# AQUILA Deployment Guide: EDR Installation via AD GPO with Scheduled Task

<span style="color: rgb(53, 152, 219);">**Introduction**</span>

This guide provides a step-by-step process to deploy the **Aquila EDR Agent** across multiple Windows endpoints using **Group Policy Objects (GPO)** with a Scheduled Task. This method ensures automated, consistent deployment across the organization while maintaining centralized logging and verification.

<span style="color: rgb(53, 152, 219);">**Scope &amp; Audience**</span>

This document is intended for:

- **System Administrators** responsible for endpoint security deployment.
- **IT Operations Teams** managing Active Directory and GPO configurations.
- **Security Engineers** who need visibility into EDR installation and validation.

The guide assumes a working knowledge of **Active Directory**, **Group Policy Management Console (GPMC)**, and **basic PowerShell scripting**.

<span style="color: rgb(53, 152, 219);">**Pre-requisites**</span>

- Administrator access to the Windows Server.
- A valid copy of the **Aquila Agent EXE installer**.
- The provided **Install-EDRAgent.ps1** PowerShell deployment script.
- Active Directory domain with client computers joined.

<span style="color: rgb(53, 152, 219);">**Step 1: Log in to the Windows Server**</span>

1. Sign in with an **Administrator account** to ensure you have the required permissions.
2. Confirm you can access **Active Directory Users and Computers (ADUC)** and **Group Policy Management**.

<span style="color: rgb(53, 152, 219);">**Step 2: Prepare Deployment Folders**</span>

On the server, create the following directories in the system drive (`C:\`):

- **C:\\Script** → Stores the PowerShell script (`Install-EDRAgent.ps1`)
- **C:\\EXE** → Stores the installer (`AquilaAgent.exe`)
- **C:\\Logs** → Stores deployment logs from each client computer
- **C:\\ZIP →** Stores the EDR zip file

Or you can choose where the folder and files will be placed just take note of the advanced shared path on each

![1.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/A2YRhir2Zf6adOMl-1.png)

<span style="color: rgb(53, 152, 219);">**Step 3: Configure Folder Sharing and Permissions**</span>

**1. Script Share (C:\\Script)**

- Right-click the folder → **Properties** → **Sharing** tab → **Advanced Sharing**.
- Check **Share this folder**.
- Click **Permissions**:
    
    
    - Remove *Everyone* (optional).
    - Add **Domain Computers** → grant **Read**.
- Click **OK** → **Apply**.
- Go to **Security (NTFS Permissions)** → **Edit**:
    
    
    - Ensure **Domain Computers** have:
        
        
        - ✔ Read &amp; Execute
        - ✔ List Folder Contents
        - ✔ Read

**2. Software Share (C:\\Software)**

- Right-click the folder → **Properties** → **Sharing** → **Advanced Sharing**.
- Check **Share this folder**.
- Click **Permissions**:
    
    
    - Add **Domain Computers** → grant **Read**.
- Click **OK** → **Apply**.
- Go to **Security (NTFS Permissions)** → **Edit**:
    
    
    - Ensure **Domain Computers** have:
        
        
        - ✔ Read &amp; Execute
        - ✔ List Folder Contents
        - ✔ Read

![2.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/2KSiwomiOvOnqcZw-2.png)

![3.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/taehzgi5tmJtYXwq-3.png)

**3. DeployLogs Share (C:\\DeployLogs)**

- Right-click the folder → **Properties** → **Sharing** → **Advanced Sharing**.
- Check **Share this folder**.
- Click **Permissions**:
    
    
    - Add **Domain Computers** → grant **Change** (or Full Control).
- Click **OK** → **Apply**.
- Go to **Security (NTFS Permissions)** → **Edit**:
    
    
    - Ensure **Domain Computers** have:
        
        
        - ✔ Modify
        - ✔ Read &amp; Execute
        - ✔ List Folder Contents
        - ✔ Write

![4.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/rOVTDdVQlKACTMBi-4.png)

![5.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/t2BZHpqDiuYNqoWh-5.png)

<span style="color: rgb(53, 152, 219);">**Important Note:**</span>

After all permissions have been configured, please take note of the **network paths** for each folder:

- **Script** → `\\YourServerHostNameHere\Script`
- **Software** → `\\YourServerHostNameHere\Software`
- **DeployLogs** → `\\YourServerHostNameHere\DeployLogs`

(Replace **YourServerHostNameHere** with the actual hostname or FQDN of your server.)

<span style="color: rgb(53, 152, 219);">**Script:**</span>

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/t5wQATNL9Gfn60Sp-image.png)

<span style="color: rgb(53, 152, 219);">**Software:**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/FmGsfUFKvcW1xN8Q-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/FmGsfUFKvcW1xN8Q-image.png)

**<span style="color: rgb(53, 152, 219);">DeployLogs:</span>**

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/GcC9nlW7h9DfGTUv-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/GcC9nlW7h9DfGTUv-image.png)

These **UNC paths** will be required when:

- Configuring the **GPO Scheduled Task (Action Tab)** to point to the PowerShell script.
- Editing the script to reference the correct **server hostname** in your environment.

