> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/setup-and-deploy/install-protect-agent/install-protect-agent.md).

# Install PROTECT Agent

The GuardWare PROTECT Agent is installed on endpoint devices and applies file protection policies directly on the device. It enables users to protect sensitive files, apply classifications, and enforce access restrictions while working in their normal applications.

With the Agent deployed, organisations can protect data at the endpoint, control how files are shared, and enforce policy-based access to sensitive content.

{% hint style="warning" %}
Before installing the Agent, [**whitelist PROTECT**](/setup-and-deploy/install-protect-agent/whitelist-protect.md) and confirm the device meets the [**system requirements**](/setup-and-deploy/install-protect-agent/system-requirements-for-protect.md).
{% endhint %}

## Azure AD Users

For users registered with Azure AD, proceed directly to the [Install GuardWare PROTECT Agent](#install-guardware-protect-agent) section.

## Local AD and External Users (On-Premises and Outside the Organisation)

If your users are registered with on-premises Active Directory (local AD), complete the [Pre-installation steps](#pre-installation-setup) below and then proceed to [install the PROTECT Agent](#install-guardware-protect-agent).

This also applies to users who are outside your organisation, such as partners, contractors, or clients, who are not part of your organisation’s Azure AD or Local AD.

### Pre-Installation Setup

Local AD users and external users need an invitation from GuardWare Australia to use GuardWare PROTECT. Once you receive an invitation, follow these steps:

1. Accept the invitation sent to your email.
2. After accepting, you’ll be prompted to **send a code to your email**. Click **Send code**.

<div align="left"><img src="/files/12445f9bdc75eec4e4c2a1cb9dceb39ba52c42f3" alt="" width="375"></div>

3. Enter the code sent to your email and **sign in**.
4. GuardWare requests certain permissions. Read the requested permission and accept. You’ll then be directed to the Welcome page, where you can see details on how to get started.

<div align="left"><img src="/files/649f5cb40dc942324c2d801f79b2ab13b85e524e" alt="" width="375"></div>

## Install GuardWare PROTECT Agent

1. Double-click the provided **PROTECT Agent installer** file to begin the installation.
2. In the **Setup Wizard**, click **Next** to continue.

<div align="left"><figure><img src="/files/bfc2e4a91bab9fad1cec0e56edbe8b73856669ea" alt="" width="375"><figcaption></figcaption></figure></div>

3. Read and accept the **End User Licence Agreement (EULA)** and click **Next**.

<div align="left"><img src="/files/zaPFKlP7uEZBXuJEIzlV" alt="" width="375"></div>

4. Choose the folder where you want to install GuardWare PROTECT and click **Next**. By default, PROTECT will be installed in: `C:\Program Files\`.
5. Click **Install**. The installation may take a few minutes to complete.

<div align="left"><figure><img src="/files/9be44d3a0aa9d718b2341bc6d482182597a08b98" alt="" width="375"><figcaption></figcaption></figure></div>

6. If you do not have Microsoft Azure CLI installed, a Setup Wizard will prompt you to install it. Read and agree to the licence agreement terms and click **Install**.

<div align="left"><figure><img src="/files/uRRwnIu5dO0in1ilCgg5" alt="" width="375"><figcaption></figcaption></figure></div>

7. If you do not have Microsoft Visual C++ Redistributable installed, a Setup Wizard will prompt you to install it. Read and agree to the licence agreement terms and click **Install**.\
   ![](/files/A2C839dOz6ImVUQnfgLo)
8. Once the installation is complete, click **Finish** to exit the Setup Wizard and continue with the PROTECT Agent installation.
9. During the agent installation, a User Account Control (UAC) dialog box may appear. This is a standard Windows security feature that verifies whether you want to allow the installer to make changes to your computer. When this dialog appears:
   1. Verify that the publisher is GuardWare Australia Pty Ltd.
   2. Click **Yes** to allow the installation to proceed. Clicking **No** cancels the installation.
10. Once the PROTECT Agent installation is complete, click **Finish** to exit the wizard.
11. You’ll be prompted to restart your device. Click **Yes**. After restarting your device, follow the steps in [Post-Installation Setup](#post-installation-setup).<br>

    <figure><img src="/files/I14UpyDdsg5SDwlhJCdu" alt=""><figcaption></figcaption></figure>

Restarting is mandatory for GuardWare PROTECT to install successfully.

## Post-Installation Setup

After restarting your device, a **Welcome Wizard** appears automatically. If you do not see it right away, please wait a few minutes.

