Intune on Linux
Deploy the standalone DefenseClaw enterprise profile to Intune-managed Ubuntu and Red Hat Enterprise Linux devices with a root platform script, report its health, deliver the AI Defense key and remove it.
Template
Intune manages Ubuntu and Red Hat Enterprise Linux devices that are enrolled with the Microsoft Intune app. It deploys Bash platform scripts, but no Linux app packages. So one root platform script downloads, verifies, installs and configures DefenseClaw. This recipe follows the MDM contract; read that first for the exit codes, detection and logs.
Before you start
- Devices: a distribution and version on Microsoft's list of Intune-supported Linux platforms, enrolled with the Microsoft Intune app, running systemd 239 or later. The package depends on systemd 239. On a host where systemd is not running, the package installs but the deployment stays inactive.
- Release: verify
checksums.txtand read the pin of the artifact you deploy, as in What you deliver. Ubuntu needs the.deb, RHEL the.rpm. The payload archivedefenseclaw-enterprise-<version>-linux-<arch>.tar.gzworks on both. - Config: write the config as described in Configuration. Keep the AI Defense key out of it.
1. Host the artifact
Put the package or payload archive on an HTTPS location the devices can reach,
for example an Azure Blob Storage container or your artifact server. The
wrapper downloads it with curl (or wget) and accepts only https:// URLs.
If the download needs a proxy, set DC_HTTPS_PROXY in the next step; only
the download uses it.
2. Fill in the wrapper's settings block
Copy packaging/mdm/linux/defenseclaw-enterprise.sh and edit the settings
block at the top of your copy. Intune runs the script with no arguments, so
every value goes here:
DC_ACTION=ensure
DC_SOURCE_URL="https://downloads.example.com/defenseclaw/defenseclaw-enterprise-1.4.0-linux-amd64.deb"
DC_SOURCE_SHA256="replace-with-the-64-hex-sha256-from-checksums.txt"
DC_TRUST_MODE=hash_pinned
DC_PRODUCT_VERSION="1.4.0"For GPG trust, when the release ships signatures, set DC_TRUST_MODE=signed,
DC_GPG_KEYRING to a root-owned keyring you deploy separately (convert
defenseclaw-enterprise-release-key.asc with gpg --dearmor), and
DC_SIGNATURE_URL to the artifact's .asc. The wrapper still checks
DC_SOURCE_SHA256 when you set it.
Ubuntu and RHEL need different packages. Create one script per distribution and assign each to a device group that holds only that distribution, or use the payload archive in a single script.
Then paste the config between the DEFENSECLAW_CONFIG markers in
dc_inline_config. This minimal config protects Claude Code and Codex in
observe mode; build yours from
Choose the agents to protect:
dc_inline_config() {
cat <<'DEFENSECLAW_CONFIG'
config_version: 8
deployment_mode: managed_enterprise
data_dir: /var/lib/defenseclaw
policy_dir: /etc/defenseclaw/policies
enterprise:
profile: standalone
gateway:
api_bind: 127.0.0.1
api_port: 18970
guardrail:
enabled: true
mode: observe
connectors:
claudecode:
enabled: true
codex:
enabled: true
DEFENSECLAW_CONFIG
}On Linux, data_dir must be exactly /var/lib/defenseclaw. Never put the AI
Defense key in the script: Microsoft states that custom scripts must not carry
sensitive information.
3. Add the platform script
Go to Devices > Manage devices > Scripts and remediations > Platform scripts > Add > Linux:
| Setting | Value |
|---|---|
| Execution context | Root. The script then runs whether or not a user is signed in. The first run can ask the user for consent. |
| Execution frequency | Daily. ensure changes nothing when the host already matches, but with DC_SOURCE_URL set every run downloads the artifact before it compares versions. Run more often only if that download is acceptable, or leave DC_SOURCE_URL empty once installed. |
| Execution retries | 3. Exit 75 means dpkg, rpm or another lifecycle run held a lock, and a later run succeeds. |
| Execution script | Your edited copy of defenseclaw-enterprise.sh |
Assign it to device groups. On each run the wrapper downloads the artifact,
verifies it, installs the package only when its version differs from the
installed one, runs ensure with the config, and exits with the lifecycle's
code. A busy package manager, for example during unattended upgrades, exits
75 (mdm_package_manager_busy).
4. Report health
The platform script's own run status is the first signal: it fails whenever
ensure fails. For a separate health signal, add a second root platform
script: a copy of packaging/mdm/linux/detect.sh with
DC_REQUIRE_HEALTHY=1 and, optionally, DC_MIN_VERSION="1.4.0" in its
settings block. In the default exit format it exits 0 when DefenseClaw is
installed, new enough and passes verify, and 1 otherwise, so its run status
reports health. Set its retries to No retries.
Intune's custom compliance cannot run detect.sh: Microsoft runs Linux
discovery scripts in the signed-in user's context, and DefenseClaw's status
is readable only by root.
On the device, the package database answers inventory for the deb and rpm channels:
dpkg-query -W -f='${Status} ${Version}\n' defenseclaw-enterprise
rpm -q defenseclaw-enterpriseDeliver the Cisco AI Defense key
After DefenseClaw is installed, deliver the key once through an administrator channel, such as SSH, your configuration-management tool or a secrets agent that runs as root. First make sure the config turns the feature on; see Cisco AI Defense key.
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise secret set \
--name ai-defense-api-key --from-file /root/ai-defense.key
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise secret statusOr, from tooling that can drop a root-only file, run the wrapper with
--secret-name ai-defense-api-key --secret-file /path/to/root-only-file.
Delete the source file afterwards. Storing the key re-runs ensure, which
applies it.
Change the config, upgrade and roll back
- Change the config: edit the config in the script and save it. The next
run validates and applies it. An invalid config fails the run with
config_invalidand leaves the installed config unchanged. - Upgrade: host the new artifact, then update
DC_SOURCE_URL,DC_SOURCE_SHA256andDC_PRODUCT_VERSION. Keep each host on one channel: a host installed from the deb or rpm refuses a payload-archive upgrade. - Roll back:
rpm -Urefuses an older rpm. See Roll back.
Remove DefenseClaw
First remove the devices from the install script's assignment. Then assign a
root platform script with packaging/mdm/linux/uninstall.sh. It stops and
removes the services, removes DefenseClaw's hooks and machine-policy entries
(administrator entries stay), and removes the deb or rpm. Set DC_PURGE=1 in
its settings block to also remove /etc/defenseclaw (config, policies, key),
the state and the logs. On a host with nothing installed it exits 0, so
repeated runs are harmless.
Notes
- SELinux: after installing files, the lifecycle runs
restoreconon/opt/defenseclawand/etc/defenseclaw, so they get their default contexts. - Logs: the wrapper writes
/var/log/defenseclaw-enterprise-mdm.log(root,0600). The package's ownensureresult is in/var/lib/defenseclaw-enterprise/last-package-result.json. - Status on a device:
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise linux status --jsonIntune on macOS
Deploy the standalone DefenseClaw enterprise profile to Apple silicon Macs with a Microsoft Intune shell script, report its version with a custom attribute, deliver the AI Defense key and remove it.
Deploy with Jamf Pro
Install, configure, detect, repair, upgrade and remove the standalone DefenseClaw enterprise profile on Macs with Jamf Pro packages, policy scripts and an extension attribute.