treated as a starting point rather than as universal sizing values for every organization.
The required processor, memory, storage, and database resources depend on several factors. These include the number of managed endpoints, the number of technicians, the enabled product modules, the selected license, the number and frequency of reports, patch and software repository usage, inventory data, database growth, and how frequently devices communicate with the central server.
The basic requirements may be suitable for an environment containing approximately 500 to 1,000 endpoints and a limited number of technicians. However, larger environments and installations using more modules will require additional resources.
Before building the server, evaluate your expected endpoint count, future growth, retention settings, enabled features, and technician activity. It is always better to size the server with enough capacity for future expansion rather than assigning only the minimum resources required for the initial installation.
𝗖𝗛𝗢𝗢𝗦𝗜𝗡𝗚 𝗕𝗘𝗧𝗪𝗘𝗘𝗡 𝗕𝗨𝗡𝗗𝗟𝗘𝗗 𝗣𝗢𝗦𝗧𝗚𝗥𝗘𝗦𝗤𝗟 𝗔𝗡𝗗 𝗠𝗜𝗖𝗥𝗢𝗦𝗢𝗙𝗧 𝗦𝗤𝗟 𝗦𝗘𝗥𝗩𝗘𝗥
ManageEngine Endpoint Central includes a bundled PostgreSQL database, which makes the initial installation easier because a separate database server is not required.
The bundled PostgreSQL database may be suitable for small and medium-sized environments. However, when the number of managed endpoints approaches approximately 3,000 or when the installation becomes more demanding, I strongly recommend evaluating Microsoft SQL Server as the external database platform.
The final database decision should be based on the current Endpoint Central sizing documentation, the total endpoint count, expected database growth, reporting requirements, high-availability needs, backup strategy, and your organization’s existing database standards.
If Microsoft SQL Server will be used, its server, instance, authentication, permissions, connectivity, backup, maintenance, and high-availability requirements should be prepared before the Endpoint Central migration or integration.
𝗨𝗡𝗗𝗘𝗥𝗦𝗧𝗔𝗡𝗗𝗜𝗡𝗚 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗡𝗘𝗧𝗪𝗢𝗥𝗞 𝗥𝗘𝗤𝗨𝗜𝗥𝗘𝗠𝗘𝗡𝗧𝗦
Endpoint Central also has several network requirements.
For the initial installation and the configurations demonstrated in this video, the main requirements include internet access from the central server, technician access to the Endpoint Central web console, communication with Active Directory, and communication with the organization’s outgoing mail server.
However, these are not all of the ports and network flows that may be required by Endpoint Central.
Different features require different communication paths. For example, deploying agents, managing remote offices, distributing software, downloading and deploying patches, remotely controlling computers, deploying operating systems, managing mobile devices, using a Secure Gateway Server, and enabling security add-ons can introduce additional ports and infrastructure requirements.
When we cover those modules in later videos, I will also explain the relevant ports, traffic directions, and infrastructure dependencies.
For now, we will focus only on the communication requirements needed for the initial server installation and post-installation configuration.
𝗣𝗥𝗘𝗣𝗔𝗥𝗜𝗡𝗚 𝗧𝗛𝗘 𝗦𝗘𝗥𝗩𝗘𝗥 𝗕𝗘𝗙𝗢𝗥𝗘 𝗜𝗡𝗦𝗧𝗔𝗟𝗟𝗔𝗧𝗜𝗢𝗡
Before beginning the Endpoint Central installation, I want to share several recommendations that will help prepare the environment correctly.
First, the Endpoint Central server should use a static IP address. The IP address should not change after agents have been distributed because agents and supporting components must be able to communicate with the central server consistently.
Second, I recommend configuring the Windows regional format and system locale as English, United States, especially when this setting is recommended by the product documentation or support team. Consistent regional settings can help avoid date, number, database, and script interpretation problems.
Third, confirm that the server has sufficient processor, memory, and disk resources for the expected endpoint count and enabled features.
The operating system should also be fully updated, supported by the Endpoint Central version you are installing, and protected according to your organization’s server security standards.
You should also decide on the server hostname, DNS name, FQDN, database platform, service account requirements, firewall rules, backup destination, and certificate strategy before distributing any agents.
Once these prerequisites have been reviewed, we can download the Endpoint Central installer and begin the installation.
𝗗𝗢𝗪𝗡𝗟𝗢𝗔𝗗𝗜𝗡𝗚 𝗧𝗛𝗘 𝗠𝗔𝗡𝗔𝗚𝗘𝗘𝗡𝗚𝗜𝗡𝗘 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗧𝗥𝗜𝗔𝗟
To download the installer, search for the ManageEngine Endpoint Central free trial and open the official product download page.
The trial edition allows us to evaluate the product for a limited period and test its available capabilities before purchasing a license.
