Deploy Agents at scale with Intune

Package the per-machine installer with a deployment token as an Intune Win32 app, so every PC installs silently for all users and enrolls itself — the token is the only secret in the package.

Applies toAgentWindows
Needsdevices.manage

For a few PCs the manual install is fine. For a lab, a block or a whole estate you want every device installed silently for every user and enrolled with nobody clicking through a sign-in screen. You download four files, paste one token into a script, zip them into an Intune package, and Intune installs it everywhere. About 30 minutes, and it works with any MDM that can push a Windows Win32 app.

Before you start

Have these ready.

  • Agent 0.6.0 or newer — the current release is 0.6.2.
  • Microsoft Intune, or another MDM that deploys Win32 apps. Targets are Windows 10 1809 or later / Windows 11, 64-bit.
  • Microsoft's Win32 Content Prep Tool (IntuneWinAppUtil.exe).
  • Access to Agent Setup → Mass Deployment on the dashboard. Revoking a token needs Super Admin.
  • Two or three PCs you can physically check for the pilot.
  1. 01

    Understand what the token does

    Each PC redeems the deployment token once, on its first run, for a credential unique to that machine, and receives your organisation's details in the same reply. So every device appears separately under Agent Devices and can be revoked on its own, the token stops working after the number of machines and days you choose, and it is the only secret in the package.

    This replaces the older approach of writing organisation credentials into each device. Nothing organisation-wide ever leaves the dashboard; a leaked package is a leaked token with a machine cap and an expiry, not a leaked tenant.

    MassComs Agent Setup, Mass Deployment tab, showing the deployment kit downloads and the deployment tokens panel.
    Mass Deployment tabMassComs Agent Setup, Mass Deployment tab, showing the deployment kit downloads and the deployment tokens panel.
  2. 02

    Download the four files

    Agent Setup → Mass Deployment → 1. Windows Intune Deployment Kit. Put all four in one empty folder. The card shows the installer version and its SHA-256, and links the Packaging Guide, which opens in a new tab with a Download as PDF button.

    Field or controlWhat it does
    Per-machine installer (.exe)The file name ends in -perMachine.exe (agent-0.6.2-x64-perMachine.exe). It installs into Program Files as SYSTEM.
    Certificate (.cer)MassComsLimited.cer — the install script imports it into the machine's Trusted Root store before installing.
    Install.ps1Install-MassComsAgentLite.ps1 — silent install, drops the token config, adds the two LAN-controller firewall rules.
    Uninstall.ps1Uninstall-MassComsAgentLite.ps1 — silent uninstall and clean-up.

    Do not package the Windows download from the Desktop Agent tab — it installs per user and fails under Intune. Do not package the .msi either: it carries no token, so every PC would show the Setup window.

  3. 03

    Create a deployment token

    Same page, 2. Deployment tokens. Give it a label, the maximum number of machines and how many days it stays valid, then Create deployment token. The token is shown once — copy it straight away.

    The table below lists every token with Label, Location, Machines (used / max), Expires and Status — active, exhausted or revoked. A Super Admin can Revoke one; machines already enrolled are not affected.

    Field or controlWhat it does
    LabelHow you will recognise it later, e.g. Student laptops Sept 2026.
    Max machines1 to 5000, default 200. The token stops working after this many enrolments.
    Valid for (days)1 to 90, default 30. Enrolled PCs are unaffected when it expires.
    Initial location for this fleet (optional)Site → Building → Floor. Every PC enrolled with this token inherits it, so a whole batch is placed at once. Leave as No specific site for a fleet that spans the organisation; each PC can be moved later from its tray (Reconfigure…).

    One token per package. If you manage several tenants, one token and one package per tenant, labelled unmistakably.

    MassComs Agent Setup, Mass Deployment tab, showing the deployment kit downloads, the token form with initial location, and one active token in the table.
    Deployment tokensMassComs Agent Setup, Mass Deployment tab, showing the deployment kit downloads, the token form with initial location, and one active token in the table.
  4. 04

    Paste the token into the script

    Open Install-MassComsAgentLite.ps1 in Notepad and replace the placeholder on the one line near the top. Save. That is the only edit.

    • $EnrollmentToken = "REPLACE_WITH_DEPLOYMENT_TOKEN"

    Leave $CloudUrl as it is — the Agent accepts only that origin and fetches your organisation's details itself.

    Treat the filled-in script like a password until the token expires: not in source control, not on a shared drive.

