RdpGuard deployment: silent installation, activation, updates, and removal.
RdpGuard
Intrusion prevention system for your Windows Server
 
Follow

RdpGuard Silent Installation and Deployment

Deploy RdpGuard from a script, a software distribution system, or an automation agent using the EXE or MSI installer. This guide covers unattended installation, activation, updates, and removal. The options below apply to the 64-bit installers for RdpGuard 10.3.7 and later; do not use older packages for these examples.

Silent installation

Run the installer with administrator privileges on a supported 64-bit Windows system. Install .NET Framework 4.8 or later first; the RdpGuard installer checks this prerequisite but does not install it for you. Silent switches do not bypass elevation or prerequisite checks.

The examples use Command Prompt (cmd.exe), not PowerShell. Replace rdpguard-setup.exe or rdpguard-setup.msi with the actual downloaded installer filename. The ^ character continues a command on the next line.

EXE installer:

start /wait "" "rdpguard-setup.exe" ^
  /VERYSILENT /SUPPRESSMSGBOXES /SP- ^
  /NORESTART /RESTARTEXITCODE=3010 ^
  /LOG="%TEMP%\rdpguard-install.log"
echo Exit code: %ERRORLEVEL%

/VERYSILENT hides the wizard and progress window; /SUPPRESSMSGBOXES suppresses message boxes during silent setup. Use both for unattended deployment. /SP- disables the initial confirmation. The RdpGuard dashboard is not launched after a silent installation.

MSI installer:

start /wait "" msiexec.exe ^
  /i "rdpguard-setup.msi" /qn /norestart ^
  /L*v "%TEMP%\rdpguard-install.log"
echo Exit code: %ERRORLEVEL%

/qn disables the MSI user interface. Both examples prevent an automatic reboot and wait for the installer to finish. Log paths and %TEMP% belong to the account running the deployment, which may be SYSTEM rather than the signed-in user. If you choose another log directory, create it first.

Standard options are documented in the Inno Setup command-line reference and the Windows Installer command-line reference.

Installation options

Add the appropriate argument to your installation command:

  • Custom installation directory: use /DIR="C:\Apps\RdpGuard" for EXE, or TARGETDIR="C:\Apps\RdpGuard" for MSI.
  • EXE installer language: use /LANG=en, /LANG=de, /LANG=es, /LANG=fr, or /LANG=ru. The MSI wizard is in English.
  • No desktop shortcut from EXE: use /TASKS="" to deselect optional tasks. Start Menu shortcuts are separate from these tasks.

EXE switches start with /. MSI properties such as TARGETDIR are uppercase NAME=value arguments without a slash.

License activation

Activate during deployment: supply a protected text file containing your license key. Add the matching argument to the EXE or MSI installation command above:

EXE:

/RDPGUARD_LICENSE_KEY_FILE="C:\Deploy\RdpGuard\license-key.txt"

MSI:

RDPGUARD_LICENSE_KEY_FILE="C:\Deploy\RdpGuard\license-key.txt"

Pass the file path, not the key itself. Activation requires access to the RdpGuard licensing service. Prepare the file using your deployment system's secure secret-file mechanism and meet these requirements:

  • Use an absolute path on a local fixed drive. Network paths, mapped network drives, symbolic links, junctions in the path, and alternate data streams are not accepted.
  • Use a UTF-8 text file containing one key. The file must be no larger than 4,096 bytes; the trimmed key must be no longer than 1,024 characters.
  • The file owner must be SYSTEM or the built-in Administrators group. Its permission entries must grant access only to those identities, including inherited permissions. Ensure the installer can read it; for MSI, the activation action runs as SYSTEM. A file in an ordinary user profile may fail these checks even when setup is elevated.
  • Remove the key file after the installer has finished, including after a failure. The installer does not delete a caller-supplied key file.

Activate later: use /DEFERACTIVATION=1 for EXE or DEFERACTIVATION=1 for MSI. Do not combine this with a license-key file. This skips the installer's online activation check; it does not activate a license, start a new trial, or extend maintenance. An existing local paid-license certificate is retained, but it must still be valid for the installed build.

A fresh installation without a key file also leaves activation to the installed product. Installation success alone does not mean protection is active. Confirm the license or trial and protection status before treating deployment as complete. During an update, a failed activation check stops silent setup instead of asking for a key.

Updating an existing installation

Run the newer installer using the same silent command and the same format as the existing installation: EXE over EXE, or MSI over MSI. Keep the existing installation directory. Schedule a maintenance window because setup stops the RdpGuard service while updating its files.

EXE and MSI registrations are independent. Switching formats can leave two uninstall entries for shared files and one service; removing either can break the remaining installation. Do not use a format switch as an upgrade strategy. For MSI installation and updates, Windows Installer rollback must remain enabled.

Silent uninstall and data cleanup

EXE installation: run the uninstaller from the actual installation directory. This example uses the default path; use the registered uninstall path if it differs.

start /wait "" "C:\Program Files\RdpGuard\unins000.exe" ^
  /VERYSILENT /SUPPRESSMSGBOXES /NORESTART ^
  /LOG="%TEMP%\rdpguard-uninstall.log"
echo Exit code: %ERRORLEVEL%

MSI installation: use the original MSI for the installed version, or its registered ProductCode. Do not substitute the MSI for a different release.

start /wait "" msiexec.exe ^
  /x "rdpguard-setup.msi" /qn /norestart ^
  /L*v "%TEMP%\rdpguard-uninstall.log"
echo Exit code: %ERRORLEVEL%

Both formats keep settings, data, and logs by default. To explicitly remove them, add /REMOVEDATA=1 for EXE or REMOVEDATA=1 for MSI. Back up anything you need before using this option.

Cleanup targets %ProgramData%\RdpGuard but preserves its Licensing subdirectory. It does not reset a trial or bypass normal license deactivation. Linked directories are not followed, and locked or inaccessible files may remain. This is a cleanup option, not a guaranteed secure wipe.

Exit codes and deployment checks

Capture the installer's exit code immediately after it finishes. For the installation commands above, 0 means success and 3010 means success with a reboot required. The EXE command explicitly selects 3010 with /RESTARTEXITCODE=3010; it is not the default Inno Setup behavior. Treat other results as unsuccessful deployment and inspect the log before retrying.

A failed prerequisite or activation check is not fixed by repeatedly launching setup. Check the logged reason, administrator permissions, .NET availability, key-file permissions, and licensing-service connectivity. See the EXE setup exit codes and MSI error codes.

After installation, verify that the RdpGuard service is running, the license or trial is confirmed, and the required protection engines are enabled and configured. An already disabled service remains disabled. Installation alone is not a health check.

Use the RdpGuard command line interface for post-install configuration, and verify the Windows logon audit policy on each server where it is needed for detection.

RdpGuard 10.3.7 Free Trial

RdpGuard protects:

Our customers say

"This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques

"Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson

"Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford

"Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch

"Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan

"It's a great product - really stopping those RDP attackers :-)" - Dave, UK

"First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes

Our Other Products
Copyright © 2012-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.