On the download page, select the On-Premises edition because we are installing Endpoint Central on our own Windows server.
Before downloading the on-premises edition, it is also worth considering the Endpoint Central Cloud edition if you do not want to allocate and maintain an internal server.
The cloud edition can be useful for organizations that want to begin endpoint management quickly without building an on-premises infrastructure. A free cloud edition may also be available for a limited number of devices, allowing you to register mobile devices and manage a small number of computers.
For this video, however, we will continue with Endpoint Central On-Premises.
Click Download and save the installer to the server.
I will fast-forward the download process so that we can continue without waiting.
𝗜𝗡𝗦𝗧𝗔𝗟𝗟𝗜𝗡𝗚 𝗠𝗔𝗡𝗔𝗚𝗘𝗘𝗡𝗚𝗜𝗡𝗘 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟
After the download is complete, open the folder containing the installation file and double-click the executable.
The Endpoint Central installation process is straightforward. Like many ManageEngine products, the wizard can be completed quickly when the prerequisites have already been prepared.
On the welcome screen, click Next.
Review the license agreement, accept it if you agree, and continue.
The wizard then asks for the destination folder.
The default path is under Program Files. In this demonstration, I will use a dedicated ManageEngine installation directory. You can keep the default location or select another supported local path according to your server and storage design.
Avoid using an unstable, removable, or network-mounted destination for the main product installation.
The installer also displays the web console ports.
The default HTTP port is 8020, and the default HTTPS port is 8383. You can keep these values unless they conflict with another application or your organization requires different ports.
If you change these ports, remember to update the local firewall, network firewall, load balancer, reverse proxy, monitoring system, bookmarks, and any documentation that refers to the Endpoint Central web console.
Continue through the wizard by clicking Next.
The installation will take a few minutes.
The wizard may ask for registration or contact information. For this demonstration, I will skip that section.
When the installation is complete, click Finish.
Endpoint Central will start its central server service and initialize the required product modules.
𝗖𝗛𝗘𝗖𝗞𝗜𝗡𝗚 𝗧𝗛𝗘 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗪𝗜𝗡𝗗𝗢𝗪𝗦 𝗦𝗘𝗥𝗩𝗜𝗖𝗘𝗦
After installation, open the Windows Services console.
You will see ManageEngine-related services installed on the server. The main Endpoint Central server service must be running for the product and web console to operate.
The service may take several minutes to start for the first time because Endpoint Central initializes its modules, creates database structures, and prepares the web console.
Do not assume that the server is ready only because the Windows service status has changed to Running. The application may still be loading internal modules in the background.
𝗠𝗢𝗡𝗜𝗧𝗢𝗥𝗜𝗡𝗚 𝗦𝗧𝗔𝗥𝗧𝗨𝗣 𝗧𝗛𝗥𝗢𝗨𝗚𝗛 𝗧𝗛𝗘 𝗪𝗥𝗔𝗣𝗣𝗘𝗥 𝗟𝗢𝗚
To monitor the startup process, open the Endpoint Central installation directory and then open the logs folder.
Locate the wrapper log file, commonly named wrapper.txt.
This log records the startup of the central server and its internal modules. If Endpoint Central does not start correctly, the wrapper log is one of the first files you should review.
Open the file and scroll to the bottom.
You can see the modules loading with their corresponding timestamps. If a component cannot start, the log may contain the related error, exception, port conflict, database connection problem, or module failure.
The file does not always refresh dynamically while it is open. To see new entries, close and reopen it, or use a log viewer that can follow changes in real time.
When the log reports that the server has started and is listening successfully, the web console should be ready.
Some internal ports may appear in the wrapper log. Do not confuse those internal module ports with the HTTP and HTTPS ports used to access the web console.
𝗢𝗣𝗘𝗡𝗜𝗡𝗚 𝗧𝗛𝗘 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗪𝗘𝗕 𝗖𝗢𝗡𝗦𝗢𝗟𝗘
To open the web console over HTTP, enter the server address followed by port 8020.
To use HTTPS, enter HTTPS at the beginning of the address and use port 8383.
At this stage, the HTTPS connection may use the default self-signed certificate, so the browser may display a certificate warning.
Once the web console opens, we can begin the post-installation configuration.
Even though some of the settings shown in this video are optional, I strongly recommend reviewing each one and applying the options that are appropriate for your environment.
𝗦𝗜𝗚𝗡𝗜𝗡𝗚 𝗜𝗡 𝗙𝗢𝗥 𝗧𝗛𝗘 𝗙𝗜𝗥𝗦𝗧 𝗧𝗜𝗠𝗘
The default username and password for the initial login are admin and admin.
Enter the credentials and click Sign In.
