Deploy the scanner
Choose how to get the Surface scanner onto your laptops, from a single test machine to a managed fleet.
The scanner is a small program that runs in the background on each laptop. Getting it onto laptops has three parts: install the package, enroll the laptop with your organization, and check that it reports.
Choose a method
MDM deployment
Jamf, Intune, Kandji, Mosyle, or Group Policy. Laptops enroll on their own. Recommended for fleets.
Install script
One command per laptop. Good for pilots and small teams.
Manual install
Download the .pkg, .msi, .deb, or .rpm and install it yourself.
All three install the same package. They differ only in how the laptop gets its credentials.
Before you begin
Read Requirements for supported operating systems and the network access the scanner needs. It is short.
After installation
- The laptop appears on Endpoints within a few minutes.
- Its AI tools appear in Inventory after the first scan.
- Insights updates once risk has been evaluated.
On the laptop itself, sudo surface status shows the version, whether the service is running, and the organization it joined.