Automate post-image provisioning with SmartDeploy and PDQ Connect
Use SmartDeploy to image Windows devices, install the PDQ Connect Agent, trigger a baseline package, and track completion with registry-based dynamic groups.
Last updated: September 2, 2026 | Workflow status: Tested and working
Outcome: A newly imaged device enrolls in PDQ Connect, enters the Pending group, receives the required baseline packages, and moves to the Completed group after the Registry Scanner records the final state.
Before you continue
Make sure the following items are available before you enable the automation:
- A working SmartDeploy image, answer file, Platform Pack, and deployment method.
- Permission to create or edit SmartDeploy Application Packs and Answer File tasks.
- The Windows PDQ Connect Agent MSI downloaded from the correct organization or tenant.
- Permission in PDQ Connect to create scanners, groups, packages, automations, and deployments.
- Tested PDQ Connect packages for each application included in the post-image baseline.
- A non-production device for end-to-end validation.
Important: Do not install or enroll the PDQ Connect Agent in the SmartDeploy reference VM. This procedure installs the agent after imaging through a SmartDeploy Application Pack so each deployed device enrolls as a unique endpoint.
Workflow overview
SmartDeploy owns the imaging and initial agent installation. PDQ Connect owns application delivery, completion tracking, and dynamic group membership.
| State | BaselineRequired | BaselineVersion | Dynamic group |
|---|---|---|---|
| Newly imaged / pending | 1 | 0 | SmartDeploy Baseline - Pending |
| Baseline complete | 0 | 1 | SmartDeploy Baseline - Completed |
| Reimaged again | 1 | 0 | SmartDeploy Baseline - Pending |
Source of truth: BaselineRequired is the queue flag. A value of 1 means the baseline is pending. A value of 0 means the completion script finished successfully. SmartDeployReimage retains the most recent imaging timestamp.
Step 1: Download the PDQ Connect Agent installer
- In PDQ Connect, open Devices and select Install Agent.
- Select Download Windows Installer.
- Save the MSI in a dedicated folder that contains no unrelated files. The SmartDeploy Application Pack Wizard includes every file and subfolder in the selected folder.
- Confirm that the file name begins with PDQConnectAgent. You may change text after that prefix, but the installation fails if the required prefix is removed.
Note: The Windows Agent MSI is unique to its organization or tenant and expires after one year. Refresh the MSI used by SmartDeploy at least annually; installed agents update themselves.
Step 2: Create the PDQ Connect Agent Application Pack
Build a reusable SmartDeploy Application Pack for the organization-specific PDQ Connect Agent MSI. This keeps the agent out of the reference image and allows the same post-image installation method to be used across deployments.
For the complete SmartDeploy wizard walkthrough, see Create a Custom Application Pack.
Test the silent installation command
Before creating the pack, test the MSI on a lab device from an elevated command prompt. Replace the sample file path and version with the installer you downloaded:
msiexec.exe /i "C:\Path\PDQConnectAgent-X.X.X.msi" ALLUSERS=1 /qn /norestart /log "C:\Windows\Temp\PDQConnectAgent-install.log"Confirm that the installation finishes without user interaction and that the device appears in the correct PDQ Connect organization or tenant. Remove the test agent before repeating the pack test on the same device, when appropriate.
Build the Application Pack
- Open the SmartDeploy Web Console or desktop console and select Application Packs.
- Select Actions > Create.
- On the Welcome page, select Next.
- On Installation Files, select the dedicated folder that contains the Agent MSI. For Executable Path, select the PDQConnectAgent MSI, then select Next.
- On Details, confirm or enter the pack information. Use a clear title such as PDQ Connect Agent and confirm the publisher and version.
- On Installation Task, enable Quiet Installation, No Restart, and ALLUSERS. Review the command preview before continuing.
- On Installation Detection, confirm the MSI product code and version detected by the wizard.
- Review the Summary, select Next, then select Finish.
- Save the pack in the SmartDeploy Application Packs directory, such as \SmartDeploy\Application Packs\.
| Application Pack setting | Recommended value |
|---|---|
| Title | PDQ Connect Agent |
| Installer | Organization- or tenant-specific PDQConnectAgent-X.X.X.msi |
| Quiet installation | Enabled |
| No restart | Enabled |
| ALLUSERS | Enabled |
| Detection | MSI product code and version confirmed |
Important: The standard Application Pack Wizard adds product name and version filters automatically. A test deployment can report that the pack is not applicable when the same or a newer agent is already installed. Test the pack on a clean or appropriately prepared device.