After signing in, Endpoint Central displays a welcome or onboarding window that highlights several configurations required to begin using the product.
Before moving to endpoint management modules, we will configure the most important server settings from the Admin tab.
𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗜𝗡𝗚 𝗧𝗛𝗘 𝗣𝗥𝗢𝗫𝗬 𝗦𝗘𝗧𝗧𝗜𝗡𝗚𝗦
The first configuration is the proxy setting.
Endpoint Central needs to know how the central server can access the internet. Depending on your environment, the server may use a direct internet connection, connect through an authenticated or unauthenticated proxy server, or operate in an isolated network without internet access.
Open the proxy configuration from the onboarding reminder or the Admin settings.
In this environment, the server has direct internet access, so I will select Direct Connection to the Internet and click Save.
Endpoint Central then tests access to the required ManageEngine or content-delivery addresses used for product communication, patch metadata, software catalogs, and other online services.
As you can see, the connectivity test completes successfully.
If the test fails, review the server’s DNS configuration, default gateway, proxy settings, SSL inspection, outbound firewall rules, and access to the required vendor FQDNs.
𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗜𝗡𝗚 𝗡𝗔𝗧 𝗦𝗘𝗧𝗧𝗜𝗡𝗚𝗦 𝗔𝗡𝗗 𝗧𝗛𝗘 𝗦𝗘𝗥𝗩𝗘𝗥 𝗙𝗤𝗗𝗡
Next, return to the Admin tab.
Under Server Settings, open NAT Settings.
NAT Settings are extremely important because they define the server name that Endpoint Central agents use when communicating with the central server.
In this example, the environment will manage agents only inside the local network, so I will select the Inside LAN option.
When Inside LAN is selected, agents connect to Endpoint Central through the internal network and internal DNS.
If the environment includes roaming endpoints outside the corporate network, a Secure Gateway Server can be used to provide protected external communication. In that type of design, the Via Internet option and public connectivity requirements must also be considered.
The FQDN should be selected carefully before agents are deployed.
Changing the Endpoint Central FQDN after agent distribution may require additional certificate, DNS, NAT, Secure Gateway Server, and agent communication steps. For that reason, define a stable and meaningful FQDN at the beginning of the implementation.
𝗖𝗥𝗘𝗔𝗧𝗜𝗡𝗚 𝗧𝗛𝗘 𝗜𝗡𝗧𝗘𝗥𝗡𝗔𝗟 𝗗𝗡𝗦 𝗔 𝗥𝗘𝗖𝗢𝗥𝗗
Before entering the FQDN in Endpoint Central, create the corresponding DNS record.
First, confirm the static IP address assigned to the Endpoint Central server. In this example, the server uses 192.168.10.12.
Open DNS Manager on the Active Directory DNS server.
Under the appropriate Forward Lookup Zone, create a new Host, or A, record.
For this example, I will use a name such as epc.ginar.com and map it to the Endpoint Central server’s IP address.
After creating the record, verify that the FQDN resolves to the correct server address from the Endpoint Central server, technician computers, and future managed endpoints.
If you select Via Internet and plan to manage roaming devices through a Secure Gateway Server, the required public DNS record must also be created. External agents query public DNS and must reach the externally published service according to the Secure Gateway Server architecture.
Because this example uses only the Inside LAN option, the internal DNS record is sufficient.
Return to Endpoint Central, enter the selected FQDN, and save the NAT settings.
Endpoint Central warns that changing the server communication name can affect existing agents. Because no agents have been distributed yet, we can proceed safely.
The product requests a central server restart after the NAT setting is changed.
Before restarting, we will also configure an SSL certificate that matches this FQDN. This allows us to apply both changes with a single restart.
𝗨𝗣𝗟𝗢𝗔𝗗𝗜𝗡𝗚 𝗔 𝗧𝗥𝗨𝗦𝗧𝗘𝗗 𝗦𝗦𝗟 𝗖𝗘𝗥𝗧𝗜𝗙𝗜𝗖𝗔𝗧𝗘
Return to the Admin tab.
Under Security and Privacy, open Manage SSL Certificate.
By default, Endpoint Central uses a self-signed certificate. The self-signed certificate can be sufficient for a lab or test environment, and the product can renew it automatically.
For a production environment, however, I recommend using a trusted certificate that matches the Endpoint Central FQDN.
You can use a certificate issued by a public certificate authority or by your organization’s internal Active Directory Certificate Services infrastructure, depending on how the server will be accessed and which devices must trust it.
For an internally accessible server, an internal certificate authority may be suitable as long as every managed endpoint and technician device trusts the complete certificate chain.
In this example, I have already created a wildcard certificate through Active Directory Certificate Services.
The certificate must include the required private key and should normally be exported in PFX format.
Click Browse and select the PFX certificate.
Enter the certificate password and continue.
