# Client Installation Guide (INSIGHT v5)

The GuardWare INSIGHT Client is installed on endpoint devices and runs as a background service, continuously monitoring user activity and data movement. Activity data is transmitted securely to the INSIGHT Management Console via HTTPS, where administrators can review logs, identify risky behaviour, and enforce policies.

With the Client deployed, organisations gain visibility into endpoint activity, apply protection policies at the device level, and detect or prevent data exfiltration attempts.

## System Requirements

Verify that endpoint devices meet the following requirements before installing the Client.

<table><thead><tr><th width="307">Component</th><th width="372">Minimum Requirements</th></tr></thead><tbody><tr><td><strong>Processor</strong></td><td>Dual-core or higher</td></tr><tr><td><strong>Memory</strong></td><td>8 GB RAM</td></tr><tr><td><strong>Disk Space</strong></td><td>500 MB free</td></tr><tr><td><strong>Operating System</strong></td><td>Microsoft Windows 10 or later</td></tr></tbody></table>

## Upgrading from Client v4

{% hint style="warning" %}
If you are installing the INSIGHT Client for the first time, skip this section and proceed to [**Whitelist Components**](#whitelist-components).&#x20;
{% endhint %}

GuardWare INSIGHT Client v5 requires a clean installation and is not compatible with v4 components or Server v4 environments. Before deploying Client v5, fully remove any existing Client v4 installation, including residual files, registry entries, and previous server configurations, as these can interfere with v5.

Client v4 cannot communicate with Server v5, and Client v5 cannot communicate with Server v4. Existing v4 settings and configurations are not preserved during the upgrade and must be reconfigured after deployment.

#### &#x20;[**Uninstall Client v4**](http://docs.guardware.com/guardware-insight/uninstallation/uninstall-insight-agent)&#x20;

Contact GuardWare to obtain the uninstaller, then complete the following steps on each target device.

1. Open **Command Prompt** with administrator privileges.&#x20;
2. Run the uninstaller with the `sjunix` flag:  \
   `GWUninstaller_NoDecrypt_5.1.0.1_2026.06.exe sjunix`&#x20;

   <div align="left"><figure><img src="/files/wRhZG53FKjh2Y9XPU6sA" alt="" width="563"><figcaption></figcaption></figure></div>
3. In the same window, delete the following services as well:

```
   sc delete gwscanner
   sc delete gwusbmon
   sc delete gwchatdocmon
   sc delete gwpg
   sc delete gwdogfile
   sc delete guardware client
   sc delete guardware proxy
```

4. Close the Command Prompt window and launch File Explorer.&#x20;
5. Navigate to the following folders and delete them:

```
   C:\Program Files (x86)\Guardware\INSIGHT
   C:\ProgramData\GuardWare\INSIGHT
```

5. Finally, open the **Registry Editor** and delete the following folder: \
   `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuardWare\INSIGHT`&#x20;

<div align="left"><figure><img src="/files/p3hZwO8JHYdtfPvzlLCg" alt="" width="563"><figcaption></figcaption></figure></div>

4. **Restart** your device.

## Whitelist Components

Before deploying Client v5, add INSIGHT components to your antivirus, EDR, or XDR trusted applications list. This prevents security tools from blocking or interfering with the installation and runtime behaviour.

Some security solutions may flag INSIGHT executables, services, or drivers by default. To ensure a smooth deployment, configure exclusions in advance.

{% hint style="warning" %}
For the full list of components, see [**Whitelist GuardWare INSIGHT**](/insight/guardware-insight/getting-started/whitelist-guardware-insight.md).
{% endhint %}

## Installation Methods

The Client supports multiple deployment methods to suit different infrastructure requirements.

