Browse Troubleshooting
- Dashboard overview
- Insights overview
- Sites Overview - Network Deployments
- Policies Overview - Create and Edit
- Custom Lists overview
- Clients Overview - Device Agents and Profiles
- Users Overview - Directory Users and Personas
- Organizations Overview - MSP Tenant Management
- Lookup Tool Overview
- Query Log Overview
- Settings Overview - Account Administration
- Help & Support Overview
- Signing In - Login, 2FA, and Password Reset
- Two-factor authentication (2FA)
- Add system users (role-based access)
- Check domain classification with the Lookup Tool
- Configurable objects and their associations
- Configure notifications
- Working with organizations (multi-tenant)
- Working with policies
- Content categories
- Security categories
- Application categories (Zero Trust app management)
- Working with allow and block lists
- Zero Trust TLD Filters
- Safe Search explained
- Safe Search supported search engines
- YouTube Restricted Mode explained
- Custom block pages
- Prevent DNS bypass
- Don't mix DNS providers
- Active Directory group policies
- Entra ID group policies
- Tracking individual users
Client download link not working
If the device-agent installer download fails with a 404, a broken file, or stops mid-download, here are the common causes and how to fix each.
If the installer download from an install key returns a 404, an empty file, or a corrupted installer, work through the checks below.
Verify the key is still valid
The installer isn’t tied to the key, but registration is. If the agent installs and the device never shows up under Manage Clients, check the key’s duration and install cap.
- Open the profile in the Admin Console.
- Find the key under the Install Keys list.
- Confirm Duration has not lapsed and Installs remaining is greater than zero.
If either is expired, edit the key to extend the duration or raise the install cap. Also confirm the device was installed with the install command from the key, since the installer file doesn’t contain the key. See Roaming clients (device agents) for key configuration details.
[!NOTE] Already-installed agents are not affected by deleting or rotating a key. Keys are only consumed during initial registration.
Check your browser
Browsers occasionally interfere with installer downloads:
- Ad blockers / privacy extensions can block
.msior.pkgdownloads. Allow the download host shown in the key’s URL and retry. - Safe Browsing / SmartScreen may flag the file as “uncommonly downloaded.” The file is signed; choose Keep to complete the save.
- Corporate proxy / WAF may rewrite or strip the download. Try downloading from a network that doesn’t transit the proxy as a test.
Confirm the right installer
Each key points to a platform-specific installer:
| Platform | File | Common confusion |
|---|---|---|
| Windows x64 | .msi |
Don’t run on macOS |
| Windows x86 | .msi |
Only for legacy 32-bit Windows |
| macOS Intel (x86) | .pkg |
Don’t run on Apple Silicon |
| macOS Apple Silicon (ARM) | .pkg |
Don’t run on Intel Macs |
A mismatched platform won’t install. If you need to support both Intel and Apple Silicon Macs, generate one key per architecture.
Still stuck?
If the download keeps failing on a clean browser and from a network with no proxy in front, contact support with:
- The profile name
- The install key ID (visible in the Install Keys list)
- A screenshot of the error or the network request from your browser’s developer tools