Quest KACE Systems Management Review

Enables mass deployment and mass uninstallation in a very intelligent way

What is our primary use case?

We use the KACE solution for endpoint management, since our posture is based on endpoints. We have almost 2,000 endpoints.

We have two KACE boxes. It's not a virtual appliance, it is a physical appliance.

How has it helped my organization?

It's not only saving time but increasing IT productivity. If you have a KACE box, you're going to save a lot. Having KACE is a blessing for IT administrators for endpoint management. They can do a lot of work remotely, as well as troubleshooting, mass deployment, and mass uninstallation. KACE is very intelligent and it has its own uninstaller.

An example of how KACE helped is that there was a McAfee service-provider who was visiting us to do a McAfee upgrade for our antivirus system. They are experienced people, the subject matter experts for deploying McAfee, the client, the agent, et cetera. He was having an issue uninstalling a McAfee firewall client. If you deploy a McAfee in your network, the uninstaller should be from McAfee, but the uninstaller from McAfee was an outdated version. Uninstalling the firewall client from McAfee requires a lot of effort. It's not impossible, but it's time-consuming and if you try to uninstall from the control panel, of course it won't allow you. There is a popup for the password and, without that, a lot of problems are going to occur. 

He told me he was facing this issue. The solution for uninstalling it was provided by KACE. I demonstrated it to him for one of our clients and he was shocked. He started writing that command, and the next day he sent me a text message, saying, "Thank you. You made my life easier." He gave that command to another customer, a client of his who is an IT administrator, to run that command via a batch file to all the end-users, because they didn't have KACE. 

For an IT department in any organization that pays for endpoint management, KACE is really a blessing for them.

What is most valuable?

The most valuable feature of KACE is the mass package deployment. There are a lot of endpoint management solutions in the market. The way KACE responds is with the installation management feature, which is done in a very intelligent way, as well as scripting. It's wow. It's really wow. On top of that, there is a mass undeployment feature as well.

For example, we had an issue a while back where there was a plugin for the SAP module being deployed to almost 1,800 computers. It was taking a backup, restarting the machine, and updating it automatically. Our end-users were complaining every day. We were receiving hundreds of calls. We found out that the issue was this plugin. It was updating and restarting machines without informing the users. When we did inventory, we started finding this application, but we didn't know about the history of that application. Luckily, KACE gave us an uninstallation path, the command line. When we deployed it, believe it or not, it worked as a massive uninstallation feature and it took care of almost 1,800 computers within one hour.

It's really very time-saving stuff. It's all up to you, how you are going to utilize KACE, but if you know the way, the features are very user-friendly and it does not require scripting. There are built-in features where you can build your own script and execute it remotely through KACE. 

I have never officially worked on the service desk model of KACE, but when I went through it, it was fine. It's good for a small IT department. It's more than enough. It has asset inventory and printer inventory. You enable the SNMP features and you can get reports on printers and even printer cartridge utilization reports. It's a very handy tool for organizations that have a lot of endpoints in place.

We also used the Systems Deployment Appliance for Windows 7. Now, we are planning to use it for the Windows 10 upgrade for the rest of our machines. If you're going to capture the image of a machine and re-image that machine, it's great. Over the network, it took us 18 minutes to deploy 19 GB of images. And that was not on the same campus. It was a remote campus. For the same campus, we also used it to deploy and it took us, I think, 16 minutes and a few seconds for almost 18 GB of Windows 7 images.

There are a lot of nice features.

What needs improvement?

There is a module for agent management when you right-click on the inventory. If you want to connect remotely you can do so. But sometimes the agent check-in does not happen. You can do the first check-in through a script, at the same time. 

But there should be a mini toolbox, like the competitors of KACE have, with the small features for KACE administrators. That would make their lives easier. If you are troubleshooting a specific endpoint, remote control is available as is Wake-on-LAN. But if you want to execute some commands, you have to use a third-party tool, the PS tool. If they would integrate those small things, it would make KACE more powerful.

For how long have I used the solution?

I have been using Quest KACE Systems Management for almost five years.

What do I think about the stability of the solution?

Initially, four years back, we were having a lot of issues with the KACE agent. But as the solution has grown, the maturity level has really increased and the stability and the reliability have as well. My KACE machine has not been down for a single day in the last five years. It's a very stable product.

