Skip to main content

How to Install New & Improved CyberSmart Active Protect

How to Install New & Improved CyberSmart Active Protect


​

Individual enrolment

Individual enrolment allows you to send an end user an install link via email. The end user will then follow the instructions to install the software.

This method is predominantly used when there is no single platform for device management. For example, where a business has user-managed devices and bring your own devices (BYOD) this method would be best suited to them.

However, if the business is planning to deploy via RMM, this method would not be supported for this type of deployment. Please see the guidance for Bulk / Centralised deployment below for more information on this deployment method.
​
To invite users to install the application via individual enrollment, just add the new users from the Manage users section of the dashboard:

  1. On the dashboard, open Manage users (Active Protect users tab) and click Add users.

  2. In the Add New App Users window, choose which installer to send — for desktop, select Active Protect Desktop only. (Active Protect for Desktop and Mobile, and Active Protect Mobile only, are also available.)

  3. Enter each user's First name, Last name and Email, and optionally assign them to a Group. Use + Add Row to add more users, or CSV upload to import them in bulk.

  4. Click Submit. An installation link is emailed to each user automatically, and they open it to install Active Protect.


​
If you want to resend Active Protect please go to the relevant user's device page and click Resend Active Protect and select Desktop as the Active Protect version.


Bulk/Centralised Deployment

This deployment method uses the same installer for all users within the organisation.
​
The installer can be downloaded directly from the Dashboard. You can choose any centralised tool of your choice to automate this deployment such as Group Policy Objects (GPO), RMM or MDM tools.

Selecting a Deployment option will prompt you to set a revocable Activation Key (see the CyberSmart Active Protect: Revocable Authentication Mechanism article for the full detail).

For RMM tools set Silent Install Switches & Silent Uninstall Switches to --NoUI


Below are examples of how to deploy using various RMM tools on Windows, for Mac you can use the following guide: MacOS RMM Deployment Script and Steps

ActionONE example:

image1.png

Datto example:

image2.png

To install via powershell use the script below

Link to PowerShell Script

Usage via CMD through PowerShell as Admin

powershell -ExecutionPolicy ByPass -File "CyberSmartActiveProtectInstaller.ps1" "

"

Usage via PowerShell directly as Admin

Firstly run this command in PowerShell:

Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope Process -Force

Then run this:

  • CyberSmartActiveProtectInstaller.ps1 "

    "

Microsoft Intune Example:

Intune counts as a centralised (MDM) deployment, so it uses the same Dashboard installer as the RMM examples above. The difference is that the downloaded installer is already tied to your organisation — the activation key is embedded — so there is nothing to pass at install time. You simply deploy the installer silently and assign it to your groups.

The simplest approach is to deploy the MSI as a line-of-business app:

  1. On the CyberSmart Dashboard, go to Deploy Active Protect and choose Windows or macOS, then generate and download the installer (for Windows this is the .msi, the link beneath the blue Download button; for macOS it is the .pkg).
    ​
    ​

  2. In the Intune admin center, go to Apps > All apps > Create. In Select app type, set the Platform to Windows (or macOS) and the App type to Line-of-business app, then click Select.
    ​
    ​

  3. Click Select app package file and upload the CyberSmart Active Protect installer (.msi for Windows, .pkg for macOS).

  4. On the App information tab, complete the required fields — Name (pre-filled from the installer), Description, and Publisher (e.g. CyberSmart Ltd) — and set App install context to Device. No command-line arguments are needed, and the remaining fields (Ignore app version, Category, URLs, Logo) can be left at their defaults. Click Next.

  5. On the Assignments tab, under Required, click Add group and select the groups you want CAP installed on. Click Next.

  6. On the Review + create tab, check the summary and click Create.

On Windows, if you would rather use the .exe or need pre/post-install steps, package it as a Win32 app instead and use the following as the install command:

"CyberSmart Active Protect Installer.exe" --NoUI

One thing specific to MDM: if you set an expiry on the activation key when generating the download, devices that enrol after it expires will not activate. For an ongoing Intune rollout, set the key to never expire (or to a window that matches the deployment) and revoke it later from CyberSmart Dashboard > Organisation Management > Activation Keys when it is no longer needed.

Group Policy (GPO) Example:

For on-premises Active Directory environments, you can deploy CAP as an assigned MSI through Group Policy. Because the Activation Key is embedded in the MSI, no command-line arguments are needed — the package installs and activates on its own.

  1. Download the CyberSmart Active Protect MSI from the Dashboard, following the Activation Key steps above (Deploy Active Protect > Windows > Generate Download > the .msi link).

  2. Create a network shared folder (on a server or elsewhere on the network) and place the MSI in it.

  3. Share the folder to Domain Computers with Read access.

  4. On the domain controller, open Group Policy Management (Start > Administrative Tools > Group Policy Management).

  5. Expand Forest > Domains > YOURDOMAIN > Group Policy Objects.

  6. Right-click Group Policy Objects and choose New.

  7. Name it, e.g. CyberSmart Active Protect Install, and click OK.

  8. Select the new GPO and, under Security Filtering, remove the default entries.

  9. Add Domain Computers to Security Filtering so the GPO applies to all domain computers.

  10. Right-click your Domains > YOURDOMAIN and choose Link an Existing GPO…

  11. Select CyberSmart Active Protect Install and click OK.

  12. Back under Group Policy Objects, right-click CyberSmart Active Protect Install and choose Edit.

  13. Go to Computer Configuration > Policies > Software Settings > Software installation.

  14. Right-click the empty right-hand pane and choose New > Software Package.

  15. Browse to the MSI using its UNC share path — not the local folder on the server — e.g. \\SERVER\ShareName\CyberSmart Active Protect Installer.msi.

  16. Choose Assigned and click OK.

  17. Close the editor and reboot the workstations. Assigned software installs at startup, before the user logs on.

Because it is assigned to the computer, CAP installs at boot in the system context. You can run gpupdate /force on a client to pull the policy sooner, but the install itself still completes on the next restart.

As with Intune, the MSI on the share is tied to its Activation Key. If the key expires, machines that have not yet installed will fail to activate — set the key to never expire for a standing GPO deployment, or replace the MSI on the share whenever you rotate the key.

Did this answer your question?