Deployment
Effortless installation and maintenance
A Linux server with Docker on your premises, a signed MSI agent on your devices, a three-step enrolment. After that, agents are updated from the console.
01Requirements
What you need
| Server | Linux with Docker, installed inside your network |
|---|---|
| Sizing | Indicative: 4 vCPU and 8 GB of RAM for 1,000 devices. Confirmed when we review your fleet. |
| Fleet size | 100 to 1,000 devices per installation |
| Managed systems | Windows (workstations and servers), Linux (servers) |
| Network | Agents reach the server outbound, on port 8443, over your local network or VPN. No port open on devices. |
| Console | Reachable from the networks you authorise, never exposed to the Internet. In French and English. |
| Backups | Automatic every night, with a documented restore procedure |
Roaming devices outside the VPN are not supported yet.
02Enrolment
Three steps per device
Create an enrolment token
In the console, you generate a time-limited, use-limited token. You can revoke it at any time.
Install the agent
Signed MSI installer: a double-click, or a silent msiexec command rolled out through GPO or Intune.
The device shows up
The device joins the console, identified by the key stored in its TPM chip. It is ready to be monitored and updated.
Silent deployment
A single command, distributed through GPO or Intune across the whole fleet.
PS> msiexec /i EPMAgent.msi /qn
- Reinstall without losing history: the machine is recognised by its TPM chip.
- Windows and Linux agents updated from the console, with automatic rollback if the agent does not reconnect.
- Revoke a device in one click.
09:12:00 MSI installer · Authenticode signature verified 09:19:01 Device key created in the TPM 2.0 chip (non-exportable) 09:26:02 Enrolment token accepted 10:33:03 Outbound connection to the EPM server · TLS 1.3 · mTLS 10:40:04 Server authority pinned 10:47:05 Device enrolled · inventory sent
Let's plan your installation
Tell us how many devices and servers you manage, and how they reach your network.