<span style="color: rgb(53, 152, 219);">**Step 4: Place the Required Files**</span>

The following deployment files are provided by our team and must be placed in the correct folders:

- Copy **Aquila Agent.msi** to `C:\Software`.
- Copy **DeployEDR.ps1** to `C:\Script`.

<span style="color: rgb(53, 152, 219);">**Step 5: Open Group Policy Management**</span>

1. On your Windows Server, open **Group Policy Management** (`gpmc.msc`).
2. Decide which **Organizational Unit (OU)** contains the computers you want to deploy the EDR to.
    
    
    - Example: `Workstations` OU or `Servers` OU.

<span style="color: rgb(53, 152, 219);">**Step 6: Create a New GPO for Deployment**</span>

1. Right-click the target **OU** → select **Create a GPO in this domain, and Link it here**.
2. Name the GPO clearly, e.g., **EDR Deployment – Aquila Agent**.
3. Right-click the new GPO → select **Edit**.

<span style="color: rgb(53, 152, 219);">**Step 7: Configure the Scheduled Task (to Run the Script)**</span>

Inside the GPO Editor:

1. Navigate to:  
    `Computer Configuration → Preferences → Control Panel Settings → Scheduled Tasks`
2. Right-click → **New** → **Scheduled Task (At least Windows 7)**.

**General Tab**

- **Name:** `Deploy EDR – Aquila Agent`
- **Description:** Runs the deployment script to install Aquila Agent.
- **Action:** Create
- **Security Options:**
    
    
    - **When running the task** textbox, type **NT AUTHORITY\\SYSTEM** 
        - (This runs the task as the **SYSTEM** account — full local privileges; no password needed.)
    - Check **Run whether user is logged on or not**.
    - Check **Run with highest privileges**.
    - **Configure for:** Select `Windows®️ 7, Windows Server<strong class="Yjhzub" data-complete="true">™</strong> 2008R2` (or choose whichever fits in your organization).

**Triggers Tab**

- Click **New** →
    
    
    - Begin the task: **At Startup** (ensures every reboot attempt deployment).
    - Alternatively: **At Logon** (runs when any user logs in).
- Check **Enabled** → OK.

**Actions Tab**

- Click **New** →
    
    
    - Action: **Start a program**.
    - Program/script: `powershell.exe`
    - Add arguments:
        
        <div class="sticky top-9">  
        </div><div class="overflow-y-auto p-4" dir="ltr">`-ExecutionPolicy Bypass -File "\\YourServerHostNameHere\Script\DeployEDR.ps1"`</div>
    - (Replace YourServerHostNameHere with the actual hostname or FQDN of your server.)
    - Click Ok.

**Settings Tab**

- Check: **Allow task to be run on demand**.
- Check: **If the task fails, restart every 1 hour, up to 3 times**.
- Check: **Stop the task if it runs longer than X hours** (e.g., 2 hours).

Click **OK** to save the Scheduled Task.

<span style="color: rgb(53, 152, 219);">**Step 8: Edit the Script Before Testing**</span>

Before running any tests, update the script with the correct server hostname.

1. On the server, navigate to:  
    `C:\Script`
2. Locate **DeployEDR.ps1** → right-click → **Open with Notepad**.
    
    
    - Alternatively: Open **Windows PowerShell ISE** → **File → Open** → navigate to `C:\Script\DeployEDR.ps1`.
3. In the script, scroll to the **Configuration Block** section.
4. Locate the following fields:
    
    
    - **`$MsiPath`**
    - **`$CentralLogShare`**
5. Replace **`YourServerHostNameHere`** with the **actual server hostname**.

---

<span style="color: rgb(53, 152, 219);">**Example Configuration Block**</span>

**Before editing:**

<div class="overflow-y-auto p-4" dir="ltr" id="bkmrk-%23-configuration-bloc">`# Configuration Block$MsiPath = "\\YourServerHostNameHere\Software\Aquila Agent.msi"$CentralLogShare = "\\YourServerHostNameHere\DeployLogs" `</div> **After editing (example if hostname = SRV-DC01):**

<div class="overflow-y-auto p-4" dir="ltr" id="bkmrk-%23-configuration-bloc-1">`# Configuration Block$MsiPath = "\\SRV-DC01\Software\Aquila Agent.msi"$CentralLogShare = "\\SRV-DC01\DeployLogs"`</div>---

💡 **Tip:** If you are unsure of the server hostname:

1. Open **Command Prompt**.
2. Run:
    
    <div class="contain-inline-size rounded-2xl relative bg-token-sidebar-surface-primary"><div class="overflow-y-auto p-4" dir="ltr">`hostname`</div></div>
3. Copy the displayed **hostname** and use it in the script.

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-09/scaled-1680-/gMYJpdzyT4zkuIip-image.png)

<span style="color: rgb(53, 152, 219);">**Step 9: Force GPO Update on Clients (Testing First)**</span>

Before rolling out to production, always **test the GPO deployment** on a small set of test machines (e.g., lab devices or a pilot group). This ensures the script, permissions, and scheduled task all work as expected.

