ITAI

Help

Installer troubleshooting

The same page as Help in the ITAI dashboard.

Windows warnings, antivirus, firewalls, a PC that never appears, reinstalling and uninstalling.

What the installer needs

  • A Windows PC or server, and someone who can approve the "allow this app to make changes" box as an administrator.
  • Python 3.10 or newer for all users. You do not need to install it first: if it is missing the installer asks (press Enter for Yes), or installs it without asking when nobody is at the PC to answer, as when an RMM tool runs it as SYSTEM.
  • A way to reach ITAI over HTTPS. The PC only connects outward, so no inbound firewall ports are needed. See Firewall and proxy.

Windows says "Windows protected your PC" or "Unknown publisher"

ITAI's installer is not code-signed yet, so Windows (its SmartScreen filter) cannot confirm who published it. The warnings are expected and go away once the installer is signed.

  • Browser warning ("isn't commonly downloaded" or "could harm your device"): choose Keep. In Edge, use the ... menu beside the download, then Keep. If Edge asks again, click Show more, then Keep anyway.
  • Blue box "Windows protected your PC": click More info, check the file name starts with Install-ITAI (or Install ITAI for the file inside the zip), then click Run anyway.
  • "The publisher could not be verified": click Run.
  • Blocked with no way to run it (some work PCs, or Windows 11 with Smart App Control on): use the install command under For IT pros on the Install page, run in PowerShell opened as administrator, or ask your IT contact. Do not turn security features off to get past it.

If the file name does not start with those words, or you did not expect the file, do not run it.

Antivirus or endpoint protection removes or blocks it

Signs: the file vanishes from Downloads, will not open, or a security product reports a threat.

  • The installer is not code-signed, and its first step starts Windows PowerShell with the execution policy bypassed, then runs the installer script in memory after checking that script's fingerprint (SHA-256) against the one issued with your file. Some security products treat that pattern as suspicious.
  • Ask whoever manages the product to allow the installer file by name. Do not switch protection off.
  • If protection removes files from C:\ProgramData\ITAIReceiver after the install, the PC will stop checking in. Allow that folder, then run the installer again.
  • IT staff can use the install command from the Install page instead of the file. See Reinstalling.

Firewall and proxy

ITAI only makes outbound HTTPS (port 443) connections. Nothing needs to reach into the PC. These addresses are used:

AddressUsed forWhen
api.itaibot.ioDownloading the installer script and ITAI on the PC, then every check-in afterwardsAlways. The exact address your installer uses is the -BackendUrl value in the install command on the Install page.
winget's own addresses (set by Microsoft)Installing PythonOnly when Python is missing and winget works
www.python.orgPython's official installer, checked by hash and signature before it runsOnly when Python is missing and winget is absent or fails
pypi.org and files.pythonhosted.orgThe libraries ITAI on the PC needs, each checked against a fixed hashEvery install and reinstall
  • The install runs as an administrator and the service runs as SYSTEM, so a proxy setting that belongs to one signed-in person does not apply to them. The simplest fix is to allow the addresses above without a proxy sign-in.
  • The library download deliberately ignores pip's configuration files, so it needs to reach pypi.org directly or through the HTTPS_PROXY environment variable.
  • A firewall or proxy that answers with its own page can make ITAI on the PC log a refusal that is really the proxy talking. Check the address first.
  • Check the PC's date and time. An expired-looking installer on a PC with a wrong clock is a common cause: the installer says so, and says nothing was installed.

