The device path: a short route from a signed agent to live coverage across a managed fleet.
Updated July 2026
The shortest real path from a signed installer to live device coverage. This is Endpoint Protection's quickstart, the device product; for the hosted connector with nothing to install, start at the Connect quickstart. A fleet rollout is three steps: push the agent, push the trust profile, watch devices appear in the console. Nothing on this page requires an employee to do anything.
Onboarding provisions two things for the firm: a dedicated single-tenant stack in its own AWS account, and the signed agent installers with a per-tenant enrollment key. The on-premise and private deployment guide covers what is inside that stack. For an individual evaluation on one machine, the trial demo is the faster route; this page is the fleet path. An Endpoint pilot follows the same path at a smaller scale: after the review meeting, one approved test laptop first, then a small pilot group for twenty-one days measured from activation, and a decision in writing at the end.
Deploy the signed package for each platform, a notarized .pkg on macOS and a signed .msi on Windows, through the MDM the firm already runs (Jamf, Intune, Kandji, Mosyle, Workspace ONE, JumpCloud). The package carries the agent and the companion app in one bundle. The MDM rollout guide has the per-MDM specifics.
Alongside the package, push the per-tenant certificate profile (com.apple.security.root on macOS, a Trusted Certificate profile in Intune on Windows). This is what lets the agent inspect AI traffic. It is the same mechanism enterprise TLS-inspection products use, and it is the one step that cannot be skipped: without the trusted certificate the agent stays in passthrough and inspects nothing. It never breaks a site either way.
The agent activates itself at first boot. It registers the device against the firm's stack with the enrollment key, mints its own signing keys, configures the system proxy, and begins inspecting AI traffic. There is no first-run wizard and no employee prompt in the MDM path.
Open the console. The Overview page has two views: Flow shows employees and the AI providers they reached, and Servers shows which AI surfaces are covered. A newly enrolled device appears as soon as it sees its first AI traffic. The chain pill in the corner confirms the signed record is intact and growing.
| To understand | Read |
|---|---|
| What the agent inspects and what it never touches | The device proxy |
| What happens to a sensitive prompt | Redaction and tokenization |
| How AI agents and their tools are governed | Agent governance |
| Where alerts actually arrive day to day | Slack and Teams |
| How to prove it out on one machine first | Single-device validation |
| The exact hosts the agent talks to | Network endpoints |
| How to take it all back out | Rollback and uninstall |