Deploy and Run task

Deploy and Run tasks are a crucial part of the checklist, especially for checks where continuous monitoring is not feasible.

These tasks are prerequisite actions that must be executed on the target endpoints before accurate compliance results can be reported. The task includes all the necessary action scripts and should be performed periodically (e.g., once per day) to update the compliance data collected for the Fixlets listed in the Deploy and Run Task description tab.
Figure 1. List of Fixlets depend on the Deploy and run tasks

List of Fixlets depend on the Deploy and run tasks

Windows checklists require you to run the Deploy and Run tasks to populate the necessary properties on the endpoints, enabling relevance evaluation.

The site includes all required action scripts. When scheduled or executed, it runs all the scripts and stores the results under the BigFix folder structure: C:\Program Files (x86)\BigFix Enterprise\BES Client\__BESData\__SCMData.
Note: For more details about the folder structure and its output, refer to the Understanding the output of deploy and Run task section.
Note: You do not need to complete this task if your checklist does not include these checks.
The check Fixlets from these sites will only display current results once the Deploy and Run tasks are completed. If you are using any mixed content sites, schedule the periodic execution of the Deploy and Run Task.
  1. From the Security Configuration domain, navigate to All Security Configuration > Sites > External Sites.
  2. Select a checklist and click Fixlets and Tasks.
  3. In the List panel, locate and click the Deploy and Run Task.
    Figure 2. Deploy and Run Task in the CIS Checklist Windows 2022 DC

    Deploy and Run Task in the CIS Checklist Windows 2022 DC
  4. Click Take Action to deploy the task, or click the appropriate link in the Actions box.
  5. Select the appropriate endpoints in your environment.
  6. Click the Execution tab.
    Figure 3. Take Action - Execution tab

    Take Action - Execution tab
  7. Set the Deploy and Run Task to run daily and click OK.
  8. Once the task is complete, refresh the endpoints.

The Deploy and Run Task will update the reports in the Security and Compliance Analytics console (now known as BigFix Compliance Analytics) with the latest results. To ensure that you get the most current content, run this task on the endpoint before initiating an import. For automatic daily imports to BigFix Compliance Analytics, scheduling more than one run of the Deploy and Run Task action is unnecessary.