Windows Agent Installation
You can install the Agent on Windows endpoints via GPO, CWP (Captive Web Portal), or manually using email, USB, etc.
Windows Agent Installation
Download and Install via Agent Download Page
- Agent Download
- https://(IP or Domain)/agent
- Agent Selection : Do not change the file name to avoid file name conflicts.
- Windows Installer Version : GnUpdate_(IP or FQDN) .exe
- Agent Installation Token
- If the Block Agent Not Using Token option in Preferences > Agent is activated, the user must enter an installation token when installing the agent.
Note
If the user does not have file installation permissions, the installer cannot be executed, so it must be run with administrator privileges that include file installation permissions.
Agent Installation via CWP
If the agent is not installed, network access may be blocked by the enforcement policy and redirected to the CWP (Captive Web Portal) for agent installation. Click the Agent Installation button on the CWP screen to download and install the agent.
To apply the "Agent Installation" policy option,
- Go to Policy in the top panel.
- Go to Node Policy.
- Click "Node Policy ID" to specify where to apply the policy.
- Find the Agent Policy item.
- In the Agent checkbox, select on.
- Select Enforcement Policy in the left menu to enable the Block Agent Not Installed policy.
Note
Nodes assigned a node policy will be redirected to the CWP page by the enforcement policy (Block Agent Not Installed policy) if the agent is not installed, and an "Agent Installation button" will be displayed on the CWP page.
Agent MSI Package Installation via Active Directory GPO
MSI Installation Package Download
- Access Management WebUI and go to System menu at the top. Go to Update Management > Software menu on the left.
- If the agent is currently uploaded to the Policy Server, click the
MSI
button to the right of Genian NAC Agent for Windows item to download the MSI installation package.
Note
Genian NAC 5.0.38 or higher versions can proceed directly with the Agent Deployment using Active Directory GPO Policy process. Genian NAC 5.0.37 or lower versions should proceed with MSI file modification in the MSI file configuration document below, then proceed with deployment.
Agent Deployment using Active Directory GPO Policy
Note
If the logged-in account's privilege is a user privilege, the agent may not function properly, and the agent's execution account must be changed to a Local System Account.
Modify the node policy agent's execution account according to the sequence below:
Go to Policy in the top panel.
Go to Node Policy.
Click "Node Policy ID" to specify where to apply the policy.
Find the Agent Policy item.
Select Local System Account for execution account.
Click Modify and Apply Change Policy.
Deploy MSI Package via Active Directory GPO
Windows Agent Installation Confirmation
- Select Management > Node.
- In the Node List window, click the NT AG SS column. (If an agent is installed on the node, an agent icon will be displayed.)
Genian Agent Options for Windows Endpoint
- Go to the TrayIcon location at the bottom right of the Windows endpoint screen.
- Find and right-click the Genians Agent icon.
- You can perform the following using the listed options:
- View Announcements: Shows current announcements from the administrator.
- View Notification Messages: Displays the administrator's current messages.
- Check My Status: Shows the current endpoint's security policy compliance status via a web page.
- User Authentication (L): Allows the user to log in, and upon successful login, the CWP page is displayed.
- User Authentication Release (O): Allows the user to log out.
- User Authentication Information: Allows the user to view account information upon successful login.
- Network Connection Information: Allows the user to view activated network connected endpoints.
- USB Device Information: Allows the user to view information about USB endpoints.
- Remote Agent Deletion: (Users cannot delete the installed agent; this operation must be performed by the administrator)
- Program Information: Allows viewing version information for the installed Agent.
Windows Endpoint Agent Log Location
- Open File Explorer on the Windows endpoint.
- Go to C: / Program Files / Geni / Genian / Logs.
#. Sort by Date Modified. .. note:
Installer logs related to agent installation exist in the Windows directory as ``Installer"YYYYMMDD".log``.
Windows Supported List
Refer to: Operating System Plugin Support List