> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/aikido-device-protection/deploying-aikido-endpoint/device-protection-mdm-guides/windows/deploy-aikido-endpoint-with-jumpcloud.md).

# JumpCloudでデバイス保護を展開する

JumpCloud を使用して、必要な権限を設定したうえで、管理対象の Windows フリート全体に Aikido Device Protection を展開します。

{% hint style="info" %}
すべてのデバイスを [JumpCloud Windows MDM](https://jumpcloud.com/support/get-started-windows-mdm) に登録しておく必要があります。
{% endhint %}

## インストール

{% stepper %}
{% step %}
**必要なもの**

開始する前に、Aikido Device Protection ダッシュボードから次のものを用意してください。

* あなたの **PowerShell のインストール コマンド** （ダッシュボードのユーザー グループ セレクターからコピーされたもので、トークン + インストーラーのダウンロードを含みます）

見当たらない場合は、戻って [Aikido Device Protection ダッシュボード](https://app.aikido.dev/endpoint-protection/devices)、 **デバイスを接続**.
{% endstep %}

{% step %}
**管理対象デバイスでインストール コマンドを実行する**

1. JumpCloud 管理ポータルで、 **デバイス管理** → **コマンド**.
2. クリック **+ コマンド** を選択し、 **コマンド**.
3. 名前を付けます（例: 「Aikido Device Protection のインストール」）。
4. 次を設定します】【： **タイプ** を **Windows PowerShell**。JumpCloud は Windows コマンドを `LocalSystem` （NT Authority\System）アカウントとして実行するため、追加のユーザーコンテキストは不要です。
5. Aikido Device Protection ダッシュボードからコピーした PowerShell のインストールコマンドを、コマンド本文に貼り付けます。
6. 有効のままにし **起動タイプ** として **一回限り**.
7. 次を選択します。 **デバイス** タブで対象の Windows デバイスグループにコマンドを割り当てます。
8. クリック **保存**、その後 **今すぐ実行**.

このコマンドはインストーラーを取得し、デバイスをユーザーグループのトークンに登録し、サイレントインストールを実行します。
{% endstep %}

{% step %}
**ロックダウン ポリシーを適用する**

JumpCloud には、Windows サービスをロックし、アプリのアンインストーラーをブロックする単一の組み込みポリシーはないため、これら 2 つのポリシーを組み合わせて適用します。

**Aikido Device Protection アプリのアンインストールをブロックする**

1. JumpCloud 管理ポータルで、 **デバイス管理** → **ポリシー管理**.
2. 次をクリックします】【： **(+)** アイコンをクリックし、 **Windows** タブを選択して、 **アプリケーション制限ポリシー**をクリックします。 **を設定する**.
3. ポリシーに名前を付けます（例: 「Aikido Device Protection のロックダウン」）。
4. 次の項目の下で **ファイル パス ルール**で、Aikido Device Protection のアンインストーラー実行ファイルの完全なパスを追加して、その実行をブロックします: `%ProgramFiles%\Aikido Device Protection\unins000.exe`.
5. 次を選択します。 **デバイスグループ** タブでポリシーを同じ Windows デバイスグループに割り当てます。
6. クリック **保存**.

このポリシーは AppLocker ルールを使用してアンインストーラーの実行をブロックします。アプリケーション制限ポリシーは、指定したバイナリの実行をブロックします。アプリ自体を削除したり、ダウンロードを防止したりはしません。ここではそれが意図した動作です。

**ユーザーが Aikido サービスを停止または無効化するのを防ぐ**

Aikido Device Protection インストーラーは、非管理者ユーザーがサービスを停止または無効化できないように、自身のサービス ACL を強化します。追加の JumpCloud ポリシーは必要ありません。

{% hint style="warning" %}
JumpCloud のカスタム レジストリ キー ポリシーでは、 `Security\` レジストリ パス配下の ACL を変更できません。そのため、サービス権限の強化は JumpCloud ではなく Aikido インストーラー自体によって強制されます。
{% endhint %}
{% endstep %}

{% step %}
**インストール後にデバイスを再起動する**

1. JumpCloud 管理ポータルで、 **デバイス管理** → **ポリシー管理**.
2. 次をクリックします】【： **(+)** アイコンをクリックし、 **Windows** タブを選択して、 **再起動をスケジュール**をクリックします。 **を設定する**.
3. 頻度を **1回** に設定し、インストールコマンドの実行直後の日時を選択します。
4. 次を選択します。 **デバイスグループ** タブでポリシーを同じ Windows デバイスグループに割り当てます。
5. クリック **保存**.

単一デバイスをただちに 1 回だけ再起動するには、 **デバイス管理** → **デバイス**、の3点メニューをクリックし、 **アクション** 列で、次を選択します **デバイスを再起動**.

エージェントは次回の起動時に完全に有効化されます。
{% endstep %}
{% endstepper %}

## トラブルシューティング

| 問題                           | 修復                                                                                                    |
| ---------------------------- | ----------------------------------------------------------------------------------------------------- |
| スクリプト実行後、デバイスがダッシュボードに表示されない | デバイスを再起動してください。エージェントは次回の起動時に完全に登録されます                                                                |
| MDM コンソールでスクリプトがエラーで終了する     | テスト用ホストで SYSTEM としてスクリプトを手動実行し、完全なエラーを確認してください。デバイスがインストーラーをダウンロードするためのインターネット接続を持っていることを確認してください     |
| エージェント サービスが実行されていない         | デバイスを再起動してください。サービスがまだ存在しない場合は、インストール スクリプトを再実行してください                                                 |
| スクリプトが実行ポリシーによってブロックされている    | MDM 経由で実行されるスクリプトは SYSTEM として実行され、ユーザーレベルの実行ポリシー制限を回避します。MDM がスクリプトの実行を制限する追加のポリシーを適用していないことを確認してください |
| インストール後、デバイスが非アクティブとして表示される  | エージェントが完全に有効になるには再起動が必要です。再起動後に確認してください                                                               |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/aikido-device-protection/deploying-aikido-endpoint/device-protection-mdm-guides/windows/deploy-aikido-endpoint-with-jumpcloud.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
