Automate post-image provisioning with SmartDeploy and PDQ Connect

Use SmartDeploy to image Windows devices, install the PDQ Connect Agent, trigger a baseline package, and track completion with registry-based dynamic groups.

Last updated: September 2, 2026 | Workflow status: Tested and working

Outcome: A newly imaged device enrolls in PDQ Connect, enters the Pending group, receives the required baseline packages, and moves to the Completed group after the Registry Scanner records the final state.

Before you continue

Make sure the following items are available before you enable the automation:

  • A working SmartDeploy image, answer file, Platform Pack, and deployment method.
  • Permission to create or edit SmartDeploy Application Packs and Answer File tasks.
  • The Windows PDQ Connect Agent MSI downloaded from the correct organization or tenant.
  • Permission in PDQ Connect to create scanners, groups, packages, automations, and deployments.
  • Tested PDQ Connect packages for each application included in the post-image baseline.
  • A non-production device for end-to-end validation.

Important: Do not install or enroll the PDQ Connect Agent in the SmartDeploy reference VM. This procedure installs the agent after imaging through a SmartDeploy Application Pack so each deployed device enrolls as a unique endpoint.

Workflow overview

SmartDeploy owns the imaging and initial agent installation. PDQ Connect owns application delivery, completion tracking, and dynamic group membership.

01-end-to-end-provisioning-flow.png
State BaselineRequired BaselineVersion Dynamic group
Newly imaged / pending 1 0 SmartDeploy Baseline - Pending
Baseline complete 0 1 SmartDeploy Baseline - Completed
Reimaged again 1 0 SmartDeploy Baseline - Pending

Source of truth: BaselineRequired is the queue flag. A value of 1 means the baseline is pending. A value of 0 means the completion script finished successfully. SmartDeployReimage retains the most recent imaging timestamp.

Step 1: Download the PDQ Connect Agent installer

  1. In PDQ Connect, open Devices and select Install Agent.
  2. Select Download Windows Installer.
  3. Save the MSI in a dedicated folder that contains no unrelated files. The SmartDeploy Application Pack Wizard includes every file and subfolder in the selected folder.
  4. Confirm that the file name begins with PDQConnectAgent. You may change text after that prefix, but the installation fails if the required prefix is removed.

Note: The Windows Agent MSI is unique to its organization or tenant and expires after one year. Refresh the MSI used by SmartDeploy at least annually; installed agents update themselves.

Step 2: Create the PDQ Connect Agent Application Pack

Build a reusable SmartDeploy Application Pack for the organization-specific PDQ Connect Agent MSI. This keeps the agent out of the reference image and allows the same post-image installation method to be used across deployments.

For the complete SmartDeploy wizard walkthrough, see Create a Custom Application Pack.

Test the silent installation command

Before creating the pack, test the MSI on a lab device from an elevated command prompt. Replace the sample file path and version with the installer you downloaded:

msiexec.exe /i "C:\Path\PDQConnectAgent-X.X.X.msi" ALLUSERS=1 /qn /norestart /log "C:\Windows\Temp\PDQConnectAgent-install.log"

Confirm that the installation finishes without user interaction and that the device appears in the correct PDQ Connect organization or tenant. Remove the test agent before repeating the pack test on the same device, when appropriate.

Build the Application Pack

  1. Open the SmartDeploy Web Console or desktop console and select Application Packs.
  2. Select Actions > Create.
  3. On the Welcome page, select Next.
  4. On Installation Files, select the dedicated folder that contains the Agent MSI. For Executable Path, select the PDQConnectAgent MSI, then select Next.
  5. On Details, confirm or enter the pack information. Use a clear title such as PDQ Connect Agent and confirm the publisher and version.
  6. On Installation Task, enable Quiet Installation, No Restart, and ALLUSERS. Review the command preview before continuing.
  7. On Installation Detection, confirm the MSI product code and version detected by the wizard.
  8. Review the Summary, select Next, then select Finish.
  9. Save the pack in the SmartDeploy Application Packs directory, such as \SmartDeploy\Application Packs\.
Application Pack setting Recommended value
Title PDQ Connect Agent
Installer Organization- or tenant-specific PDQConnectAgent-X.X.X.msi
Quiet installation Enabled
No restart Enabled
ALLUSERS Enabled
Detection MSI product code and version confirmed

Important: The standard Application Pack Wizard adds product name and version filters automatically. A test deployment can report that the pack is not applicable when the same or a newer agent is already installed. Test the pack on a clean or appropriately prepared device.

