> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/aikido-device-protection/deploying-aikido-endpoint/device-protection-mdm-guides/windows/deploy-aikido-endpoint-with-intune.md).

# Intune でデバイス保護を展開

必要な権限を設定したうえで、Microsoft Intune を使用して管理対象の Windows フリート全体に Aikido Device Protection を展開します。

{% hint style="info" %}
開始する前に、すべてのデバイスを Microsoft Intune の Windows 管理に登録しておく必要があります。
{% endhint %}

## インストール

{% stepper %}
{% step %}
**必要なもの**

開始前に、Aikido Device Protection ダッシュボードから次のものを用意してください:

* お客様の **PowerShell インストール コマンド** （ダッシュボードのユーザー グループ セレクターからコピーします。トークンとインストーラーのダウンロードが含まれます）

見つからない場合は、次に戻ってください: [Aikido Device Protection ダッシュボード](https://app.aikido.dev/endpoint-protection/devices)、次をクリックします: **Connect Device**.
{% endstep %}

{% step %}
**管理対象デバイスでインストール コマンドを実行する**

ダッシュボードのコマンドを、SYSTEM コンテキストで実行される 1 回限りのプラットフォーム スクリプトとして展開します。

1. Intune 管理センターで、次へ移動します **デバイス** → **スクリプトと修復** → **プラットフォーム スクリプト** → **追加** → **Windows 10 以降**.
2. 次の **基本** タブで、名前（例: 「Aikido Device Protection install」）と任意の説明を入力し、次に **次に**.
3. 次の **スクリプトの設定** タブで、保存します **PowerShell インストール コマンド** Aikido ダッシュボードから、…として `.ps1` ファイル（ファイルは 200 KB 未満で、ASCII として保存する必要があります）を保存し、その後、次を使用してアップロードします **スクリプト ファイル** 参照ボタン。
4. 設定 **サインイン中の資格情報を使用してこのスクリプトを実行する** を次に設定します: **いいえ** これにより、スクリプトは SYSTEM として実行されます。
5. 設定 **スクリプト署名のチェックを強制する** を次に設定します: **いいえ**.
6. 設定 **64 ビットの PowerShell ホストでスクリプトを実行する** を次に設定します: **はい**.
7. 次を選択します **次に**、必要なスコープ タグを追加し、次に **次に**.
8. オン **割り当て**、対象の Windows デバイス グループを選択し、次に **次に**.
9. オン **確認して追加**、 **追加**.

{% hint style="info" %}
Intune Management Extension は 8 時間ごと、および再起動のたびにチェックインします。テスト デバイスでより早く実行させるには、次のサービスを再起動します **Microsoft Intune Management Extension** そのデバイス上のサービス。
{% endhint %}
{% endstep %}

{% step %}
**ロックダウン ポリシーを適用する**

Aikido Device Protection アプリケーションのアンインストールをブロックします。

**Aikido Device Protection アプリケーションのアンインストールをブロックする**

Intune には、特定の Win32 アプリケーションに対して「アンインストール」を単純に非表示にする組み込み設定はありません。アンインストールを防ぐには、Aikido のアンインストーラーの実行を拒否する AppLocker ポリシーを展開します。

1. Intune 管理センターで、次へ移動します **デバイス** → **デバイスの管理** → **設定** → **作成** → **新しいポリシー**.
2. 設定 **プラットフォーム** を次に設定します: **Windows 10 以降** および **プロファイルの種類** を次に設定します: **テンプレート**、次に選択します: **カスタム**をクリックし、 **作成**.
3. プロファイルに名前を付けます（例: 「Aikido Device Protection uninstall block」）。
4. Aikido のアンインストーラーを拒否する AppLocker XML ポリシーを適用する OMA-URI 設定を追加します:
   * **名前**: `Aikido AppLocker アンインストール ブロック`
   * **OMA-URI**: `./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/Aikido/MSI/Policy`
   * **データ型**: **文字列**
   * **値**：次の内容を貼り付けます [aikido-applocker-deny-mdm.xml](https://raw.githubusercontent.com/AikidoSec/safechain-internals/refs/heads/main/docs/aikido-applocker-deny-mdm.xml) （リンクを開き、XML テキスト全体をコピーして、ここに貼り付けます）
5. プロファイルを同じ Windows デバイス グループに割り当てます。

{% hint style="info" %}
エンドユーザーがローカル管理者である場合、AppLocker ルールは回避される可能性があります。より強力に適用するには、このポリシーを App Control for Business (WDAC) とローカル管理者権限の削除と組み合わせてください。
{% endhint %}
{% endstep %}

{% step %}
**インストール後にデバイスを再起動する**

1. Intune 管理センターで、次へ移動します **デバイス** → **すべてのデバイス** → **デバイスの一括操作**.
2. 次の **基本** タブで、次を設定します: **OS** を次に設定します: **Windows** および **デバイス操作** を次に設定します: **再起動**、次に選択します: **次に**.
3. 次の **デバイス** タブで、対象デバイス（1 回の一括操作につき最大 100 台）を選択し、次に **次に**。より大きなグループの場合は、一括操作をバッチで繰り返すか、 **再起動** を通じてデバイス グループにコンプライアンス アクションを割り当てます **エンドポイント セキュリティ** → **デバイス コンプライアンス** → **ポリシー** を代わりに使用してください。
4. オン **確認して作成**、 **作成**.

エージェントは次回の起動時に完全に有効化されます。
{% endstep %}
{% endstepper %}

## トラブルシューティング

| 問題                           | 修正                                                                                                     |
| ---------------------------- | ------------------------------------------------------------------------------------------------------ |
| スクリプト実行後、デバイスがダッシュボードに表示されない | デバイスを再起動してください。次回の起動時にエージェントが完全に登録されます                                                                 |
| MDM コンソールでスクリプトがエラーで終了する     | 完全なエラーを確認するため、テストホストでスクリプトを SYSTEM として手動実行してください。また、インストーラーをダウンロードするためにデバイスがインターネットにアクセスできることを確認してください |
| エージェントサービスが実行されていない          | デバイスを再起動してください。サービスがまだ存在しない場合は、インストールスクリプトを再実行してください                                                   |
| 実行ポリシーによってスクリプトがブロックされている    | MDM 経由で実行されるスクリプトは SYSTEM として実行され、ユーザーレベルの実行ポリシー制限を回避します。MDM がスクリプト実行を制限する追加のポリシーを適用していないことを確認してください   |
| インストール後、デバイスが非アクティブとして表示される  | エージェントが完全に有効化されるには再起動が必要です。再起動後に確認してください                                                               |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/aikido-device-protection/deploying-aikido-endpoint/device-protection-mdm-guides/windows/deploy-aikido-endpoint-with-intune.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
