MDM Deployment Overview
Deploy the Pult Agent at scale using your MDM system.
For organizations managing devices centrally, the Pult Agent can be deployed via your MDM system. This automates both the installation and the enrollment process so employees don't need to install or sign in manually.
Deployment Steps
A typical MDM deployment involves three parts:
- Install the agent -- Upload the Pult Agent installer (
.pkgfor macOS,.msifor Windows) to your MDM and deploy it to target devices. - Provision the bootstrap token -- Deploy the bootstrap token to each device so the agent can enroll automatically. Depending on your MDM, this may be done via MSI properties, a post-install script, or file-based deployment.
- Approve device requests -- As devices enroll, review and approve the device authentication requests in the Pult Dashboard.
Platform-Specific Guides
Windows
- Microsoft Intune Deployment -- Complete guide using PSAppDeployToolkit for Intune Win32 App deployment.
- For other MDMs that run installers in user context, use MSI properties directly:
msiexec /i pult-agent.msi BOOTSTRAP_TOKEN="your-token" AUTOLAUNCHAPP=1BOOTSTRAP_TOKEN and AUTOLAUNCHAPP fail when the installer runs as SYSTEM (common
for Intune Win32). Use the Intune guide above instead of MSI properties there. Background:
Bootstrap Token Deployment (Method 2 -- MSI properties).
macOS
For macOS, the recommended pattern mirrors the Intune flow on Windows: build a single wrapper .pkg
that bundles the signed Pult Agent.app together with a postinstall script that writes the
bootstrap token. You then upload that wrapper to your MDM as a standard package install.
- Choose a deployment path:
- Build the macOS MDM Package -- one wrapper
.pkgcontaining the agent and an embedded bootstrap token. Works with any macOS MDM. - In-Browser PKG Builder -- the same
wrapper, built directly in your browser. No Mac required; your
.pkgand bootstrap token stay on your machine. - macOS Deployment via Post-install Script
-- skip the wrapper if your MDM supports post-install scripts (e.g. Kandji). The canonical
Pult-signed
.pkgdeploys as-is; the script provisions the token separately.
- Build the macOS MDM Package -- one wrapper
- Deploy through your MDM:
- Jamf Pro -- includes Extension Attribute, Smart Group, and Policy setup for continuous compliance.
- For Kandji, Mosyle, Workspace ONE, etc., upload the wrapper as a standard package install.
- Deploy a managed login item so users can't switch off launch at login.
Auto-Start Configuration
Windows
The MSI installer registers the agent for auto-start via a registry entry
(HKLM\Software\Microsoft\Windows\CurrentVersion\Run) by default (AUTOSTART_ALLUSERS=1).
macOS
The .pkg sets up launch at login for every account on the Mac.
On macOS, only the Pult Agent .pkg (0.2.10 or later) sets up launch at login. A managed login
item keeps users from switching it off; it does not start the agent. See macOS
Auto-Start.
Version Detection
Use these scripts as your MDM's audit / detection rule (e.g. a Kandji or Mosyle Custom App audit
script, or an Intune detection script) to decide whether a device needs the package installed. They
detect a missing agent and a wrong version; on macOS they can optionally also detect an agent that
was not installed through the .pkg (see REQUIRE_PKG_RECEIPT):
macOS:
#!/bin/bash
APP_PATH="/Applications/Pult Agent.app"
REQUIRED_VERSION="0.2.10-beta1"
# Optional: additionally require the macOS package receipt for the Pult Agent
# .pkg, i.e. only count the agent as installed when it was deployed through the
# .pkg (canonical or wrapper; both use the com.pult.agent identifier).
#
# "false" (default) Check the app bundle version only, regardless of how the
# agent was installed.
# "true" A manual .dmg drag-install leaves no receipt and is reported as
# non-compliant even when the version matches, so Macs that were set
# up by hand before the MDM rollout still receive the .pkg
# (system-wide LaunchAgent + bootstrap postinstall).
REQUIRE_PKG_RECEIPT="false"
PKG_ID="com.pult.agent"
# Optional, only used with REQUIRE_PKG_RECEIPT="true": the receipt must also
# carry exactly this package version. Leave empty to accept any receipt.
# Set it to the version you stamped on the wrapper .pkg ("Version override" in
# the in-browser builder, or pkgbuild --version) to force a one-time reinstall
# on Macs that already run the right app version but were installed from an
# earlier package. The override changes the package version only; the app
# bundle version checked below stays the same.
REQUIRED_PKG_VERSION=""
if [[ ! -d "$APP_PATH" ]]; then
exit 1
fi
if [[ "$REQUIRE_PKG_RECEIPT" == "true" ]]; then
# Read the "version:" line of the receipt. Empty when there is no receipt.
INSTALLED_PKG_VERSION=""
while read -r key value; do
if [[ "$key" == "version:" ]]; then
INSTALLED_PKG_VERSION="$value"
fi
done < <(/usr/sbin/pkgutil --pkg-info "$PKG_ID" 2>/dev/null)
if [[ -z "$INSTALLED_PKG_VERSION" ]]; then
exit 1
fi
if [[ -n "$REQUIRED_PKG_VERSION" && "$INSTALLED_PKG_VERSION" != "$REQUIRED_PKG_VERSION" ]]; then
exit 1
fi
fi
INSTALLED_VERSION=$(/usr/bin/defaults read "$APP_PATH/Contents/Info.plist" CFBundleShortVersionString 2>/dev/null)
if [[ "$INSTALLED_VERSION" == "$REQUIRED_VERSION" ]]; then
exit 0
else
exit 1
fiMacs installed manually from the .dmg report the current version but never ran the .pkg (no
LaunchAgent, no bootstrap token), so a version-only audit never pushes the package to them. Set
REQUIRE_PKG_RECEIPT="true" to also require the package receipt, which the .dmg does not
create. Installing the .pkg over the existing app resolves it; signed-in users stay signed in.
To force a reinstall on Macs that already have the right app version from a package (for
example to roll out the wrapper .pkg with the bootstrap token to a fleet that first received
the plain .pkg), stamp the wrapper with a new package version (Version override in the
in-browser builder, or
pkgbuild --version) and set REQUIRED_PKG_VERSION to that value. Every Mac whose receipt
still shows the old package version is then reinstalled once.
Windows (PowerShell):
$AgentPath = "C:\Program Files\Pult Agent\pult-agent.exe"
$RequiredVersion = "0.2.10-beta1"
if (-not (Test-Path $AgentPath)) {
exit 1
}
$InstalledVersion = (Get-Item $AgentPath).VersionInfo.FileVersion
if ($InstalledVersion -eq $RequiredVersion) {
exit 0
} else {
exit 1
}Exit code 0 = compliant (correct version; with REQUIRE_PKG_RECEIPT="true" on macOS, also
installed through the .pkg), exit code 1 = non-compliant (triggers re-install).
Last updated on Sep 25, 2026, 12:14 PM