Skip to main content

Overview

The Formal Endpoint for Windows ships as an MSI installer. It installs the formal CLI and the Endpoint’s background agent, and adds a Formal shortcut to the Start menu. On Windows, the Endpoint connects you to Resources through local listeners with formal connect. Transparent Mode and network rules are not available on Windows yet.

Prerequisites

  • 64-bit Windows on an x86-64 (amd64) processor. There is no Arm64 package.
  • Administrator rights. The MSI installs for all users of the machine.
  • Windows Hello set up with a fingerprint, face, or PIN, if your policies use the MFA action.

Install

1

Download the installer

In the Control Plane, click Download Formal Endpoint at the bottom of the sidebar, then choose Windows. You can also download the latest MSI directly:
2

Run the installer

Open the MSI and follow the installer. To install silently, run this from an elevated command prompt:
The installer puts formal.exe under Program Files\Formal and adds that folder to the system PATH.
3

Start the Endpoint

Open the Start menu and select Formal. The shortcut starts the Endpoint agent in the background.
4

Sign in

Open a new terminal so it picks up the updated PATH, then sign in:
A browser window opens for Formal sign-in.

Verify

formal auth whoami shows your Formal user. formal ls lists the Resources available to you. Connect to one with formal connect <resource-name>. See the CLI reference.

Upgrade

The Endpoint can’t upgrade itself on Windows, and formal upgrade reports that it isn’t supported. To move to a new version:
  1. Uninstall Formal from the Apps section of Windows Settings.
  2. Install the new MSI.
Uninstall the current version before you install a new one. Installing a new MSI over an existing install registers a second copy of Formal, and uninstalling either copy later leaves the other’s files behind.

Deploy to a Fleet

Deploy the MSI with your Windows device management tool, such as Microsoft Intune, as a standard Windows app. Use the silent install command above. The MDM Endpoint Rollout files in the Control Plane are for macOS.

Files and Logs

Troubleshooting

Cause: The terminal started before the installer updated PATH. Fix: Open a new terminal. If the problem persists, sign out of Windows and back in.
Cause: The Endpoint agent isn’t running. Fix: Start Formal from the Start menu, then retry the command.
Cause: Windows Hello isn’t set up, or you’re connected over Remote Desktop, where Windows Hello is unavailable. Fix: Set up Windows Hello on the device and sign in locally.

Next Steps

Formal Endpoint

Review authentication and connection options

CLI Reference

Connect to Resources from the terminal