Solution04 September 20265 min read1064 words

What Is Agent Management? The SignLogger Agent for Windows Log Collection and Logon 2FA

The SignLogger Agent collects Windows event logs (Security/System/Application), enforces 2FA at logon and is deployed zero-touch via GPO/SCCM with a signed MSI + EnrollToken; the fleet is managed from one center in the Agent Management module.

#agent management#windows agent#windows log collection#windows 2fa#gpo deployment#law 5651#event log

Firewall and network device logs arrive over syslog; but the event logs on Windows servers and clients (Security / System / Application) and Windows logon security need a component running on the machine itself. The SignLogger Agent is a lightweight piece of software installed on Windows machines: it collects event logs and forwards them to the SignLogger server, enforces a second factor (2FA) at logon, and is deployed zero-touch with a single signed MSI plus an EnrollToken. The Agent Management module lets you see, group, apply policy to and license that fleet from one center — without connecting to each machine in the field.

This page is for informational purposes; for setup steps see the Agent Management User Guide.

Why is an agent needed?

  • Windows logs do not arrive over syslog: a Windows server's or client's Security / System / Application logs do not flow across the network like firewall logs; an agent running on the machine must collect and send them.
  • Server / client records for Law 5651 and KVKK: who logged on to which machine and when, and which events occurred — audits ask for these records too. The agent carries them into SignLogger's signed archive.
  • A second factor at Windows logon: even a stolen password cannot open a session; a critical defence layer on RDP and terminal servers.
  • Hundreds of machines from one center: instead of installing and watching agents one by one, the fleet is viewed, grouped and licensed in one panel.

How does the agent work?

  • One package, one key: the signed SignLoggerAgent.msi provided by SYSNET is used with a single EnrollToken; no per-machine package is prepared.
  • Zero-touch rollout: the MSI and EnrollToken are applied to machines in the field via Windows Group Policy (GPO) or SCCM. At boot the machine registers itself with the SignLogger server automatically — no manual step.
  • Secure registration: a Shared Password (PSK) must be defined on the server before agents can register; with none defined, no agent can register.
  • Central policy: a registered agent receives which logs to collect and its 2FA settings from the server; different policies can be applied per group.
  • Signed retention: collected Windows logs are searchable in SignLogger alongside other logs, signed every day and retained.

What does the agent do?

Agents carry out four core jobs:

  • Log collection: collects Windows event logs (Security / System / Application) and sends them to the SignLogger server.
  • 2FA verification: enforces second-factor verification at Windows logon (TOTP / SMS); supports emergency-access and exemption scenarios.
  • Zero-touch deployment: with the same signed MSI + a single EnrollToken, machines register themselves automatically at boot.
  • Licensing: agents are licensed individually or automatically from a licence pool reserved for agents only.

What is in the Agent Management module?

  • Overview: fleet health, registered / offline agent counts and licence status on one card.
  • Agents: each machine's status, last-seen time, version and applied policy; individual or bulk actions.
  • Agent Groups: groups such as servers, clients or branches; separate log and 2FA policy per group.
  • Agent Settings: Shared Password (PSK), EnrollToken and default policies.
  • Agent Licences: the agent licence pool; individual or automatic licensing.
  • Windows log search: collected event logs are queried in SignLogger's log-search module, in the same experience as other sources.

Where is it used?

  • Active Directory environments: event logs of domain-joined servers and clients are retained centrally and signed.
  • RDP and terminal servers: a mandatory second factor on remote desktop sessions.
  • Multi-branch organisations: branch PCs are rolled out once via GPO; each branch is monitored as its own group.
  • Law 5651 and KVKK audits: server access and session records produced in signed, tamper-evident form.

Windows 2FA uses the same verification infrastructure as the VPN and firewall 2FA solution; for network access see the NAC solution.

What does the SignLogger Agent offer?

  • One center: hundreds of Windows machines in one panel; group, policy and licence management.
  • Zero touch: GPO / SCCM rollout with a signed MSI + EnrollToken; no per-machine manual work.
  • Signed Windows logs: event logs enter the Law 5651 archive and are signed every day.
  • Windows logon 2FA: TOTP / SMS second factor; emergency-access and exemption scenarios.
  • On your own infrastructure: agent data stays on the SignLogger server inside the organisation.

For the quick start (9 steps), screen guides and troubleshooting see the Agent Management User Guide.

Frequently Asked Questions

Can I collect Windows logs without an agent?

No. Windows event logs do not flow across the network over syslog like firewall logs; the SignLogger Agent running on the machine collects them and sends them to the server. Firewalls and network devices need no agent — they are collected over syslog / API.

Do I have to install the agent on every machine by hand?

No. The same signed SignLoggerAgent.msi and a single EnrollToken are distributed to all machines via Windows Group Policy (GPO) or SCCM; machines register themselves automatically at boot. No per-machine manual step is required.

I deployed via GPO but the agents do not appear in the panel — why?

The most common causes: no Shared Password (PSK) is defined on the server (with none defined, no agent can register), the MSI was deployed without the EnrollToken parameter, or the machine cannot reach the SignLogger server. Check the PSK and EnrollToken under Agent Settings and the registration status on the Agents page; for step-by-step diagnosis see the guide's Troubleshooting section.

Which methods does Windows logon 2FA use?

TOTP (the one-time code in apps such as Google / Microsoft Authenticator) and SMS. Emergency-access and exemption scenarios are supported, so an administrator does not lose access to a machine during an outage.

How are agents licensed?

Agents are licensed from a licence pool reserved for agents only; assignment can be individual or automatic. Pool status is monitored on the Agent Licences page.

I cannot see the Agent Management menu?

The full module is visible only with root-domain / Super User authority. If your permissions are insufficient you will see a dash (—) on the cards and a "retry with Super User" warning.

Are the collected Windows logs signed for Law 5651?

Yes. The event logs sent by the agent are retained in SignLogger together with other logs, signed every day and presented as a signed archive in an audit; their integrity is proven with the independent verification tool.

Last updated: 04 September 2026

See how SignLogger delivers this solution for your organization

Request a free demo