Note: Windows 7 requires SP1 in order to install IE11.
Description
With Microsoft's recent End Of Support for versions of IE older than 11, its important to get up to date in order to receive technical support and security updates for workstations.
This document covers the procedures and expectations for installing Internet Explorer 11 using Ivanti EPM Patch and Compliance Manager.
Identifying Workstations that need to upgrade to Internet Explorer 11
We will be using a Query to identify what workstations currently have a version of Internet Explorer less than 11 installed.
To get the most accurate results, we'll want to identify all versions of Internet Explorer 11 that are currently installed on workstations, and exclude any device running those versions. This query will vary between networks, but the following screenshot should give a rough idea:
![Query.png]()
Be sure to Include Computer > Browser > Version in the result columns so the different versions can be seen in the results.
Now that we have our list of devices that need to upgrade, we know what devices we can apply to the upgrade process.
Creating a Custom Group to include Internet Explorer 11 Patch and Prerequisites
For the sake of Simplicity, we'll want to gather all necessary patches for the Internet Explorer 11 upgrade to one area. To do this, create a custom group and name it something related to Internet Explorer 11.
Search the "Scan" folder for patch ID IE11, and drag it to the new Custom Group just created. A prompt will open asking if the 9 prerequisites should be included.
These prerequisites are needed in order for Internet Explorer 11 to be detected and installed on the machine. Click Yes.
![Include Prerequisites.png]()
Another prompt may be generated warning that not all patches are downloaded. Be sure to download all associated patches for these 10 IDs as the job will fail otherwise.
Now that we have all necessary patches grouped together, its time to apply them to machines using either Manual Installation or Autofix.
Using Autofix to apply Internet Explorer 11
Assuming that Autofix is not enabled globally, you will need to useutilize scopes for the Internet Explorer 11 autofix upgrade. To create the appropriate scope, simply browse the Network View. right-click Scopes and select New Scope from Query.
![Scope Creation.png]()
Select the Query created above and click OK. This will create a new Scope with the same name as the Query created earlier.
![Query and Scope.png]()
Highlight all 10 of the patches in the Custom Group created above, right click and select Autofix> Autofix Settings.
![Autofix Settings.png]()
Select the checkbox next to the Scope created earlier and click OK.
The devices that qualify for the scope created will now upgrade to Internet Explorer 11 as they scan for definitions.
Apply Internet Explorer 11 manually using Scheduled Repair jobs
The manual installation of Internet Explorer 11 will be using theQuery and Custom Group created earlier in this document.
To begin, highlight all patches in theCustom Groupand selectRepair. This will create a scheduled task window.
![Scheduled Task.png]()
There are a number of ways to assign devices to this scheduled task. The first being to associate the Query created earlier to the scheduled task.
This is done by selecting Target Devices > Targeted Queries > *Query Name.* This will add all devices associated with the Query to apply to this scheduled task. Furthermore, the devices will fall out of the query as the patch is applied via policy.
![Target Devices.png]()
A different method would be to stagger the devices within the Query and add them in increments to the scheduled task.
Click Save. A new task will be added to the Scheduled Task Window.
If the task was associated with a Query, Right-Click the task and select Start Now> All. Otherwise, devices will need to be added to the task before starting.
What to Expect
1. When using Autofix to upgrade Internet Explorer 11, the device will automatically fall out of the Query created as they upgrade. By association, they will fall out of the scope. There's no need to worry about devices running the upgrade more than once.
2. This upgrade will often require 1 or more Reboots. Plan accordingly with Reboot behavior. In this lab, a Windows 7 x64 install with Internet Explorer 8 was used. A total of 3 Reboots was required to fully upgrade.
3. The install script for Internet Explorer 11 includes a /norestart command. This means the final reboot needed will not immediately prompt the user.
4. Internet Explorer does NOT need to be closed before the patch is applied. It can be done silently in the background, and the install will complete on the next reboot.