Skip to main content

Threatlocker Deployment - Windows

Summary

Triggers the Threatlocker Deployment' automation on Windows machines where deployment is enabled.

Details

Name: Threatlocker Depoyment - Windows
Description: Triggers the auto-deployment script for Threatlocker on Windows machines where deployment is enabled.

Recommended Agent Policies: It is advised to configure this compound policy within the following default agent policies:

  • Windows Server [Default]
  • Windows Workstation [Default]

Dependencies

Compound Condition Creation

Compound conditions can be configured within an Agent Policy. This document provides an example using the default Windows Workstation [Default] policy for demonstration purposes.

Navigate to Administration > Policies > Agent Policies.
Navigate

Search for Windows Workstation and select the default Windows Workstation [Default] policy.
DefaultWindowsWorkstation

This will navigate you to the policy's landing page, which is the Conditions section. Note that conditions may vary across different policies and environments. The provided screenshot is for demonstration purposes only.
Conditions

Navigate to the Compound Conditions section. Note that existing compound conditions may vary across different policies and environments. The provided screenshot is for demonstration purposes only.
CompoundConditions

Click the + Add button to add a compound condition.
AddButton

Clicking the + Add button opens the compound condition creation window.
AddACompoundCondition

Conditions

Condition 1: Custom fields

  • Click the + Add condition button.
    AddCondition

  • Select the Custom fields option from the list that will appear after clicking the + Add condition button.
    CompoundConditionCustomFields

  • Add custom fields condition screen will appear on selecting the Custom fields option:
    CompoundConditionCustomFieldsScreen

  • Click the + Add button within the upper section labeled Custom field value must meet ALL conditions.
    AddButtonCustomFields

  • A new row will be added upon clicking the + Add button.
    NewRow

  • Search and select the cPVAL Threatlocker Deployment - Exclude custom field.

  • Condition: cPVAL Threatlocker Deployment - Exclude does not equal Yes

    Image1

  • Click the + Add button within the lower section labeled Custom field value must meet ANY conditions.
    AddButtonCustomFields

  • A new row will be added upon clicking the + Add button.
    NewRow

  • Search and select the cPVAL Threatlocker Deployment custom field.

  • Condition: cPVAL Threatlocker Deployment equals Windows

    Image3

  • Click the + Add button within the lower section labeled Custom field value must meet ANY conditions.
    AddButtonCustomFields

  • A new row will be added upon clicking the + Add button.
    NewRow

  • Search and select the cPVAL Threatlocker Deployment custom field.

  • Condition: cPVAL Threatlocker Deployment equals Windows and Macintosh

    Image2

  • Click the Apply button to save the custom field condition.
    Image5

Automations

Navigate to Automations section.
AutomationSections

Click the + Add automation button.
AddAutomation

Automation Library will appear upon clicking the + Add Automation button.

Note that existing automation library may vary across different environments. The provided screenshot is for demonstration purposes only.
AutomationLibrary

Search and select the Threatlocker Deployment script.
Image6

Click the Apply button to add the automation.
Image7

Completed Automation Section:
Image8

Settings

Navigate to Settings section.
SettingsSection

Set the Settings section as follows:

Name: Threatlocker Depoyment - Windows
Auto Reset:

  • After: True, 24 hour
  • When no longer met: True

Run Every: 24 hour
Minimum uptime for Trigger: True, 10 minutes

Image9

Notifications

Leave the Notifications section untouched.

Completed Component

Click the Apply button at the bottom to save the compound condition.
Apply

Image10

Saving Agent Policy

Click the Save button located at the top-right corner of the screen to save the agent policy.
Save

You will be prompted to enter your MFA code. Provide the code and press the Continue button to finalize the process.
MFA