# Update Agents Automatically

> Turn on agent self-update for an agent configuration group so agents install new PerformanceGuard agent versions without manual deployment.

Source: https://docs.capaone.com/performanceguard/installation/install-performanceguard-agents/update-agents-automatically/  
Product: PerformanceGuard — a separate CapaSystems product; do not apply this page to any other.

You can let PerformanceGuard agents update themselves when a new agent version is released. You turn on self-update per agent configuration group, so you can test it on a small group of computers first.

:::note[Before you start]
- You need the PerformanceGuard administrator role.
- The agents must be version 8.2 or newer. Older agents don't include the updater. Upgrade them once by hand, see [Agent Upgrade](/performanceguard/installation/install-performanceguard-agents/agent-upgrade/).
- The computers must have Microsoft .NET Framework 4.6.1 or newer.
- The computers need outbound HTTPS access (TCP port 443) to `api.capaone.com`, where the agent checks for and downloads new versions.
:::

## Turn on self-update

1. In the PerformanceGuard web interface, select **Administration → Agent configuration → Configurations**.
2. Select **Edit** next to the agent configuration group you want to update automatically.
3. In the **Agent Updater** section, select **Enable Agent self-update using CapaOne (requires agent internet access)**.
4. Select **Save Configuration**.

The agents in the group turn on their updater the next time they receive their configuration from the server. The agents then check for a new version each time the computer starts. To turn self-update off again, clear the check box and save.

## How an update runs

The agent installation adds a scheduled task to Windows Task Scheduler. For the standard agent, it's called **Capa_pga_AgentUpdater**. It runs when the computer starts and starts the agent's updater service, **pga_updater**.

Each time the updater runs, it does the following:

1. It stops at once if self-update is turned off for the agent's configuration group.
2. It checks the latest released agent version for the computer's architecture, 32-bit or 64-bit.
3. If the installed agent is already the latest version, it stops.
4. It downloads the new installer and checks that the file is digitally signed and that its checksum matches. If either check fails, it doesn't install the file.
5. It waits up to 10 minutes if another Windows Installer installation is running.
6. It installs the new version silently, as an upgrade of the installed agent. The agent keeps its agent ID.
7. It checks that the agent service is running after the installation. If the installation failed, it reinstalls the previous agent version.

## Run an update now

You don't have to wait for the schedule. On a computer where self-update is turned on:

1. Open Task Scheduler.
2. Find the **Capa_pga_AgentUpdater** task.
3. Right-click the task and select **Run**.

## Check the result

- In the PerformanceGuard web interface, search for the computer and check **Agent Version** in its computer information. See [Computer Info](/performanceguard/analyze/computer-search/computer-info/).
- On the computer, the updater writes an installation log for each update to the `updater` folder in the agent installation folder, by default `C:\Program Files\PerformanceGuard\Agent\updater`. The log files are named `install-<date>.log`. If the updater had to reinstall the previous version, it also writes `rollback-<date>.log`.

## Update agents without self-update

If your computers can't reach the internet, deploy new agent versions with your software distribution tool. You can download the latest agent installer from the PerformanceGuard web interface, see [Download/Install Latest Agent from PerformanceGuard](/performanceguard/installation/install-performanceguard-agents/download-install-latest-agent-from-performanceguard/).
