Choose an installation path
Install directly
Download the package for one device and install it locally. Use this path for a pilot, a test device, or a device that is not managed through MDM.
Deploy with MDM
Push the package and managed configuration to a fleet. On macOS, also push the Edge certificate as a device-scoped trusted root.
Before you begin
You need:- A running Bifrost Enterprise deployment with an Edge entitlement and an available device seat.
- The HTTPS URL users and devices use to reach Bifrost.
- Access to Governance settings and Edge Control in the Bifrost dashboard.
- An Edge agent package for the target operating system and architecture. Bifrost provides packages through the organization-specific download location shared during Edge onboarding.
- For the recommended identity flow, a configured identity provider and a provisioned user with access to an active virtual key.
If your deployment does not have an identity provider, Edge can use a user-entered Bifrost virtual key when Allow virtual key sign-in is enabled in Edge Settings. This is a separate sign-in path; it does not create an IdP user session.
Setup sequence
1
Prepare Bifrost identity and access
Configure user provisioning, roles, access profiles, and the users who will run Edge. Confirm that each intended user can resolve to an active virtual key.
2
Configure Edge
Set up the interception certificate authority, choose the initial approval behavior, and review the agent sync and sign-in settings.
3
Install the agent
Follow either the direct installation or MDM deployment path.
4
Sign in and verify
After the active CA is trusted, restart the computer so the certificate change takes effect. Then confirm the tray reports a connected state, the device appears in Edge Devices, Diagnostics is healthy, and a supported AI request reaches Bifrost.
Verify setup
Do not treat installation alone as a successful rollout. A device is ready when:- The tray shows Connected or Connected (virtual key).
- The computer was restarted after the active CA was first trusted or last changed.
- Edge Diagnostics confirms that the service, credential, configuration, certificate, traffic capture, and gateway checks are healthy.
- The device appears under Edge Control → Devices with the expected owner and hostname.
- A request from a supported application is visible in Bifrost.