Step 3: Add the Agent Application Pack to the answer file
- Create or edit the SmartDeploy answer file used for imaging.
- On the Application Packs page, select PDQ Connect Agent and use the right arrow to add it to the deployment list.
- Place the Agent Application Pack with the other post-image applications in the required installation order.
- Continue through the Answer File Wizard and save the answer file.
Note: This article uses an Application Pack for the PDQ Connect Agent. An Answer File task can also run the MSI silently, but the agent should not be installed or enrolled in the reference VM.
Step 4: Create the First Boot registry marker
Add a First boot as system task to the same answer file. The task creates the registry values that PDQ Connect uses to identify a newly imaged device.
- Open Advanced Options > Tasks and select Add.
- Set Phase to First boot as system.
- Paste the command below into Command line and select OK.
C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -Path 'HKLM:\SOFTWARE\PDQ' -Force; New-ItemProperty -Path 'HKLM:\SOFTWARE\PDQ' -Name 'SmartDeployReimage' -Value (Get-Date -Format 'yyyy-MM-ddTHH:mm:ss') -PropertyType String -Force; New-ItemProperty -Path 'HKLM:\SOFTWARE\PDQ' -Name 'BaselineRequired' -Value 1 -PropertyType DWord -Force; New-ItemProperty -Path 'HKLM:\SOFTWARE\PDQ' -Name 'BaselineVersion' -Value 0 -PropertyType DWord -Force"Why Sysnative is used: The tested SmartDeploy task started from a 32-bit process. Sysnative launches native 64-bit Windows PowerShell so the marker is written to HKLM\SOFTWARE\PDQ instead of the redirected WOW6432Node location.
| Registry value | Type | Initial data | Purpose |
|---|---|---|---|
| SmartDeployReimage | String | yyyy-MM-ddTHH:mm:ss | Records the most recent imaging time. |
| BaselineRequired | DWORD | 1 | Places the device in the Pending workflow. |
| BaselineVersion | DWORD | 0 | Indicates that no baseline version has completed. |
Media update: If the edited answer file is embedded in USB, ISO, WDS, or offline media, recreate or update that media before testing.
Step 5: Validate the deployed device
After SmartDeploy finishes, validate both the PDQ Connect Agent and the native registry marker before creating the automation target.
- Confirm that the device appears online in the expected PDQ Connect organization or tenant.
- On the device, run the following command from Command Prompt:
reg query "HKLM\SOFTWARE\PDQ" /reg:64The command should return SmartDeployReimage, BaselineRequired set to 0x1, and BaselineVersion set to 0x0.
Stop here if validation fails: Do not build the PDQ Connect groups around a key written under WOW6432Node. Correct the First Boot task and confirm the 64-bit query succeeds first.
Step 6: Create the PDQ Connect Registry Scanner
In PDQ Connect, open Tools > Scanners, create a scanner, and select Registry as the type.
| Setting | Value | Notes |
|---|---|---|
| Name | SmartDeploy Baseline Image | Identifies the scanner in Registry results. |
| Type | Registry | |
| Hive | HKEY_LOCAL_MACHINE | |
| Path | SOFTWARE\PDQ | Do not add a leading or trailing backslash. |
| Search subkeys | Off | The values are directly under the path. |
| Scope | Value | Key is not required for this workflow. |
| Match type | All | Returns every value under the path. |
Validated scanner path: Use only SOFTWARE\PDQ. Do not add SOFTWARE\WOW6432Node\PDQ unless you intentionally support an older 32-bit marker implementation.
- Save the scanner.
- Open the device, select Scan device, then go to Additional data > Registry.
Search for BaselineRequired or SOFTWARE\PDQ. The three marker values should appear under the native path.
Validate the agent context when needed
If the local registry query works but the scanner remains empty, run these commands from the device Commands tab in PDQ Connect:
whoami
reg query "HKLM\SOFTWARE\PDQ" /reg:64The output should identify nt authority\system and return all three registry values.