What the installer's messages mean

It saysWhat it means and what to do
This installer has expiredInstallers work for 7 days after they are downloaded, or until an admin clicks Stop old installers. Nothing was installed. Download a fresh one. If the PC's date is wrong, correct it first.
The ITAI dashboard did not accept this installer's keyThe key was replaced (rotated) or the file is too old. Download a fresh installer from the Install page.
This PC could not reach ITAINo route to the address in the table above. Check the internet connection, firewall and proxy, then run the installer again.
The installer downloaded from ITAI is not the one this file expectsITAI has been updated since the file was made, so the installer refused to run it and installed nothing. Download a fresh file.
This installer file is damaged or incompleteA download cut short or a changed file. Nothing ran. Download it again.
Windows did not give this installer administrator rightsSign in with an administrator account of the PC, or ask your IT contact, then run it again.
The administrator window closed before it could install ITAICopy the file to the Desktop or Documents folder (not a network drive or a zip) and double-click it there.
ITAI was NOT installedRead the line "What went wrong" and the advice under it. ITAI's own files and service are put back as they were (Python stays installed if the installer added it). Run the file again; if it fails the same way, send a photo of the window to whoever gave you the installer.
ITAI was installed but its service is not running yetRestart the PC. If the PC still does not appear in ITAI after that, see the next section.

The PC never appears in Devices

Work down this list. Most cases end at one of the first four.

  1. Did the install window end with "Done. ITAI is installed and running"? If not, find its message above. A PC appears within a minute of that line.
  2. Is it in the right place? A PC joins the organization whose installer it ran. Check the client filter on Devices, and the Retired and Pending tabs: a PC enrolled while your account's payment was past due waits under Pending until it is paid.
  3. On the Install page, open For IT pros, then Recent enrollments. It lists the hostname, time and address of each PC that enrolled in the last 30 days. If the PC is there, it reached ITAI.
  4. Two PCs with the same name in one organization: ITAI keeps both records apart and says so on the device page. Rename one PC in Windows.
  5. On the PC, open Services and look for ITAI Diagnostic Receiver (service name ITAIReceiver). It should be Running and set to Automatic. If it is stopped, start it and watch whether it stays up.
  6. On the PC, read C:\ProgramData\ITAIReceiver\logs\receiver.log (the default install folder). It says whether the PC reached ITAI and whether ITAI refused its key.
  7. The key may have changed. If the log says the key was refused, download a fresh installer from the Install page and run it.
  8. A PC that was reinstalled without its saved state can be refused as "already enrolled". An Admin opens that PC's page in Devices and clicks Reset credential; the PC enrolls again by itself on its next attempt.
  9. Still nothing: email support@itaibot.io with the hostname, the time you ran the installer and the last lines of receiver.log. Failed installs also keep the receiver's log in C:\ProgramData\ITAIReceiver-install-logs.

Reinstalling

  • Running the installer again on a PC that already has ITAI upgrades it. The PC is never left without a working ITAI: the new copy is checked before the old one stops, and a failure puts the old one back, running.
  • Use a fresh installer. An old file stops working after 7 days.
  • ITAI's program on your PCs updates itself in stages. The updates section of Company settings sets the channel (Stable or Early) and the hours PCs may update in. A PC never restarts the program in the middle of a diagnosis or a fix.
  • A PC that was reset or retired for going silent needs a fresh installer run on it. Restoring the record in Devices alone does not put ITAI back on the PC.
  • After an uninstall from the dashboard, run the Install page's installer or command on that PC again.
  • IT staff can run the install command in PowerShell opened as administrator, push the installer file with /S for a silent install (exit code 0 means installed), or use a computer startup script. The Install page has the details under For IT pros.

Uninstalling

Either way the service and its install folder are removed, and the entry in Windows' app list goes with them.

  1. From the dashboard (Admin or Superadmin): open the PC in Devices, click Uninstall, and type the PC's name to confirm. It also retires the device. The uninstall runs the next time the PC checks in, usually within a minute. If the PC stays off for more than an hour, ITAI gives up waiting: when it is back, check the device page and click Uninstall again if ITAI is still there. If it does not show up again, uninstall it on the PC itself (below).
  2. On the PC itself, for example when it has changed hands: sign in as an administrator, open Settings, Apps, Installed apps, find ITAI Receiver and click Uninstall.

Retire is different: it only takes the PC out of your list and stops new tickets and the device fee for it. ITAI stays installed. Restore it any time.