To apply the new GPO immediately on a test client machine:

1. Open **Command Prompt as Administrator** (Run as Admin).
2. Run:
    
    `gpupdate /force`

> ⚠️ Note: Running `gpupdate` without admin rights only refreshes **user policies**. Since this deployment is a **computer policy**, it must be executed in an elevated (Administrator) Command Prompt.

<span style="color: rgb(53, 152, 219);">**Step 10: Verify Scheduled Task on Clients**</span>

After **forcing** the GPO, confirm that the scheduled task has been created.

1. On the client computer, open **Task Scheduler (taskschd.msc) as Administrator**.
    
    
    - ⚠️ Running without admin rights may prevent you from seeing the scheduled task.
2. Navigate to **Task Scheduler Library**.
3. Locate and verify that the task **“Deploy EDR – Aquila Agent”** exists.
4. Confirm the task is configured to:
    
    
    - Run under the **SYSTEM** account.
    - Trigger **At Startup** or **At Logon** (depending on your configuration).
    - Run with **highest privileges**.
5. Alternatively, reboot the test client to automatically trigger the scheduled task.

<span style="color: rgb(53, 152, 219);">**Step 11: Verify EDR Installation and Logs**</span>

1. On the client machine, open **Programs and Features** (or run `appwiz.cpl`) → confirm that **Aquila Agent** is listed as installed.
2. Review deployment logs stored in:
    
    <div class="sticky top-9"><div class="absolute end-0 bottom-0 flex h-9 items-center pe-2"><div class="bg-token-bg-elevated-secondary text-token-text-secondary flex items-center gap-4 rounded-sm px-2 font-sans text-xs">  
    </div></div></div><div class="overflow-y-auto p-4" dir="ltr">`\\YourServer\DeployLogs`</div>
    - Each client machine writes its installation results to this shared log folder.
    - Logs will indicate whether the deployment was **successful** or if there were **errors**.

> ⚠️ **If you encounter errors in the logs** (for example, a misconfiguration in the script or hostname issues), please email the log files to our support team at **support@cytechint.com<a class="decorated-link cursor-pointer" data-end="741" data-start="720" rel="noopener"> </a>**for further assistance.

<span style="color: rgb(53, 152, 219);">**Final Note - Customization Support**</span>

If you already have an existing folder structure for hosting the **.msi installer** or the **deployment script** on your AD server, please email us at **support@cytechint.com.**  
Our team can provide a **tailor-made version of the script** to match your environment and ensure smooth deployment.

<span style="color: rgb(53, 152, 219);">**Troubleshooting Tips**</span>

<div class="_tableContainer_1rjym_1" id="bkmrk-issue-possible-cause"><div class="group _tableWrapper_1rjym_13 flex w-fit flex-col-reverse" tabindex="-1"><table class="w-fit min-w-(--thread-content-width)" data-end="6867" data-start="6167"><thead data-end="6220" data-start="6167"><tr data-end="6220" data-start="6167"><th data-col-size="sm" data-end="6179" data-start="6167">**Issue**

</th><th data-col-size="sm" data-end="6200" data-start="6179">**Possible Cause**

</th><th data-col-size="md" data-end="6220" data-start="6200">**Resolution**

</th></tr></thead><tbody data-end="6867" data-start="6275"><tr data-end="6384" data-start="6275"><td data-col-size="sm" data-end="6304" data-start="6275">Task not created on client

</td><td data-col-size="sm" data-end="6322" data-start="6304">GPO not applied

</td><td data-col-size="md" data-end="6384" data-start="6322">Run `gpresult /r` to confirm policy applied to computer.

</td></tr><tr data-end="6514" data-start="6385"><td data-col-size="sm" data-end="6424" data-start="6385">MSI installation fails (Exit Code 1)

</td><td data-col-size="sm" data-end="6458" data-start="6424">Wrong path or missing installer

</td><td data-col-size="md" data-end="6514" data-start="6458">Verify `$MsiPath` UNC path and folder permissions.

</td></tr><tr data-end="6632" data-start="6515"><td data-col-size="sm" data-end="6536" data-start="6515">Logs not generated

</td><td data-col-size="sm" data-end="6568" data-start="6536">Wrong `$CentralLogShare` path

</td><td data-col-size="md" data-end="6632" data-start="6568">Ensure DeployLogs share is accessible to Domain Computers.

</td></tr><tr data-end="6743" data-start="6633"><td data-col-size="sm" data-end="6658" data-start="6633">gpupdate has no effect

</td><td data-col-size="sm" data-end="6685" data-start="6658">Not run as Administrator

</td><td data-col-size="md" data-end="6743" data-start="6685">Re-run `gpupdate /force` in elevated Command Prompt.

</td></tr><tr data-end="6867" data-start="6744"><td data-col-size="sm" data-end="6769" data-start="6744">Script doesn’t execute

</td><td data-col-size="sm" data-end="6797" data-start="6769">Execution policy blocking

</td><td data-col-size="md" data-end="6867" data-start="6797">Ensure `-ExecutionPolicy Bypass` is in Scheduled Task arguments.

</td></tr></tbody></table>

</div></div>*If you need further assistance, kindly contact our support at* ***support@cytechint.com*** *for prompt assistance and guidance.*