Choose a deployment method
In Forge, open Settings → Integrations → Forge Device Agent, select a
platform, and choose direct download or managed deployment. Deployment material
is created for your organization and should only be shared with administrators
responsible for the rollout.
Windows setup
For a direct installation, download the Windows setup bundle from Forge and run it as an administrator on the target device. The device appears in Fleet after it enrolls and sends its first signal. For Intune:- Connect Microsoft Entra and confirm the requested Microsoft Graph access.
- In Forge, generate the Windows deployment for your organization.
- Choose Guided upload to create the Win32 app using the settings Forge provides, or choose Automated to let Forge create it after your review.
- Assign the app as Required to a pilot Entra device group.
- Return to Forge and refresh the deployment to confirm the assignment and installed devices.
macOS setup
The macOS download contains one signed unified installation package and the setup material needed for the selected deployment method. For a direct installation, extract the ZIP on the target Mac and openInstall Forge Device Agent.command. Approve the signed installer and Forge
Network Extension when macOS asks. The generated package enrolls one device in
the organization for which it was created.
For Jamf:
- In Forge, choose Jamf and download the generated Jamf deployment bundle.
- Upload the unified signed package as a Jamf computer package.
- Upload the included
.mobileconfigas a computer configuration profile and scope it to the pilot Macs before the package policy. - Add the included Before and After scripts to Jamf. For first enrollment, place the bundle’s bootstrap token in parameter 4 of the Before script. The policy template already contains the Forge URL in parameter 5.
- Recreate the included policy template, scope it to the same pilot Macs, add the included Extension Attribute, and run the policy.
- Confirm the profile, package receipts, System Extension, authenticated heartbeat, inventory, and Extension Attribute readback before expanding the scope.
Turn on device routing
After devices enroll, open Fleet, select the exact devices you want to manage, and enable Device routing. Forge checks device health and the routing path before showing the devices as Active.
Once active, supported AI traffic is routed automatically. Users keep using
their existing applications and provider interfaces; no application-by-
application proxy configuration is required.
Updates and removal
Deploy the complete release generated by Forge whenever you update Device Agent. On Windows, publish the new signed Intune app using supersedence or a new required assignment. On macOS, deploy the new unified package together with its matching profile and scripts. Forge preserves enrollment during a normal update and reports the version currently running on each device. To remove Device Agent, start the removal from Fleet or your management workflow and wait for the device to restore its previous network settings. On macOS, remove the MDM-owned configuration profile before uninstalling the packages.Troubleshooting
For a final check, open the device in Fleet and confirm its organization,
version, recent heartbeat, and routing health. Then make a supported test
request and verify that it appears under the appropriate LLM or MCP Gateway
session.