Deploy to a fleet
The six steps to deploy DefenseClaw enterprise to managed Windows, Linux and macOS endpoints, from choosing a profile and agents to your MDM recipe, config, ensure and a ringed rollout.
This page is the short path through an enterprise deployment. Each step makes one decision and links to the page with the details. You need an MDM, configuration-management tool or administrator shell that runs commands as SYSTEM on Windows and as root on Linux and macOS. Terms such as profile, lifecycle and ensure are defined in Concepts.
Not sure enterprise deployment is what you need? Read Is this for you? first. To compare the open-source and enterprise editions feature by feature, see the support matrix.
1. Pick the profile
A managed deployment runs in one of two profiles, and each computer runs only one of them.
| Detail | Standalone | Secure Client |
|---|---|---|
| Choose it when | You deploy with Intune or any other MDM, a package, configuration management or an administrator shell | You run Cisco Secure Client and want DefenseClaw as one of its modules |
| Platforms | Windows, Linux, macOS | Windows, macOS |
| Who decides on each tool call | The local policy engine. Cisco AI Defense is added when you turn it on and store a key | Cisco AI Defense only |
| Next | Continue with step 2 on this page | Secure Client managed deployment |
The rest of this page covers the standalone profile. On Windows and macOS the
profile defaults to Secure Client, so set enterprise.profile: standalone in
the config (Two profiles).
2. Pick the agents
Each agent you protect is a key under guardrail.connectors in the config.
Nothing is protected until you list one. DefenseClaw protects each agent in
one of three ways:
| Route | Agents | What DefenseClaw writes |
|---|---|---|
| Machine policy | Claude Code, Codex, Cursor, GitHub Copilot, and OpenCode with DefenseClaw's managed OpenCode plugin | Its hooks in the vendor's administrator-owned policy files, which apply to every user of the computer |
| Per-user | Devin, Antigravity, Hermes, Amp and Kiro, and OpenCode while the managed plugin is not in force. On Linux and macOS also OpenHands and OmniGent | The guardian writes the hook, or plugin, into each enrolled user's own agent config and repairs it |
| ACP guard | Kiro in an editor that starts it over ACP | Nothing per user: the editor runs Kiro through defenseclaw-gateway enterprise acp |
OpenHands and OmniGent are refused on Windows. Which agent and OS combinations were verified in this release is in the enterprise route table. How to list agents, users and per-agent modes is in Choose the agents to protect and Plan a rollout.
3. Pick your MDM
Every recipe follows the same MDM contract and uses
the scripts in
packaging/mdm.
Each card names what you push.
Intune on Windows
A Win32 app (.intunewin) that wraps the standalone Setup and your config, plus a PowerShell 7 app it depends on.
Intune on macOS
One root shell script: the kit wrapper, which downloads the .pkg and runs ensure.
Intune on Linux
One root platform script: the kit wrapper, which downloads the .deb, .rpm or payload archive.
Jamf Pro
The .pkg from your distribution point, with kit scripts that stage the config and run ensure.
Iru (formerly Kandji)
A Custom App with the .pkg and a Custom Script that runs ensure, or a script-only route.
Workspace ONE UEM
A Win32 app from a ZIP on Windows, an internal app with the .pkg on macOS, and scripts that run ensure.
Configuration Manager
An application whose content folder holds the standalone Setup and your config.
Linux configuration management
Ansible, Puppet, Chef, Salt or plain apt and dnf, installing the .deb or .rpm package.
Any other tool
Any tool that runs a command as SYSTEM or root can call the kit wrapper directly.
The MDM recipes are templates, checked by simulating each MDM's execution context; they have not been run in a live tenant. The release files they deliver:
| OS | Release file |
|---|---|
| Windows x64 | DefenseClawSetup-Enterprise-Standalone-x64.exe |
| Linux | defenseclaw-enterprise-<version>-linux-<arch>.deb or .rpm, or the payload archive defenseclaw-enterprise-<version>-linux-<arch>.tar.gz |
| macOS (Apple silicon) | defenseclaw-enterprise-<version>-darwin-arm64.pkg |
<arch> is amd64 or arm64. DefenseClawSetup-Enterprise-x64.exe, without
-Standalone-, is the Secure Client Setup. Verify the release's signed
checksums.txt once and pin each file by its SHA-256, as
What you deliver shows.
