Setting Up and Configuring Trusted Agent
4 min
role administrators minimum version 2023 1 this topic provides an overview of the process to setup and configure a trusted agent for ldap connection overview of trusted agent setup and configuration this is an overview of the setup and configuration process for trusted agent if you are not already provided with an and/or tenant, request tenant provision for trusted agent from ivanti sales https //www ivanti com/company/contacts skip this step if you already have both tenants provided when you receive email confirmation that the new tenants are provided, request integration of the tenants the tenants must be integrated so that the framework service can be used within request the tenant integration by submitting a generic request to operations, and include both tenant url's a typical message is shown in the following example skip this step if you already have both tenants integrated with a and tenant installed and integrated, proceed to enabling the enabletrustedagent global constant, as described in enable the global constant for trusted agent docid\ a0haynshu5n26tgcudpss create a trusted agent connection and push the settings for policy creation the procedure(s) to follow is dependent on you policy type; ldap or hybrid refer to the procedures linked below for your policy type for ldap policy settings, refer to add a new ldap connection and push policy settings docid\ wfpurw9ip9cetalczxuql for hybrid policy settings, the following procedures must be completed create a self signed certificate docid\ njlu9ljfcpi3urigwiglq export the self signed certificate docid\ njlu9ljfcpi3urigwiglq create a hybrid policy docid\ njlu9ljfcpi3urigwiglq after completing the procedures, use the enrollment key you create to activate the trusted agent installation on your private network download the windows agent installer files and install the trusted agent use the enrollment key you created when required during the installation process see install trusted agent docid\ a0haynshu5n26tgcudpss complete the trusted agent setup and configuration for either ldap or powershell starting from the following topics for ldap, continue from connect trusted agent to the directory server and test the connection docid\ wfpurw9ip9cetalczxuql for powershell, continue from configuring trusted agent with powershell docid\ njlu9ljfcpi3urigwiglq common configuration setup the configuration settings in this section apply to both ldap and powershell enable the global constant for trusted agent log in to as administrator open the configuration console select build > global constants to open the global constants list locate enabletrustedagent in the list, and in the value column, set the value to true click save the global constant is now enabled for trusted agent install trusted agent system specification the minimum requirement for the trusted agent engine is 16gb ram perform this task only after you have completed setting up the trusted agent connection and successfully pushed the policy settings the procedures linked below must be completed before continuing to install trusted agent for ldap policy settings, complete the following procedures add a new ldap connection and push policy settings docid\ wfpurw9ip9cetalczxuql for hybrid policy settings, complete the following procedures create a self signed certificate docid\ njlu9ljfcpi3urigwiglq export the self signed certificate docid\ njlu9ljfcpi3urigwiglq create a hybrid policy docid\ njlu9ljfcpi3urigwiglq the ivanticloudagent exe file is installed on the same network as the private resource to which it connects the ivanticloudagent exe options file contains the tenant id and activation key, which together make up the enrollment key these files are required on the server in your private network where you intend to install trusted agent open fixed port 8883 from the trusted agent machine for message queuing telemetry transport (mqtt) connection use the test netconnection powershell command to test the connection, for example test netconnection computername \<target computer name> port 8883 informationlevel "detailed"> open iis crypto (if installed) and enable tls 1 2 for the server and client you can change the registry to enable tls 1 2 ; however, it is recommended that you install iis crypto to do this open the ivanticloudagent exe installer file using "run as administrator" on the private network server the registration dialog opens the activation key field is automatically populated with the activation key click register open a command line interface and check in the policy a ensure you are in directory c \program files\ivanti\ivanti cloud agent b enter the following command \stagentctl exe update checkin c when check in is complete, enter the following command to check the status \stagentctl exe status check the status shown on the command line interface once the registration state is "registered", and all engines are installed (as shown below) you may need to wait up to 10 minutes for the engines to be installed you can continue to wait, or run the \stagentctl exe status command again to recheck when completed successfully for ldap, continue from connect trusted agent to the directory server and test the connection docid\ wfpurw9ip9cetalczxuql for powershell, continue from configuring trusted agent with powershell docid\ njlu9ljfcpi3urigwiglq
