#quickstart
##Before you start
You need three things, none of which take long to find.
- Administrator rights on one device. Any machine will do - the first one is only there to prove the pipeline works.
- Control of the mailbox people write to when something breaks, enough to add a forwarding rule. If that mailbox does not exist yet, create it now and point it at nothing; you will have something to forward to in step four.
- The name of whoever will approve actions. One person is fine to begin with. This is the only decision in the setup that carries weight.
No directory migration required
The agent identifies devices by hardware and the signed-in account. Linking to Microsoft Entra ID or Google Workspace improves the user side of the inventory, but it is not a prerequisite and can be added on any afternoon afterwards.
##1 · Create the workspace
A workspace is one company. Service providers create one per client and manage them from a single board - see the service provider notes for how that nests.
Signing up gives you a workspace slug and an enrolment key. The slug appears in every command; the key is what lets an agent join.
workspace acme-traders enrol key ITB-7K4D-9PQ2-M1XV # rotatable from Settings → Agents region ap-south # where the workspace data lives
##2 · Install the agent on one device
Run the installer, enrol, and watch the device appear. Pick the platform you are sitting in front of.
###Windows
winget install Infotechbang.Agent --accept-package-agreements
infotechbang-agent enrol --workspace acme-traders --key ITB-7K4D-9PQ2-M1XV
# enrolled desk-04
# mode read-only
# first report 12s###macOS
brew install --cask infotechbang-agent
sudo infotechbang-agent enrol --workspace acme-traders --key ITB-7K4D-9PQ2-M1XV
# macOS will ask once for the system extension. Approve it in
# System Settings → Privacy & Security, then the agent reports in.###Linux
curl -fsSL https://pkg.infotechbang.com/install.sh | sudo sh
sudo infotechbang-agent enrol --workspace acme-traders --key ITB-7K4D-9PQ2-M1XV
sudo systemctl enable --now infotechbang-agent
# the unit runs as a dedicated service account with no shellVerify before you widen
Run infotechbang-agent status on the device. You want mode: read-only and a check-in timestamp under a minute old. If the check-in is empty, the agent cannot reach agent.infotechbang.com on port 443 - that is the only outbound rule it needs.
##3 · Roll out the rest of the fleet
Three ways, depending on what you already run.
- Group policy or Intune. Download the MSI and pass the workspace and key as properties. The device enrols silently on next policy refresh.
- MDM for Macs. Upload the package and the configuration profile together, so the system extension is pre-approved and no user sees a prompt.
- A shared enrolment link. For companies without device management: send the link, the person runs one installer, nothing is typed. The link can be set to expire and to cap the number of enrolments.
msiexec /i infotechbang-agent.msi /qn WORKSPACE=acme-traders KEY=ITB-7K4D-9PQ2-M1XV # devices appear on the board as they refresh policy # nothing is installed on the device beyond the agent itself
##4 · Connect intake
Requests should arrive where people already send them. Forward the mailbox rather than retraining everybody.
forward it-help@acme-traders.com -> acme-traders@in.infotechbang.com
# first ticket #2240 classified in 1.4s
# replies stay threaded on the same ticket
# attachments kept, including photosWhatsApp intake is a QR scan from Settings → Intake and takes under a minute. The web form is live from the moment the workspace exists; drop the link on your intranet.
##5 · Decide who approves what
Three roles. Requesters raise and read their own tickets. Operators work the queue. Admins approve anything that touches a device.
invite ravi.k@acme-traders.com role=admin approvals: all invite ops@acme-traders.com role=operator approvals: patches only invite everyone@acme-traders.com role=requester approvals: none # approval queue routed to ravi.k # every approval is recorded with the device state either side
Pick a second approver early
A single approver is a single point of delay. Critical patches sitting in a queue because one person is on leave is the most common avoidable complaint we hear in week three.
##Your first status
Once two devices have reported, the board is worth reading. The same view is available from the command line, which is what most people end up using.
A high pending-patch count on day one is normal and not a judgement on your estate. It is the first full audit most fleets have had; it falls quickly once you approve the first ring.
##Where the fifteen minutes actually goes
| Step | Typical time | What slows it down |
|---|---|---|
| Workspace created | 1 min | Nothing |
| First agent enrolled | 2 min | macOS extension approval needs a click |
| Intake forwarding | 3 min | Waiting on whoever owns the mailbox |
| Roles and approvals | 4 min | Deciding, not configuring |
| Fleet rollout | 5 min to set up | Policy refresh cycles, not the agent |
The licence picture is the one thing that is not instant. It needs most of the fleet to have checked in before seat counts mean anything, which in practice is the same working day.
##Limits
Limits - what this does not do
- The agent needs outbound HTTPS. It will not work on a fully air-gapped segment, and there is no store-and-forward relay for one.
- Devices nobody can install software on - personal phones, a client's own kit, an unmanaged contractor laptop - can be recorded by hand but will not report state.
- Network hardware is tracked as an asset with its firmware and uptime, but switches, access points and printers have no agent and cannot be patched from here.
- Intake does not read a shared mailbox in place. Forwarding is deliberate: the original mailbox stays untouched and you can stop at any time by deleting one rule.
