BigFix Documentation Homepage
BigFix 10 Lifecycle Documentation
Welcome to the BigFix Lifecycle documentation, where you can find information about how to install, maintain, and use BigFix Lifecycle.
Lifecycle overview
BigFix Lifecycle is single-agent, single-console technology that provides near real-time visibility into the state of endpoints.
Use the BigFix Software Distribution applications to deploy software to endpoints across your network from a single location. Maintain control and visibility into software delivery and installation. Device owners can use the Self Service Application to manage software and other BigFix actions that are deployed to them as offers.
BigFix Software Distribution is a part of the Lifecycle Management suite, provides a consolidated, comprehensive solution to quickly deploy software throughout a network from a single, centralized location. This solution delivers cost-effective operational control and visibility to your software delivery and installation process.
BigFix OS Deployment, which is part of the BigFix Lifecycle Management suite, provides a consolidated, comprehensive solution to quickly deploy new workstations and servers throughout a network from a single, centralized location. This solution saves time and money, enforces a standardized and approved image, and reduces risks associated with non-compliant or insecure configurations.
Product overview
Configuring the OS Deployment Environment
To start working with OS Deployment, run the configuration Fixlets and tasks listed in the Setup Node.
Managing MDT Bundles and Deployment Media for Windows targets
To perform OS Deployment of Windows operating systems, you prepare your deployment environment and resources using the Bundle and Media Manager Dashboard.
Managing Drivers for Windows Deployments
The Manage Images and Drivers node includes tasks to prepare and import drivers for deployment to Windows targets.
Managing Linux OS Resources and Deployment Media
You can import Linux OS Resources needed to create network boot media and to capture and deploy Linux images
Managing Images
The Manage Images and Drivers node includes tasks to capture, import and manage images for deployment to targets.
Reimaging is the process of saving the user state on a computer, installing a new image on it, and then restoring the user state.
Installing Windows 10 or Windows 11 using in-place upgrade
To upgrade your existing Windows systems to Windows 10 or Windows 11 you can use the in-place upgrade fixlets.
Bare Metal deployments
You can install and manage BigFix for OS Deployment servers and create profiles for bare metal deployments.
Monitoring Deployment Activities
You can track and monitor all deployment activities in your Endpoint Management network.
Maintenance and troubleshooting
You can monitor deployment activities, correct exceptions and adjust configuration settings specific to your environment through dashboards and tasks available for these purposes.
Setting up OS Deployment in an air-gapped network
You can choose to configure your OS Deployment and Bare Metal Imaging site in an air-gapped network.
Deprecated and Superseded functionalities
This topic lists the functionalities that are still present in OSD, but are deprecated.
Create Ubuntu OS Resources manually
For more information about this product, see the following resources:
BigFix Remote Control application helps to communicate between different components, clients, and endpoints within BigFix environment.
Release notes
A summary of changed or new features and enhancements included in BigFix Remote Control.
Remote Control Installation Guide
By using Remote Control you can remotely support and control thousands of PCs and servers, on an enterprise scale, from a central location or directly, in peer to peer mode.
Remote Control Administrators Guide
This guide is for users who want to administer Remote Control.
Remote Control Console User Guide
BigFix Remote Control Controller Users Guide
Remote Control Target Users Guide
Remote Control On-demand Target Guide
Use Remote Control to start remote control sessions over the internet with targets that do not have the target software installed.
Remote Control V10 Readme
Use Power Management to control, monitor, and manage conservation policies in your deployment.
Power Management User's Guide
Power Management is policy-driven software for distributed environments. Built on IBM® BigFix technology, it allows you to apply conservation policies infrastructure-wide, while providing the granularity to apply power management policies to a single computer.
Server Automation provides powerful automation. You can use it to sequence automation actions in steps across multiple endpoints.
BigFix Lifecycle Server Automation provides you with the capability to automate provisioning workflows. You can automate a sequence of Fixlets, Tasks, and Baselines across different endpoints, such as servers or computers. Server Automation exploits the agility and scalability of BigFix to deliver powerful functionality in a lean and efficient manner, with minimal impact on your network.
BigFix Lifecycle Server Automation provides you with technology to sequence actions, such as the deployment of Fixlets, across multiple endpoints. To sequence automation, you create an Automation Plan. Your Automation Plan contains all of the actions for your end-to-end automation sequence.
Virtualization is a software technology that allows multiple operating systems to run on the same host computer at the same time. Additional uses of virtualization include the quick creation of new systems for testing, training, and demonstration. Using virtualized computers saves the cost of hardware, management, and administration of the server infrastructure.
Configuring your system
This section describes how the BigFix architecture is relevant for Server Automation. It also describes how Server Automation can affect BigFix performance.
Sample Automation Plans
Server Automation is shipped with a number of sample Automation Plans that you can run out of the box. To run these Automation Plans out of the box, ensure that the Fixlets contained in them are available. Typically, you would substitute some of the Fixlets contained in these samples with particular Fixlets that you want to run. Use the information in each of the following sections to find out more about each of the sample plans.
Server Automation content
Server Automation provides content that you can use to automate processes and software deployment.
Profile Management is a WebUI-based feature of BigFix Lifecycle. It provides Security Administrators the capability to define and deploy security policies to Windows 10 and Mac OS devices.
Profile Management Overview
BigFix Profile Management is a WebUI-based feature of BigFix Lifecycle.
Profile Management tasks
You can enforce device compliance by creating and deploying profiles.
Troubleshooting profile deployments
When a deployment fails, you can determine the cause of the error by viewing the available logs and error code information.
BigFix CVE Search dashboard and Web Report are available as part of a new Vulnerability Reporting site.
BigFix CVE Search dashboard and Web Report provide operators with ability to analyze vulnerabilities in their environment based on their CVE ID. For each CVE, operator can report on:
Enable Vulnerability Reporting Site
In the site list, find the site named vulnreport (or Vulnerability Reporting). Click on the site and gather it.
CISA KEV (BOD 22-01) CVE list
CVE Search dashboard and web report also provide latest information on Known Exploitable Vulnerability (KEV) List provided by the Cybersecurity & Infrastructure Security Agency (CISA) Binding Operational Directive 22-01 (BOD 22-01).
Relevant Fixlet Checkbox
CVE Search dashboard and web report provide ability to include/exclude non-relevant Fixlets from view and calculations. To do this, uncheck/check the “Show Relevant Only” checkbox respectively.
Superseded Fixlet Checkbox
BigFix provides a unique view into patches that have been superseded by their vendor. By default, Fixlets for these patches get a relevance statement added to them to ensure that they will not evaluate as relevant on any system. However, a subset of these Fixlets can be evaluated using a “superseded evaluation” setting. Currently, this feature is supported for windows operating system patches.