The certificate’s Common Name or Subject Alternative Name must match the FQDN that agents and technicians use to connect to Endpoint Central.
Endpoint Central displays a warning explaining that the root certificate of the uploaded SSL certificate must exist in the trusted certificate store of all endpoints.
This means that clients must trust the certificate authority that issued the Endpoint Central certificate. For Windows computers, the required root certificate should normally be present under Trusted Root Certification Authorities.
Because this certificate was issued by the Active Directory Certificate Authority and domain computers trust that authority, we can continue.
Click Proceed and save the certificate.
The interface now shows the certificate issuer, certificate name, domain information, and validity details.
𝗥𝗘𝗦𝗧𝗔𝗥𝗧𝗜𝗡𝗚 𝗧𝗛𝗘 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗦𝗘𝗥𝗩𝗘𝗥
The central server must be restarted to activate the new FQDN and SSL certificate.
Open Services and locate the main ManageEngine Endpoint Central server service.
Restart the service.
The web console will be temporarily unavailable while the service and product modules restart.
Use the wrapper log again to monitor the startup process.
When the log reports that the server has started successfully, return to the web console.
Open the console by using the newly configured FQDN and HTTPS port 8383.
Check the browser certificate details.
As you can see, the new certificate is active and the FQDN matches the server address.
Sign in again.
𝗘𝗡𝗙𝗢𝗥𝗖𝗜𝗡𝗚 𝗛𝗧𝗧𝗣𝗦 𝗖𝗢𝗠𝗠𝗨𝗡𝗜𝗖𝗔𝗧𝗜𝗢𝗡
Endpoint Central may display a security notification recommending HTTPS-only communication.
Return to the Admin tab and open the relevant Security Settings.
Enable HTTPS communication for the Endpoint Central server.
Confirm the change.
The system may restart the service automatically. If it does not, restart the central server manually after completing the remaining changes.
Enforcing HTTPS helps protect technician sessions, credentials, and data exchanged between the browser and the Endpoint Central server.
The uploaded certificate must remain valid and trusted by all systems that connect to the service.
𝗜𝗡𝗧𝗘𝗚𝗥𝗔𝗧𝗜𝗡𝗚 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗪𝗜𝗧𝗛 𝗔𝗖𝗧𝗜𝗩𝗘 𝗗𝗜𝗥𝗘𝗖𝗧𝗢𝗥𝗬
The next configuration is Active Directory integration.
Open the Admin tab and then navigate to the Domain configuration under Agent Settings.
Active Directory integration is useful for several reasons.
First, it allows Active Directory users to be added as Endpoint Central technicians, depending on the product configuration and assigned roles.
Second, it simplifies agent deployment because Endpoint Central can retrieve domain computer objects and display them in the console.
Third, it provides access to several Active Directory-related reports.
The domain is currently configured as a workgroup entry. Change the domain type to Active Directory and enter the required domain information.
In this test environment, the Active Directory domain is ginar.local, and the domain controller is AD.
Enter the username and password for the account that Endpoint Central will use.
A standard domain account may be sufficient for reading Active Directory objects and synchronizing domain information. However, if the same credentials will be used for remote agent installation, the account must also have the required administrative permissions on the target endpoints.
In a production environment, avoid using a Domain Administrator account for routine synchronization or deployment. A delegated service account with only the required permissions is a better security practice.
Because this is a test environment, I will use a Domain Administrator account for the demonstration.
𝗖𝗛𝗢𝗢𝗦𝗜𝗡𝗚 𝗟𝗗𝗔𝗣 𝗢𝗥 𝗟𝗗𝗔𝗣𝗦
Endpoint Central allows Active Directory communication over standard LDAP or secure LDAPS.
Standard LDAP normally uses TCP port 389.
When SSL communication is enabled, LDAPS normally uses TCP port 636.
For this demonstration, I will continue without enabling LDAPS.
In a production environment, consider using secure LDAP if your domain controllers and certificate infrastructure are configured for it.
After entering the credentials, continue.
If the console reports an incorrect username or password, verify the account format, password, domain name, domain controller name, DNS resolution, account status, and required ports.
After correcting the credentials, submit the configuration again.
𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗜𝗡𝗚 𝗔𝗖𝗧𝗜𝗩𝗘 𝗗𝗜𝗥𝗘𝗖𝗧𝗢𝗥𝗬 𝗦𝗬𝗡𝗖𝗛𝗥𝗢𝗡𝗜𝗭𝗔𝗧𝗜𝗢𝗡
Endpoint Central asks how frequently it should synchronize objects from Active Directory.
Synchronizing once per day is usually sufficient for many environments. If computer and organizational unit changes occur frequently, you can select twice per day or every six hours.
For this demonstration, I will keep the daily synchronization.
