---
title: "Prerequisites for ControlUp for Desktops"
slug: "prerequisites-for-controlup-for-desktops"
updated: 2026-05-29T13:56:23Z
published: 2026-05-29T13:56:23Z
canonical: "support.controlup.com/prerequisites-for-controlup-for-desktops"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.controlup.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Prerequisites for ControlUp for Desktops

Important

Read this article and make sure you meet the prerequisites **before** you deploy ControlUp for Desktops.

This article covers the prerequisites for implementing ControlUp for Desktops. For prerequisites for other ControlUp products, visit the following articles:

- [ControlUp Synthetic Monitoring communication requirements](/tim-reorg/docs/networking-requirements)
- [ControlUp for VDI communication ports (US Region)](/tim-reorg/docs/communication-ports-used-by-controlup-hybrid-cloud-us-customers)
- [ControlUp for VDI communication ports (EU Region)](/tim-reorg/docs/communication-ports-used-by-controlup-hybrid-cloud-eu-customers)

## Network tester tool

You can download and run the [ControlUp Tester tool](/v1/docs/how-to-check-network-connectivity-to-controlup-cloud-services) to verify that all required URLs are accessible.

## Network requirements

Tenant name

Some of these URLs require you to enter your tenant name. To find your tenant name, go to **Devices > Configuration > Downloads**. ![AccessAgentDownloadsPage.png](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/AccessAgentDownloadsPage%281%29.png)

Managed physical endpoints must have access to these URLs:

| URL | Type | Notes |
| --- | --- | --- |
| <tenant-name>.sip.controlup.com | HTTPS and WSS over port 443 (SSL) | The ControlUp for Desktops Agent connects to WSS (secure websocket) on the tenant for Remote Control, Remote Shadow, and Remote Shell using the configured proxy. If you use domain-based firewall rules, you might need to add an extra URL. [Read below for details](/v1/docs/prerequisites-for-controlup-for-desktops#requirement-for-domainbased-firewall-rules). |
| downloads.sip.controlup.com | HTTPS over port 443 (SSL) | Used for downloading ControlUp for Desktops Agent versions and ControlUp for Apps browser extensions. |
| Depending on your region: **US** agentblobeastus.blob.core.windows.net **EU** agentblobwesteurope.blob.core.windows.net **Canada** agentblobcanadacentral.blob.core.windows.net | HTTPS over port 443 (SSL) | Required for downloading/uploading files using the [file browser](/v1/docs/file-browser), and importing/exporting registry files using the [registry editor](/v1/docs/registry-editor). |
| cdn.spm.controlup.com/waapi | HTTPS over port 443 (SSL) | Required only for [ControlUp for Compliance](https://support.controlup.com/docs/secure-dx-overview) |
| cdn.spm.controlup.com/agent | HTTPS over port 443 (SSL) | Required only for [ControlUp for Compliance](https://support.controlup.com/docs/secure-dx-overview) |
| securedx-cdn.controlup.com | HTTPS over port 443 (SSL) | Required only for [ControlUp for Compliance](https://support.controlup.com/docs/secure-dx-overview) |
| **For Google Chrome**: https://edgedx.blob.core.windows.net/artifacts /appdx/latest/appdx_chrome.crx https://downloads.sip.controlup.com/appdx /latest/appdx_chrome.xml **For Microsoft Edge or Island**: https://edgedx.blob.core.windows.net/artifacts /appdx/latest/appdx_edge.crx https://downloads.sip.controlup.com/appdx /latest/appdx_edge.xml | HTTPS over port 443 (SSL) | Required for deploying the [ControlUp for Apps](/v1/docs/controlup-for-apps-overview) browser extensions **from our CDN**. |
| **For Google Chrome or Island**: https://clients2.google.com/service/update2/crx **For Microsoft Edge**: https://edge.microsoft.com/extensionwebstorebase/v1/crx | HTTPS over port 443 (SSL) | Required for deploying the [ControlUp for Apps](/v1/docs/controlup-for-apps-overview) browser extensions **from the web stores**. |

