# Deploy Elastic Agent 8.3.2 via Windows GPO

**URL:** <https://discuss.elastic.co/t/deploy-elastic-agent-8-3-2-via-windows-gpo/310689>\
**Category:** Endpoint Security\
**Tags:** windows-installer, elastic-agent\
**Created:** [July 26, 2022, 9:33pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-8-3-2-via-windows-gpo/310689 "2022-07-26T21:33:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbs2web](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbs2web/32/108402_2.png) [@bbs2web](https://discuss.elastic.co/u/bbs2web)\
**Post date:** [July 26, 2022, 9:33pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-8-3-2-via-windows-gpo/310689/1 "2022-07-26T21:33:31Z")

</div>

Hi,

The following is a working PowerShell script to deploy Elastic Agent to Windows workstations via Group Policy 'Startup Script'. Group Policy service by default does not include the permission for it to create SymLinks so the PowerShell script adds this privilege to those requested when starting scripts.

Creates HKLM\SOFTWARE\Admin\_Scripts\ElasticAgent when installed, to avoid constantly recopying files.

GPO settings are as simple as it gets:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c7d76e8976825182f40d54eba6b7971165c4182.png)

I prefer placing smaller deployment tools on the replicated netlogon share. The script copies the content to the local workstation and then installs and registers the agent:

```auto
# Variables:
$Source = "\\ad.company.com\netlogon\ElasticAgent\elastic-agent-8.3.2-windows-x86_64"
$Destination = "$env:temp\ElasticAgent"
$RegistryHive = "HKLM:\\SOFTWARE"
$RegistryKey = "Admin_Scripts"
$ScriptName = "ElasticAgent"

# Group Policies are installed via the gpsvc service, extend rights so that it can create symbolic links and install it next time:
$perm = (Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\gpsvc").RequiredPrivileges;
If ($perm -NotContains "SeCreateSymbolicLinkPrivilege") {
	$perm = $perm + "SeCreateSymbolicLinkPrivilege";
	Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\gpsvc" -Name RequiredPrivileges -Value $perm -Type MultiString;
	Exit 1
};

# Make non-terminating errors terminating.
Trap {
	Write-Error $_ -ErrorAction Continue
	Stop-Transcript
	Exit 1
}
$ErrorActionPreference = 'Stop'

function GetAgent {
	If (!(Test-Path "$env:temp\ElasticAgent")) {
		New-Item -Path $env:temp -Name $ScriptName -ItemType "directory" | Out-Null
	}
	Start-Transcript -Path $Destination"\"install_log.txt -Append -IncludeInvocationHeader
	If (!(Test-Path $Source) -Or !(Test-Path $Destination)) { Throw "$Source and/or $Destination folders are invalid." }
	Copy-Item -Path "$Source\*" -Destination $Destination -Recurse -Force
	If (!(Test-Path $Destination"\elastic-agent.exe")) { Throw "Copy failed." }
}

function InstallAgent {
	cd $Destination
	$ErrorActionPreference = 'Continue'
	.\elastic-agent.exe install --force --url=https://elastic-fleet.company.com:8220 --enrollment-token= ***************************************** 2>&1 | Out-Default
	if ($LastExitCode -ne 0) { Throw "Installation failed." }
	$ErrorActionPreference = 'Stop'
	cd ..
	Start-Sleep -Seconds 5
}

If (Test-Path $RegistryHive"\"$RegistryKey) {
	$reg = Get-Itemproperty -Path $RegistryHive"\"$RegistryKey -Name $ScriptName -ErrorAction SilentlyContinue
}
If (!($reg)) {
	GetAgent
	InstallAgent
	If (!(Test-Path $RegistryHive"\"$RegistryKey)) {
		New-Item -Path $RegistryHive -Name $RegistryKey | Out-Null
	}
	New-ItemProperty -Path $RegistryHive"\"$RegistryKey -Name $ScriptName -Value "1" -PropertyType "DWord" -Force | Out-Null
	Stop-Transcript
	Remove-Item -Force -Recurse $Destination
}
Exit 0

```

---

<div class="post-metadata">

**Author:** ![bbs2web](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbs2web/32/108402_2.png) [@bbs2web](https://discuss.elastic.co/u/bbs2web)\
**Post date:** [July 26, 2022, 9:35pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-8-3-2-via-windows-gpo/310689/2 "2022-07-26T21:35:41Z")

</div>

Kept stumbling in to the following post which provided the base structure of the script I hacked together:

> [@Installing ElasticAgent with GPO](https://discuss.elastic.co/t/installing-elasticagent-with-gpo/302250):
>
> Hi all, I'm looking for installing elastic-agent 7.16 on several Windows PCs with a GPO, EPs could be too many to install it manually. I can't find any guide to do it, so I tried to do it by myself creating a Powershell script to run with a Startup/Logon Script GPO My problem is that the installation seems to work and the C:\Program Files\Elastic\Agent folder is created at the end of the process, but the agent doesn't enroll to the fleet server and the C:\Program Files\Elastic\Agent\elastic-a…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2022, 9:35pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-8-3-2-via-windows-gpo/310689/3 "2022-08-23T21:35:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
