EnterpriseInstall with an MDM

Deploy with Configuration Manager

Install, configure, detect, repair, upgrade and remove the standalone DefenseClaw enterprise profile on Windows with a Microsoft Configuration Manager application and compliance settings.

Template

This recipe is a template, validated by simulating the MDM execution context. It has not been run in a live tenant.

This recipe deploys the standalone profile to Windows devices with Microsoft Configuration Manager, formerly System Center Configuration Manager (SCCM) and Microsoft Endpoint Configuration Manager (MECM). An application installs and upgrades DefenseClaw, and an optional configuration item keeps it healthy. For the contract every recipe follows, such as exit codes, detection and how config and keys are delivered, see Install with an MDM.

Prerequisites

  • Devices on native x64 Windows that meet the Windows requirements.
  • No Cisco Secure Client DefenseClaw deployment on the device.
  • PowerShell 7 from Microsoft's x64 MSI, deployed as its own application. The standalone lifecycle runs on it and refuses without it. The kit recommends 7.4 or later.
  • Your administrator config.yaml. See Where the config lives and Choose the agents to protect. The default config protects no agent.
  • DefenseClawSetup-Enterprise-Standalone-x64.exe from the release, verified against the release's cosign-signed checksums.txt; see Install with an MDM.

How Configuration Manager runs the application

BehaviorConfiguration ManagerSource
Deployment typeScript Installer, for setup programs and script wrappersCreate applications
IdentityInstallation behavior: Install for system installs once, for all usersCreate applications
BitnessRun installation and uninstall program as 32-bit process on 64-bit clients is an option; leave it clearedCreate applications
TimeoutMaximum allowed run time, 120 minutes by defaultCreate applications
Return codesScript Installer defaults: 0 Success (no reboot), 1641 Hard Reboot, 3010 Soft Reboot, 1618 Fast Retry. Other codes are failures. Fast Retry retries every two hours, 10 times in total.Create applications
Detection scriptA non-zero exit code means detection failed and the state is Unknown. Exit 0 with output means Installed; exit 0 with no output means Not installed.Create applications
Re-evaluationClients re-evaluate deployments every seven days by defaultClient settings
Scripts the client runsThe PowerShell execution policy client setting defaults to All SignedClient settings

Build the content

On an administrator workstation with PowerShell 7.4 or later, run the kit's packager without -IntuneWinAppUtil, and use its content folder as the content location. Despite its name, the content does not depend on Intune:

./packaging/mdm/intune/windows/New-DefenseClawIntunePackage.ps1 `
  -SetupPath .\DefenseClawSetup-Enterprise-Standalone-x64.exe `
  -Sha256 <SHA-256 from the cosign-verified checksums.txt> `
  -ConfigPath .\config.yaml `
  -OutputDirectory \\server\sources\DefenseClaw\1.4.0 `
  -ProductVersion 1.4.0

The content folder holds:

FileRole
DefenseClawSetup-Enterprise-Standalone-x64.exeThe standalone Setup
config.yamlYour administrator config. The packager refuses one with an inline api_key.
Install-DefenseClawIntune.ps1The launcher that runs as the installation program
intune-package.jsonThe SHA-256 pins of the Setup and the config

Setup refuses relative paths, and the client cache path is not known in advance. The launcher solves both: it re-checks the pins, then starts DefenseClawSetup-Enterprise-Standalone-x64.exe /ensure JSON=1 with an absolute CONFIG= path to the config in its own folder. It runs in 32- or 64-bit Windows PowerShell 5.1.

Setup also refuses a config file that a non-administrator can change, or that sits in a folder a non-administrator can replace. If the client cache does not meet that, Setup stops with exit code 1603 and names the file.

