For IT teams · Updated

Deploying JiggleGuard on Windows

How the Windows agent installs, what it needs, where it keeps its configuration and how to remove it. This describes the current private beta; check the status table before planning a rollout.

What you need

  • Company-managed Windows computers and administrator rights to install software on them.
  • An agent API key, generated on the Deploy page of your JiggleGuard console.
  • Outbound HTTPS from each computer to your JiggleGuard console address.
  • A staff notice and, where needed, a DPIA before you switch monitoring on. See data and privacy.

Install

Put the MSI and Deploy-JiggleGuard.ps1 together (for example on a network share or in an Intune Win32 package) and run the script as an administrator:

.\Deploy-JiggleGuard.ps1 -ApiKey "<your agent API key>"

The script installs the MSI silently, writes the agent's configuration and starts the JiggleGuard service. Optional parameters set a fixed agent ID (otherwise one is generated), a different console address, the alert threshold (low, medium, high or critical; medium by default) and the reporting interval (five minutes by default). An install log is written to the Windows temp folder.

  • Intune: package the MSI and script as a Win32 app and use the script as the install command.
  • Group Policy: run the script as a computer startup script, with the MSI on a share the computers can read.
  • SCCM: add the script as a task-sequence step.

These are the deployment routes the installer is designed for. We're still validating them across real fleets in the beta, so tell us which one you plan to use.

What it puts on the computer

  • The agent program in Program Files\JiggleGuard, registered as the JiggleGuard service with delayed automatic start.
  • Its configuration in ProgramData\JiggleGuard\config.json. The folder is restricted to SYSTEM, Administrators and the service account, and the API key is protected with Windows DPAPI.
  • A rolling ten-minute input buffer in memory, and a local queue of up to 10 MB for reports that couldn't be sent yet.

Staff don't need to do anything, but they should know the agent is there and what it does. What it reads and sends is set out in data and privacy.

Remove

.\Deploy-JiggleGuard.ps1 -Uninstall

This stops the service, uninstalls the MSI and deletes the configuration folder. Records of the computer already sent to the console stay there until retention removes them or you ask us to delete them.

Other platforms

The macOS agent is in development. It will need the Input Monitoring permission, granted at scale through an MDM configuration profile. Linux isn't supported. Managing a mix of clients? See JiggleGuard for MSPs, and the full feature status in how detection works.

Plan a Windows pilot

We're inviting a small number of organisations to the private beta. Join the list for an invitation, or ask us a question first.