Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Deploy and Monitor the Status of the Skyhigh Client Proxy (SCP) on WindowsOS using Intune

This topic provides step-by-step instructions for deploying the Skyhigh Client Proxy (SCP) on Windows devices using Microsoft Intune. It also explains how to monitor the SCP status, which ensures the client is functioning seamlessly across managed devices. 

Steps for Validating SCP Deployment and Monitoring the Status of the Skyhigh Client Proxy

Enroll the Device 

Enrolling the device in Microsoft Intune helps you in enabling centralized management, enforcing policies, and remotely deploying the SCP.

  1. Navigate to Settings > Accounts > Access work or school > Add a work or school account.
  2. Enter the user’s credentials to link the device to the organization’s domain. 

Deploy Skyhigh Client Proxy and Apply Policy  

Deploying the SCP and applying the policies on managed devices ensures consistent security enforcement and effective traffic control.

Prerequisites 
  1. Active Intune subscription.
  2. Intune-managed device.
Deploy SCP
  1. Download the SCP version using this link.
  2. Login to the Intune Admin portal using this link.
  3. From the menu, select Apps.

1.PNG

  1. Select the platform as Windows.

2.PNG

  1. Click Create.

4_1.PNG

  1. In the App Type fieldselect Line-of-business app.

4_2.PNG

  1. Click Next.
  2. Browse and select the SCP client MSI file from the App package file
  3. Click Ok.

5_1.PNG

  1. Enter the following settings:
    • Name = Skyhigh Client Proxy
    • Description = Skyhigh Client Proxy
    • Publisher = Skyhigh Security
    • Ignore app version = Yes
    • Category = Other app
    • Show this as a featured app in the Company Portal = Yes
    • Developer= Skyhigh Security
    • Owner = Skyhigh Security
    • Logo = Select the Skyhigh Security Logo 

6_1.PNG

  1.  Click Review + save.
  2. In the Assignment tab, add All Devices for Required and All users for Available for enrolled devices.

    7.PNG
     
  3. Click Next.
  4. Review the app details and click Create.

2025-03-14_16-28-08.png

The apps created are displayed in the app section of the Intune Admin portal. 

2025-03-14_16-30-09.png

OPG File Deployment 
  1. Create a folder by navigating C:\Config_files\. in the local machine. 
  2. Export the.opg policy file from the  Skyhigh Security Tenant
  3. Rename the  .opg file to scppolicy.opg
  4. Copy the file scppolicy.opg to C:\Config_files\
  5. Create the following .bat files by navigating  C:\Config_files\:
    1. copy.bat
    2. del.bat
  6. Copy the following code to copy.bat file. 
    clipboard_e2d35d8fce2d9abf3defdf9c7e17e705b.png
  7. Copy the following code to del.bat file.
    clipboard_e02cf82e75d954c6ac66240162845a93a.png

 C:\Config_files\ contains these 3 files:

clipboard_e280e0405ad7a38e4d6c93cb34ada1ecb.png

  1. Download the IntuneWinAppUtil.exe File using the link.
  2. Create a folder by navigating C:\Temp\Build\ in the local machine. 
  3. Run the IntuneWinAppUtil.exe in CMD with admin permissions.
  4. Run the following settings in the CMD prompt :

clipboard_eb37218fea189d1f4f9683535dded1cc6.png

The output looks like this: 

clipboard_e11a4680d1c1f5a9feacfdca62c0af054.png

  1. Ensure that the copy.intunewin file are created in C:\Temp\Build\.

    The OPG deployment package generated can be utilized with Intune to configure the SCP policy.

clipboard_e05884a87ae75e01f77457750d5fb96b4.png

  1. Login to Intune Admin Portal.
  2. Click Create.
  3. Select Windows app (Win32) In the App type.

14_1.PNG

  1. Click Next.
  2. Browse and select the copy.intunewin file from the App package file.

2025-03-17_10-56-44.png

  1. Enter the following settings:
    • Name = Skyhigh OPG
    • Description = Skyhigh Proxy Config
    • Publisher = Skyhigh Security
    • App version = 4.9.3

image_2.png

  1. Click Next.
  2. Select Install command and Uninstall command files in the Program tab.

16_3_1.PNG

  1. Click Next.
  2. Select Operating system architecture and the Minimum operating system in the Requirements tab.

16_4_1.PNG

  1. Click Next.
  2. Select Manually configure detection rules in the Detection rules tab.

16_5_1.PNG

  1. Click Next.
  2. Review the dependencies, if added in the Dependencies tab.

16_6_2.PNG

  1. Click Next.
  2. Review the Supersedence, if added in the Supersedence tab.

16_7_1.PNG

  1. Click Next.
  2. Add All users for Required and All devices for Available for enrolled devices, in the Assignments tab.

16_8_1.PNG

  1. Click Next.
  2. Review the policy details and click Create.

16_9_1.PNG

The SCP client and the corresponding OPG file are automatically deployed to the Intune-managed device.

Create an SCP Compliance Script to Monitor SCP Status 

The creation of a compliance script by Intune helps in monitoring the SCP, which provides the real-time functionality status for managed devices.

NOTE: Scripts are temporarily available for download at https://drive.google.com/drive/folders/1-_f0xZuMQLXM-NtApuLZSdX441qGeZnw

  1.  Login to Intune Admin portal.
  2. Navigate to Devices > Compliance > Scripts > Add > select Windows 10 and later.

Script 1.PNG

  1. In the Basics tab, add Name, Description, and Publisher as Skyhigh Security.

Script 2.PNG

  1. Click Next.
  2. In the Detection script field, add the script.

3.PNG

  1. Click Next.
  2. In the Review+create tab, review the compliance script and click Create.

4.PNG

The newly created configuration is displayed under Devices > Compliance.

compliance_5.PNG

  1. Navigate to Devices > Compliance > Policy> Create Policy > select platform as Windows 10 and later.

compliance_6_1.PNG

  1. Click Create.
  2. Enter Name and Description in the Basics tab. 

compliance_7_1.PNG

  1. Click Next.
  2. In Compliance settings, select Required as Custom Compliance and select the script created in step 7. 

compliance_8_1.PNG

  1. Upload the validation.json script.

compliance_9_1.PNG

  1. Click Next.

compliance_10_1.PNG

  1. Select All users and All devices In the Assignments tab. 

compliance_11_1.PNG

  1. Click Next.
  2. Review the Windows 10/11 compliance policy and click Create.

    SCP compliance status is found under Devices > Windows devices > select the device > Device compliance.

compliance_12_1.PNG

 

NOTE: 

 

 

 

 

  • Was this article helpful?