Software Secure Workload
Activity Configure

Generate Agent Token

In the agent configuration profile, you can enable service protection to prevent uninstallation, disabling, and stopping Windows agent services. To perform any changes to the agents, you can disable this protection on the agent configuration profile. However, if you are unable to disable the protection because of connectivity issues, you can generate an agent token to disable the service protection on workload. The token is valid for 15 minutes.

Supported roles to generate and retrieve agent tokens:

  • Site administrators: For clusters or tenants.

  • Customer support: For tenants.

  • Agent installer: For agent-specific tokens.

  • Tenant owner: For tenants on SaaS.


 

You can generate time-based agent tokens only for Windows OS-based software agents.

To generate and download agent tokens, perform these steps:

Procedure

1

In the navigation pane, click Manage > Workloads > Agents > Agent List.

Based on your requirement, you can choose one of the agent token types—Cluster, tenant, or agent-specific. For the agent-specific token, go to Step 5.

2

Click the menu icon and choose Agent Token.


 

The Agent Token option is only visible for site administrators or customer support user roles.

3

Select a token type:

  • Token For Cluster—This option is visible only to site administrators and the token is applicable for all the agents.
  • Token For Tenant—Applicable for the agents under a selected tenant.
4

To download the token key, click Download Token.

5

To view and download token key details of a specific agent:

  1. Go to the Agent List tab and click the required agent. Under Agent Details > Agent Token, you can view the token key and expiry details of the token.

  2. To download the agent-specific token, click Download Token.

What to do next

After downloading the agent token file, run the following command on the agent to disable service protection: "C:\Program Files\Cisco Tetration\TetSen.exe” -unprotect <token>, where token is the downloaded agent token.

After the service protection is disabled using a token, it may be automatically re-enabled when the service restarts and connects to the Secure Workload cluster.