4. Deliver the config and the AI Defense key
The config is one YAML file that only administrators can change. The lifecycle installs it at a fixed path:
| OS | Installed config |
|---|---|
| Windows | C:\ProgramData\Cisco\DefenseClaw\etc\config.yaml |
| Linux | /etc/defenseclaw/config.yaml |
| macOS | /opt/cisco/defenseclaw/etc/config.yaml |
Start from A minimal config, which protects Codex and Claude Code in observe mode. A first install on Windows needs a config. On Linux and macOS an install without one protects no agents. How each wrapper takes the config is in Deliver the config.
The Cisco AI Defense key is optional. It never goes in the config, an MDM
script or a command line. Store it with enterprise secret set, from
standard input or a file only administrators can change: after the install
on Windows, and before or after it on Linux and macOS; see
Deliver the AI Defense key
and Cisco AI Defense key.
5. Run ensure and read the result
ensure is the one action your MDM runs. It installs when nothing is
installed, upgrades when the version differs, repairs drift and applies a
changed config. When the host already matches, it changes nothing and reports
"noop": true, so it is safe on every check-in. The kit's wrappers print one
result document per run and exit with one of these codes:
| Result | Windows | Linux, macOS | MDM action |
|---|---|---|---|
| Success, or nothing to do | 0 | 0 | Success |
| Failed. The change has already rolled back | 1603 | 1 | Read errors[].code |
| Another run or the package manager is busy | 1618 | 75 | Retry later |
| Invalid arguments, such as a first Windows install without a config | 1639 | 2 | Fix the assignment |
For MDM detection, use the registry marker (Windows), the package database or
pkg receipt for inventory, and detect.ps1 or detect.sh with the health
option for health; see Detection. To check a
host by hand:
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise linux status --json
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise linux verify --jsonsudo /opt/cisco/defenseclaw/bin/defenseclaw-gateway enterprise macos status --json
sudo /opt/cisco/defenseclaw/bin/defenseclaw-gateway enterprise macos verify --json# From an elevated PowerShell
$Cli = 'C:\Program Files\Cisco\DefenseClaw\bin\defenseclaw.exe'
& $Cli enterprise windows status --profile standalone --json
& $Cli enterprise windows verify --profile standalone --jsonRead coverage_complete and security_complete in the result
(Health fields). Every exit code
is listed in Exit codes.
6. Pilot in observe mode, then expand in rings
Deploy a pilot ring with guardrail.mode: observe. Observe mode records every
decision, including what DefenseClaw would have blocked, without blocking on
policy verdicts. When the pilot is healthy and the decisions are reviewed, set
guardrail.mode: action and deliver the config again. Then grow the
deployment in rings (pilot, early, broad, everyone), moving on only when a
ring is healthy.
Plan a rollout has a ring plan with sizes and exit criteria (Step 5), and covers choosing users, handling existing per-user installs and planning upgrades and rollback.
Next steps
Threat model
Trust zones, how each boundary is protected, and the risks that remain.
Operate
Check status and health, read logs and events, and verify machine policy.
Upgrade, repair and remove
Upgrade, roll back, change the config, repair and uninstall.
Troubleshooting
Fix a deployment by lifecycle error code, MDM wrapper code, hook refusal code or symptom.
Enterprise deployment
What DefenseClaw enterprise hardening is, which profile to choose, what runs on each endpoint, and what a standard user can and cannot change on Windows, Linux, and macOS.
Plan a rollout
Plan a DefenseClaw enterprise rollout. Choose agents and users, pilot in observe mode, remove per-user installs, and expand in rings.