Step 3: Add the Agent Application Pack to the answer file

  1. Create or edit the SmartDeploy answer file used for imaging.
  2. On the Application Packs page, select PDQ Connect Agent and use the right arrow to add it to the deployment list.
  3. Place the Agent Application Pack with the other post-image applications in the required installation order.
  4. Continue through the Answer File Wizard and save the answer file.

Note: This article uses an Application Pack for the PDQ Connect Agent. An Answer File task can also run the MSI silently, but the agent should not be installed or enrolled in the reference VM.

Step 4: Create the First Boot registry marker

Add a First boot as system task to the same answer file. The task creates the registry values that PDQ Connect uses to identify a newly imaged device.

  1. Open Advanced Options > Tasks and select Add.
02-smartdeploy-answer-file-wizard-tasks-tab.png
  1. Set Phase to First boot as system.
  2. Paste the command below into Command line and select OK.
03-smartdeploy-add-edit-task-window.png
C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -Path 'HKLM:\SOFTWARE\PDQ' -Force; New-ItemProperty -Path 'HKLM:\SOFTWARE\PDQ' -Name 'SmartDeployReimage' -Value (Get-Date -Format 'yyyy-MM-ddTHH:mm:ss') -PropertyType String -Force; New-ItemProperty -Path 'HKLM:\SOFTWARE\PDQ' -Name 'BaselineRequired' -Value 1 -PropertyType DWord -Force; New-ItemProperty -Path 'HKLM:\SOFTWARE\PDQ' -Name 'BaselineVersion' -Value 0 -PropertyType DWord -Force"

Why Sysnative is used: The tested SmartDeploy task started from a 32-bit process. Sysnative launches native 64-bit Windows PowerShell so the marker is written to HKLM\SOFTWARE\PDQ instead of the redirected WOW6432Node location.

Registry value Type Initial data Purpose
SmartDeployReimage String yyyy-MM-ddTHH:mm:ss Records the most recent imaging time.
BaselineRequired DWORD 1 Places the device in the Pending workflow.
BaselineVersion DWORD 0 Indicates that no baseline version has completed.

Media update: If the edited answer file is embedded in USB, ISO, WDS, or offline media, recreate or update that media before testing.

Step 5: Validate the deployed device

After SmartDeploy finishes, validate both the PDQ Connect Agent and the native registry marker before creating the automation target.

  1. Confirm that the device appears online in the expected PDQ Connect organization or tenant.
  2. On the device, run the following command from Command Prompt:
reg query "HKLM\SOFTWARE\PDQ" /reg:64

The command should return SmartDeployReimage, BaselineRequired set to 0x1, and BaselineVersion set to 0x0.

04-registry-editor-showing-smartdeploy-marker.png

Stop here if validation fails: Do not build the PDQ Connect groups around a key written under WOW6432Node. Correct the First Boot task and confirm the 64-bit query succeeds first.

Step 6: Create the PDQ Connect Registry Scanner

In PDQ Connect, open Tools > Scanners, create a scanner, and select Registry as the type.

Setting Value Notes
Name SmartDeploy Baseline Image Identifies the scanner in Registry results.
Type Registry
Hive HKEY_LOCAL_MACHINE
Path SOFTWARE\PDQ Do not add a leading or trailing backslash.
Search subkeys Off The values are directly under the path.
Scope Value Key is not required for this workflow.
Match type All Returns every value under the path.

Validated scanner path: Use only SOFTWARE\PDQ. Do not add SOFTWARE\WOW6432Node\PDQ unless you intentionally support an older 32-bit marker implementation.

  1. Save the scanner.
  2. Open the device, select Scan device, then go to Additional data > Registry.

Search for BaselineRequired or SOFTWARE\PDQ. The three marker values should appear under the native path.

05-pdq-connect-registry-scanner-results.png

Validate the agent context when needed

If the local registry query works but the scanner remains empty, run these commands from the device Commands tab in PDQ Connect:

whoami
reg query "HKLM\SOFTWARE\PDQ" /reg:64

The output should identify nt authority\system and return all three registry values.

06-pdq-connect-commands-output.png

Step 7: Create the Pending dynamic group

Create a Windows dynamic group that includes only devices whose baseline is still required. Use exact equality instead of contains.