Create the application

Create the PowerShell 7 application first, with a Windows Installer deployment type for the x64 MSI. Then create the DefenseClaw application in Software Library > Application Management > Applications > Create Application, choose Manually specify the application information, and add a Script Installer deployment type (Create applications):

PageSettingValue
ContentContent locationThe content folder, such as \\server\sources\DefenseClaw\1.4.0\content
Installation programpowershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File .\Install-DefenseClawIntune.ps1
Uninstall programDefenseClawSetup-Enterprise-Standalone-x64.exe /uninstall JSON=1
Run installation and uninstall program as 32-bit process on 64-bit clientsCleared
Detection MethodSetting typeRegistry
HiveHKEY_LOCAL_MACHINE
KeySOFTWARE\Cisco\DefenseClaw\Enterprise
ValueProductVersion
Data TypeVersion
RuleThis registry setting must satisfy the following rule: Greater than or equal to 1.4.0
This registry key is associated with a 32-bit application on 64-bit systemsCleared
User ExperienceInstallation behaviorInstall for system
Logon requirementWhether or not a user is logged on
Installation program visibilityHidden
Maximum allowed run time (minutes)120
DependenciesDependency groupThe PowerShell 7 application, with Auto Install

Keep the default return codes on the deployment type's Return Codes tab. Deploy the application to a device collection as Required.

The lifecycle's 1603 and 1639 then report as failures: read the error code before you retry, because 1639 always needs a fix. 1618 means another DefenseClaw lifecycle run holds the lock, and Fast Retry handles it. Setup does not return 3010 or 1641 today.

Why registry detection

The lifecycle writes ProductVersion under HKLM\SOFTWARE\Cisco\DefenseClaw\Enterprise only after a successful install, upgrade, repair or ensure, in the 64-bit registry view, and removes the key after a successful uninstall. Only SYSTEM and administrators can write it.

Do not use packaging/mdm/windows/detect.ps1 as the detection script here. It follows Intune's convention and exits 1 when DefenseClaw is not installed, which Configuration Manager reports as Unknown, not Not installed.

The first install needs the config in the content: /ensure without one exits 1639.

Keep it healthy

The registry value proves what is installed, not that it is enforcing. To repair drift between deployments, create a configuration item in Assets and Compliance > Compliance Settings > Configuration Items > Create Configuration Item, type Windows Desktops and Servers (custom), with one setting (Create custom configuration items):

SettingValue
Setting typeScript
Data typeString
Discovery scriptThe PowerShell discovery script below
Remediation scriptThe PowerShell remediation script below
Compliance ruleValue rule: the value Equals Compliant, with Remediate noncompliant rules when supported

The discovery script reads the protected marker in the 64-bit registry view and runs the installed CLI's read-only verify:

# DefenseClaw health check for a Configuration Manager configuration item.
# Prints Compliant when verify passes, or when DefenseClaw is not installed
# (the application deployment installs it).
$hklm = [Microsoft.Win32.RegistryKey]::OpenBaseKey(
    [Microsoft.Win32.RegistryHive]::LocalMachine, [Microsoft.Win32.RegistryView]::Registry64)
$marker = $hklm.OpenSubKey('SOFTWARE\Cisco\DefenseClaw\Enterprise')
if ($null -eq $marker) { 'Compliant'; exit 0 }
$cli = Join-Path ([string]$marker.GetValue('InstallRoot')) 'bin\defenseclaw.exe'
$null = & $cli enterprise windows verify --profile standalone --json 2>&1
if ($LASTEXITCODE -eq 0) { 'Compliant' } else { 'NonCompliant' }

The remediation script runs ensure, which repairs from the installed payload. Configuration Manager reports a remediation failure only when the script throws, so it throws on a non-zero exit code:

# DefenseClaw repair for a Configuration Manager configuration item.
# Runs ensure, which repairs from the installed payload; throws on failure
# so Configuration Manager reports the remediation as failed.
$hklm = [Microsoft.Win32.RegistryKey]::OpenBaseKey(
    [Microsoft.Win32.RegistryHive]::LocalMachine, [Microsoft.Win32.RegistryView]::Registry64)
$marker = $hklm.OpenSubKey('SOFTWARE\Cisco\DefenseClaw\Enterprise')
if ($null -eq $marker) { exit 0 }
$cli = Join-Path ([string]$marker.GetValue('InstallRoot')) 'bin\defenseclaw.exe'
$null = & $cli enterprise windows ensure --profile standalone --json 2>&1
if ($LASTEXITCODE -ne 0) { throw "DefenseClaw ensure exited $LASTEXITCODE" }

