Deployment
Windows Connection Agent Lifecycle
The Windows Agent path from selection and enrollment to health, updates, disablement, and exit.
The Windows Agent operates a Windows machine as a governed CerberusD resource. This page defines the deployment and operating boundary of the connection agent. Use Connection agent and Identity, scope, and assignment for session decisions and person-resource assignments.
Lifecycle
- Path selection: Select Windows Agent when the target and deployment responsibility fit that path. Linux, terminal, and Kubernetes targets use agentless access.
- Enrollment and approval: Deploy the package, wait for the machine to appear as a pending resource, and approve the record in the correct workspace.
- Health: Agent service state, version, last-seen time, and readiness signals become visible on the resource. These signals do not grant session authority by themselves.
- Update: Select the new version from the deployment’s published release channel. Review old and new version, resource state, and connection result together during the change.
- Rollback boundary: If an update or preparation result is unusable, the resource is not ready for a new session; use the visible checks in connection troubleshooting. Supported rollback behavior belongs to the deployment release notes; this page invents no commands or versions.
- Disablement: When the resource leaves operation temporarily, close new assignments and disable the Agent connection. Review active-session and closure state through Revocation and evidence.
- Unregister and exit: When the machine leaves the workspace, the deployment owner applies the claim/record removal and local uninstall plan. Exit evidence shows the resource identity, last state, closure time, and that remaining assignment/session records were reviewed.
Operating boundary
The Agent supplies health signals; it does not own role, assignment, duration, or session-policy decisions. Local-account, password-rotation, private-network, and protocol preparation depend on the selected deployment and enabled policy. Agentless resources do not provide these machine-local signals.
Records to review
- enrollment and approval time,
- workspace and resource identity,
- Agent version, last-seen time, and service state,
- update or preparation result,
- disablement, removal, and exit result.
These records establish the machine’s deployment stage. Session success and video evidence use their own readiness and policy checks.