It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda XDR

Barracuda Campus is getting an upgrade!

We are excited to announce that Barracuda Campus will migrate to a new platform around mid-January 2026. Please see the announcement on the Campus Dashboard to find out more.

Setting up Endpoint Protection Using Scripting (Windows)

  • Last updated on

You can install endpoint protection on a local endpoint from the local Command Line (CMD) or with a deployment tool such as GPO, SCCM, or Tanium.

The following procedure is for deploying from the local command line or with PowerShell.

You can also use the parameters below in a deployment tool such as GPO, SCCM, or Tanium, as long as you have an administrator account. We don't provide the required code/packages for such tools.

Note

This option is available only for Agent version 22.2 and higher.

To download the installation package
  1. In Barracuda XDR Dashboard, click Downloads > Endpoint Protection.
  2. In the Step 2 area, click Windows.

The installation package downloads. 

To install the package
  1. Log in to one of the following:
    • The command prompt on a local endpoint.
      In Windows Start or Search, type CMD. In the results, right-click Command Prompt, and select Run as administrator.
    • PowerShell
  2. Navigate to the folder where you downloaded the installation package.
    For example, cd C:\Users\adminWin\Downloads.
  3. Run one of the following commands:

    Do not add /NORESTART to the following commands. By default, installing the Agent does not reboot the endpoint.

    • From the command prompt, <SentinelOneInstaller.exe> -t <site_Token> -q, where <SentinelOneInstaller.exe> is the full package name and <site_Token> is the site token. -q or -qn can be used for quiet mode.
      For example,  SentinelOneInstaller_windows_64bit_v22_2_1_200.exe -t a1b2c3d4e5f6g7h8i9a1b2c3d4e5f6g7h8i9 -q
    • From PowerShell, ./<SentinelOneInstaller.exe> -t <site_Token or group_Token>, where <SentinelOneInstaller.exe> is the full package name and <site_Token or group_Token> is the site or group token. -q or -qn can be used for quiet mode.
      For example, ./SentinelOneInstaller_windows_64bit_v22_2_1_200.exe -t a1b2c3d4e5f6g7h8i9a1b2c3d4e5f6g7h8i9 -q.

In quiet mode, the installer does not show the status of the upgrade as it progresses and does not automatically show a return code when the upgrade completes.

If more capabilities will be enabled after you reboot the endpoint, a notification appears.

From here, you may want to proceed to Setting up Endpoint Security Groups