Installing the Agent
The Pckgr agent is a Windows service that runs on each managed device. It handles application deployments, script execution, policy enforcement, and status reporting.
For Mac devices, see Installing the Agent on macOS.
Prerequisites
- Windows 10 or Windows 11
- Administrator access on the device
- Network access to the Pckgr API
- An enrollment token (generated from the portal)
If your devices run AppLocker, App Control for Business, Attack Surface Reduction rules or a restrictive PowerShell execution policy, read Hardened Environments before enrolling: it lists every path the agent runs from, which files are signed, and the rules to put in place.
Generating an Enrollment Token
Before installing the agent, you need an enrollment token:
- Go to Settings > Agent Setup in the portal sidebar.
- Click New Token.
- Configure the token:
- Expires In - How many days until the token expires (1–365 days, default: 7).
- Never expires - Turn this on instead of setting days when the token will be baked into an Intune or other MDM deployment. The token stays valid until you delete it, so give it a sensible use limit and delete it once the rollout is done.
- Maximum Uses - How many devices can enroll with this token (1–10,000, default: 100).
- Click Create Token.
- Copy the token value. You can only view the full token at creation time.
Token Status
| Status | Meaning |
|---|---|
| Active | Token can be used for enrollment |
| Expired | Token has passed its expiration date |
| Exhausted | Token has reached its maximum use count |
You can delete tokens you no longer need. Deleting a token does not affect devices that have already enrolled with it.
Silent Install (Recommended)
Run this command in an elevated command prompt or PowerShell:
This installs the agent silently and enrolls the device in one step. The agent starts automatically as a Windows service.
To include a log file for troubleshooting:
To skip automatic device renaming for this device (even if device naming is enabled on the tenant):
See Skipping Device Rename below for more details.
Interactive Install
- Double-click the MSI installer.
- Follow the installation wizard.
- When prompted, paste your enrollment token.
- Optionally check Skip automatic device renaming if you don't want this device to be renamed.
- Complete the wizard. The agent service starts automatically.
Deploying via Group Policy or SCCM
You can distribute the MSI through your existing deployment tools:
- Place the MSI on a network share accessible to target devices.
- Configure the MSI property:
ENROLLMENT_TOKEN=<your-token> - Optionally add
SKIP_RENAME=1to prevent automatic device renaming. - Deploy as a standard MSI package.
Manual Enrollment (CLI)
If you installed the agent without an enrollment token, you can enroll manually:
To skip automatic device renaming:
Skipping Device Rename
When device naming is enabled on a tenant, every newly enrolled device is automatically renamed. If you want to enroll a specific device without renaming it (e.g., servers, kiosks, or machines that already have a correct name), you can opt out on a per-device basis.
| Method | How to Skip |
|---|---|
| Interactive install | Check Skip automatic device renaming on the enrollment dialog |
| Silent install | Add SKIP_RENAME=1 to the msiexec command |
| CLI enrollment | Add --skip-rename to the enroll command |
| Group Policy / SCCM | Add SKIP_RENAME=1 to the MSI properties |
This is a per-device decision made at enrollment time. It does not change the tenant-level setting - other devices will continue to be renamed as normal. If you later want to rename a device that was enrolled with skip rename, you can assign a name manually from the device detail page in the portal.
Verifying the Installation
After installation, verify the agent is running:
Check the service
The service should show STATE: RUNNING.
Check enrollment status
Check the portal
The device should appear on the Devices page within a minute of enrollment.
How the Agent Works
Once installed, the agent runs continuously in the background:
- Polls for jobs every 15–30 seconds to check for new deployments or scripts
- Executes deployments by downloading application packages, running the installer, and reporting results
- Reports status including connection health, Windows Update information, and installed software inventory
- Enforces policies by applying configuration settings and reporting compliance
- Uploads logs after each job for review in the portal
Connection Status
The portal shows each device's connection status based on how recently it checked in:
| Status | Meaning |
|---|---|
| Online | Checked in within the last 7 minutes |
| Away | Checked in 7–30 minutes ago |
| Offline | Checked in more than 30 minutes ago |
| Dormant | No check-in for longer than the dormant threshold (default: 30 days) |
Uninstalling the Agent
To remove the agent:
This stops the service and removes agent data. To also remove the device from the portal, delete it from the Devices page.
Troubleshooting
Device doesn't appear in the portal
- Verify the service is running:
sc query PckgrAgent - Review the agent log at
C:\ProgramData\Pckgr\Logs\agent.log - Ensure the device has network access to the Pckgr API
- Verify the enrollment token is still active and not expired or exhausted
Jobs are not executing
- Confirm the service is running
- Check agent logs for errors
- Verify the device is in a group that has app assignments
Agent service won't start
- Check Windows Event Viewer under Application for error details
- Ensure no other instance is running
- The service automatically restarts on failure (with a 60-second delay)