Skip to content

Lockfy Agent

The Lockfy Agent is installed on managed workstations so the platform can enforce lock policy, collect endpoint inventory, and perform local account actions such as password rotation and temporary password generation.

For the operational view of deployed endpoints, see Workstations List and Workstation Details.

Choose the deployment method that best fits your environment:

If your deployment uses agent credentials, review Authorization Clients and make sure a client with the appropriate scope is available before rollout.

If you need to uninstall the agent manually, use the PowerShell removal guide.

Make sure you have the following before deploying the agent:

  • Administrative access to the target device or domain.
  • The signed Lockfy deployment or removal script provided by your organization.
  • The values required by the script, such as your Lockfy API base URL and agent credentials where applicable.

The default script shown in Default Workstation Settings can also be used as a reference when validating deployment values.

The deployment script also depends on the following on each target machine. If any is missing, the script fails with a generic console error rather than naming the cause, so confirm them first when a rollout fails on some machines but not others:

  • Outbound HTTPS to your Lockfy API base URL. The value passed as the script’s base URL must be reachable from the endpoint, through any proxy or firewall in the path.
  • The Background Intelligent Transfer Service (BITS) running. The script uses BITS to fetch the agent package. A disabled or stopped BITS service is a common cause of failures on hardened builds.
  • TLS 1.2 enabled. Older images with TLS 1.2 disabled cannot complete the download.

The agent installs as a Windows service and runs continuously. It also registers a Windows Scheduled Task named Lockfy for Business Update Task.

This task is a failsafe, not the normal update path: the agent updates itself while running, and the task exists to recover a machine where the agent has stopped or failed to update on its own. It runs as a service account, is triggered at system boot and on session state changes, and re-runs the deployment script.

Expect to see this task on every managed endpoint. It is worth knowing about before an endpoint audit or a security review raises it, since a scheduled task that re-runs a PowerShell script at boot is exactly the kind of thing such a review flags.