To deploy the Secure Access Module from Microsoft Intune:
- In the TrendAI Vision One™ console, go to Zero Trust Secure Access > Secure Access Configuration > Secure Access Module.
- Click Download agent installer.
- Specify the agent installer package settings.
- Select Windows (32-bit, 64-bit).
- Select the proper the OS architecture.
- Click the Download installer.
- On your local machine, unzip the agent installer package to a folder that is easy to find.
- Download the Microsoft Win32 Content Prep Tool, and unzip it.
- Run
IntuneWinAppUtil.exeand specify the information when prompted.Prompt Setting Source folder Specify the directory where the agent installer is located. The following example uses
D:\TMEndpointBasecampZTSAM-x86_64-active.Setup file Type the full file path with EndpointBasecamp.exe.Output folder Specify the destination for the created package. The following example uses the same location as the unzipped agent installer package.
Specify catalog folder Type NThe tool creates a deployment package named
EndpointBasecamp.intunewin. - In Microsoft Intune, go to Apps > All apps and click Add.
The Select app type window appears. - Select Windows app (Win32).
The Add App window appears. - On the App information tab, click Select app package file.
- In the App package file screen, click the folder icon to locate the
EndpointBasecamp.intunewinpackage. - Click OK.
- Specify a unique Name for the app.
TrendAI™ recommends using a name which includes the agent information, such asTrendAI Vision One Endpoint Sensor Agent. - Specify a Description to easily identify the purpose of the app.
- For Publisher, type
TrendAI™. - Click Next.
- Configure the Program tab and click Next.
- Install command: Type
EndpointBasecamp.exe - Uninstall command: Type
EndpointBasecamp.exe /qn
- Install command: Type
- Configure the Requirements tab and click Next.
- Operating system architecture: Select 64-bit.
- Minimum operating system: Refer to the Secure Access Module System Requirements for your agent and security environment needs.
- Configure the Detection rules tab.
- For Rules format, select Manually configure detection rules.
- Click Add to add new detection rules.
Rule Type Settings File - Path: %ProgramFiles%\Trend Micro\ZTSA
- File or folder: ZTSAWindows.exe
- Detection method: Select File or folder exists.
- Associated with a 32-bit app on 64-bit clients: Select No.
- Click Next, then click Next again to go to the Scope tags tab.
- Click Select scope tags to assign a scope tag for the agent installer.
- Click Next to go to the Assignments tab.
- Add the groups or users you wish to deploy the agent installer to, then click Next.
- Review the settings and then click Create.
