Prepare an image in Sysprep for Malwarebytes Endpoint Protection endpoint agent

Document created by djacobson Employee on Jul 2, 2019Last modified by bgoddard on Aug 28, 2019
Version 17Show Document
  • View in full screen mode

When creating a base image with a Malwarebytes Endpoint Protection installation, the Malwarebytes installer should be prevented from connecting to the internet before the image is generalized by Sysprep. This may be easier to accomplish if the Malwarebytes installation is saved for the last step when configuring an image.


If the endpoint agent is allowed to reach the internet and check into Malwarebytes servers, a unique software ID will be assigned to the endpoint agent machine. As a result, any other machine spun up from this image will be a duplicate entry of the original ID accidentally assigned to your base image's Malwarebytes installation.


There are two parts to the process: create the installer, and install Malwarebytes on your base image.


Create the installer

Before you create the image, you need to select an installer package. There are 2 types of packages to choose from:

  • Full installer package - This includes needed system prerequisites.
  • MSI installer - Useful If the installation's system prerequisites are already satisfied. For MSI installer requirements, see the Malwarebytes Cloud Console Administrator Guide .


  1. To create the installer, follow steps 1–6 in this article: Manually add endpoints in Malwarebytes cloud platform .

  2. After exporting the package in step 5 or 6, return to this article and follow the steps below.


Install Malwarebytes on your base image

  1. Copy the installer to your base image environment.

  2. Disconnect your base image environment from the network.

  3. Run the Malwarebytes installer.
    1. If you need to add proxy information, you may do so during the installation process. See Change proxy settings for Malwarebytes Endpoint Protection.
    2. If you prefer to script environment setup tasks, proxy information can be set with switches when using the MSI-based installer. Refer to the Network Proxy section of Malwarebytes Endpoint Security to Malwarebytes Endpoint Protection migration best practices.  

  4. If you require a network connection to complete other tasks before Sysprep, stop the agent service to avoid automatic ID assignment:
    1. Open services.msc.
    2. Right-click on the Malwarebytes Endpoint Agent service and select Stop.
    3. It is now safe to re-enable network connectivity for the base image machine.

  5. When installation is complete and the agent is on the base image machine, you may safely perform Sysprep generalization and subsequent image capture.

  6. When ready to deploy your new base image, be sure to test it on 2 or 3 machines first to ensure the endpoint agent does not encounter any issues.


Post-deployment notes

Once the image is deployed and the endpoint user logs into Windows, the Malwarebytes Endpoint Protection agent

  • Performs a check-in
  • Receives an ID assignment
  • Downloads and installs real-time protection and scanning engine items, which are configured according to the  Group and Policy settings in the Malwarebytes Cloud Console.


More information