Product → OPERATIONS GUIDE · AGENT INSTALLATION
OPERATIONS GUIDE · AGENT INSTALLATION
Install the Windows agent and verify the first heartbeat
The agent is installed with an organization-specific enrollment key. It communicates outbound over HTTPS/WSS, reports health and receives approved management commands from the Lira portal.
Use a pilot and keep an independent recovery channel. Lira changes access controls on real Windows servers. Keep console, hypervisor, iLO/iDRAC, VPN or tested WinRM access available before applying a policy.
What a successful enrollment means The server appears in the registry with the expected hostname and address.
The agent reports a current heartbeat and can receive a test command. No inbound management port is required for the normal agent channel.
Related security guidance
1. Generate an organization key Register the organization and open the agent installation dialog in the portal. Use the individual enrollment URL or command generated for this organization. Treat the key as a credential: do not publish it in tickets, screenshots or public documentation. 2. Install on the pilot server Open an elevated PowerShell or Command Prompt session. Run the generated installer command exactly as shown in the portal. Wait for the agent service to start; do not create a second enrollment for the same server while the first is pending. 3. Verify and expand Confirm hostname, internal/external address, Windows version and agent version. Wait for the first heartbeat and review the server event in the portal. Test a read-only status command before enabling MFA, firewall, Defender or update policies. Roll out to additional servers in small groups and record the change owner. Recovery when the agent is offline Check the Windows service and outbound HTTPS/WSS connectivity. Use previously configured WinRM or a console to restart the service. If the server was enrolled with a wrong identity, stop the old service and create a fresh organization key instead of reusing a name or IP. Never delete and recreate an active server record until the identity and last heartbeat have been reviewed.
Before installation Administrator PowerShell or CMD is available. The server can make outbound HTTPS connections. The organization has an available server licence. An independent recovery path has been tested. The server clock is synchronized.
Common questions Does the agent require an inbound port? No. The standard channel is outbound HTTPS/WSS. WinRM is an optional recovery and diagnostics path.
Can I reuse one key on several servers? No. Generate and use an individual enrollment key for each server so identity, events and recovery remain unambiguous.
Connect one pilot server first Use an organization-specific key, verify the heartbeat and only then extend the policy to the rest of the server park.
Open the Lira console