Make sure the time zone and synchronization time are appropriate for your location and operating schedule.
Click Modify Domain.
The synchronization status changes to Started.
After the synchronization is complete, the console will update the domain, organizational unit, and computer object information.
You can also check the synchronization status from the Computers section.
Open Computers and select Add Computers.
The synchronization status is displayed at the top of the window. After the objects are imported, the domain computers become available for agent deployment.
As you can see, Endpoint Central has retrieved several computers from Active Directory.
We will not deploy agents in this video, so I will close this section.
The Active Directory integration is now complete.
𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗜𝗡𝗚 𝗧𝗛𝗘 𝗢𝗨𝗧𝗚𝗢𝗜𝗡𝗚 𝗠𝗔𝗜𝗟 𝗦𝗘𝗥𝗩𝗘𝗥
The next important configuration is the outgoing mail server.
Open the Admin tab and then open Mail Server Settings.
Endpoint Central uses the mail server to send alerts, scheduled reports, password-related notifications, approval messages, and other product emails.
Depending on your mail platform, Endpoint Central may support basic authentication or OAuth authentication.
OAuth is generally more secure than basic authentication because it avoids storing and transmitting a traditional mailbox password in the same way. If OAuth is supported by your mail environment and Endpoint Central version, I recommend using it.
I do not have an Exchange or SMTP server in this lab, so I will not complete the mail server configuration. However, let’s review the required fields.
The Server Name field contains the outgoing SMTP server name or FQDN.
The port is commonly 25, 465, or 587, depending on the mail server and encryption method.
The Sender Name can be something meaningful, such as ManageEngine Endpoint Central or Endpoint Management.
The Sender Email Address must be a valid address that the mail server permits to send messages.
Depending on your environment, you may also need to configure SMTP relay permissions so that the Endpoint Central server can send email.
Choose the appropriate security option, such as SMTP, SMTPS, STARTTLS, or TLS, according to the available product fields and your mail server configuration.
If the mail server requires authentication, enter the credentials or configure OAuth for the sender account.
Use the Test Email Address field to send a test message.
Do not consider the configuration complete until the test email is received successfully.
Mail settings should be configured before adding users who require email confirmation or before enabling scheduled reports and notifications.
𝗖𝗛𝗔𝗡𝗚𝗜𝗡𝗚 𝗧𝗛𝗘 𝗗𝗘𝗙𝗔𝗨𝗟𝗧 𝗔𝗗𝗠𝗜𝗡 𝗣𝗔𝗦𝗦𝗪𝗢𝗥𝗗
The default Endpoint Central username and password are admin and admin.
Because Endpoint Central is a critical management server with extensive control over endpoints, keeping the default password would create a serious security risk.
The password must be changed immediately after the initial login.
Open the user menu in the upper-right corner and select Personalize.
Under Authentication, enter the current password and then define a strong new password.
Use a unique password that is not shared with other systems or technicians.
Click Save.
The interface may offer an option to terminate all active web and mobile sessions. Use this option if you suspect that the old credentials may have been used elsewhere or if you want to force every session to authenticate again.
For this demonstration, I will keep the current session active.
The administrator password has now been changed.
𝗔𝗗𝗗𝗜𝗡𝗚 𝗔𝗡𝗗 𝗠𝗔𝗡𝗔𝗚𝗜𝗡𝗚 𝗧𝗘𝗖𝗛𝗡𝗜𝗖𝗜𝗔𝗡𝗦
From the Users section, you can add additional Endpoint Central technicians and assign roles according to their responsibilities.
Avoid sharing the built-in administrator account among multiple technicians.
Create individual accounts so that actions can be audited and permissions can be limited through role-based access control.
If the selected user onboarding method requires email confirmation or registration, configure the mail server before adding the users.
Apply the principle of least privilege. Give each technician only the modules, device scopes, remote-control permissions, and administrative functions required for their work.
𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗜𝗡𝗚 𝗧𝗛𝗘 𝗣𝗔𝗧𝗖𝗛 𝗗𝗔𝗧𝗔𝗕𝗔𝗦𝗘 𝗦𝗬𝗡𝗖 𝗦𝗖𝗛𝗘𝗗𝗨𝗟𝗘
The next configuration is the Patch Database synchronization schedule.
We will not deploy patches in this video, but the Patch Database schedule should be configured before patch management begins.
Open the Patch Management section, select Settings, and then open Patch Database Settings.
This page controls which patch catalogs are synchronized with the central server.
Depending on your environment, you can enable or disable operating system and third-party application catalogs that are not required.
The main purpose in this video is to configure a scheduled synchronization time.
Enable the schedule and select an appropriate time.
I normally recommend running the Patch Database synchronization outside the busiest business hours, while ensuring that the server has internet access and enough time to complete the process.
