Idolbe Patch

Install the Windows agent

Requirements, one-click install, silent and mass deployment, what the agent does, uninstall.

The Windows agent is a single executable, IdolbePatchAgent.exe, that runs as a Windows service under the SYSTEM account. It inventories the computer, detects missing updates and vulnerabilities, and executes the actions you queue in the console.

Requirements

ItemRequirement
Operating systemWindows 10 or 11 (64-bit), Windows Server 2016 or later
Built-in componentsPowerShell 5.1 and the Windows Update Agent (present on every supported version)
Third-party updatesApp Installer (winget) from the Microsoft Store, present by default on Windows 10 1809+ and Windows 11
NetworkOutbound HTTPS (TCP 443) to the console. No inbound port, no VPN, no proxy configuration required when the system proxy allows HTTPS
Rights to installLocal administrator (the installer elevates itself and asks for confirmation)
Disk and memoryAbout 30 MB on disk; the service idles at a few MB of RAM

Install on one computer

  1. In the console open Getting started and click Download Agent. The downloaded file is unique to your organization: the enrollment key is embedded in it, so there is nothing to type.
  2. Run the file on the computer and approve the Windows security prompt.
  3. The agent copies itself to C:\Program Files\IdolbePatch\, enrolls the computer, installs the IdolbePatchAgent service and starts it. A confirmation window says "This computer is now managed by Idolbe Patch".
  4. Back in the console, Getting started shows Agent installed and the computer appears under Endpoints within a minute.

Running the same file again on an already-managed computer upgrades the agent in place and keeps its identity; it never creates a duplicate endpoint.

Windows executables and the MSI are Authenticode-signed (publisher: IT HELP SERVICES). Windows SmartScreen may still show "Windows protected your PC" on the first installations while the certificate builds its reputation: click "More info" then "Run anyway", or deploy silently as described below, which shows no prompt. Every release is also signed with an Ed25519 key that the agent verifies before any self-update.

Silent install (Group Policy, Intune, SCCM, RMM)

Getting started → Other options shows these commands with your key filled in. Run them elevated (SYSTEM or an administrator):

# Enroll, then install the service (no user interaction)
IdolbePatchAgent.exe -register -enrollmentkey "<your enrollment key>"
IdolbePatchAgent.exe -install

MSI package for Group Policy software installation, Intune Win32 apps or SCCM: Getting started → Other options → Download IdolbePatchAgent.msi (the key is a property, not baked in):

msiexec /i IdolbePatchAgent.msi ENROLLMENTKEY="<your enrollment key>" /qn
msiexec /x IdolbePatchAgent.msi /qn

The MSI installs the same executable, enrolls the computer and registers the service as SYSTEM. Installing a newer MSI upgrades in place and keeps the endpoint's identity; /x tells the console and removes the service. Intune detection rule: the service IdolbePatchAgent exists.

Download and install in one step from a startup script or an RMM tool:

Invoke-WebRequest "<console URL>/api/agents/download?key=<your enrollment key>" -OutFile "$env:TEMP\IdolbePatchAgent.exe"
& "$env:TEMP\IdolbePatchAgent.exe" -register -enrollmentkey "<your enrollment key>"
& "$env:TEMP\IdolbePatchAgent.exe" -install

The enrollment key identifies your organization, not a computer. Treat it like a password: anyone who has it can enroll computers into your organization. Rotate it from Organizations → Rotate key if it leaks; agents already enrolled keep working (they hold their own per-endpoint token).

Active Directory Deployer

Agent Deployment turns one enrolled domain computer into a deployer: it scans Active Directory for computers without the agent and installs it remotely with the domain credentials you provide. The credentials are stored encrypted in the console and handed to the deployer once per scan; they never appear in the queued command. See the page itself for prerequisites (admin shares, WinRM or SMB reachability).

What the agent does

  • Check-in every hour: hardware, operating system, logged-on user, network, disks, installed software (machine and per-user, including Microsoft Store and winget applications), antivirus, BitLocker, pending reboot, Windows Update settings.
  • Missing updates: Windows Update including the Microsoft Update service (Office MSI editions, .NET, SQL Server, drivers), Windows feature updates (version upgrades such as 23H2 → 24H2, shown as "Feature Updates" when Windows Update offers them to the device), Microsoft 365 Apps click-to-run builds compared with the latest build of the device's update channel, and third-party applications through winget in the user's session plus the version catalog. Drivers are hidden by the default "All except Drivers" filter but are available.
  • Vulnerabilities: the console correlates the inventory with NVD, CISA KEV and Microsoft advisories; nothing is scanned on the computer itself.
  • Commands every 30 seconds: Run Script (PowerShell or CMD, as SYSTEM), Deploy Updates (Windows Update, feature updates, Microsoft 365 Apps through the Office click-to-run client, winget), Deploy Software (MSI, EXE, MSIX, winget), Uninstall Software, Reboot with the branded end-user prompt, data source collections.
  • Self-update: when the console publishes a newer agent, the agent downloads it at its next check-in, verifies the signature and restarts itself. Agent Auto-Update can be turned off under Advanced → Endpoints.

Command output is capped at 4 MB and every command has a timeout (per action type, or the timeout you set in the payload); a runaway script is killed together with its child processes.

Files, logs and permissions

PathContent
C:\Program Files\IdolbePatch\IdolbePatchAgent.exeThe service executable
C:\ProgramData\IdolbePatch\agent.jsonIdentity and per-endpoint token. Readable by SYSTEM and Administrators only
C:\ProgramData\IdolbePatch\agent.logRolling log (2 MB); the first place to look when something is wrong
C:\ProgramData\IdolbePatch\shared\Branding and prompt definitions readable by users (reboot prompt)
C:\ProgramData\IdolbePatch\user\Third-party update list written by the per-user winget helper

The agent hardens these permissions at every start.

Uninstall

From an elevated prompt:

"C:\Program Files\IdolbePatch\IdolbePatchAgent.exe" -uninstall

The agent tells the console first (the endpoint disappears immediately instead of lingering as disconnected), stops and deletes the service, then removes its configuration, logs and program files. When an organization is closed from Subscription → Close Account, every online agent receives this order automatically (Data retention and account closure).

Deleting an endpoint from the console (Endpoints → Delete, or the API) also removes the agent: at its next check-in the console answers that the endpoint was revoked and the agent uninstalls itself (agents 0.11.4 and later; older agents stop with an error in their log). Running the download again on that computer enrolls it deliberately and lifts the revocation.

Moving a computer to another organization

Uninstall the agent, then run the download of the new organization. The agent refuses to switch organizations silently: an enrolled computer only ever re-enrolls into the organization whose key it holds.