Cigent Full Drive Encryption (FDE) supports silent installation using a Microsoft Windows Installer (MSI) package. This method is intended for system administrators who need to automate FDE deployments using scripts, Group Policy, or enterprise software management tools.
Silent installation allows Cigent FDE to be installed without displaying the installation wizard and can optionally automate the creation of the initial FDE administrator account.
Prerequisites
Before performing a silent installation, ensure that:
- The system meets the Cigent FDE Installation Requirements.
- Windows 11 version 23H2 x64 or later is installed and fully updated.
- The Microsoft UEFI CA 2023 certificate is present in the system firmware.
- Important system and user data has been backed up.
- The installation is performed with administrator privileges.
- The Cigent FDE MSI installation package is available.
Silent Installation Command
The following example installs Cigent FDE silently and automatically creates an initial administrator account.
Example:
msiexec /i "FDE_Installer_v1.2.1.19.msi" /qn ^
USER_NAME="cigent" USER_CRED="YourSecurePassword!" ^
OS_ONLY=Y ACCEPT_EULA=Y DATABACKEDUP=Y ^
/l*v "fde_install.log"
Replace the example username and password with the desired initial FDE administrator credentials.
The command is formatted for Windows Command Prompt. The caret (^) allows the command to continue across multiple lines.
The /qn option suppresses the installer user interface, while /l*v enables verbose installation logging.
Required MSI Parameters
The following parameters are required for every silent installation:
Parameter | Description |
ACCEPT_EULA=Y | Confirms acceptance of the Cigent End User License Agreement. |
DATABACKEDUP=Y | Confirms that system data has been backed up before installation. |
In addition, one of the following credential configuration methods must be selected.
Initial Administrator Configuration
Cigent FDE provides three mutually exclusive methods for configuring the initial installation credentials.
Method | Parameters | Description |
Setup password | USER_PASSWORD | Specifies a setup password. The initial administrator account is created during the first restart. |
Default setup password | USE_DEFAULT_PASSWORD | Uses the default setup password. The initial administrator account is created during the first restart. |
Automatic administrator creation | USER_NAME, USER_CRED | Automatically creates the initial administrator account during installation, eliminating the need for administrator enrollment after the first restart. |
The optional USER_EMAIL parameter can also be provided when using automatic administrator creation.
Note: These installation methods are mutually exclusive. Do not combine the setup password methods with automatic administrator creation in the same installation command.
Optional MSI Parameters
The following parameters allow administrators to customize the deployment.
Parameter | Description |
OS_ONLY | Set to Y to encrypt only the Windows OS partition, or N to encrypt the OS and supported data partitions. |
LICENSE_FILE | Specifies the path to an FDE license file to use during installation. |
APPDIR | Specifies the Windows application installation directory. The default is C:\Program Files\Cigent\FDE. |
ENROLLCODE | Specifies an enrollment code for smart card self-enrollment. |
ENROLL_USAGE_LIMIT | Specifies the maximum number of times the enrollment code can be used. A value of 0 allows unlimited usage. |
ENROLL_EXPIRES_UTC | Optionally specifies the UTC expiration time of the enrollment code. |
When using smart card self-enrollment, both ENROLLCODE and ENROLL_USAGE_LIMIT must be supplied.
Example: Silent Installation with Smart Card Enrollment
The following example installs Cigent FDE, creates an administrator account, enables encryption of supported data partitions, and configures a smart card enrollment code.
msiexec /i "FDE_Installer_v1.2.1.19.msi" /qn ^
USER_NAME="cigent" USER_CRED="YourSecurePassword!" ^
OS_ONLY=N ACCEPT_EULA=Y DATABACKEDUP=Y ^
ENROLLCODE="YourEnrollmentCode!" ^
ENROLL_USAGE_LIMIT=10 ^
LICENSE_FILE="license.lic" ^
/l*v "fde_install.log"
This example permits the enrollment code to be used up to 10 times.
The enrollment code must be between 10 and 128 characters and meet the applicable password complexity requirements.
Completing Installation
A system restart is required after the MSI installation completes.
The behavior after restarting depends on the credential configuration method selected:
- Automatic administrator creation: The initial administrator account is already configured, and the user can authenticate using the credentials supplied during installation.
- Setup password installation: The FDE authentication setup page appears during the first restart, allowing the initial administrator account to be created.
After the initial setup is complete and Windows starts, Cigent FDE begins encrypting the selected partitions.
Encryption progress can be monitored using the Cigent FDE Windows application by opening the Status page.
Additional Notes
- Silent installation suppresses the installer interface but does not eliminate the required system restart.
- Administrator credentials and enrollment codes should be protected when used in deployment scripts or command-line parameters.
- If a license file is not provided, Cigent FDE automatically generates a 30-day trial license during installation.
- Cigent FDE currently supports encryption of the Windows OS drive and supported data partitions on that drive. Secondary physical drives are not supported.
For complete installation instructions and additional information about MSI parameters, refer to Section 3.5, Installing Cigent FDE Using MSI, in the Cigent FDE Installation Guide and User Manual, available from Cigent Support.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article