> Source: [sk132233](https://support.checkpoint.com/results/sk/sk132233)

# sk132233 - ID-Guard Agent - Installation and Enrollment 

| Property | Value |
|----------|-------|
| Solution ID | sk132233 |
| Date Created | 2018-11-18 |
| Last Modified | 2021-10-21 |
| Technical Level | General |
| Products | Email Security |
| Versions | Cloud |

## Solution

**Table of Contents:**

* Agent Installation
  * Desktop
  * Mobile
* Agent Enrollment
  * First Device Enrollment
  * Additional device Enrollment

Agent Installation {#Agent Installation}
----------------------------------------

### Desktop {#Desktop}

#### **Prerequisites**

The prerequisites for PC Agent installation are:

* Windows 7 and Above
* .Net framework 4.0 and above
* Administrator privileges on the computer for installation

#### **Installation**

Download the relevant PC Agent version from <https://portal.checkpoint.com>, under Identity Protection\\Downloads.

You can do the deployment manually or by using GPO (or similar tools).

### Mobile {#Mobile}

#### **Prerequisites**

The Mobile Agent installation is currently limited to:

* iOS: 8.x, 9.x, 10.x, 11.x
* Android: 4.x, 5.x, 6.x, 7.x, 8.x.

#### **Installation**

* **Customers using an MDM (Mobile Device Management)**: If you are using an MDM to manage your mobile devices, you can use it to push the SandBlast Mobile Protect Application to those devices.
* **Customers using no MDM (Mobile Device Management)**: In order to install the ID-Guard agent, you will need to download the SandBlast Mobile Protect from the Google Play Store or the Apple App Store.

Agent Enrollment {#Agent Enrollment}
------------------------------------

First Device Enrollment {#First Device Enrollment}
--------------------------------------------------

### Desktop

#### Automated Enrollment:

Make sure the following prerequisites are met:

1. The PC is part of the AD FS's domain. Users' email addresses are configured in the Active Directory, in the **E-mail** field:

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk132072/Image11807160101.png)

2. The AD FS server address is configured as **Local intranet** under Windows Internet Options. Configure this automatically if the AD FS address is under the same domain as the PC (e.g., the PC is in domain.com, and the AD FS address is adfs.domain.com).

3. Security settings for **Local intranet zone** are set to **Automatic logon with current user name and password** (Windows default) / Automatic logon only in Intranet zone:

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk132072/Image21807160102.png)

4. The PC Agent uses WIA (Windows Integrated Authentication) in order to securely verify the logged-on user's identity. Configure your AD FS server(s) to enable WIA for the PC Agent by running the following PowerShell command on each AD FS server:

` Set-AdfsProperties -WIASupportedUserAgents ((Get-ADFSProperties | Select -ExpandProperty WIASupportedUserAgents)+"CheckPointAutoRegistration")`  

#### Manual Enrollment:

1. Launch Check Point Identity Protect.
2. Enter your email address.
3. Enter your password.
4. Enter the registration key (received via enrollment email or generated on a registered device).

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk132072/Image31807160104.png)

```

```

### Mobile

#### SandBlast Mobile users:

If you received an enrollment email, open the email from the mobile device you want to enroll and click the link for faster registration.

Otherwise:

1. Launch SandBlast Mobile Protect.
2. Click on the **My Identity** tab.
3. Enter your email address.
4. Enter your password.
5. Enter your registration key.

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk132072/Image41807160107.png)

#### Non-SandBlast Mobile users

Download the SandBlast Mobile Protect application from Google Play or the Apple Store.

If you received an enrollment email, open it from the mobile device you want to enroll and click the link for faster registration.

Otherwise:

1. Launch SandBlast Mobile Protect
2. Enter your email address and your registration key.
3. Enter your password.

Additional Device Enrollment {#Additional device enrollement}
-------------------------------------------------------------

You can register additional devices using a device already registered.

### Desktop

1. Follow the instructions above for Desktop manual installation and enrollment.
2. When prompted for a registration key, open the ID-Guard agent interface on a registered device.
3. Click the**+** icon under the **Devices** section to generate a registration key.

### Mobile

* Follow the instructions above for Mobile manual installation and enrollment.
* When prompted for a registration key, open the ID-Guard agent interface on a registered device.
* Click the **+** icon under the **Devices**section to generate a registration key.

**Related Documentation:**

[Check Point CloudGuard SaaS Identity Protection](https://www.checkpoint.com/downloads/products/cloudguard-saas-identity-protection-technical-brief.pdf)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