For this example, I will schedule it for 4:00 a.m.
Verify the selected time zone and click Save.
A current Patch Database is essential because Endpoint Central uses the catalog information to identify missing patches, assess vulnerabilities, and prepare deployments.
𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗜𝗡𝗚 𝗧𝗛𝗘 𝗜𝗡𝗩𝗘𝗡𝗧𝗢𝗥𝗬 𝗦𝗖𝗔𝗡 𝗦𝗖𝗛𝗘𝗗𝗨𝗟𝗘
Endpoint Central needs regular inventory scans to keep hardware and software information current.
Open the Inventory section and select Schedule Scan.
Under the Inventory Scan tab, click Configure Schedule.
A daily scan is appropriate for many environments, although the ideal frequency depends on the number of endpoints, network availability, reporting expectations, and how quickly software and hardware changes must appear in the console.
Select Daily and choose a suitable time.
The scan should be scheduled when a large percentage of the managed devices are expected to be online. If you schedule the scan outside business hours but laptops and user computers are powered off, those agents cannot report at that time.
For this environment, I will schedule the inventory scan for 9:00 a.m.
Click Save.
The same area may also include a File Scan schedule.
File scanning can be useful for specific software compliance, file discovery, or auditing requirements, but it is not essential for this initial configuration. We will discuss the Inventory module in more detail in another video.
𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗜𝗡𝗚 𝗦𝗖𝗛𝗘𝗗𝗨𝗟𝗘𝗗 𝗗𝗔𝗧𝗔𝗕𝗔𝗦𝗘 𝗕𝗔𝗖𝗞𝗨𝗣𝗦
Endpoint Central includes both the application and, when bundled PostgreSQL is used, the product database.
For disaster recovery, scheduled backups must be configured.
Open the Admin tab, go to Database Settings, and select Configure Backup Details.
Choose a backup time outside the busiest business hours.
Configure the backup retention period according to your recovery requirements and available storage. The retention value determines how many backup sets remain available before older backups are removed.
The backup location is also important.
As a best practice, do not keep the only backup copy on the same disk or server as Endpoint Central. If the server, operating system, or storage fails, a local-only backup may be lost with it.
Specify a supported remote location or another protected storage destination.
Make sure the Endpoint Central service account or backup process has permission to write to the selected location and that the path remains available during the scheduled backup window.
𝗣𝗥𝗢𝗧𝗘𝗖𝗧𝗜𝗡𝗚 𝗕𝗔𝗖𝗞𝗨𝗣𝗦 𝗪𝗜𝗧𝗛 𝗔 𝗣𝗔𝗦𝗦𝗪𝗢𝗥𝗗
Endpoint Central also allows the backup to be protected with a password.
A backup may contain sensitive information about managed endpoints, technicians, software, patches, configurations, and product settings.
Enter a strong backup password and store it securely.
Anyone restoring the protected backup must provide the correct password. If the password is lost, the restore process may fail.
You can also define a password hint, but the hint should not reveal the actual password.
After entering the schedule, retention, location, password, and hint, click Save Changes.
In this lab, the configuration may display an error because the mail server has not been configured.
In a production environment, configure the outgoing mail server first so that backup success and failure notifications can be delivered to the responsible administrators.
𝗘𝗡𝗔𝗕𝗟𝗜𝗡𝗚 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗦𝗘𝗥𝗩𝗘𝗥 𝗠𝗔𝗜𝗡𝗧𝗘𝗡𝗔𝗡𝗖𝗘
The next option is Central Server Maintenance.
Endpoint Central includes a scheduled maintenance feature designed to help maintain application and database performance.
Open the Admin tab, go to Server Settings, and select Central Server Maintenance.
The feature is disabled in this environment.
For a production server, I recommend enabling it and selecting a time when the management service can perform maintenance with minimal operational impact.
For example, we can run comprehensive maintenance every 15 days on Sunday at 2:00 a.m.
Comprehensive maintenance can include database maintenance and central server optimization tasks.
Review the expected service impact, backup status, database platform, and product recommendations before selecting the schedule.
Click Save.
Regular maintenance helps prevent unnecessary database growth and supports stable long-term product performance.
𝗜𝗡𝗖𝗥𝗘𝗔𝗦𝗜𝗡𝗚 𝗧𝗛𝗘 𝗔𝗨𝗗𝗜𝗧 𝗟𝗢𝗚 𝗥𝗘𝗧𝗘𝗡𝗧𝗜𝗢𝗡
Endpoint Central records technician and administrative actions in its audit logs.
The default retention period may be too short for a production environment, especially when the organization has compliance, forensic, troubleshooting, or accountability requirements.
Open the Audit and Action Log Viewer.
This page shows which technician performed an action and when the action occurred.