<table data-header-hidden="false" data-header-sticky><thead><tr><th width="248">Installation Type</th><th>Description</th></tr></thead><tbody><tr><td><a href="#manual-installation"><strong>Manual Installation</strong></a></td><td>Suitable for individual devices or small-scale deployments.</td></tr><tr><td><a href="#active-directory-deployment"><strong>Active Directory</strong></a></td><td>Automated deployment across domain-joined devices via Group Policy.</td></tr><tr><td><a href="#microsoft-intune-deployment"><strong>Microsoft Intune</strong></a></td><td>Cloud-based deployment for enrolled Windows devices.</td></tr><tr><td><a href="#third-party-deployment"><strong>Third-Party Solutions</strong></a></td><td>RMM tools for enterprise-scale deployments.</td></tr></tbody></table>

<details open>

<summary>Manual Installation</summary>

Manual installation is performed by running the installer directly on each endpoint device and completing the setup wizard.

1. Double-click the installer file.
2. In the Setup Wizard, click **Next** to continue.

   <div align="left"><img src="/files/5794d509538b6ff400f31c1dd34b229dcbc9f5cd" alt="" width="375"></div>
3. The Client will be installed in `C:\Program Files (x86)\Guardware\INSIGHT`. Click **Next** to continue.

   <div align="left"><figure><img src="/files/SASVVh3c3zn68OL0lLXG" alt="" width="375"><figcaption></figcaption></figure></div>
4. Click **Install** to begin the installation. The installation may take a few minutes to complete.<br>

   <div align="left"><figure><img src="/files/sfs1dxVhYCGOHeszbrDc" alt="" width="375"><figcaption></figcaption></figure></div>
5. If a User Account Control (UAC) prompt appears, verify that the publisher is listed as **GuardWare Australia Pty Ltd**, then click **Yes** to proceed. Clicking **No** cancels the installation.
6. Once the installation is complete, click **Finish** to exit the wizard.

</details>

<details>

<summary>Active Directory Deployment</summary>

Group Policy-based deployment automates Client installation across multiple domain-joined computers. This method ensures consistent deployment across organisational units with minimal manual intervention.

1. On the domain controller or an admin workstation with RSAT installed, open **Active Directory Users and Computers**.

   <div align="left"><img src="/files/ffebdd431b4cd3ec92b7714e7548735b85595a1b" alt="" width="375"></div>
2. On the toolbar, click **Create a new Organisational Unit (OU).** A dedicated OU prevents the deployment policy from conflicting with existing group policies.

   <div align="left"><img src="/files/e89281f36bb8065e20936010e08e5966c9fcc1c7" alt="" width="563"></div>
3. Enter a name for the new OU, for example, **Install GW Client v5,** and click **OK**.

   <div align="left"><img src="/files/474e1695ad9081d81c7a4b3d69bed40774ac75b9" alt="" width="375"></div>
4. Search for **Group Policy Management** and click to launch the console.

   <div align="left"><img src="/files/f9497974a2891eeee4b5146872d004a73afb8a56" alt="" width="563"></div>
5. Locate the new OU, right-click it, and select **Create a GPO in this domain, and Link it here…**
6. Enter a descriptive name for the policy, such as **GW INSIGHT v5 Installation**, and click **OK**. The same GPO can be linked to additional OUs if required.

   <div align="left"><img src="/files/dd35dc2773e991f1cb6a91bb32be9856d28dc736" alt="" width="563"></div>
7. Right-click the new GPO and select **Edit** to open the **Group Policy Object Editor**.

   <div align="left"><img src="/files/2cc567b767520e85d63c62d1284215c95c3896b7" alt="" width="563"></div>
8. In the GPM editor, go to **Computer Configuration** > **Policies** > **Software Settings** > **Software Installation**.

   <div align="left"><img src="/files/7185c20cfcad896c16f48c0f0078d5edfa3f743d" alt="" width="563"></div>
9. Right-click **Software Installation**, select **New** > **Package…**, and browse to the v5 Client MSI file.

   <div align="left"><img src="/files/c8de96dfc12f61cca587ac031041308d58772741" alt="" width="563"></div>
10. Enter the package path using the FQDN (Fully Qualified Domain Name) format, for example, `\\DC01\client\Client.msi`, where `DC01` is the name of your domain controller, and `client` is the shared folder containing the MSI installer.
11. Select the package, click **Open** to add it to the policy, then close the **Group Policy Object Editor** once the package has been added.