To use the ControlUp application in your browser, you must have access to the these URLs:

| URL | Type | Notes |
| --- | --- | --- |
| <tenant-name>.sip.controlup.com | HTTPS and WSS over port 443 (SSL) | WSS (secure websocket) connection to the tenant is required for Remote Control, Remote Shadow, and Remote Shell. |
| app.controlup.com | HTTPS over port 443 (SSL) |  |
| google.com/recaptcha | HTTPS over port 443 (SSL) | Used for authentication (reCAPTCHA) |
| gstatic.com/recaptcha | HTTPS over port 443 (SSL) | Used for authentication (reCAPTCHA) |
| maps.google.com | HTTPS over port 443 (SSL) |  |
| edgedx-functions.azurewebsites.net | HTTPS over port 443 (SSL) | Required only for the first time you sign in to your environment and create your tenant. |
| https://prod-dex-login-eastus.controlup.com (for US region) or https://prod-dex-login-westeurope.controlup.com (for EU region) | HTTPS over port 443 (SSL) | Required only for SAML SSO |
| https://employee-cdn-prod.controlup.com | HTTPS over port 443 (SSL) | Required to access the [Employees dashboards](/v1/docs/employees-view-overview) |

### Requirement for domain-based firewall rules

Your tenant URL is normally in the format: `&lt;tenant-name&gt;.sip.controlup.com`. This is a CNAME record pointing to an Azure domain which can point to a Load Balancer or your ControlUp tenant directly. If you use domain-based firewall rules, you might also need to allow your access to the intermediary CNAME domain. To find it, run an nslookup on `&lt;tenant-name&gt;.sip.controlup.com`.

![LoadBalancerURL.png](https://cdn.document360.io/098100b7-b9da-4bea-b4b9-017140ab863e/Images/Documentation/LoadBalancerURL.png)

### SSL inspection

If you have a proxy or firewall performing SSL inspection, you must have the trusted certificate installed on devices with the ControlUp for Desktops Agent installed. The certificate must be accessible to the Computer account (and not only the User account).

Alternatively, you can disable SSL inspection for your tenant URL (<tenant-name>.sip.controlup.com).

### Proxy server

You can configure the ControlUp for Desktops Agent to use a proxy server during Agent installation.

If your proxy is only open when a user account is signed in, and you want to monitor the device when no user account is signed in, configure your proxy to bypass the following URLs:

- <tenant-name>.sip.controlup.com
- downloads.sip.controlup.com

### ZScaler VPN

If you are using a ZScaler VPN, follow the instructions in [this article](/tim-reorg/docs/show-the-real-ip-address-for-devices-using-zscaler-vpn) to ensure that you can see the real IP addresses of your devices.

## Antivirus exclusions

Whitelist the following directories in your antivirus software (including next-gen security products such as Crowdstrike, Carbon Black, etc.):

```
C:\Program Files\Avacee\sip_agent\
C:\ProgramData\Avacee\sip_agent\scripts
C:\Program Files\ControlUp\AgentManager
C:\ProgramData\ControlUp\EdgeDx\UserSurveys
```

Alternatively, if you are unable to whitelist directories, you can whitelist the following executables:

```
C:\Program Files\Avacee\sip_agent\SIPAgent.exe
C:\Program Files\Avacee\sip_agent\RCNotifications.exe
C:\Program Files\Avacee\sip_agent\UserPrompt.exe
C:\Program Files\Avacee\sip_agent\WinFocusMonitor.exe
C:\Program Files\Avacee\sip_agent\Wow64MIHelper.exe
C:\Program Files\Avacee\sip_agent\Survey.exe
C:\Program Files\Avacee\sip_agent\SentimentUI.exe
C:\Program Files\Avacee\sip_agent\cu_rc.exe
C:\Program Files\Avacee\sip_agent\hookldr.exe
C:\Program Files\ControlUp\AgentManager\AgentManager.exe
```
