Skip to main content

Secureframe Agent: Employee Installation Device Guide

Written by Brady Price

Quick start

If your employer asked you to install the Secureframe Agent, follow these four steps:

  1. Download your agent package from the Employee Onboarding page (Device Management in the left sidebar). Choose your operating system and click Download Agent. Each person gets a unique package, so only download from your own account.

  2. Install the package on your device. Windows: Double-click the downloaded file and click Yes. Mac: Double-click the downloaded file and click Install. Linux: Open a terminal in the download folder and run sudo dpkg -i secureframe-agent.deb (Ubuntu) or sudo rpm -i secureframe-agent.rpm (CentOS/RHEL).

  3. Complete onboarding: Return to the Employee Onboarding page and click "If you have downloaded the agent or your operating system is not listed, click here to pass the onboarding installation step." Skipping this step is a common reason onboarding does not show as complete.

  4. Done. Keep your device online for at least 5 minutes so the agent can check in. Sync can take a few hours. You do not need further action unless your admin asks you to configure additional security settings (see below).

Tip: Having trouble downloading or installing? See our FAQs: Secureframe Agent: overview and common questions for help with a spinning download button, offline agent, macOS install warnings, and more.


Supported Operating Systems

Secureframe Agent is a read-only agent that reports key device settings your organization needs for compliance. It only sends the minimum data required to determine whether a device is compliant.

These are the current operating system versions we support:

OS

Supported version(s)

MacOS

13.X+ (Ventura and above)

Windows

10, 11

Linux

Ubuntu 20.04+, RHEL 9.0+, CentOS 8 (EoL)

Note: ChromeOS / Chromebooks are not supported. If you only use a Chromebook, tell your Secureframe admin so they can handle compliance another way.


Installing the Secureframe Agent on Your Device

If you received an onboarding email from Secureframe, your employer has partnered with us to streamline compliance tasks such as security training, policy reviews, and device management.

This guide walks through how to download and install the Secureframe Agent, also called Device Management in Employee Onboarding. You will not find the download in admin Personnel Settings.


Downloading your Agent package

  1. Log into Secureframe and open Employee Onboarding.

  2. In the left sidebar, click Device Management.

  3. Choose your operating system and click Download Agent.

Tip: If the download button keeps spinning, wait a few minutes and refresh the page. Secureframe builds a unique installer for each user, which can take a few minutes. For more help, see FAQs: Secureframe Agent installation, coverage, and troubleshooting.


Installing your Agent package

  • Windows: Double-click your downloaded package and click Yes.

  • MacOS: Double-click your downloaded package and click Install. If macOS shows a “could not verify” / blocked developer warning, see the macOS install guidance in FAQs: Secureframe Agent installation, coverage, and troubleshooting.

  • Linux: Open a terminal in the download folder and run sudo dpkg -i secureframe-agent.deb for Ubuntu (.deb), or sudo rpm -i secureframe-agent.rpm for CentOS/RHEL (.rpm).

After installing, return to Employee Onboarding and click "If you have downloaded the agent or your operating system is not listed, click here to pass the onboarding installation step."

Important:

  • One package per person: Each download is a unique installation package that links your user account to your device. Do not install the same package on multiple devices or share your download link. That can cause devices to disappear or report incorrect statuses.

  • Windows Defender warnings: If using Windows Defender, you may see an unknown publisher warning. Secureframe Agent packages are signed for users joined after Feb 8, 2025. Contact your admin if this is a problem. Manual evidence can be uploaded if you choose not to install the Agent.


Additional security settings after install

Installing the agent reports your device to Secureframe, but your organization may also require specific security settings on your laptop. If a compliance check is failing, use the guides below for step-by-step setup:

On Linux, some checks are not supported due to operating system limitations. See Fields Pulled for details.


Installed but onboarding still incomplete?

If you installed the agent but Employee Onboarding still shows the device step as incomplete, or your admin says your device is missing, check the following before contacting support:

  1. Allow time to sync. Keep the device online for at least 5 minutes after install. Full sync can take a few hours. Your admin may then see the device in Asset Inventory. Employees should use Employee Onboarding task status to confirm their own progress.

  2. Click the pass-onboarding link. Installing the agent alone does not mark onboarding complete. Return to Employee Onboarding and click "If you have downloaded the agent or your operating system is not listed, click here to pass the onboarding installation step."

  3. Use only your own package. Each user must download and install their own agent build. Installing the same package on multiple devices (or sharing a download link) can prevent devices from reporting correctly.

  4. Confirm the agent is running. On Windows, check Services for Fleet osquery or Orbit Osquery. If the agent shows as offline, see the FAQ articles under More help.

  5. Re-download if needed. If installation appeared successful but nothing syncs, uninstall the agent, download a fresh package from Employee Onboarding, and reinstall. Uninstall the old agent before installing a new one.

If the issue persists after trying the steps above, contact [email protected] with your device name, operating system, and the email address you use to log into Secureframe.


Frequently Asked Questions (FAQ)

Where do I download the Agent? I do not see a Download button.

  • Open Employee OnboardingDevice Management (left sidebar). The Agent download is not under admin Personnel Settings. If your org enabled Agent only for certain personnel groups, you may see an install task without a download button. Ask your Secureframe admin to confirm your group is included.

Can I install Secureframe Agent on a Chromebook?

  • No. ChromeOS is not supported. Tell your admin so they can track compliance another way for Chromebook users.

How do I know the install worked?

  • After install, click the pass-onboarding link on Employee Onboarding, keep your device online for at least 5 minutes, then wait for sync (can take a few hours). Your onboarding device task should move forward. Your admin can confirm the device in Asset Inventory after check-in.

macOS blocked the installer or the Agent crashes on a new macOS version. What should I do?


More help

For additional questions about installation, troubleshooting, and agent behavior, see:

Did this answer your question?