Step 7: Create the Pending dynamic group
Create a Windows dynamic group that includes only devices whose baseline is still required. Use exact equality instead of contains.
| Group setting | Value |
|---|---|
| Name | SmartDeploy Baseline - Pending |
| Type | Dynamic |
| OS | Windows |
| Connector | Data source | Field | Operator | Value |
|---|---|---|---|---|
| Registry | Name | equals | BaselineRequired | |
| AND | Registry | Value data | equals | 0x00000001 (1) |
| AND | Registry | Path | equals | SOFTWARE\PDQ |
Use equals, not contains: Connect displays DWORD data as hexadecimal plus decimal text. A Completed filter using contains 0 can also match 0x00000001 (1). Exact equality keeps Pending and Completed mutually exclusive.
Step 8: Create the baseline package
Create a PDQ Connect custom package named SmartDeploy Package Delivery. Add the application packages required on every newly imaged device as nested package steps.
| Order | Step | Purpose |
|---|---|---|
| 1..n | Nested application packages | Install the approved applications and configuration steps. |
| Last | Mark SmartDeploy Baseline Complete | Update and verify the registry state after all earlier steps succeed. |
Critical ordering rule: Keep the completion script as the final step, and configure the package so it does not run after a failed application step. Otherwise a partially provisioned device could be marked complete.
Add the completion PowerShell step
$Path = "HKLM:\SOFTWARE\PDQ"
# The SmartDeploy First Boot task must have created this key.
if (-not (Test-Path $Path)) {
throw "Registry path $Path does not exist. Baseline status cannot be updated."
}
# Mark baseline version 1 as complete.
Set-ItemProperty `
-Path $Path `
-Name "BaselineRequired" `
-Value 0 `
-ErrorAction Stop
Set-ItemProperty `
-Path $Path `
-Name "BaselineVersion" `
-Value 1 `
-ErrorAction Stop
# Read the final state and write useful deployment output.
$Result = Get-ItemProperty -Path $Path -ErrorAction Stop
Write-Output "SmartDeploy baseline update completed."
Write-Output "SmartDeployReimage : $($Result.SmartDeployReimage)"
Write-Output "BaselineRequired : $($Result.BaselineRequired)"
Write-Output "BaselineVersion : $($Result.BaselineVersion)"
# Fail the package if the expected values were not written.
if ($Result.BaselineRequired -ne 0) {
throw "BaselineRequired was not successfully changed to 0."
}
if ($Result.BaselineVersion -ne 1) {
throw "BaselineVersion was not successfully changed to 1."
}
Write-Output "Baseline registry verification successful."Step 9: Create the automation
Open Automations and create an automation with the following settings:
| Setting | Value |
|---|---|
| Name | SmartDeploy Baseline Deployment |
| Package | SmartDeploy Package Delivery |
| Deploy to | SmartDeploy Baseline - Pending |
| Initial validation trigger | Manual or a controlled test trigger |
| Production trigger | A recurring schedule appropriate to the environment |
Timing recommendation: Choose a recurrence longer than the expected package run plus the inventory refresh delay. A device remains in Pending until Connect records BaselineRequired=0, so an aggressive schedule can start duplicate deployments.
Step 10: Create the Completed dynamic group
Create a second Windows dynamic group that identifies devices whose completion script has finished.
| Group setting | Value |
|---|---|
| Name | SmartDeploy Baseline - Completed |
| Type | Dynamic |
| OS | Windows |
| Connector | Data source | Field | Operator | Value |
|---|---|---|---|---|
| Registry | Name | equals | BaselineRequired | |
| AND | Registry | Value data | equals | 0x00000000 (0) |
| AND | Registry | Path | equals | SOFTWARE\PDQ |
BaselineVersion remains available for reporting and future version-specific groups. The validated Completed group uses BaselineRequired as the primary state flag.
Step 11: Validate the complete workflow
- Deploy the SmartDeploy image and answer file to one test device.
- Confirm the PDQ Connect Agent installs through the Application Pack and the device appears online in the correct organization or tenant.
- Confirm HKLM\SOFTWARE\PDQ contains SmartDeployReimage, BaselineRequired=1, and BaselineVersion=0.
- Run Scan device and confirm the Registry Scanner returns all three values.
- Confirm the device enters SmartDeploy Baseline - Pending.
- Run or allow SmartDeploy Baseline Deployment to start.
- Confirm every nested application step completes successfully.
- Confirm the final PowerShell output reports BaselineRequired=0 and BaselineVersion=1.
- Run Scan device again when necessary.
- Confirm the device leaves Pending and enters SmartDeploy Baseline - Completed.