Add the configuration item to a configuration baseline and deploy the baseline with remediation. Configuration Manager runs these scripts under the PowerShell execution policy client setting, which defaults to All Signed: sign the scripts, or change the setting. Scripts time out after 60 seconds unless you raise Script Execution Timeout (seconds) in the compliance client settings, up to 600 (Client settings). A full repair can take longer than that. If the remediation times out, run the application's /ensure again on that device. On unsigned (hash-pinned) releases the script's ensure keeps the marker's hash_pinned trust mode, so detect.ps1 and uninstall.ps1 keep accepting the unsigned CLI.

Health means what verify reports; see Health fields.

Deliver the AI Defense key

The key is optional. Without it the local policy engine decides alone. Do not put it in the content, in config.yaml, in a command line or in a script.

Store it after the first install, from an elevated session or your secrets tooling, on standard input:

Get-Content -Raw C:\secure\ai-defense-key.txt | & 'C:\Program Files\Cisco\DefenseClaw\bin\defenseclaw.exe' enterprise secret set --name ai-defense-api-key --from-stdin --json

enterprise secret set runs only elevated and only when a standalone deployment is installed. It stores the key and restarts the gateway, and exits 1639 for invalid input or 1603 on failure. Then set enterprise.inspection.ai_defense.enabled: true and credential: ai-defense-api-key in config.yaml. See Deliver the AI Defense key and AI Defense key.

Upgrade, roll back and change the config

TaskWhat to do
UpgradeBuild content for the new release and create a new application. On its Supersedence tab, add the old application and leave Uninstall cleared, so the new deployment type upgrades in place (Revise and supersede applications). Raise the detection rule to the new version. /ensure upgrades in place, keeps the state, and applies the config in the new content.
Roll backensure refuses to downgrade on Windows. Follow Roll back.
Change the configBuild new content with the new config.yaml and deploy it the same way. /ensure validates the config, applies it, and rolls back if applying fails.

See Upgrades, rollback and config changes.

Uninstall

Deploy the application with the Uninstall action. The uninstall program, DefenseClawSetup-Enterprise-Standalone-x64.exe /uninstall JSON=1, stops and deletes the services, removes DefenseClaw's hooks and machine-policy entries while it keeps administrator entries, and removes the Add/Remove Programs entry and the registry marker. Remove the configuration baseline deployment first, so remediation does not run against a removed deployment.

Logs

WhereWhat
%WINDIR%\CCM\Logs\AppEnforce.logInstall and uninstall actions for applications (Log file reference)
%WINDIR%\CCM\Logs\AppDiscovery.logApplication detection
%WINDIR%\CCM\Logs\DcmWmiProvider.logConfiguration item scripts
%WINDIR%\Logs\DefenseClaw\enterprise-lifecycle.logEvery lifecycle result, one JSON line per run
DefenseClaw event log, source DefenseClaw Lifecycle (legacy copy: Application log, source DefenseClaw Enterprise)Installed, upgraded, repaired, failed, busy and refused events

See Logs.

Exit codes in Configuration Manager

CodeMeaningConfiguration Manager
0Success, or nothing to doSuccess (no reboot)
1603The action failed and rolled back, the config does not validate, Setup is not elevated, or a non-administrator can change the config fileFailure; read errors[].code in enterprise-lifecycle.log and see Lifecycle error codes
1618Another lifecycle run holds the lockFast Retry
1639Invalid arguments, such as a first install without a config, an unknown Setup property, or a relative or environment-expanded CONFIG= pathFailure; fix the content
3010Reserved; Setup does not return it todaySoft Reboot

For the full table, see Exit codes.