DataLocker PortBlocker

Mass Deployment


DATALOCKER PORTBLOCKER · MSI DEPLOYMENT v3.0


For mass deployment of PortBlocker 3.0 on Windows through any tool that wraps msiexec (Group Policy, SCCM/MECM, PDQ, and similar). Each endpoint installs silently, auto-registers against your SafeConsole tenant from values written at install time, and can run in a temporary audit-mode grace window during rollout.

Requirements

  • PortBlocker 3.0 MSI: PortBlocker-Setup.msi (x64) or PortBlocker-Setup-arm64.msi (Arm64).

  • Windows 10 or Windows 11.

  • Your SafeConsole tenant /connect URL.

  • Outbound TCP 443 from the endpoint to the tenant host.

msiexec Options

Option

Purpose

/i <package>

Install the MSI.

/qn

Fully silent (no UI). Use /qb for a basic progress bar.

/norestart

Do not reboot after install.  When upgrading from 2.x to 3.x, a reboot is recommended.

/l*v <path>

Write a verbose install log, useful for first-rollout debugging.

MSI Properties

Public properties are passed NAME=VALUE on the command line (uppercase, no space around =). They are written to HKLM\SOFTWARE\DataLocker\PortBlocker\AutoRegister and read by the service at first start to auto-enroll the endpoint.


Property


Req.


Values / Example


Effect


URLYeshttps://<tenant>.safeconsolecloud.io/connectYour SafeConsole tenant /connect URL. Must be the full endpoint URL, not the console login page.
EULAYes1Acknowledges the end-user license agreement. Required for silent installs and upgrades (/qn, /qb); the install aborts without it. Interactive installs accept through the EULA dialog instead.
USERNoExample: eiA1ePbLrlHSwYV1IywEg==Register PortBlocker to a specific user and path pre-defined in SafeConsole (Path Token Recommended)
ENABLEAUDITMODEDAYSNo1–365Days of allow-all-devices with logging after install before the endpoint switches to block-default. The window closes early the moment registration succeeds. Recommended for the first 24–72 hours of a rollout.
LAUNCH_CLIENTNo1 | 0 (default 1)Whether the tray client launches right after install. Set 0 for hands-off mass deployment; the tray still appears at the next user logon. To keep it hidden for good, use the SafeConsole Hide Client UI policy.
PASSWORDNoany stringUninstall protection. If set, msiexec /x fails unless the same value is passed back. Once the endpoint registers, SafeConsole's uninstall-password policy replaces it.


Examples

Silent install with auto-register and a 7-day audit window:


msiexec /i PortBlocker-Setup.msi /qn /norestart ^

 URL="https://<tenant>.safeconsolecloud.io/connect" ^

 USER="eiA1ePbLrlHSwYV1IywEg==" ^

 EULA=1 ^

 ENABLEAUDITMODEDAYS=7 ^

 /l*v "C:\Windows\Temp\PortBlocker-install.log"


Uninstall (when a password was set):


msiexec /x PortBlocker-Setup.msi /qn PASSWORD="<your-uninstall-password>"

Audit Mode

ENABLEAUDITMODEDAYS=N opens a time-bounded grace window that starts when the agent first runs. While the endpoint is not yet registered and the window is open, every device is allowed and every connection is logged, so users keep working during the rollout. The window closes the moment registration succeeds or after N days, whichever comes first, and the endpoint then follows the policy from SafeConsole. Audit mode is a fresh-install grace window only; it does not return after an unregister.

Uninstall Password

The uninstall password is controlled via a SafeConsole policy for both Windows and macOS.  This will override the password set through the MSI install process.


Hide Client UI

With this policy, the PortBlocker client UI will be hidden from the desktop.  Notifications will also be unavailable.




© 2026 DataLocker Inc. All rights reserved. · PortBlocker 3.0 MSI Command Line Arguments
Support: https://support.datalocker.com


DATALOCKER PORTBLOCKER · MSI DEPLOYMENT v2.3

Installation

The Portblocker-Setup.msi installer will deploy three key parts to the target workstation.  The three parts consist of a Device Driver, Windows Service, and a Windows Application that the user can interact with. The installation will require local admin privileges to complete the process and is recommended to run as the system account to avoid UAC prompts. Once PortBlocker is installed, all mass storage type devices will be blocked. The following arguments can be used during installation.  


/i: This is the msiexec option for install.

 

/quiet: used for silent installations on new installs and version upgrades.

 

/S: hides the notification that PortBlocker is already installed

 

/norestart: Prevents the machine from restarting automatically after the installation is completed. 

 

/forcerestart: The machine will be restarted after the installation is complete.


Registration

Registration is needed before devices can be allowed. When registration parameters are successfully passed to the installer, PortBlocker will automatically register after installation.  The following arguments can be used during installation to automatically register PortBlocker after registration. 


URL=<SafeConsoleConnectionToken>: the SafeConsole connection token (https://myserver.safeconsolecloud.io/connect)

 

EULA=1: Accept the end-user license agreement on behalf of the user

 

USER=<UniqueToken>: OPTIONAL, register the PortBlocker Install to a specific user already in SafeConsole

 

LAUNCH_CLIENT=1 | 0: Launch Windows client application after installation. The default value is 1 (launch client application). It is recommended to set to 0 (do not launch client application) for mass deployment scenarios to avoid unresponsive client processes in the background. The client application should be launched by the user or startup script on user login in this case.


DISABLE_AUTO_UPDATE=1 | 0: OPTIONAL, Disables the automatic application update prompt.  Set to value back to 0 to revert the change.  (Requires 1.4.14.2+)


DISABLE_UI_SYS_STARTUP=1 | 0: OPTIONAL, Disables the PortBlocker UI during OS startup. UI can still be started by running the PortBlocker application. (Requires 1.6+)


HIDE_CLIENT_UI=1 | 0: OPTIONAL, Disables the PortBlocker UI. This will run PortBlocker as a process but UI cannot be triggered. (Requires 1.6+)


It is recommended that the SafeConsole Server be configured with both unique token and admin approval disabled. This will allow a simple registration process for the end-user. 


Uninstall Password 

As of PortBlocker version 1.4, and SafeConsole version 5.7, the uninstall password is controlled via a SafeConsole policy for both Windows and macOS.




The following argument can be used when uninstalling PortBlocker.


PASSWORD=: PortBlocker may be uninstalled via CMD or Powershell. Use "PASSWORD=" to specify the uninstallation password.


For more information regarding the uninstall process, please see the process in the PortBlocker admin guide starting on page 23:

PortBlocker Admin Guide


Requirements

  • PortBlocker 1.4.3+ or later MSI Installer
  • Windows 10 and Windows 7
  • SafeConsole Connection Token, ex: https://myserver.safeconsolecloud.io/connect
  • Public server share to host installer, ex: \\nas\share\PortBlocker-Setup.msi 


Example

This example PowerShell script can be modified for use with your software deployment tool. 


*Note*  Windows by default restricts execution of PowerShell script. However, this execution policy will not need to be changed for deployment as the script will execute with the privilege of the local system account. When testing the script locally, the PowerShell execution policy may need to be modified. For more information see Microsoft's documentation.


# Location of msi, such as a public network share
Set-Variable -Name "installer" -Value "\\nas\share\PortBlocker-Setup.msi"

# SafeConsole Connection URL
Set-Variable -Name "safeConsoleURL" -Value '"https://server.safeconsolecloud.io/connect"'

$installerArgs = "/i $installer /quiet /norestart EULA=1 URL=$safeConsoleURL LAUNCH_CLIENT=0"
Start-Process msiexec.exe -Wait -ArgumentList $installerArgs