- Confirm the expected applications and settings are present on the device.
| Check | Pass condition |
|---|---|
| Agent installation | The device appears online in the correct Connect organization or tenant. |
| SmartDeploy marker | HKLM\SOFTWARE\PDQ contains all three expected values. |
| Pending state | The device enters Pending only when BaselineRequired equals 0x00000001 (1). |
| Package execution | All nested application steps and the completion step return success. |
| Completion state | BaselineRequired equals 0 and BaselineVersion equals 1 locally and in Connect. |
| Group transition | The device leaves Pending and enters Completed after inventory refresh. |
| Reimage reset | A later reimage resets Required=1 and Version=0 and starts the workflow again. |
Monitoring and logs
Deployment output
Open Deployments, select the Complete or Failed count for the deployment, and open View Output for the device. The final PowerShell step writes the three registry values to this output, which is the primary place to confirm success or diagnose a script failure.
- Use Export log to save the full deployment output when escalating a failure.
- The Deployed by column identifies the automation that started the deployment.
Device inventory and commands
- Device > Additional data > Registry shows the last Registry Scanner result stored by Connect.
- Device > Commands can run whoami and the 64-bit reg query to prove LocalSystem access.
- Use Scan device when testing a state change instead of restarting the agent service.
Local diagnostic logs
For agent or scanner failures, review Event Viewer > Applications and Services Logs > PDQ.com. The Agent installation log from the sample command is stored at C:\Windows\Temp\PDQConnectAgent-install.log. Additional Connect Agent data is located under C:\ProgramData\PDQ\PDQConnectAgent.
Troubleshooting
| Symptom | Likely cause | Corrective action |
|---|---|---|
| Agent Application Pack fails | The MSI name was changed, the embedded token expired, or the silent command is incorrect. | Use a current installer whose name begins with PDQConnectAgent; retest the silent MSI command and review the install log. |
| Device enrolls in the wrong organization or tenant | The MSI came from a different Connect organization or tenant. | Download a new installer from the intended tenant and rebuild the Application Pack. |
| Application Pack is not applicable | The wizard detection filter found the same or a newer agent version. | Test on a clean device or review the generated product/version filters. |
| Registry key is under WOW6432Node | The First Boot task used 32-bit PowerShell. | Use the tested Sysnative command and validate with /reg:64. |
| Sysnative cannot be found | The task host is already a native 64-bit process. | Replace Sysnative with System32, rerun the task, and verify the native key. |
| Local query works but the scanner is empty | The scanner path, scan timing, or agent context is wrong. | Use only SOFTWARE\PDQ with no trailing slash, save, run Scan device, and test through Connect Commands as SYSTEM. |
| Pending and Completed contain the same device | The filter uses contains instead of equals. | Use the exact DWORD strings 0x00000001 (1) and 0x00000000 (0). |
| Deployment succeeds but the device stays Pending | Connect has not scanned the new local value yet. | Confirm BaselineRequired is 0 locally, then run Scan device. |
| Device is marked complete after an application failure | The completion script ran after a failed step. | Keep the completion step last and stop the package when an earlier step fails. |
| Automation deploys more than once | The automation recurred before group membership refreshed. | Increase the recurrence interval and keep application steps safe to rerun. |
Escalation boundary: If Connect Commands running as nt authority\system can read all three values but the single-path scanner still returns no rows after Scan device, collect the PDQ.com event log and deployment output for a support case.
Maintenance and baseline versioning
| Change | Required action |
|---|---|
| Refresh the PDQ Connect Agent installer | Download a new organization- or tenant-specific MSI, rebuild or update the Application Pack, and test it. Do this at least once per year. |
| Add or replace baseline applications | Update and test SmartDeploy Package Delivery. |
| Release baseline version 2 | Change the completion script so BaselineVersion is set to 2. |
| Retain reimage behavior | Keep the First Boot task setting BaselineRequired=1 and BaselineVersion=0. |
| Retry a device without reimaging | Reset the two state values, then run Scan device. |
| Pause the workflow | Disable the automation. The scanner and dynamic groups can remain in place. |
Manual retry script
$Path = "HKLM:\SOFTWARE\PDQ"
Set-ItemProperty -Path $Path -Name "BaselineRequired" -Value 1 -ErrorAction Stop
Set-ItemProperty -Path $Path -Name "BaselineVersion" -Value 0 -ErrorAction Stop
Get-ItemProperty -Path $Path -Name SmartDeployReimage, BaselineRequired, BaselineVersionAfter running the retry script, request a new device scan so the endpoint can re-enter Pending.