OpenFrame is on your phone now!

Install the OpenFrame Agent on Windows

ENDPOINT MANAGEMENTGUIDEIMPLEMENTATIONOPENFRAMETUTORIALWINDOWS

Phase 2 — Device Deployment · Step 2

Section

September 23, 2026

Published

Vladislav Marchenko

Vladislav Marchenko

Head Of Marketing

Install the OpenFrame Agent on Windows

Phase 2 — Device Deployment · OpenFrame Onboarding

Guide maintenance · Owner: Conrad Lunderstedt · Last full review: 23 Sep 2026
Each section below carries its own Last verified date. When the installer or the Add Device screen changes, update that section and its date only.

The OpenFrame agent installs on Windows with a single PowerShell command. It downloads the client, unpacks it, and registers the PC to the customer you chose. Do one by hand first, the way this guide walks through it, so you know what "working" looks like before you push it fleet-wide.

Everything you need is in one place: Devices → Add Device.


What you'll do

Last verified: 23 Sep 2026

StepWhereTakes
Check you have the right accessOpenFrame and the PC1 min
Copy the install commandOpenFrame → Devices → Add Device1 min
Add antivirus exclusionsThe PC's AV console2 min, third-party AV only
Run the commandAn elevated PowerShell on the PC2 min
Confirm it's onlineOpenFrame → Devices1 min

Work through them in this order. The AV step is the one people skip and then regret.


Before you start

Last verified: 23 Sep 2026

You'll need:

  • The Admin role in OpenFrame.
  • Local administrator rights on the PC, so you can open an elevated PowerShell (Run as administrator).
  • The right customer picked out. Every customer has its own install command, and whatever you copy decides where the PC lands.

Tip: Choose the customer carefully. Moving a device to a different customer or group after install currently means uninstalling and reinstalling the agent. Ten seconds of checking here saves a reinstall later.


Get the install command

Last verified: 23 Sep 2026

  1. In OpenFrame, go to Devices → Add Device.
  2. Under Select Customer, choose the client this PC belongs to.
  3. Under Select Platform, choose Windows.
  4. Optionally add a Device Tag; it's applied when the device is created.
  5. The command appears under OpenFrame Installation Script. Click Copy Install Command.

The command downloads and extracts openframe-client.exe. It always pulls the latest release, so there's nothing to version-pin.

Tip: Copy it fresh for each customer. A command copied last week for a different client will put this PC in the wrong place.


Add antivirus exclusions

Last verified: 23 Sep 2026

Some antivirus products flag the installer or the remote-control component on first run. It's a false positive, and it's easiest to head off before you run anything. Defender usually lets it through; if the PC runs third-party AV (Avast, AVG, Bitdefender, Webroot and similar), add these folder exclusions first.

  • C:\Program Files\OpenFrame
  • C:\ProgramData\OpenFrame
  • C:\ProgramData\OpenFrameInstall
  • C:\Program Files\Orbit
  • C:\Program Files\Mesh Agent

The Mesh Agent folder is the remote-control component and the one third-party AV most often flags after install, so don't leave it out.

If you skipped this and the install was blocked, add the exclusions, restore anything quarantined, and run the command again. It's safe to re-run.

Tip: Rolling out to a whole customer? Push these exclusions through the AV console as a policy before you deploy, rather than per machine.


Run the command

Last verified: 23 Sep 2026

  1. On the Windows machine, open PowerShell as administrator (right-click → Run as administrator).
  2. Paste the command you copied and press Enter.
  3. Wait for it to finish. You'll see the download and extraction progress, then a completion message. Don't close the window early.

That's it for the machine. Everything else happens in OpenFrame.

Tip: If PowerShell refuses with "running scripts is disabled", start a session with powershell -ExecutionPolicy Bypass and paste the command there.


Confirm it's online

Last verified: 23 Sep 2026

Back in OpenFrame, open Devices. The PC should appear under the customer you chose and show Online within a minute or two. Full verification and first checks are in Confirm Your First Device Is Connected.


