Overview
The Formal Endpoint for Windows ships as an MSI installer. It installs theformal CLI and the Endpoint’s background agent, and adds a Formal shortcut to the Start menu.
On Windows, the Endpoint connects you to Resources through local listeners with formal connect. Transparent Mode and network rules are not available on Windows yet.
Prerequisites
- 64-bit Windows on an x86-64 (amd64) processor. There is no Arm64 package.
- Administrator rights. The MSI installs for all users of the machine.
- Windows Hello set up with a fingerprint, face, or PIN, if your policies use the MFA action.
Install
1
Download the installer
In the Control Plane, click Download Formal Endpoint at the bottom of the sidebar, then choose Windows. You can also download the latest MSI directly:
2
Run the installer
Open the MSI and follow the installer. To install silently, run this from an elevated command prompt:The installer puts
formal.exe under Program Files\Formal and adds that folder to the system PATH.3
Start the Endpoint
Open the Start menu and select Formal. The shortcut starts the Endpoint agent in the background.
4
Sign in
Open a new terminal so it picks up the updated A browser window opens for Formal sign-in.
PATH, then sign in:Verify
formal auth whoami shows your Formal user. formal ls lists the Resources available to you. Connect to one with formal connect <resource-name>. See the CLI reference.
Upgrade
The Endpoint can’t upgrade itself on Windows, andformal upgrade reports that it isn’t supported. To move to a new version:
- Uninstall Formal from the Apps section of Windows Settings.
- Install the new MSI.
Deploy to a Fleet
Deploy the MSI with your Windows device management tool, such as Microsoft Intune, as a standard Windows app. Use the silent install command above. The MDM Endpoint Rollout files in the Control Plane are for macOS.Files and Logs
Troubleshooting
formal is not recognized as a command
formal is not recognized as a command
Cause: The terminal started before the installer updated
PATH. Fix: Open a new terminal. If the problem persists, sign out of Windows and back in.The CLI cannot connect to the Formal app
The CLI cannot connect to the Formal app
Cause: The Endpoint agent isn’t running. Fix: Start Formal from the Start menu, then retry the command.
MFA prompts fail
MFA prompts fail
Cause: Windows Hello isn’t set up, or you’re connected over Remote Desktop, where Windows Hello is unavailable. Fix: Set up Windows Hello on the device and sign in locally.
Next Steps
Formal Endpoint
Review authentication and connection options
CLI Reference
Connect to Resources from the terminal