Deploying Blitz Agent to Windows computers

Release status

Blitz Agent 0.3.0 has Windows x64 and ARM64 development previews. Windows 11 ARM64 and Windows Server 2025 x64 test VMs passed the documented reporting/action checks. These builds are unsigned: use approved test devices only until publisher verification, signing and signed customer-release acceptance are complete. Do not bypass your organisation's software restrictions to install a preview.

Before installation

An authorised BlitzDesk administrator needs an existing computer asset, access to its enrollment controls and a Windows administrator able to install on the device. Determine whether Windows is x64 or ARM64 in Settings → System → About. Select the matching download; ARM64 is not the same as x64.

Download from the asset's Agent controls. Compare the ZIP's SHA-256 checksum with the published checksum using Windows PowerShell Get-FileHash -Algorithm SHA256 PATH-TO-ZIP. Extract the archive. Keep the installer and checksum together in your approved software repository. A checksum confirms file consistency, not publisher trust.

Devices need outbound HTTPS to your deployment's blitz-agent-control endpoint. Ask your IT/security team to approve it. No inbound remote-access port is required by the Agent. Government and managed devices require their organisation's normal software approval; ordinary users should not circumvent it.

Install and enrol one device

1. In BlitzDesk Assets, open the intended computer and create a single-use enrollment token. Tokens expire after ten minutes.

2. On that computer, open Command Prompt as administrator and change to the extracted installer directory.

3. Run the following command, replacing the URL with your deployment's gateway:


   blitz-agent.exe install https://YOUR-PROJECT.supabase.co/functions/v1/blitz-agent-control

4. Paste the token at the hidden prompt. Do not put it in command arguments, scripts, emails or screenshots. Do not reuse a token on another device.

5. Confirm installation succeeds. Use sc query BlitzAgent to inspect service state. The installed service uses LocalService and automatic startup.

6. Return to the asset or Blitz Agent workspace and confirm its hostname, architecture, inventory and latest contact correspond to that computer. Reports normally arrive every five minutes; investigate errors rather than repeatedly reinstalling.

Each device generates its own credential locally. Do not clone an enrolled VM/image or copy protected identity files to another computer. The service is not remote desktop software.

What it collects and can do

Inventory includes hostname, Windows version/build and architecture, manufacturer/model/serial, CPU, logical processors, memory and up to eight fixed-volume capacity readings. It does not collect browsing history, user files, installed applications, MAC/network addresses or Windows users.

With separate organisation opt-in and human review, Blitz Actions can refresh inventory, flush DNS cache and restart the Agent service. Restarting the Agent does not reboot Windows. Arbitrary scripts, commands and software deployment are not supported.

Credentials and execution journals use protected Windows directories and machine DPAPI encryption. Ordinary users cannot modify the installed binary or read its protected identity. Local administrators remain privileged; these protections are not a defence against them.

Managed deployment and upgrades

The current enrollment flow is interactive. Intune, Group Policy, Configuration Manager and RMM packages are not implemented or validated as unattended deployment workflows. Do not describe the preview as a bulk installer. Once signing is complete, evaluate your management tool's approved packaging process on a small pilot before rollout. Automatic upgrades are not implemented.

Troubleshooting and removal

If a token expires or was used, generate a new one for the correct asset. For missing reports, check the service, outbound connectivity and the asset's installation state. Authentication denial, invalid payload or sequence conflict stops reporting for investigation; do not copy another device's credentials as a workaround. Offline retry uses bounded backoff from five seconds to thirty minutes and one pending request.

To retire a device, revoke its installation in BlitzDesk, then run blitz-agent.exe uninstall from an elevated terminal. Uninstall removes the service and archives protected identity state. Re-enrollment needs a fresh token; do not manually restore an old credential. Follow your organisation's retention policy for retired devices and archived state.

See Agent acceptance, protocol, Actions and technical installer README.