> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/aikido-device-protection/deploying-aikido-endpoint/device-protection-mdm-guides/windows/deploy-aikido-endpoint-with-absolute.md).

# Absolute で Device Protection を導入

必要な権限が付与された状態で、Absolute を使用して管理対象の Windows フリート全体に Aikido Device Protection を展開します。

{% hint style="info" %}
開始する前に、すべてのデバイスに Absolute エージェントがインストールされ、Absolute コンソールにレポートしている必要があります。
{% endhint %}

## インストール

{% stepper %}
{% step %}
**必要なもの**

開始前に、Aikido Device Protection ダッシュボードから次のものを用意してください:

* お客様の **PowerShell インストール コマンド** （ダッシュボードのユーザーグループ選択欄からコピー）

見つからない場合は、次に戻ってください: [Aikido Device Protection ダッシュボード](https://app.aikido.dev/endpoint-protection/devices)、次をクリックします: **Connect Device**.
{% endstep %}

{% step %}
**管理対象デバイスでインストール コマンドを実行する**

Absolute の Device Reach 機能を使用して、Aikido ダッシュボードから PowerShell コマンドを Windows フリートに配信します。

1. Absolute コンソールで、次へ移動します **Device Reach** 左側のナビゲーションで。
2. 次を選択します **カスタム スクリプト**、次にクリック **スクリプトを作成**.
3. プラットフォームを次に設定します **Windows** そしてスクリプトの種類を次に設定します **PowerShell**.
4. Aikido Device Protection ダッシュボードからコピーしたインストールコマンドをスクリプト エディターに貼り付けます。
5. タイムアウトを少なくとも **30 分** に設定して、インストーラーのダウンロード時間を確保します。
6. スクリプトを対象のデバイス グループに割り当て、次をクリックします **実行**.

{% hint style="info" %}
スクリプトの実行後、Device Reach の結果パネルを確認して、各デバイスで正常に実行されたことを確認します。
{% endhint %}
{% endstep %}

{% step %}
**ロックダウン ポリシーを適用する**

Absolute の機能を使用して、Aikido Device Protection がインストールされたまま維持されるようにし、サービスを改ざんから強化します。

**Aikido Device Protection アプリのアンインストールをブロックする**

Absolute の Device Reach を使用して、ユーザーが Aikido アンインストーラーを実行できないようにする AppLocker ポリシーを配信します。

1. Absolute コンソールで、次へ移動します **Device Reach** 左側のナビゲーションで。
2. 次を選択します **カスタム スクリプト**、次にクリック **スクリプトを作成**.
3. プラットフォームを次に設定します **Windows** そしてスクリプトの種類を次に設定します **PowerShell**.
4. 次の PowerShell スクリプトをスクリプト本文に貼り付けます:

```powershell
$tmp = "$env:TEMP\aikido-applocker.xml"
Invoke-WebRequest -Uri "https://raw.githubusercontent.com/AikidoSec/safechain-internals/refs/heads/main/docs/aikido-applocker-deny-mdm.xml" -OutFile $tmp
Set-AppLockerPolicy -XmlPolicy $tmp -Merge
Remove-Item $tmp -Force
```

5. スクリプトを対象のデバイス グループに割り当て、次をクリックします **実行**.

**Application Persistence による削除を防止する**

Absolute の Application Persistence 機能を使用して、Aikido Device Protection アプリケーションの削除を検出し、修復します。

1. Absolute コンソールで、次へ移動します **耐障害性** 左側のナビゲーションで。
2. 次を選択します **Application Persistence**、次にクリック **アプリケーションを追加**.
3. Aikido Device Protection アプリケーション名を検索または入力します。
4. 永続化アクション（再インストールまたはアラート）を設定し、対象のデバイス グループに割り当てます。
5. 設定を保存します。
   {% endstep %}

{% step %}
**インストール後にデバイスを再起動する**

1. Absolute コンソールで、次へ移動します **デバイス** そして対象の Windows デバイスを選択します。
2. 使用 **Device Reach** PowerShell の再起動コマンドを実行するには：

```powershell
Restart-Computer -Force
```

エージェントは次回の起動時に完全に有効化されます。
{% endstep %}
{% endstepper %}

## トラブルシューティング

| 問題                           | 修正                                                                                                     |
| ---------------------------- | ------------------------------------------------------------------------------------------------------ |
| スクリプト実行後、デバイスがダッシュボードに表示されない | デバイスを再起動してください。次回の起動時にエージェントが完全に登録されます                                                                 |
| MDM コンソールでスクリプトがエラーで終了する     | 完全なエラーを確認するため、テストホストでスクリプトを SYSTEM として手動実行してください。また、インストーラーをダウンロードするためにデバイスがインターネットにアクセスできることを確認してください |
| エージェントサービスが実行されていない          | デバイスを再起動してください。サービスがまだ存在しない場合は、インストールスクリプトを再実行してください                                                   |
| 実行ポリシーによってスクリプトがブロックされている    | MDM 経由で実行されるスクリプトは SYSTEM として実行され、ユーザーレベルの実行ポリシー制限を回避します。MDM がスクリプト実行を制限する追加のポリシーを適用していないことを確認してください   |
| インストール後、デバイスが非アクティブとして表示される  | エージェントが完全に有効化されるには再起動が必要です。再起動後に確認してください                                                               |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/aikido-device-protection/deploying-aikido-endpoint/device-protection-mdm-guides/windows/deploy-aikido-endpoint-with-absolute.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