Group setting Value
Name SmartDeploy Baseline - Pending
Type Dynamic
OS Windows
Connector Data source Field Operator Value
Registry Name equals BaselineRequired
AND Registry Value data equals 0x00000001 (1)
AND Registry Path equals SOFTWARE\PDQ
07-smartdeploy-pending-dynamic-group.png

Use equals, not contains: Connect displays DWORD data as hexadecimal plus decimal text. A Completed filter using contains 0 can also match 0x00000001 (1). Exact equality keeps Pending and Completed mutually exclusive.

Step 8: Create the baseline package

Create a PDQ Connect custom package named SmartDeploy Package Delivery. Add the application packages required on every newly imaged device as nested package steps.

Order Step Purpose
1..n Nested application packages Install the approved applications and configuration steps.
Last Mark SmartDeploy Baseline Complete Update and verify the registry state after all earlier steps succeed.

Critical ordering rule: Keep the completion script as the final step, and configure the package so it does not run after a failed application step. Otherwise a partially provisioned device could be marked complete.

Add the completion PowerShell step

$Path = "HKLM:\SOFTWARE\PDQ"

# The SmartDeploy First Boot task must have created this key.
if (-not (Test-Path $Path)) {
    throw "Registry path $Path does not exist. Baseline status cannot be updated."
}

# Mark baseline version 1 as complete.
Set-ItemProperty `
    -Path $Path `
    -Name "BaselineRequired" `
    -Value 0 `
    -ErrorAction Stop

Set-ItemProperty `
    -Path $Path `
    -Name "BaselineVersion" `
    -Value 1 `
    -ErrorAction Stop

# Read the final state and write useful deployment output.
$Result = Get-ItemProperty -Path $Path -ErrorAction Stop

Write-Output "SmartDeploy baseline update completed."
Write-Output "SmartDeployReimage : $($Result.SmartDeployReimage)"
Write-Output "BaselineRequired   : $($Result.BaselineRequired)"
Write-Output "BaselineVersion    : $($Result.BaselineVersion)"

# Fail the package if the expected values were not written.
if ($Result.BaselineRequired -ne 0) {
    throw "BaselineRequired was not successfully changed to 0."
}

if ($Result.BaselineVersion -ne 1) {
    throw "BaselineVersion was not successfully changed to 1."
}

Write-Output "Baseline registry verification successful."
08-pdq-connect-completion-powershell-step.png

Step 9: Create the automation

Open Automations and create an automation with the following settings:

Setting Value
Name SmartDeploy Baseline Deployment
Package SmartDeploy Package Delivery
Deploy to SmartDeploy Baseline - Pending
Initial validation trigger Manual or a controlled test trigger
Production trigger A recurring schedule appropriate to the environment

Timing recommendation: Choose a recurrence longer than the expected package run plus the inventory refresh delay. A device remains in Pending until Connect records BaselineRequired=0, so an aggressive schedule can start duplicate deployments.

Step 10: Create the Completed dynamic group

Create a second Windows dynamic group that identifies devices whose completion script has finished.

Group setting Value
Name SmartDeploy Baseline - Completed
Type Dynamic
OS Windows
Connector Data source Field Operator Value
Registry Name equals BaselineRequired
AND Registry Value data equals 0x00000000 (0)
AND Registry Path equals SOFTWARE\PDQ

BaselineVersion remains available for reporting and future version-specific groups. The validated Completed group uses BaselineRequired as the primary state flag.

Step 11: Validate the complete workflow

  1. Deploy the SmartDeploy image and answer file to one test device.
  2. Confirm the PDQ Connect Agent installs through the Application Pack and the device appears online in the correct organization or tenant.
  3. Confirm HKLM\SOFTWARE\PDQ contains SmartDeployReimage, BaselineRequired=1, and BaselineVersion=0.
  4. Run Scan device and confirm the Registry Scanner returns all three values.
  5. Confirm the device enters SmartDeploy Baseline - Pending.
  6. Run or allow SmartDeploy Baseline Deployment to start.
  7. Confirm every nested application step completes successfully.
  8. Confirm the final PowerShell output reports BaselineRequired=0 and BaselineVersion=1.
  9. Run Scan device again when necessary.
  10. Confirm the device leaves Pending and enters SmartDeploy Baseline - Completed.
  11. Confirm the expected applications and settings are present on the device.
Check Pass condition
Agent installation The device appears online in the correct Connect organization or tenant.
SmartDeploy marker HKLM\SOFTWARE\PDQ contains all three expected values.
Pending state The device enters Pending only when BaselineRequired equals 0x00000001 (1).
Package execution All nested application steps and the completion step return success.
Completion state BaselineRequired equals 0 and BaselineVersion equals 1 locally and in Connect.
Group transition The device leaves Pending and enters Completed after inventory refresh.
Reimage reset A later reimage resets Required=1 and Version=0 and starts the workflow again.

