Agent Distribution I: Windows 10/11 Devices
Distribute Empirum agent on modern devices
With the power of Matrix42 Unified Endpoint Management, you can benefit from combining the capabilities of a modern enterprise mobility management solution with all the capabilities that the classic lifecycle management provides. With a hybrid management it is very easy to provide a streamlined onboarding process for new employees on macOS or Windows 10/11 platform devices, where devices will be shipped to employees to utilize an Out-of-the-box enrollment with the Apple Device Enrollment Program or Windows 10/11 Autopilot to a modern management layer (Silverback) and the fulfillment of classic management scenarios (Empirum), like installations of legacy applications. This ensures an easy starting process for new employees which is very easy to handle, fast and quite unique in the Secure Unified Endpoint Management market. In such scenarios the device is set up and configured with Silverback, which will be leveraged to install the Empirum Agent on top. The following guide describes the steps and configuration to achieve co-managed devices with Matrix42 Secure Unified Endpoint Management.
Requirements
- Computers require Windows 10 1803 or later
- The UEM Agent Platform (x64) must match the used Windows version (x64)
- The UEM Agent must be able to connect to the Empirum (depot) server. Usually this will be done via https
- Empirum should be prepared for automatic assignments in order to automate the process of assigning and activating computers
- Configured File Upload Service
Agent Integration
There are two options to download and integrate the UEM Agent in Silverback.
- Automated integration (recommended)
- Manual integration (optional)
Automated integration
The automated integration requires UUX for UEM 21.0.1.56 or newer
- Open the Unified User Experience
- Login with UEM Object Library Manager or Administrative credentials
- Navigate to Agent Configurations
- Select Templates
- Select the Agent Template which will be used as configuration for the integrated UEM Agent.
- Click on Integrate UEM Agent in Silverback
- The dialog shows the option to integrate the Windows and macOS UEM Agent. Click on one or both buttons to automatically integrate the UEM Agent. An App and a associated Tag will automatically created.
- Close the dialog
- Proceed with Create Assignment
Manual integration
Download UEM Agent
- Open Matrix42 Marketplace and perform a login
- Navigate to Empirum
- Navigate to Add-Ons
- Navigate to UEM Agent Windows
- Right click the UEM Agent Icon and save it your files (optional)
- Click Details and Downloads
- Download the latest UEM Agent
- Unzip the package
- Open the unzipped folder and navigate to
- Empirum\Configurator\Packages\Matrix42\UEM Agent Windows\MSI\
- Open the version folder
- Here you will find the 64-bit and 32-bit *.msi package
Add to Software Library
- Open your Unified User Experience
- Login with Administrative credentials
- Navigate to Software Distribution
- Select Apps
- Click + Add Application
- Drag and drop now your *.msi package
As there is a validation for *.msi, please ensure to have the file type in lowercase.
- Enter as Name e.g. Matrix42 UEM Agent
- Enter a description
- Upload an icon (optional)
- Under Configuration, enter your adjusted installation parameters
- e.g. with the sample MSI installation parameters:
/quiet /l*v "c:\Windows\Temp\UEMAgentMSI.log" Server="empirum.imagoverum.com" User="IV\agentuser" Password="C1125447A6305BB8259495B37C348B3464D31A5AB7B888387E8021388FD1B1FF335CB5094D9D9444B3D2CBB27AB6EE9242A56121F8CCC0B2" Protocol="https" Port="443"
The password is encrypted with the Empirum tool Empcrypt
- Press Upload
- Wait until the upload process is finished
- Press Finish
You can review the Add application process in the Administration application under Integration > Enterprise Service Bus > Remote Actions
Create Assignment
- Navigate to Assignments
- Click + Add Assignment
- Enter a name, e.g. Unified Endpoint Management Agent
- Enter a description e.g. Unified Endpoint Management Agent deployment to modern managed Windows devices (optional)
- Change the Status to Active
- Click Devices
- Click +
- Select your target device(s) and proceed with Select
- Click Objects
- Locate for the application name, e.g. Matrix42 UEM Agent with the Object Type: Tag
Tags are assignable Objects for Modern managed devices.
- Select the Matrix42 UEM Agent (Tag)
- Proceed with Select
- Press Summary
- Review your Configuration, Assigned Devices and Assigned Objects
- Press Save to finish the assignment
- Wait until the assignment process is finished
The Tag is now assigned to included Windows devices and when the device the next time performs a check-in, the UEM Agent will be installed automatically. To speed up the process you can initiate remotely a device sync, which will be explained in the following sections.
Device Synchronization
After the Assignment is done, you can initiate a device sync for speed up the Agent Installation on your target device(s). This can be done either via the Unified User Experience or on the device itself.
Initiate remotely a device sync
- Navigate to Endpoint Devices
- Locate your target device(s), which you added to the Assignment
Before installing the agent, the Management Type Modern is displayed
- Click on the device to open the Device Preview
- Press Refresh to force a device check-in
Perform a manual device sync
- On your Windows Device
- Press Start
- Open Settings
- Select Accounts
- Press Access work or school
- Open the Silverback Profile
- Press Info
- Scroll Down to Device sync status and perform a sync
Review Agent Installation
- After the Device sync ,the agent will now be transferred to the device. It may take some time. Please be patient
- On your Windows device, reopen the Silverback Profile to see under Applications the status
- e.g. EnforcementCompleted
- e.g. DownloadInProgress
- Check hidden folder on device for C:\EmpirumAgent
- After a couple of time the Empirum Agent icon should appear on the bottom right
If Windows UAC is switched on, the UEM Agent will started automatically after a restart.
- After the agent installation, perform again in the Unified User Experience a device refresh
- Click Refresh to refresh the current tab
- The Management Status should now switch from Modern to Co-Managed
Next Steps
- Learn how to set up a Co-Managed macOS Device
- Review your Agent Installations with the Distribution Dashboard