    <div align="left"><img src="/files/498e6747a39b07b774cde8d08ee5b2da78120368" alt="" width="563"></div>
12. In the Group Policy Management Console, confirm the new GPO is listed under **Linked Group Policy Objects** for the selected OU.

    <div align="left"><img src="/files/8d0070c5fa007d575ef451a309b7ba88b31dd35e" alt="" width="563"></div>
13. Press **Win + R**, type `gpupdate /force`, and click **OK** to apply the policy on the local machine. Endpoints in the selected OU will receive the policy at their next startup or group policy refresh.

    <div align="left"><img src="/files/653b04747a6251626bfb49872936d149b3d59690" alt="" width="375"></div>

</details>

<details>

<summary>Microsoft Intune Deployment</summary>

Microsoft Intune enables centralised, automated deployment of the Client to enrolled Windows devices.

1. Sign in to the [**Microsoft Intune Admin Center**](https://intune.microsoft.com/) using an administrator account.
2. From the left navigation menu, navigate to **Apps** > **All apps**.

   <div align="left"><img src="/files/bd4359331872b8e60c2723e81f6754ddfbd20dcc" alt="" width="563"></div>
3. Select **Windows Apps** and click **+ Create** to create a new application.

   <div align="left"><img src="/files/d9d39e1e32868d50a61fa3defa1b0f29370951f5" alt="" width="563"></div>
4. Under **Select app type**, choose **Line-of-business app**, and click **Select**.

   <div align="left"><img src="/files/d4a14de019600d854432fc3ac9fd8ea082f00cf2" alt="" width="375"></div>
5. In the **App information** section, click **Select app package file**, then browse and upload the GuardWare INSIGHT Client installer file. Review the app details and click **OK**.

   <div align="left"><img src="/files/5eb8fbc0e5f42a2d4c9005c3663dbcc9989114a9" alt="" width="375"></div>
6. Enter the following information in the **App information** section, then click **Next**.
   1. **Name:** Enter a display name of the application that appears in Intune and on endpoint devices during installation.
   2. **Description:** Enter a description for the application.
   3. **Publisher:** Enter the publisher’s name.

      <div align="left"><figure><img src="/files/c1796d5db690a03bf381c754654d8891c3006af7" alt="" width="563"><figcaption></figcaption></figure></div>
7. In the **Assignments** tab, click **Add group** under **Required** and select the Azure AD device or user groups that should receive the Client.

   <div align="left"><figure><img src="/files/23bd37e99d50da67e3e967386ee5623744eb82ba" alt="" width="563"><figcaption></figcaption></figure></div>
8. Click **Next**, review the configuration summary, and click **Create** to publish the deployment.

   <div align="left"><img src="/files/48350e8778b309d6bee4fd6528fae058bea1ef6c" alt="" width="563"></div>

The Client will install automatically on all assigned devices the next time they check in with Intune. Monitor installation progress under **Apps > Monitor > Installation status** in the Intune Admin Center.

</details>

<details>

<summary>Third-Party Deployment</summary>

The Client can be deployed using third-party RMM tools such as PDQ Deploy, Datto RMM, ConnectWise Automate, or similar solutions. These tools support silent MSI installation using the following parameters:

```
msiexec /i "InsightAgent.msi" /quiet /norestart
```

{% hint style="warning" %}
Replace `InsightAgent.msi` with the filename of the downloaded installer.
{% endhint %}

Consult your RMM platform's documentation for specific deployment procedures. Most platforms support:

* Scheduled or immediate deployment.
* Target computer or group selection.
* Pre-installation scripts (for uninstallation of Client v4 if installed).
* Post-installation verification scripts.
* Installation status reporting.

The client service starts automatically after installation. Verify deployment success by checking client connectivity in the INSIGHT Management Console.

</details>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.guardware.com/insight/guardware-insight/insight-v5/client-installation-guide-insight-v5.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
