Fortinet white logo
Fortinet white logo

FortiDLP Agent Deployment Guide

Bulk deploying the FortiDLP Agent to Windows

Bulk deploying the FortiDLP Agent to Windows

Fortinet provides an MSI installation package for installing the FortiDLP Agent on Windows- and Windows Server-based devices. You can download this installer from the Next DLP Support Portal or the FortiDLP Console's Agent deployment tab.

When using Microsoft GPO, to facilitate the Agent's enrollment on devices, you will also need to create an MSI transform (MST) file.

See the following instructions:

  1. How to create the FortiDLP Agent installer's MST file
  2. How to bulk deploy the FortiDLP Agent using Microsoft GPO.
How to create the FortiDLP Agent installer's MST file
  1. In the Orca tool, open the FortiDLP Agent installer (MSI file).
  2. On the menu bar, click Transform > New Transform.
  3. In the left-hand panel, click Property.
  4. Do one of the following:
    • To enroll Agents using an enrollment code, add a new ENROLL_CODE property and set its value to the enrollment code you generated.
    • To enroll Agent's using an enrollment bundle:
      1. Save the enrollment bundle to an accessible file share.
      2. Add a new BUNDLE_FILEPATH property and set its value to the full Universal Naming Convention (UNC) path of the file share on which the enrollment bundle file resides.
        Note

        This can be a bundle that has been configured to enroll multiple devices or if you plan to use a different bundle for each device, you can include Windows Environment Variables, such as %COMPUTERNAME%, which will be automatically replaced on each machine. The path must be fully qualified, including either the correct drive root or the resolvable file server name.

  5. On the menu bar, click Transform > Generate Transform.
  6. Save the MST file to your preferred directory.
How to bulk deploy the FortiDLP Agent using Microsoft GPO

In the following instructions, Windows Server 2022 is acting as a domain controller.

  1. Create a network share to host the FortiDLP Agent installer MSI file and MST file and copy both files to it.
  2. Note

    A network share (with a path beginning with \\) is required, rather than a drive share (with a path beginning with C:\ or D:\).

  3. In Microsoft GPO, open Group Policy Management, and then create a GPO named Install Agent.
  4. Open the GPO you created, and in the Security Filtering section, select the users/computers for the Agent installation.
  5. Right-click the policy and select Edit.
  6. Expand Computer Configuration > Policies > Software Settings, right-click Software installation, and then select New > Package.
  7. On the network share you created, select the FortiDLP Agent installer.
  8. In the Deploy Software dialog box, select the Advanced radio button, and then click OK.
  9. Click the Modifications tab and add the MST file you created.
  10. Return to the Group Policy Management panel, and do the following:
    1. In the left-hand panel, right-click the organizational unit you want to apply the policy to.
    2. Select Link an existing GPO.
    3. Select Install Agent.
    4. Click OK.
Note

If you are deploying the Agent to devices using a language other than English, in the Deployment tab, ensure you select the Ignore language when deploying this package checkbox.

The FortiDLP Agent will be installed and enrolled on devices after they are restarted.

Note

FortiDLP's automatic upgrade functionality (via Agent configuration groups) CANNOT be used in conjunction with Microsoft GPO. Upgrades should instead be pushed using a Group Policy with the new version of the Agent MSI file and the existing MST file.

Bulk deploying the FortiDLP Agent to Windows

Bulk deploying the FortiDLP Agent to Windows

Fortinet provides an MSI installation package for installing the FortiDLP Agent on Windows- and Windows Server-based devices. You can download this installer from the Next DLP Support Portal or the FortiDLP Console's Agent deployment tab.

When using Microsoft GPO, to facilitate the Agent's enrollment on devices, you will also need to create an MSI transform (MST) file.

See the following instructions:

  1. How to create the FortiDLP Agent installer's MST file
  2. How to bulk deploy the FortiDLP Agent using Microsoft GPO.
How to create the FortiDLP Agent installer's MST file
  1. In the Orca tool, open the FortiDLP Agent installer (MSI file).
  2. On the menu bar, click Transform > New Transform.
  3. In the left-hand panel, click Property.
  4. Do one of the following:
    • To enroll Agents using an enrollment code, add a new ENROLL_CODE property and set its value to the enrollment code you generated.
    • To enroll Agent's using an enrollment bundle:
      1. Save the enrollment bundle to an accessible file share.
      2. Add a new BUNDLE_FILEPATH property and set its value to the full Universal Naming Convention (UNC) path of the file share on which the enrollment bundle file resides.
        Note

        This can be a bundle that has been configured to enroll multiple devices or if you plan to use a different bundle for each device, you can include Windows Environment Variables, such as %COMPUTERNAME%, which will be automatically replaced on each machine. The path must be fully qualified, including either the correct drive root or the resolvable file server name.

  5. On the menu bar, click Transform > Generate Transform.
  6. Save the MST file to your preferred directory.
How to bulk deploy the FortiDLP Agent using Microsoft GPO

In the following instructions, Windows Server 2022 is acting as a domain controller.

  1. Create a network share to host the FortiDLP Agent installer MSI file and MST file and copy both files to it.
  2. Note

    A network share (with a path beginning with \\) is required, rather than a drive share (with a path beginning with C:\ or D:\).

  3. In Microsoft GPO, open Group Policy Management, and then create a GPO named Install Agent.
  4. Open the GPO you created, and in the Security Filtering section, select the users/computers for the Agent installation.
  5. Right-click the policy and select Edit.
  6. Expand Computer Configuration > Policies > Software Settings, right-click Software installation, and then select New > Package.
  7. On the network share you created, select the FortiDLP Agent installer.
  8. In the Deploy Software dialog box, select the Advanced radio button, and then click OK.
  9. Click the Modifications tab and add the MST file you created.
  10. Return to the Group Policy Management panel, and do the following:
    1. In the left-hand panel, right-click the organizational unit you want to apply the policy to.
    2. Select Link an existing GPO.
    3. Select Install Agent.
    4. Click OK.
Note

If you are deploying the Agent to devices using a language other than English, in the Deployment tab, ensure you select the Ignore language when deploying this package checkbox.

The FortiDLP Agent will be installed and enrolled on devices after they are restarted.

Note

FortiDLP's automatic upgrade functionality (via Agent configuration groups) CANNOT be used in conjunction with Microsoft GPO. Upgrades should instead be pushed using a Group Policy with the new version of the Agent MSI file and the existing MST file.