There are several ways to create the Windows installer for Agent and ESET security application:
•Quick Links > Deploy Agent
•Installers > Add
•ESET PROTECT On-Prem Tour
Click Windows > Download installer or use ESET Remote Deployment Tool.
|

|
The installer package is an .exe file for Microsoft Windows only.
|
1.Distribution—Select Download installer or use ESET Remote Deployment Tool.
2.Components—Select one or more check boxes from the following options:
•Management Agent—If you do not select other items in the Components, the installer will include only the ESET Management Agent. Select this option if you want to install the ESET security application on the client computer later or if the client computer already has an ESET security application installed.
•Security Application—Include the ESET security application with the ESET Management Agent. Select this option if the client computer does not have any ESET security application installed, and you want to install it with the ESET Management Agent.
• Full Disk Encryption—Include ESET Full Disk Encryption in the installer. This option is visible only with an active ESET Full Disk Encryption subscription.
• ESET Inspect Connector—Include ESET Inspect Connector in the installer. This option is visible only with an active ESET Inspect On-Prem subscription.
|

|
A missing ESET application check box
If the ESET application check box (Full Disk Encryption or ESET Inspect Connector) is missing or deselected automatically after you select the Parent Group, you do not have the application subscription or the application subscription is not allocated to the ESET Business Account site or ESET MSP Administrator company for which you have selected the Parent Group, even if you have access rights to the subscription. Allocate the ESET application subscription to the site (in ESET Business Account) or company (in ESET MSP Administrator). Then the ESET application check box becomes available, and you can include the ESET application in the installer.
|
3.Select the Participate in product improvement program check box to send anonymous telemetry data and crash report to ESET (OS version and type, ESET application version and other application-specific information).
4.Parent group—Select the Parent group where the ESET PROTECT Web Console will place the computer after an Agent installation.
•You can select an existing static group or create a new one to which the device will be assigned after the installer is deployed.
•Selecting a Parent group will add all policies applied to the group to the installer.
•Selecting the Parent Group does not affect the installer location. After you create the installer, it is placed in the current user's Access Group. Access Group sets the object's Static Group and access to the object based on the user's access rights.
• The parent group is mandatory if you use ESET Business Account with sites or ESET MSP Administrator and optional if you use ESET Business Account without sites.
5.Server hostname (optional)—Type the ESET PROTECT Server hostname or IP address. If necessary, specify the Port number (default is 2222).
|

|
The Server hostname field does not support special characters—for example, letters with diacritics.
|
6.Peer certificate:
•ESET PROTECT certificate—A Peer Certificate for Agent installation and ESET PROTECT Certification Authority are selected automatically. To use a different certificate, click the ESET PROTECT Certificate Description to select from a drop-down menu of available certificates.
•Custom certificate—If you use a custom certificate for authentication, click Custom Certificate > Select , upload the .pfx certificate and select it when installing the Agent. For more information, see Certificates.
Certificate passphrase—Type the certificate passphrase if needed—if you have specified a passphrase during ESET PROTECT Server installation (in the step where you created a Certification Authority) or you use a custom certificate with a passphrase. Otherwise, leave the Certificate passphrase field blank.
|

|
•The certificate passphrase must not contain the following characters: " \ These characters cause a critical error during Agent initialization.
•The password must contain at least 14 characters in three categories: lowercase letters, uppercase letters, digits or special characters. We recommend using a password with no less than 17 characters. |
|

|
You can extract the Certificate passphrase because it is embedded in the installer.
|
7.
Customize more settings
•Type the Installer name and Description (optional).
•Components installation—Select the Always install the latest available version of applications and components check box. The latest version of selected application and components will install on devices connected to the internet. If a device does not have internet access, the version you select in the next step of this wizard is installed. Select this check box to use the installer for a longer time to ensure you always install the latest version of applications and components.
• Click Select tags to assign tags.
• Initial configuration (optional)—Use this option to apply a configuration policy to ESET Management Agent. Click Select under Agent configuration and choose from the list of available policies. If none of the pre-defined policies are suitable, you can create a new policy or customize the existing ones.
• If you use an HTTP Proxy (we recommend using ESET Bridge), select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port, Username and Password) to download the installer via Proxy and set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Server. The Host field is the address of the machine running the HTTP Proxy. ESET Bridge uses port 3128 by default. You can set a different port if needed. Ensure to set the same port also in the HTTP Proxy configuration (see ESET Bridge Policy).
|

|
The communication protocol between Agent and ESET PROTECT Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT Server that requires authentication will not work.
|
The Use direct connection if HTTP proxy is not available check box is pre-selected. The installer wizard enforces the setting as a fallback—you cannot deselect the check box. You can disable the setting using an ESET Management Agent policy:
oDuring the installer creation—include the policy in the Initial Configuration
oAfter the ESET Management Agent installation—assign the policy to the computer |
8. Click Finish or Application Setup.
9.
Security application
a.Click the pre-selected ESET security application and change its details:
oSelect another compatible ESET security application.
o Select the language from the Language drop-down menu.
oSelect the Advanced check box. By default, the latest version is pre-selected (recommended). You can select an earlier version.
|

