Documentation

Security Suite · Guides

Deployment at scale

Roll the Security Suite agent out to a whole fleet — via RMM/MDM, group policy, or scripted install — verify coverage, and migrate from an existing EDR without a protection gap.

Getting started covers your first few devices. This guide is about covering the whole fleet — reliably, and without a gap in protection.

Deployment methods

MethodBest for
RMM / MDM (Intune, Jamf, etc.)Managed fleets — push the agent to enrolled devices.
Group Policy / config managementWindows domains; Ansible/Chef for servers.
Scripted installOne-liners for imaging and provisioning pipelines.
Manual installerSmall counts and one-off machines.

Each method installs the same agent, which auto-enrolls into the policy group you assign.

Roll out

Download the tenant installer

Get your account-specific installer/token from Security Suite → Deployment. The token binds the agent to your tenant.

Assign a default group

Choose which policy group new devices land in so they're protected the moment they enroll.

Push in waves

Deploy to a pilot ring, confirm health, then expand — servers, then workstations, then the long tail.

Verify coverage

In the Network Portal, reconcile enrolled devices against your asset inventory to find machines still missing the agent.

Migrating from another EDR

Avoid a protection gap

Don't remove your existing EDR before the Suite agent is confirmed healthy on a device — but don't leave two aggressive EDRs fighting long-term either. The safe order is: install the Suite agent → confirm it's reporting → remove the old agent. For servers, do this in a maintenance window.

If you'd rather keep a third-party EDR, you can — forward its telemetry to the Managed SOC instead (see supported log sources), or keep it under centralized management of third-party EDR so ESET, Defender, CrowdStrike, SentinelOne, or Sophos stays where it is while inventory, status, and actions run from one place. The Suite is the simplest path to protection and SOC coverage, not the only one.

Confirm you're covered

A device is fully protected when it shows healthy, is in the right policy group, reports disk encryption on, and its telemetry is reaching the SOC. The Portal flags any device missing one of these.

Need a hand with Security Suite?Talk to our team →