Click Edit Audit Log Settings.
The default retention period in this environment is 30 days.
I believe 30 days is too limited for many production systems, so I will increase the value to one year.
Your organization may choose a different retention period, such as six months, one year, or up to two years, depending on policy, storage capacity, and regulatory requirements.
There is also an option to resolve and store the hostname by using the IP address and DNS information. Enable it if this information is useful and reliable in your environment.
Click Apply.
Longer audit retention improves accountability and helps administrators investigate configuration changes, deployments, remote actions, and security events.
𝗘𝗡𝗔𝗕𝗟𝗜𝗡𝗚 𝗧𝗛𝗘 𝗔𝗖𝗧𝗜𝗩𝗘 𝗗𝗜𝗥𝗘𝗖𝗧𝗢𝗥𝗬 𝗥𝗘𝗣𝗢𝗥𝗧 𝗦𝗖𝗛𝗘𝗗𝗨𝗟𝗘𝗥
The final configuration is optional but useful.
Endpoint Central is not a dedicated Active Directory auditing or administration product, but it can retrieve several useful reports from Active Directory.
Open the Active Directory Report Settings.
Enable the AD Report Scheduler and select the required domains.
Choose the appropriate scan mode.
For this example, I will use Update Complete Object so that the product retrieves the complete and current object information.
Configure the schedule by selecting Actions and then Modify.
I want the Active Directory report data to be updated every day, so I will select all days and schedule the scan for 9:00 p.m.
Click Schedule and then Save.
After the scheduler runs, the Reports section can display predefined reports related to users, computers, groups, domains, organizational units, and other directory information.
These reports can also be scheduled and delivered according to the organization’s needs after the mail server is configured.
𝗥𝗘𝗩𝗜𝗘𝗪𝗜𝗡𝗚 𝗧𝗛𝗘 𝗘𝗡𝗗𝗣𝗢𝗜𝗡𝗧 𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗔𝗧𝗜𝗢𝗡 𝗢𝗥𝗗𝗘𝗥
We have now completed the initial ManageEngine Endpoint Central installation and best-practice configuration.
Before ending the video, I want to review what we configured and why the order is important.
I recommend following this order and applying the options that are feasible and appropriate for your infrastructure.
𝗣𝗥𝗢𝗫𝗬 𝗔𝗡𝗗 𝗜𝗡𝗧𝗘𝗥𝗡𝗘𝗧 𝗖𝗢𝗡𝗡𝗘𝗖𝗧𝗜𝗩𝗜𝗧𝗬 𝗥𝗘𝗖𝗔𝗣
The first configuration was the proxy setting.
We defined how Endpoint Central reaches the internet. Depending on the environment, this can be a direct connection, a proxy server, or an isolated configuration.
We saved the setting and confirmed that the central server could reach the required online services.
𝗡𝗔𝗧 𝗦𝗘𝗧𝗧𝗜𝗡𝗚𝗦 𝗔𝗡𝗗 𝗙𝗤𝗗𝗡 𝗥𝗘𝗖𝗔𝗣
The second configuration was NAT Settings under Server Settings.
We explained that the server FQDN is extremely important for agent communication and should be selected before agents are deployed.
We created an internal DNS record that maps the selected FQDN to the Endpoint Central server.
If a Secure Gateway Server and internet-based agent management are used, the required public DNS and external connectivity must also be configured.
Because this demonstration uses only internal LAN communication, the internal DNS record was sufficient.
𝗦𝗦𝗟 𝗖𝗘𝗥𝗧𝗜𝗙𝗜𝗖𝗔𝗧𝗘 𝗥𝗘𝗖𝗔𝗣
After defining the FQDN, we opened Manage SSL Certificate under Security and Privacy.
We uploaded a PFX certificate that matches the Endpoint Central FQDN and confirmed that managed endpoints trust the issuing certificate authority.
We then restarted the central server and verified that the certificate was active when opening the HTTPS web console.
To avoid restarting the server twice, you can configure NAT Settings and the SSL certificate first and then restart the service once.
𝗔𝗖𝗧𝗜𝗩𝗘 𝗗𝗜𝗥𝗘𝗖𝗧𝗢𝗥𝗬 𝗜𝗡𝗧𝗘𝗚𝗥𝗔𝗧𝗜𝗢𝗡 𝗥𝗘𝗖𝗔𝗣
After configuring HTTPS, we integrated Endpoint Central with Active Directory.
We opened the Domain configuration under Agent Settings, changed the domain type from Workgroup to Active Directory, entered the domain controller and credentials, and configured the synchronization schedule.
If your organization has multiple Active Directory domains, you can add and configure them individually according to the available product options and network access.