It's really reliable now and very intelligent on top of that. When we do a mass deployment, there isn't a single day when my network admin asks me, "Why are you deploying this?" I deployed Office 2013 with KACE, in a massive way, and our network guys never said, "Oh, we can see there is a bandwidth spike." The way that KACE intelligently deploys and manages installation is great. It's really kind of a miracle. I believe that they select a group, copy the file over the network to the cache of the local machine, execute the command, and then install the media file on the local machine.

What do I think about the scalability of the solution?

KACE is very scalable.

We started with 700 clients and today we are at almost 2,000 clients. There hasn't been a single day where I have been concerned about the scalability or the of KACE. 

How are customer service and technical support?

Quest Support for KACE is good. They are responsive and they always give you a solution in a  timely manner. 

We faced a problem two or three years back, an issue with the inventory of Forescout Secure Connector. We could not find out how many machines had Secure Connect Connector because it's installed as a service. It was a very complex problem for us and KACE support came up with a solution: Create a new, customized inventory to get Secure Connect to be considered as a process. On that basis, we had a new entry and this solved our problem.

Which solution did I use previously and why did I switch?

We have not used another asset management solution in this organization. I did use SCCM in my old company.

How was the initial setup?

For us, the initial setup was not complex. The problem was that the environment, the network we work in, is a very restrictive environment. We have a lot of firewall policies and a layer of firewalls across the network. Because of the complex network architecture, we struggled a bit with the network discovery of the endpoints. We used one of the best practices: Do auto-discovery and then apply the agents.

At that point in time, I didn't really know KACE. It was a new box. I started discovering what would be next. The next thing that happened was another blessing from KACE which was having it do the Active Directory group policy deployment for the agents. I deployed it and that discovery was running for almost a week, but we started installing the agent within about four to five days. It was time-consuming. It took us two weeks because we ran it organization-to-organization because it would have slowed down the network. We did not want to take any risks. If we had taken the risk, it wouldn't have been an issue, as far as the KACE agent deployment is concerned. 

Now, whenever a new machine comes into our network, the KACE agent is automatically installed. Right after that, KACE is installing one of our NEC client agents automatically. Then, KACE will discover that this machine is a part of the McAfee agent, and if it is not, it will automatically install the McAfee agent. Then I configure McAfee to sync with Active Directory. 

So for us, when a new machine is joining, the desktop engineer will run only one command, GPUpdate. The machine will restart and then all the group policies, the KACE policies will be deployed. KACE will then install all of our small plugins automatically and they're good to go.

One of the best parts of KACE is when you go for a version upgrade. Once you do a version upgrade for any KACE module—any KACE virtual appliance or physical appliance—it's very user-friendly. In addition, the agent upgrade is a miracle. When you do the agent upgrade for the KACE appliance for the first time, it's "super-wow". The last upgrade I did was for almost 1,900 PCs, and all the agents were updated automatically when I upgraded the agent package. It took only 24 hours.

I am the only KACE administrator in our organization, but there are desktop engineers who log in to KACE. They review machines, but I do all the administration and configuration. They use it to take inventory or check the memory and see what replacements are required. They are read-only administrators.

What was our ROI?

We have seen a lot of return on our investment in KACE. One area is headcount. We are a military hospital. Imagine having 2,000 computers on the ground in different remote locations, yet having only seven desktop support engineers. If you do the math, there should be no way that seven desktop engineers can support 2,000 endpoints. Even the best-case scenario is one engineer working with 100 desktop machines, max. That gives you an idea of the headcount savings.

We are also saving on the licensing fee, compared to other endpoint management solutions.

Which other solutions did I evaluate?

KACE is very easy to use and user-friendly compared to the other endpoint management tools, like Microsoft SCCM and other third-party tools, in terms of IT administration. Compared to its competitors, it's easy to get machine inventory.

What other advice do I have?

If any organization wants to manage its endpoints, having KACE, as I said, is a blessing for the IT administrators.

I would give it an eight out of 10. I am being demanding because there are some more improvements that can be made. But KACE can be a superpower in endpoint management.

Which deployment model are you using for this solution?

**Disclosure: IT Central Station contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
More Quest KACE Systems Management reviews from users
...who work at a Financial Services Firm
...who compared it with SCCM
Learn what your peers think about Quest KACE Systems Management. Get advice and tips from experienced pros sharing their opinions. Updated: July 2021.
522,693 professionals have used our research since 2012.
Add a Comment
ITCS user