Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Deploy Skyhigh Client Using Intune

This topic provides step-by-step instructions for deploying the Skyhigh Client (SC) on Windows using Microsoft Intune. It also explains how to monitor the SC status, which ensures the Client is functioning seamlessly across managed devices. 

► Deploy the Skyhigh Client on Windows

Steps for Validating SC Deployment and Monitoring the Status of the Skyhigh Client 

  • Enroll the Device
  • Deploy Skyhigh Client and Apply Policy 
  • Create an SC Compliance Script to Monitor SC Status 

Enroll the Device 

Enrolling the device in Microsoft Intune helps you in enabling centralized management, enforcing policies, and remotely deploying the SC.

  1. Navigate to Settings > Accounts > Access work or school > Add a work or school account.
  2. Enter the user’s credentials to link the device to the organization’s domain. 

Deploy Skyhigh Client and Apply Policy  

Deploying the Skyhigh Client and applying the policies on managed devices ensures consistent security enforcement and effective traffic control.

Prerequisites 
  1. Active Intune subscription.
  2. Intune-managed device.
Deploy Skyhigh Client
  1. Download the Skyhigh Client version using this link.
  2. Log in to the Intune Admin portal using this link.
  3. From the menu, select Apps.

    1.PNG
  4. Select the platform as Windows.

    2.PNG
  5. Click Create.

    4_1.PNG
  6. In the App Type fieldselect Line-of-business app.

    4_2.PNG
  7. Click Next.
  8. Browse and select the Skyhigh Client MSI file from the App package file.

NOTE: The Scpinstaller.x64.msi represents the application package of Skyhigh Client. The app package filename will be renamed accordingly in the future release.​​​​​

5_1.PNG

  1. Click OK.
  2. Enter the following settings:
    • Name = Skyhigh Client
    • Description = Skyhigh Client 
    • Publisher = Skyhigh Security
    • Ignore app version = Yes
    • Category = Other app
    • Show this as a featured app in the Company Portal = Yes
    • Developer= Skyhigh Security
    • Owner = Skyhigh Security
    • Logo = Select the Skyhigh Security Logo 

      6_1.PNG
  3.  Click Review + save.
  4. In the Assignment tab, add All Devices for Required and All users for Available for enrolled devices.

    7.PNG
     
  5. Click Next.
  6. Review the app details and click Create.

    2025-03-14_16-28-08.png
    The apps created are displayed in the app section of the Intune Admin portal. 

    2025-03-14_16-30-09.png
OPG File Deployment 
  1. Create a folder by navigating C:\Config_files\. in the local machine. 
  2. Export the.opg policy file from the  Skyhigh Security Tenant.
  3. Rename the  .opg file to scppolicy.opg
  4. Copy the file scppolicy.opg to C:\Config_files\
  5. Create the following .bat files by navigating  C:\Config_files\:
    1. copy.bat
    2. del.bat
  6. Copy the following code to copy.bat file. 
    clipboard_e2d35d8fce2d9abf3defdf9c7e17e705b.png
  7. Copy the following code to del.bat file.
    clipboard_e02cf82e75d954c6ac66240162845a93a.png

 C:\Config_files\ contains these 3 files:

     clipboard_e280e0405ad7a38e4d6c93cb34ada1ecb.png

  1. Download the IntuneWinAppUtil.exe File using the link.
  2. Create a folder by navigating C:\Temp\Build\ in the local machine. 
  3. Run the IntuneWinAppUtil.exe in CMD with admin permissions.
  4. Run the following settings in the CMD prompt :

clipboard_eb37218fea189d1f4f9683535dded1cc6.png

The output looks like this: 

clipboard_e11a4680d1c1f5a9feacfdca62c0af054.png

  1. Ensure that the copy.intunewin file are created in C:\Temp\Build\.

    The OPG deployment package generated can be utilized with Intune to configure the SCP policy.

clipboard_e05884a87ae75e01f77457750d5fb96b4.png

  1. Login to Intune Admin Portal.
  2. Click Create.
  3. Select Windows app (Win32) In the App type.

    14_1.PNG
  4. Click Next.
  5. Browse and select the copy.intunewin file from the App package file.

2025-03-17_10-56-44.png

  1. Enter the following settings:
    • Name = Skyhigh OPG
    • Description = Skyhigh Proxy Config
    • Publisher = Skyhigh Security
    • App version = 5.0.0

      image_2.png
  2. Click Next.
  3. Select Install command and Uninstall command files in the Program tab.

    16_3_1.PNG
  4. Click Next.
  5. Select Operating system architecture and the Minimum operating system in the Requirements tab.

    16_4_1.PNG
  6. Click Next.
  7. Select Manually configure detection rules in the Detection rules tab.

    16_5_1.PNG
  8. Click Next.
  9. Review the dependencies, if added in the Dependencies tab.

    16_6_2.PNG
  10. Click Next.
  11. Review the Supersedence, if added in the Supersedence tab.

    16_7_1.PNG
  12. Click Next.
  13. Add All users for Required and All devices for Available for enrolled devices, in the Assignments tab.

    16_8_1.PNG
  14. Click Next.
  15. Review the policy details and click Create.

    16_9_1.PNG

The SCP client and the corresponding OPG file are automatically deployed to the Intune-managed device.

Create an SC Compliance Script to Monitor SC Status 

The creation of a compliance script by Intune helps in monitoring the SC, which provides the real-time functionality status for managed devices.

NOTE: Download the scripts using this link

  1.  Login to Intune Admin portal.
  2. Navigate to Devices > Compliance > Scripts > Add > select Windows 10 and later.

    Script 1.PNG
  3. In the Basics tab, add Name, Description, and Publisher as Skyhigh Security.

    Script 2.PNG
  4. Click Next.
  5. In the Detection script field, add the script.

    3.PNG
  6. Click Next.
  7. In the Review+create tab, review the compliance script and click Create.

    4.PNG

The newly created configuration is displayed under Devices > Compliance.

compliance_5.PNG

  1. Navigate to Devices > Compliance > Policy> Create Policy > select platform as Windows 10 and later.

    compliance_6_1.PNG
  2. Click Create.
  3. Enter Name and Description in the Basics tab. 

    compliance_7_1.PNG
  4. Click Next.
  5. In Compliance settings, select Required as Custom Compliance and select the script created in step 7. 

    compliance_8_1.PNG
  6. Upload the validation.json script.

    compliance_9_1.PNG
  7. Click Next.

    compliance_10_1.PNG
  8. Select All users and All devices In the Assignments tab. 

    compliance_11_1.PNG
  9. Click Next.
  10. Review the Windows 10/11 compliance policy and click Create.

    SC compliance status is found under Devices > Windows devices > select the device > Device compliance.

    compliance_12_1.PNG

NOTE: 

 

 

 

  • Was this article helpful?