Getting started covers your first few devices. This guide is about covering the whole fleet — reliably, and without a gap in protection.
Deployment methods
| Method | Best for |
|---|---|
| RMM / MDM (Intune, Jamf, etc.) | Managed fleets — push the agent to enrolled devices. |
| Group Policy / config management | Windows domains; Ansible/Chef for servers. |
| Scripted install | One-liners for imaging and provisioning pipelines. |
| Manual installer | Small counts and one-off machines. |
Each method installs the same agent, which auto-enrolls into the policy group you assign.
Roll out
Download the tenant installer
Get your account-specific installer/token from Security Suite → Deployment. The token binds the agent to your tenant.
Assign a default group
Choose which policy group new devices land in so they're protected the moment they enroll.
Push in waves
Deploy to a pilot ring, confirm health, then expand — servers, then workstations, then the long tail.
Verify coverage
In the Network Portal, reconcile enrolled devices against your asset inventory to find machines still missing the agent.
Migrating from another EDR
Avoid a protection gap
Don't remove your existing EDR before the Suite agent is confirmed healthy on a device — but don't leave two aggressive EDRs fighting long-term either. The safe order is: install the Suite agent → confirm it's reporting → remove the old agent. For servers, do this in a maintenance window.
If you'd rather keep a third-party EDR, you can — forward its telemetry to the Managed SOC instead (see supported log sources), or keep it under centralized management of third-party EDR so ESET, Defender, CrowdStrike, SentinelOne, or Sophos stays where it is while inventory, status, and actions run from one place. The Suite is the simplest path to protection and SOC coverage, not the only one.
Confirm you're covered
A device is fully protected when it shows healthy, is in the right policy group, reports disk encryption on, and its telemetry is reaching the SOC. The Portal flags any device missing one of these.