𝗠𝗔𝗜𝗟 𝗦𝗘𝗥𝗩𝗘𝗥 𝗔𝗡𝗗 𝗢𝗔𝗨𝗧𝗛 𝗥𝗘𝗖𝗔𝗣
We then reviewed the outgoing mail server configuration.
We discussed basic authentication and OAuth authentication and explained why OAuth should be preferred when it is supported by the mail platform and Endpoint Central version.
The mail server configuration is required for alerts, scheduled reports, backup notifications, and several user-related messages.
𝗔𝗗𝗠𝗜𝗡𝗜𝗦𝗧𝗥𝗔𝗧𝗢𝗥 𝗣𝗔𝗦𝗦𝗪𝗢𝗥𝗗 𝗥𝗘𝗖𝗔𝗣
To improve security, we changed the default admin password.
We opened Personalize, selected Authentication, entered the old password, and defined a strong new password.
In a production environment, technicians should use individual accounts with role-based access instead of sharing the built-in administrator account.
𝗣𝗔𝗧𝗖𝗛 𝗗𝗔𝗧𝗔𝗕𝗔𝗦𝗘 𝗔𝗡𝗗 𝗜𝗡𝗩𝗘𝗡𝗧𝗢𝗥𝗬 𝗦𝗖𝗛𝗘𝗗𝗨𝗟𝗘 𝗥𝗘𝗖𝗔𝗣
After changing the password, we configured the Patch Database synchronization and Inventory Scan schedules.
Under Patch Database Settings, we enabled a scheduled catalog synchronization and selected an appropriate time and time zone.
Under Inventory, Schedule Scan, and Inventory Scan, we created a daily schedule that runs while most endpoints are expected to be online.
These schedules help keep patch, hardware, and software information current.
𝗗𝗔𝗧𝗔𝗕𝗔𝗦𝗘 𝗕𝗔𝗖𝗞𝗨𝗣 𝗥𝗘𝗖𝗔𝗣
We then configured scheduled database backups.
Under Admin and Database Settings, we defined the backup start time, retention period, remote destination, backup password, and password hint.
We explained that the only backup copy should not remain on the same server or storage device as Endpoint Central.
A protected remote backup is important for disaster recovery.
𝗖𝗘𝗡𝗧𝗥𝗔𝗟 𝗦𝗘𝗥𝗩𝗘𝗥 𝗠𝗔𝗜𝗡𝗧𝗘𝗡𝗔𝗡𝗖𝗘 𝗥𝗘𝗖𝗔𝗣
After the backup settings, we configured Central Server Maintenance.
We enabled comprehensive maintenance, which includes database maintenance and server optimization, and selected an appropriate frequency and start time.
This scheduled maintenance helps keep the Endpoint Central database and application performance optimized.
𝗔𝗨𝗗𝗜𝗧 𝗟𝗢𝗚 𝗥𝗘𝗧𝗘𝗡𝗧𝗜𝗢𝗡 𝗥𝗘𝗖𝗔𝗣
We also reviewed the Audit and Action Log Viewer.
The default audit retention was 30 days, which may be too short for a production environment.
We increased it to one year. Depending on your organization’s requirements, you may choose a longer or shorter period.
This allows technician actions to remain available for troubleshooting, accountability, and compliance reviews.
𝗔𝗖𝗧𝗜𝗩𝗘 𝗗𝗜𝗥𝗘𝗖𝗧𝗢𝗥𝗬 𝗥𝗘𝗣𝗢𝗥𝗧𝗦 𝗥𝗘𝗖𝗔𝗣
Finally, we enabled the Active Directory Report Scheduler.
Although Endpoint Central is not a dedicated Active Directory management product, it provides useful predefined reports for users, computers, groups, domains, and organizational units.
We selected Update Complete Object, configured the frequency, and saved the schedule.
After synchronization, these reports can be viewed and scheduled from the Reports section.
𝗖𝗢𝗡𝗖𝗟𝗨𝗦𝗜𝗢𝗡
We have reached the end of the ManageEngine Endpoint Central installation and initial configuration.
In this video, we reviewed the hardware, software, database, and network requirements; installed Endpoint Central; monitored the startup through the wrapper log; accessed the web console; configured internet connectivity; defined the server FQDN; created the DNS record; uploaded a trusted SSL certificate; enforced HTTPS; integrated Active Directory; reviewed the outgoing mail server settings; changed the default administrator password; configured Patch Database and Inventory schedules; scheduled protected database backups; enabled Central Server Maintenance; increased audit log retention; and enabled Active Directory reporting.
These settings create a much stronger foundation than installing the product and leaving every option at its default value.
Always adjust the final configuration according to your endpoint count, license, enabled modules, security policies, network architecture, database design, backup requirements, and operational needs.
I hope this information was useful.
Thank you for watching.
I will see you in the next video.
Goodbye.
Rating