|
If you do not see any application installation files, ensure to set the repository to AUTOSELECT. For more information, see the Advanced settings section of Settings.
|
b. Select the check box next to the setting to enable it for the installer:
oEnable The ESET LiveGrid® feedback system (recommended)
oEnable detection of potentially unwanted applications—Read more in our Knowledgebase article.
oAllow to change protection settings during the installation—We recommend that you do not select this check box.
c.Select the check box I agree to the current Terms of Use and additional legal documents (End User License Agreement) applicable to the installed ESET protection and acknowledge the Privacy Policy. See the legal documents for ESET subscriptions, services and applications.
d.Customize more settings:
oSubscription—Select the appropriate subscription from the list of available subscriptions. The subscription activates the ESET application during installation. The available subscriptions list does not show expired and overused subscriptions (those in the Error or Obsolete state). If you do not select a subscription, you can install the ESET application without the subscription and activate the application later. Use one of the methods described in Subscription Management to add a subscription. Subscription addition/removal is restricted to the Administrator whose home group is All and who has the Write permission on subscriptions.
oConfiguration—Optionally, you can select a Policy that will be applied on the ESET security application during its installation.
o Run ESET AV Remover—Select the check box to uninstall or remove other antivirus applications on the target device.
oApplication modules installation—The option may not be available, depending on the selected ESET security application. By default, the application installer contains only the essential ESET application modules. The remaining application modules are downloaded during the first application startup. Select the Use a security application installer with a full set of application modules check box to create the installer with all application modules (for offline deployments). |
If you have selected Full Disk Encryption or ESET Inspect Connector in step two, you can change their settings.
Full Disk Encryption
a.Click the pre-selected ESET Full Disk Encryption and change its details:
o Select the language from the Language drop-down menu.
oSelect the Advanced check box. By default, the latest version is pre-selected (recommended). You can select an earlier version.
b.Select the check box I agree to the current Terms of Use and additional legal documents (End User License Agreement) applicable to the installed ESET protection and acknowledge the Privacy Policy. See the legal documents for ESET subscriptions, services and applications.
c.Configuration—Select a policy that will be applied on ESET Full Disk Encryption during its installation.
d.Customize more settings:
oSubscription—Select the appropriate subscription from the list of available subscriptions. The subscription activates the ESET application during installation. The available subscriptions list does not show expired and overused subscriptions (those in the Error or Obsolete state). If you do not select a subscription, you can install the ESET application without the subscription and activate the application later. Use one of the methods described in Subscription Management to add a subscription. Subscription addition/removal is restricted to the Administrator whose home group is All and who has the Write permission on subscriptions. |
ESET Inspect Connector
|

|
ESET Inspect Connector requirements:
•You must have an ESET Inspect On-Prem subscription to activate ESET Inspect Connector.
•A compatible ESET security application installed on the managed computer. |
a.Click the pre-selected ESET Inspect Connector and change its details:
o Select the language from the Language drop-down menu.
oSelect the Advanced check box. By default, the latest version is pre-selected (recommended). You can select an earlier version.
b.Select the check box I agree to the current Terms of Use and additional legal documents (End User License Agreement) applicable to the installed ESET protection and acknowledge the Privacy Policy. See the legal documents for ESET subscriptions, services and applications.
c.Customize more settings:
oSubscription—Select the appropriate subscription from the list of available subscriptions. The subscription activates the ESET application during installation. The available subscriptions list does not show expired and overused subscriptions (those in the Error or Obsolete state). If you do not select a subscription, you can install the ESET application without the subscription and activate the application later. Use one of the methods described in Subscription Management to add a subscription. Subscription addition/removal is restricted to the Administrator whose home group is All and who has the Write permission on subscriptions.
oConfiguration—Click Select to select an existing ESET Inspect Connector policy or Create to create a new ESET Inspect Connector policy. The installer will apply policy settings during the ESET Inspect Connector installation.
oType the ESET Inspect Server hostname and the connection port specified during the ESET Inspect Server installation (the default port is 8093).
oSelect the Certification Authority for connection to the ESET Inspect Server. |
10. Click Finish.
11. Download the generated All-in-one installation package. Select the version you want to deploy:
o32-bit (for example, PROTECT_Installer_x86_en_US.exe)
|

|
The latest 32-bit ESET Management Agent version is 12.5. The later Agent versions do not include the 32-bit variant.
|
o64-bit (for example, PROTECT_Installer_x64_en_US.exe)
oARM64 (for example, PROTECT_Installer_arm64.exe)—You cannot install the x86 or x64 version of ESET Management Agent or ESET security application on Windows ARM64.
|

|
All data downloaded from the repository (ESET repository or a custom repository mirror) is digitally signed by ESET and ESET PROTECT Server verifies file hashes and PGP signatures. ESET PROTECT Server generates the All-in-one installer locally. Therefore, the All-in-one installer is not digitally signed, which might generate a web browser warning during the installer download or generate an operating system alert and prevent the installation on systems where unsigned installers are blocked.
|
12. After downloading the All-in-one installer package, you have two deployment options for the ESET Management Agent:
•Locally on a client computer—Run the installation package file on a client computer. It will install the ESET Management Agent and the ESET security application on the device and connect it to ESET PROTECT On-Prem. The ESET Endpoint Antivirus/Security installer created in ESET PROTECT On-Prem supports Windows 11 Enterprise for Virtual Desktops and Windows 11 multi-session mode. For step-by-step instructions, see the Setup Wizard. You can run the installation package in silent mode to hide the Setup Wizard window.
•Use the ESET Remote Deployment Tool to deploy ESET Management Agents to multiple client computers simultaneously.