Single = one host, pre-baked key (1-10 endpoints). Fleet = one enrollment installer per OS for many hosts via RMM / GPO / Ansible / MDM (each host self-enrolls). Both report through the public gateway agents.sentryglobal.net and land in tenant-<slug>.
The client's tenant. Agents are placed in tenant-<slug> (isolation + labelling).
Mixed fleet? Pick All to get one installer per OS - route each to the matching device group (GPO/Intune to Windows, Ansible to Linux, MDM to macOS).
agent idgroupmanager
After it runs, the endpoint appears Active in the SOC within ~30s. Re-generate for each host (each key is single-use per agent).
EDR / endpoint protection — · group
Multi-file bundle. Deliver it alongside the base installer above — the client runs the base installer first, then extracts this zip and runs the endpoint-protection script (elevated). The agent is already in the ransomware group, so detection config + rules push automatically.
Each installer self-enrolls its endpoints into the tenant group. The enrollment password is embedded, so treat these files as sensitive. For a mixed fleet, route each OS installer to the matching device group.
Push each file to the matching device group via RMM / GPO / Ansible / MDM (run as SYSTEM / root). Every host self-registers and appears in the SOC.