1. In the Welcome wizard, click **Login with Azure**.

<div align="left"><figure><img src="/files/b5ed8eb8d2556b94dbc9268420084f0cc40477e7" alt="" width="375"><figcaption></figcaption></figure></div>

2. For Azure AD users:
   1. Select your work email address and click **Continue**.

      <div align="left"><figure><img src="/files/33b6bb47c2b4e346bad543a44af49e7e7e5bfe84" alt="" width="375"><figcaption></figcaption></figure></div>
   2. Select your **Tenant ID** and **Subscription** and click **Submit**.

      1. **Tenant ID:** The unique identifier of your Azure AD.
      2. **Subscription:** Defines the set of resources and the billing account.

         <div align="left"><figure><img src="/files/30b1d5d4419ba857d56809abade2b281aa42c008" alt="" width="375"><figcaption></figcaption></figure></div>

      Select the Subscription that contains your Key Vault. If multiple appear, select the one where the Key Vault and Service Principal for GuardWare PROTECT are set up. If you’re not certain which subscription applies, you can verify it in the [Azure Portal](https://portal.azure.com/) under **Subscription** or contact your administrator.

      <figure><img src="/files/524fb992c642a4f4d9f7fb8f36de4f4244a53f9d" alt=""><figcaption></figcaption></figure>
3. Click **Exit** when the setup is complete.
4. For external users:
   1. Select **Work or school account**.
   2. Enter the email address where you received the invitation, and click **Next**.
   3. Check your email for a verification code, then enter the code and click **Sign in**.
   4. When prompted to sign in automatically across desktop apps and browsers, select\
      **No, this app only** (for better security). This ensures your Azure login is used only within GuardWare PROTECT, preventing other apps or browsers on the same device from automatically accessing your credentials. You can always sign in separately to other apps when needed.
   5. Click **Exit** when the setup is complete.
5. During the process, if a Windows Security prompt appears stating that **Windows Firewall has blocked some features of** **GWProtectDesktop**, click **Allow**.\
   \
   If the **prompt does not appear** or **you did not allow** it in the above step, follow the steps below to allow **GWProtectDesktop** to communicate through Windows Defender Firewall. Allowing **GWProtectDesktop** through the firewall ensures the PROTECT Agent can communicate with required services and enforce file protection policies correctly.
   1. Open **Control Panel** > **System and Security** > **Windows Defender Firewall**.
   2. Click **Allow an app or feature through Windows Defender Firewall**.
   3. Select **Change settings**.
   4. Locate **GWProtectDesktop** in the list and enable the **Private** and **Public** networks.
   5. Click **OK** to save the changes.

      <div align="left"><figure><img src="/files/6db46ab113ec759ece59d81c966e4bd16133aaa3" alt="" width="563"><figcaption></figcaption></figure></div>

You can now use GuardWare PROTECT to add protection to sensitive files, set classifications, restrict access to Security Groups, add expiry dates, restrict circulation, and so on.

## Uninstall GuardWare PROTECT Agent

{% hint style="danger" %} <mark style="color:$danger;">**Make sure to remove protection from your protected files before uninstalling PROTECT; otherwise, you won't be able to access them afterwards.**</mark>
{% endhint %}

To remove GuardWare PROTECT from your device:

1. Double-click the **PROTECT Agent installer**.
2. In the **Setup Wizard,** click **Next** to continue.

<div align="left"><img src="/files/97c1ae5b8282dd99b47cb94a51bed477ff33e577" alt="" width="375"></div>

3. You’ll get options to modify, repair, or remove PROTECT. Choose **Remove**, then click **Remove** to uninstall GuardWare PROTECT.

<div align="left"><img src="/files/ccd1d6871d7ec4462d06215525e0c4c673151db6" alt="" width="375"></div>

<div align="left"><img src="/files/9dd36c0ffaaf81c6c804110363caa0bc75c187dd" alt="" width="375"></div>

4. (Optional) To review or change installation settings, click **Back**. To exit without uninstalling, click **Cancel**.
5. During the uninstallation, you may see the following dialogs:
   1. **Installer Information**

      When the Installer Information appears, click **OK** to continue with the uninstallation.\
      ![](/files/2lm0H8KRnEa51cLNM5BB)
   2. **User Account Control (UAC)**\
      This is a standard Windows security feature that verifies whether you want to allow the installer to make changes to your computer. When this dialog appears:
      1. Verify that the publisher is displayed as GuardWare Australia Pty Ltd.
      2. Click **Yes** to allow the uninstallation to proceed. If you select **No**, the uninstallation will be cancelled.
6. After uninstallation is complete, you will be prompted to restart your device. Click **Yes**.

{% hint style="info" %}
Restarting is mandatory for GuardWare PROTECT to uninstall fully.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/setup-and-deploy/install-protect-agent/install-protect-agent.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