Troubleshooting

Last verified: 23 Sep 2026

"Running scripts is disabled on this system."
Execution policy is blocking it. From an admin PowerShell, start a bypass session with powershell -ExecutionPolicy Bypass and paste the command there, or set a policy that fits your org's standards.

Permission or access-denied errors.
You're not elevated. Close the window and reopen PowerShell with Run as administrator.

Download fails or hangs.
Check outbound internet on the PC, and confirm a proxy or web filter isn't blocking GitHub release downloads; that's where the client is hosted.

Antivirus quarantined it.
Add the exclusions above, restore anything quarantined, and re-run the command.

Installed but shows Offline.
Give it a couple of minutes. If it stays offline, follow Confirm Your First Device Is Connected, then Troubleshooting a Disconnected Device (Phase 10).

Device not appearing, or stuck pending.
TODO before publishing: insert the doctor command and what its output looks like.

Landed in the wrong customer or group.
There's no move option yet. Uninstall the agent, copy the install command from the correct customer, and run it again.


Quick checklist

Before you move on to the next device, confirm you've:

  • Selected the correct customer (moving later means a reinstall)
  • Chosen Windows and, optionally, added a tag
  • Added AV exclusions if the PC runs third-party AV
  • Run the command in an elevated PowerShell and let it finish
  • Confirmed the PC shows Online under Devices

What's next

One device in, and you know what a good install looks like. Install the OpenFrame Agent on macOS covers the Mac side; Confirm Your First Device Is Connected is where you check the agent is reporting properly before you scale up.

Vladislav Marchenko

Head Of Marketing

Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.

Related Content

Product Releases

Webinars

Case Studies

Blog Posts

Frequently Asked Questions

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.

blog

Fileless malware is malicious code that runs from memory and built-in Windows tools such as PowerShell, mshta.exe or WMI instead of a file saved to disk. Because nothing is written that a scanner can hash, signature-based antivirus has nothing to match. Microsoft sorts it into three types by how much it touches the file system; the attacks small teams meet are usually scripts that run in memory and persist through the registry or a WMI subscription.
No. A MAM selective wipe removes org data from managed apps and leaves the apps and personal data in place. Wiping the whole device, or the work partition, needs MDM enrollment.
No. App protection policies apply to unenrolled devices, Intune-enrolled devices and devices enrolled in a third-party MDM. On Android the Company Portal app must be installed and the device registered in Entra ID, but nothing enrolls.
Nine, per Ivanti's own End of Life index: Cherwell Service Management, Cherwell Asset Management, Service Desk (Powered by LANDESK), Desktop & Server Management, Endpoint Security (Powered by HEAT), PatchLink, Workspace Control, Virtual Desktop Extender and Browser Manager. DSM 2026.1 is the sharpest case, since it shipped on 13 January 2026 and loses full support in December of the same year.
Not since iOS 26, iPadOS 26 and macOS 26. Apple supports moving managed devices between management services without wiping, but only for devices enrolled through Automated Device Enrollment, and not for Shared iPad or devices configured for Return to Service with app preservation. Apps survive on iPhone and iPad only if the new service delivers them before the DeviceConfigured command. Apple also states that you need to re-create your enrollment profile and configurations in the new service.
No vendor documents an import path from Ivanti EPM. ManageEngine's migration-paths page, updated 26 August 2026, lists Ivanti DSM, Ivanti EPMM and Ivanti Neurons as supported sources and omits EPM. NinjaOne and Microsoft do not document one either. Patch policies, provisioning templates, LANDesk scripts, inventory history and custom fields get rebuilt rather than migrated.
It is the total power a switch can supply across all its ports, which is almost always less than ports times the per-port maximum. Add up the device draws at their IEEE class: 802.3af phones at 12.95 W, 802.3at access points and cameras at 25.5 W, 802.3bt devices at 51 W or 71.3 W. Add 20% headroom and buy a switch whose total budget exceeds that figure.