OpenFrame is on your phone now!

Managing the OpenFrame Client — Updates & Recovery

ENDPOINT MANAGEMENTOPENFRAMERMMTROUBLESHOOTING

Phase 10 — Ongoing Operations · Step 2

Section

June 24, 2026

Published

Vladislav Marchenko

Vladislav Marchenko

Head Of Marketing

Managing the OpenFrame Client — Updates & Recovery

Phase 10 — Ongoing Operations · OpenFrame Onboarding

The OpenFrame client on each endpoint isn't one program — it's a small bundle of agents (Fleet, MeshCentral, RMM) coordinated by an updater service. Most of the time it looks after itself. This guide shows you how to confirm it's healthy, read its versions, and what "recovery" means when it isn't.


Where to check client health

Open a device from Devices, then the Agents tab on its detail page. You'll see a card for each underlying agent:

  • Fleet — osquery-based inventory and monitoring.
  • MeshCentral — remote control and file transfer.
  • RMM — RMM agent for scripts and actions.

Each card shows the same vital signs: Status (online/offline), Last seen, ID, Version, and Last fetched. A healthy client has all three online with recent "last seen" times.


Reading versions

The Version on each card tells you what's running on that endpoint. The OpenFrame updater service keeps these current automatically — it checks in, pulls the right versions, and applies them without you touching the machine. If one device is several versions behind its peers, that's a signal its updater isn't completing (often the same root cause as a disconnect — see the next guide).

You don't push client updates per-device by hand. The model is: the updater service on each endpoint pulls what it needs. Your job is to notice when a device falls behind, not to update it manually.


What "recovery" means

The OpenFrame client is designed to recover itself:

  • On Windows, the client runs as a service registered with the Service Control Manager (SCM), which is configured to restart it automatically if it crashes or stops. That's the first line of defense — a hung agent usually comes back on its own.
  • The updater service also repairs a partial or corrupted agent install by re-fetching the correct version on its next cycle.

So "recovery" is mostly automatic. When it isn't — the service is disabled, the host is off, or the network is blocking it — recovery happens on the endpoint, not from the console. The OpenFrame web console can show you status and versions, but the fix (restart the service, check connectivity, reinstall the agent) is done on the machine itself.


When a card shows offline

If one or all agent cards show OFFLINE with an old Last seen, the client isn't reaching the server. That's a disconnected-device situation — head to Troubleshooting a Disconnected Device (next) for the step-by-step.


Quick checklist

  • Opened the device's Agents tab
  • Confirmed Fleet / MeshCentral / RMM are online with recent Last seen
  • Checked Version on each card against your fleet's norm
  • Understood updates are automatic via the updater service
  • Knew recovery (SCM restart / reinstall) happens on the endpoint

What's next

When the client can't recover on its own and a device goes dark, work through Troubleshooting a Disconnected Device.


Based on OpenFrame v0.9.19. Agent components, versions, and the updater behavior evolve between releases — what's on the endpoint and in your console wins.

Vladislav Marchenko

Head Of Marketing

Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.

Related Content

Product Releases

Webinars

Case Studies

Blog Posts

Frequently Asked Questions

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.

AI MSP

Most MSPs start with AI features inside their existing PSA, RMM, and ticketing systems rather than standalone products. Common categories include AI ticket triage, alert correlation, scripting assistants, and AI-native all-in-one platforms like OpenFrame that run intelligence across the whole stack.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.

blog

Killing the process is not enough, because the trigger brings it back. Find the persistence first: registry autorun values and file-type handlers, scheduled tasks with encoded commands, and WMI filters, consumers and bindings in the root\subscription namespace. Remove the trigger, then the payload, then reset any credentials the machine held, and confirm with Sysmon and PowerShell logs that it did not return after a reboot.
No. A MAM selective wipe removes org data from managed apps and leaves the apps and personal data in place. Wiping the whole device, or the work partition, needs MDM enrollment.
No. App protection policies apply to unenrolled devices, Intune-enrolled devices and devices enrolled in a third-party MDM. On Android the Company Portal app must be installed and the device registered in Entra ID, but nothing enrolls.
Nine, per Ivanti's own End of Life index: Cherwell Service Management, Cherwell Asset Management, Service Desk (Powered by LANDESK), Desktop & Server Management, Endpoint Security (Powered by HEAT), PatchLink, Workspace Control, Virtual Desktop Extender and Browser Manager. DSM 2026.1 is the sharpest case, since it shipped on 13 January 2026 and loses full support in December of the same year.
Not since iOS 26, iPadOS 26 and macOS 26. Apple supports moving managed devices between management services without wiping, but only for devices enrolled through Automated Device Enrollment, and not for Shared iPad or devices configured for Return to Service with app preservation. Apps survive on iPhone and iPad only if the new service delivers them before the DeviceConfigured command. Apple also states that you need to re-create your enrollment profile and configurations in the new service.
No vendor documents an import path from Ivanti EPM. ManageEngine's migration-paths page, updated 26 August 2026, lists Ivanti DSM, Ivanti EPMM and Ivanti Neurons as supported sources and omits EPM. NinjaOne and Microsoft do not document one either. Patch policies, provisioning templates, LANDesk scripts, inventory history and custom fields get rebuilt rather than migrated.