| Description | This article describes how to deploy FortiDLP Agents using Group Policy (GPO) Software Installation. |
| Scope | FortiDLP. |
| Solution |
Windows Domain Group Policy Objects (GPO) can be used to push out a specific version of the FortiDLP Agent. If using GPO to deploy the FortiDLP Agent, there are two important factors to consider:
MSI transforms (MST): To complete this process successfully, transform the installer and supply the path to an enrollment bundle or explicitly include an enrollment code so that the installer can find and use this information to enroll the agent during the initial installation.
General Method: These instructions were written assuming a Windows Server 2012 acting as Domain Controller. For earlier versions see these instructions from Microsoft, following the 'assign software' process.
Upgrades: Upgrades must NOT be pushed from the FortiDLP platform if using GPO. Doing so will conflict with the GPO-required version and result in upgrade/downgrade cycles. Upgrades should be pushed as part of the existing GPO policy with a new version of the agent MSI and any existing transform(s). For example:
Fortinet recommends keeping a copy of each MSI ever used in the same shared folder.
Troubleshooting: In some instances, the FortiDLP Agent may fail to install using the default GPO settings listed above. In such instances, it is recommended to confirm the following settings are in use:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.