Monitoring and logs

Deployment output

Open Deployments, select the Complete or Failed count for the deployment, and open View Output for the device. The final PowerShell step writes the three registry values to this output, which is the primary place to confirm success or diagnose a script failure.

  • Use Export log to save the full deployment output when escalating a failure.
  • The Deployed by column identifies the automation that started the deployment.

Device inventory and commands

  • Device > Additional data > Registry shows the last Registry Scanner result stored by Connect.
  • Device > Commands can run whoami and the 64-bit reg query to prove LocalSystem access.
  • Use Scan device when testing a state change instead of restarting the agent service.

Local diagnostic logs

For agent or scanner failures, review Event Viewer > Applications and Services Logs > PDQ.com. The Agent installation log from the sample command is stored at C:\Windows\Temp\PDQConnectAgent-install.log. Additional Connect Agent data is located under C:\ProgramData\PDQ\PDQConnectAgent.

Troubleshooting

Symptom Likely cause Corrective action
Agent Application Pack fails The MSI name was changed, the embedded token expired, or the silent command is incorrect. Use a current installer whose name begins with PDQConnectAgent; retest the silent MSI command and review the install log.
Device enrolls in the wrong organization or tenant The MSI came from a different Connect organization or tenant. Download a new installer from the intended tenant and rebuild the Application Pack.
Application Pack is not applicable The wizard detection filter found the same or a newer agent version. Test on a clean device or review the generated product/version filters.
Registry key is under WOW6432Node The First Boot task used 32-bit PowerShell. Use the tested Sysnative command and validate with /reg:64.
Sysnative cannot be found The task host is already a native 64-bit process. Replace Sysnative with System32, rerun the task, and verify the native key.
Local query works but the scanner is empty The scanner path, scan timing, or agent context is wrong. Use only SOFTWARE\PDQ with no trailing slash, save, run Scan device, and test through Connect Commands as SYSTEM.
Pending and Completed contain the same device The filter uses contains instead of equals. Use the exact DWORD strings 0x00000001 (1) and 0x00000000 (0).
Deployment succeeds but the device stays Pending Connect has not scanned the new local value yet. Confirm BaselineRequired is 0 locally, then run Scan device.
Device is marked complete after an application failure The completion script ran after a failed step. Keep the completion step last and stop the package when an earlier step fails.
Automation deploys more than once The automation recurred before group membership refreshed. Increase the recurrence interval and keep application steps safe to rerun.

Escalation boundary: If Connect Commands running as nt authority\system can read all three values but the single-path scanner still returns no rows after Scan device, collect the PDQ.com event log and deployment output for a support case.

Maintenance and baseline versioning

Change Required action
Refresh the PDQ Connect Agent installer Download a new organization- or tenant-specific MSI, rebuild or update the Application Pack, and test it. Do this at least once per year.
Add or replace baseline applications Update and test SmartDeploy Package Delivery.
Release baseline version 2 Change the completion script so BaselineVersion is set to 2.
Retain reimage behavior Keep the First Boot task setting BaselineRequired=1 and BaselineVersion=0.
Retry a device without reimaging Reset the two state values, then run Scan device.
Pause the workflow Disable the automation. The scanner and dynamic groups can remain in place.

Manual retry script

$Path = "HKLM:\SOFTWARE\PDQ"

Set-ItemProperty -Path $Path -Name "BaselineRequired" -Value 1 -ErrorAction Stop
Set-ItemProperty -Path $Path -Name "BaselineVersion"  -Value 0 -ErrorAction Stop

Get-ItemProperty -Path $Path -Name SmartDeployReimage, BaselineRequired, BaselineVersion

After running the retry script, request a new device scan so the endpoint can re-enter Pending.

Was this article helpful?