Deployment

Windows Connection Agent Lifecycle

The Windows Agent path from selection and enrollment to health, updates, disablement, and exit.

Page type: ConceptAgent lifecycleStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-27

The Windows Agent operates a Windows machine as a governed CerberusD resource. This page defines the deployment and operating boundary of the connection agent. Use Connection agent and Identity, scope, and assignment for session decisions and person-resource assignments.

Lifecycle

  1. Path selection: Select Windows Agent when the target and deployment responsibility fit that path. Linux, terminal, and Kubernetes targets use agentless access.
  2. Enrollment and approval: Deploy the package, wait for the machine to appear as a pending resource, and approve the record in the correct workspace.
  3. Health: Agent service state, version, last-seen time, and readiness signals become visible on the resource. These signals do not grant session authority by themselves.
  4. Update: Select the new version from the deployment’s published release channel. Review old and new version, resource state, and connection result together during the change.
  5. Rollback boundary: If an update or preparation result is unusable, the resource is not ready for a new session; use the visible checks in connection troubleshooting. Supported rollback behavior belongs to the deployment release notes; this page invents no commands or versions.
  6. Disablement: When the resource leaves operation temporarily, close new assignments and disable the Agent connection. Review active-session and closure state through Revocation and evidence.
  7. Unregister and exit: When the machine leaves the workspace, the deployment owner applies the claim/record removal and local uninstall plan. Exit evidence shows the resource identity, last state, closure time, and that remaining assignment/session records were reviewed.

Operating boundary

The Agent supplies health signals; it does not own role, assignment, duration, or session-policy decisions. Local-account, password-rotation, private-network, and protocol preparation depend on the selected deployment and enabled policy. Agentless resources do not provide these machine-local signals.

Records to review

  • enrollment and approval time,
  • workspace and resource identity,
  • Agent version, last-seen time, and service state,
  • update or preparation result,
  • disablement, removal, and exit result.

These records establish the machine’s deployment stage. Session success and video evidence use their own readiness and policy checks.