ESET Online Help

Search English
Select the category
Select the topic

Create Agent (and ESET security product) installer

The procedure of creating an All-in-one installer (including ESET Management Agent and an ESET security product) package is similar to a Startup Wizard.


The installer package is an .exe file and is valid for Microsoft Windows operating systems only.

Click Other Deployment Options in the Quick Links section of the menu bar. In the Deploy Agent window, click Create installer under Create All-in-one installer (Windows only). The Create All-in-one installer window will open.


Deselect the check box Participate in product improvement program if you do not agree to send crash reports and anonymous telemetry data to ESET (OS version and type, ESET product version and other product-specific information). If the check box is left selected, telemetry data and crash reports will be sent to ESET.

Package contents - Select the check box(es) from the following options:

Management Agent - If you do not select other items in the Package contents, the installer will include only the ESET Management Agent. Select this option if you want to install the ESET security product on the client computer later, or if the client computer already has an ESET security product installed.

Security Product - Include the ESET security product with the ESET Management Agent. Select this option if the client computer does not have any ESET security product installed and you want to install it with the ESET Management Agent.

Full Disk Encryption - Encryption option is visible only with active ESET Full Disk Encryption license.

Enterprise Inspector Agent - Include ESET Inspect Connector in the installer.

Security Product

1.License (Optional) - you can add a license using one of the methods described in License Management. If you already have existing licenses in License Management, simply choose the license that will be used to activate the ESET security product during the installation. If you do not choose a license, you can create an installer without it and activate the product later. Addition/removal of a license is only allowed to be done by the Administrator whose home group is set to All and who has Write permission on licenses in that group.

2.Product - Select an ESET security product that will be installed together with ESET Management Agent. The ESET Endpoint Antivirus/Security installer created in ESET PROTECT 8.1 and later supports Windows 10 Enterprise for Virtual Desktops and Windows 10 multi-session mode.


If you do not see any product installation files, make sure you have the repository set to AUTOSELECT. For more information, see the Advanced settings section of Server settings.

3.Language - Select the language version of the ESET security product installer.

4.Optionally, you can select a Policy that will be applied on the ESET security product during its installation.

5.Protection settings - select the check box next to the setting to enable it for the installer:

oEnable The ESET LiveGrid® feedback system (recommended)

oEnable detection of potentially unwanted applications - Read more in our Knowledgebase article.

Select the check box next to Do not define Protection settings right now (not recommended) if you do not want to define the protection settings for the installer and you want to set them via policy later.

6.Select the check box I accept the terms of the application End User License Agreement and acknowledge the Privacy Policy. See End User License Agreement (EULA), Terms of Use and Privacy Policy for ESET products for more information.

Enterprise Inspector Agent

ESET Inspect Agent requirements:

You must have a ESET Inspect license to activate ESET Inspect Connector.

A compatible ESET security product installed on the managed computer.

1.License (optional) - ESET recommends that you select the ESET Inspect license to activate ESET Inspect Connector during the installation. If you create the installer without the license, you can activate ESET Inspect Agent later.

2.Product/Version - Select the version of ESET Inspect Connector. The latest available version is preselected.

3.Configuration Policy (optional) - Select an existing ESET Inspect Connector policy to apply policy settings during the ESET Inspect Connector installation.

4. Select the check box I accept the terms of the application End User License Agreement and acknowledge the Privacy Policy. See End User License Agreement (EULA), Terms of Use and Privacy Policy for ESET products for more information.

5.Type the ESET Inspect Server hostname and the connection port specified during the ESET Inspect server installation (the default port is 8093).

6.Select the Certification Authority for connection to the ESET Inspect server.


A Peer Certificate and ESET PROTECT Certification Authority are chosen automatically based on the available certificates. If you want to use a different certificate than the one automatically selected, click ESET PROTECT Certificate to see a list of available certificates and then select the one you want to use. If you want to use your own Custom certificate, click the radio button and upload a .pfx certificate file.

Enter your Certificate passphrase if needed. For example, if you have specified the passphrase during the installation of ESET PROTECT, or if you are using a Custom certificate with a passphrase. Otherwise, leave the Certificate passphrase field blank.


The certificate passphrase must not contain the following characters: " \ These characters cause a critical error during the initialization of the Agent.


Be aware that it is possible to extract the Certificate passphrase because it is embedded in the .exe file.


In this section, you can customize the All-in-one installer package:

1.Optionally, you can change the Name and enter a Description for the package installer.

2.Click Select tags to assign tags.

3.Parent group (optional) - Select the Parent group where the computer will be placed after installation. You can select an existing static group or create a new static group to which the device will be assigned after the installer is deployed.

4.ESET AV Remover - Select the check box to uninstall or completely remove other antivirus programs on the target device.

5.Initial installer configuration (Optional) - Use this option to apply configuration policy to ESET Management Agent. Click Select under Agent configuration (optional) and choose from the list of available policies. If none of the pre-defined policies are suitable, you can create a new policy or customize the existing ones.

6.Server hostname (optional) - Type the ESET PROTECT Server hostname or IP address. If necessary, you can specify the Port number (default is 2222).

7.If you use an HTTP Proxy, select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port, Username and Password) to set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Server. The Host field is the address of the machine where the HTTP Proxy is running. HTTP Proxy uses the port 3128 by default. You can set a different port if needed. Make sure to set the same port also in the HTTP Proxy configuration.


The communication protocol between Agent and ESET PROTECT Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT Server that requires authentication will not work.

Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.

8.Click Finish.

9.Download the generated All-in-one installation package. Select the version you want to deploy:

oDownload 32-bit version (for example, PROTECT_Installer_x86_en_US.exe)

oDownload 64-bit version (for example, PROTECT_Installer_x64_en_US.exe)

oDownload ARM64 version (for example, PROTECT_Installer_arm64.exe) - You cannot install the x86 or x64 version of ESET Management Agent or ESET security product on Windows ARM64.


All data downloaded from the repository (ESET repository or a custom repository mirror) is digitally signed by ESET and ESET PROTECT Server verifies file hashes and PGP signatures. ESET PROTECT Server generates the All-in-one installer locally. Therefore, the All-in-one installer is not digitally signed, which might generate a web browser warning during the installer download or generate an operating system alert and prevent the installation on systems where unsigned installers are blocked.



The ESET Endpoint Antivirus/Security installer created in ESET PROTECT 8.1 and later supports Windows 10 Enterprise for Virtual Desktops and Windows 10 multi-session mode.


10. Run the installation package file on a client computer. It will install the ESET Management Agent and the ESET security product on the device and connect the device to ESET PROTECT. For step-by-step instructions, see the setup wizard. You can run the installation package in silent mode to hide the setup wizard window.