  5. 05

    Build the .intunewin package

    Run Microsoft's Win32 Content Prep Tool in a Command Prompt against the folder with the four files. The setup file is the script, not the installer.

    • IntuneWinAppUtil.exe -c "<folder with the 4 files>" -s Install-MassComsAgentLite.ps1 -o "<output folder>"
    Confirm it worked

    You get Install-MassComsAgentLite.intunewin.

  6. 06

    Add it in Intune

    Intune admin center → Apps → Windows → + Add → Windows app (Win32) → pick the .intunewin. Name it MassComs Agent, publisher Strive MassCom, then fill in exactly this and leave everything else at its defaults.

    Field or controlWhat it does
    Install commandpowershell.exe -ExecutionPolicy Bypass -File Install-MassComsAgentLite.ps1
    Uninstall commandpowershell.exe -ExecutionPolicy Bypass -File Uninstall-MassComsAgentLite.ps1
    Install behaviorSystem
    Device restart behaviorNo specific action
    Requirements64-bit · Windows 10 1809 or later
    Detection ruleManually configure → File. Path C:\Program Files\masscomsagent-tauri · File masscomsagent-tauri.exe · File or folder exists · 32-bit app on 64-bit clients: No
  7. 07

    Pilot on two or three PCs

    Assign the app as Required to a small test group. After their next Intune sync, check all three of these before going any wider.

    • Agent Devices on the dashboard lists each PC by hostname, online.
    • On the PC, the MassComs tray icon (bottom-right, maybe behind the ^ arrow) reads Connected (Cloud) on hover.
    • Mass Deployment shows the token's Machines count went up.
    Confirm it worked

    All three, on every pilot PC, with nobody having seen a Setup window.

  8. 08

    Assign to everyone and open the network paths

    Assign to the full device group. The cloud connection is outbound HTTPS only, so there is normally no firewall change; the optional offline LAN controller needs inbound TCP 47809 and UDP 47810, and the install script adds those two Windows Firewall rules itself.

    • If your edge filters by domain (Smoothwall, Lightspeed, Securly and similar): allow admin.masscoms.com, masscoms.lon1.digitaloceanspaces.com and api.elevenlabs.io.

    Domain filters are the usual cause of an Agent that installs fine and never connects. If a whole batch is missing from Agent Devices, look here before looking at the package.

  9. 09

    Place the fleet

    PCs keep the location baked into the token. To move one afterwards, open its tray icon → Reconfigure… → sign in → pick the new site, building and floor; the change is saved to the cloud, so building- and floor-scoped alerts follow it. A PC with no location receives organisation-wide alerts only.

    See Assign an Agent to a site and room.

  10. 10

    Updating later

    Agents deployed this way do not update themselves — they run as a standard user who cannot write to Program Files. For a new version, download the new per-machine installer, rebuild the package with the same script, and add it in Intune as a new app that supersedes the old one. PCs upgrade in place and keep their credential; they do not re-enroll.

Troubleshooting

When it does not go to plan.

SymptomUsual causeFix
Intune says Failed; our log says not the per-machine build or Expected binary not found.The per-user .exe from the Desktop Agent tab was packaged.Use the …-perMachine.exe from Mass Deployment and repackage.
Our log says was not filled in before packaging.The $EnrollmentToken line is still the placeholder.Paste the token in, save, repackage.
Tray says Setup required — use Reconfigure and the PC is not in Agent Devices.The token has expired, been revoked, or is out of machines.Create a new token, update the script, redeploy.
Nothing starts after login.The scheduled task is missing.Task Scheduler should have a MassComs Agent task (At log on of any user). Re-run the install.
Unknown publisher warnings on the PCs.MassComsLimited.cer was missing from the folder.Add it, repackage.
A PC that had a hand-installed Agent misbehaves after deployment.Two copies fight at login.Uninstall the hand-installed copy first (Settings → Apps → masscomsagent-tauri).

Good to know

Small details that prevent big confusion.

  • Logs: ours at C:\ProgramData\MassComs\Logs\intune-install-agent.log; Intune's at C:\ProgramData\Microsoft\IntuneManagementExtension\Logs\IntuneManagementExtension.log.
  • A token expiring or being revoked never disconnects a PC that already enrolled. Revoke a device from Agent Devices instead.
  • Any MDM that can push a Win32 app works — Intune is documented because it is the common case.
  • Silent deployment removes the user from the loop, which is the point — but nobody on the ground will notice a failure. Verify centrally.

Was this guide clear?

Help us make the next version better.