Lockfy Agent
The Lockfy Agent is installed on managed workstations so the platform can enforce lock policy, collect endpoint inventory, and perform local account actions such as password rotation and temporary password generation.
For the operational view of deployed endpoints, see Workstations List and Workstation Details.
Deployment Options
Section titled “Deployment Options”Choose the deployment method that best fits your environment:
- Group Policy Objects (GPO): Recommended for domain-joined Windows environments that need centralized rollout.
- PowerShell (Manual): Useful for individual systems, testing, or environments without Group Policy.
If your deployment uses agent credentials, review Authorization Clients and make sure a client with the appropriate scope is available before rollout.
Removal
Section titled “Removal”If you need to uninstall the agent manually, use the PowerShell removal guide.
Before You Begin
Section titled “Before You Begin”Make sure you have the following before deploying the agent:
- Administrative access to the target device or domain.
- The signed Lockfy deployment or removal script provided by your organization.
- The values required by the script, such as your Lockfy API base URL and agent credentials where applicable.
The default script shown in Default Workstation Settings can also be used as a reference when validating deployment values.
Endpoint requirements
Section titled “Endpoint requirements”The deployment script also depends on the following on each target machine. If any is missing, the script fails with a generic console error rather than naming the cause, so confirm them first when a rollout fails on some machines but not others:
- Outbound HTTPS to your Lockfy API base URL. The value passed as the script’s base URL must be reachable from the endpoint, through any proxy or firewall in the path.
- The Background Intelligent Transfer Service (BITS) running. The script uses BITS to fetch the agent package. A disabled or stopped BITS service is a common cause of failures on hardened builds.
- TLS 1.2 enabled. Older images with TLS 1.2 disabled cannot complete the download.
After Installation
Section titled “After Installation”The agent installs as a Windows service and runs continuously. It also registers a Windows Scheduled Task named Lockfy for Business Update Task.
This task is a failsafe, not the normal update path: the agent updates itself while running, and the task exists to recover a machine where the agent has stopped or failed to update on its own. It runs as a service account, is triggered at system boot and on session state changes, and re-runs the deployment script.
Expect to see this task on every managed endpoint. It is worth knowing about before an endpoint audit or a security review raises it, since a scheduled task that re-runs a PowerShell script at boot is exactly the kind of thing such a review flags.