Automate First-Boot Setup with an Ignition File
Use an ignition file to set up a MetaDefender Drive without touching its screen. Write one small INI file to MetaDefender Drive. On the next boot, MetaDefender Drive reads it, joins Wi-Fi, activates its license, enrolls with Central Management, and enrolls for Centralize Profile.
Before you begin
A Windows computer. The data partition of MetaDefender Drive is NTFS, and Windows reads and writes it without extra software.
The values you want to apply: Central Management address and registration code, a license activation key, Wi-Fi details, and a Centralize Profile approver name.
Create the file
MetaDefender Drive does not ship with an ignition file. Create one yourself:
Connect MetaDefender Drive to your computer.
Open the
configurationfolder on the data partition of MetaDefender Drive (<drive>:\configuration).Create a file named exactly
mdd_ignition.ini, in lowercase.Add the sections you need (see below). Leave out any section you do not want to apply.
Safely eject MetaDefender Drive and boot it.
The file name must be exactly
mdd_ignition.ini, in lowercase, in theconfigurationfolder. A file namedMDD_Ignition.ini, ormdd_ignition.ini.txt(Notepad adds.txtwhen you save), is deleted at boot without any message. In Windows File Explorer, turn on File name extensions (View > Show) so you can see the real file name.
At boot, MetaDefender Drive deletes files it does not recognize on the data partition. Do not store other files in the
configurationfolder, because they can be deleted. MetaDefender Drive keepsmdd_ignition.ini, its own configuration files, and any file whose name ends in.pem,.crt,.cer,.cert, or.der(not case-sensitive), so a Wi-Fi CA certificate you place there survives.
Example
This is a complete template. Every setting starts with ;, which makes it a comment. Remove the ; from each setting you want to use and replace the placeholder values. Write a comment on its own line: a comment placed after a value on the same line is not supported.
What happens at boot
MetaDefender Drive joins the Wi-Fi network from
[NETWORK], because Centralize Profile enrollment, license activation, and Central Management need a connection. Centralize Profile enrollment checks that Central Management can be reached before it enrolls. MetaDefender Drive joins even when an Ethernet cable is plugged in.MetaDefender Drive enrolls for Centralize Profile from
[OTP], but only whenenroll=trueand the Central Management server from[MO]answers. If it cannot be reached, MetaDefender Drive skips Centralize Profile enrollment and scans run without the one-time password gate.MetaDefender Drive activates the license from
[LICENSE], but only when it has no working license. If the key is rejected, MetaDefender Drive shows a warning and then falls back to its normal automatic activation.MetaDefender Drive enrolls with Central Management from
[MO]. MetaDefender Drive skips this step when it is already enrolled, or when an enrollment is pending (set up by the Toolkit or the SMC).MetaDefender Drive deletes
mdd_ignition.ini, even if an earlier step failed. Nothing is retried on the next boot.
Sections and keys
[MO] — Central Management
Key | Required / Optional | Description |
|---|---|---|
| Required | Address of the Central Management server, for example |
| Required | Registration code issued by Central Management. |
| Optional | Set to |
Both
urlandregcodeare required.If MetaDefender Drive already has a working Central Management enrollment, or an enrollment is pending (set up by the Toolkit or the SMC), the file is ignored for enrollment. The existing enrollment wins.
If the server presents a self-signed certificate that MetaDefender Drive does not already trust, enrollment is refused unless
accept_self_signed=true. MetaDefender Drive never prompts at boot, because nobody is there to answer. When you enroll from the user interface instead, MetaDefender Drive asks you whether to trust the certificate.
[LICENSE] — License activation
Key | Required / Optional | Description |
|---|---|---|
| Required | The license activation key. |
[NETWORK] — Wi-Fi
Key | Required / Optional | Description |
|---|---|---|
| Required | Name of the Wi-Fi network. |
| Required for | Wi-Fi password ( |
| Optional |
|
| Optional |
|
| Optional | Set to |
| Required for | User name for WPA/WPA2-Enterprise (802.1X). |
| Optional | Outer method: |
| Optional | Inner authentication: |
| Optional | Outer identity sent in clear before the tunnel is up. |
| Optional | The RADIUS server certificate must be issued for this domain or a subdomain of it. |
| Optional (recommended) | File name of the CA certificate (PEM or DER) that issued the RADIUS server certificate. |
Notes:
With only
ssidandpassword, MetaDefender Drive detects the security type itself.A hidden network cannot be detected. With
hidden=trueand nosecurity, MetaDefender Drive assumeswpa-pskwhen a password is given, andopenwhen it is not. Setsecurity=wpa-saefor a hidden WPA3-only network.If you set
identity, the network is treated as WPA/WPA2-Enterprise.Only username and password methods are supported. EAP-TLS (client certificate) is not supported.
To use
ca_cert, place the certificate next to the ignition file (<drive>:\configuration\<name>). The file name must end in.pem,.crt,.cer,.cert, or.der. MetaDefender Drive copies the certificate to its own storage and leaves your original in place.ca_certis used only withwpa-eap. On any other security type it is ignored.If
ca_certis named but the file is missing or is not a certificate, MetaDefender Drive does not join the network. Withoutca_cert, the server certificate is not validated, and the password goes to whichever server answers.MetaDefender Drive joins the network even if an Ethernet cable is already connected. Both links stay active, and the wired connection remains the preferred route.
A wrong password costs one bounded timeout at boot. It does not hang MetaDefender Drive.
[OTP] — Centralize Profile enrollment
The section is named [OTP] in the file.
Key | Required / Optional | Description |
|---|---|---|
| Required | Set to |
| Optional | Name of the approver. Default: |
MetaDefender Drive enrolls only when
enroll=trueand Central Management answers successfully with the registration code.[MO]must therefore be present and correct.Leave
approverout to name MetaDefender Drive after its serial number. Each drive then has a distinct name in the approver list. Name a person only when one person owns the drive.If Central Management does not answer, MetaDefender Drive skips enrollment and scans run without the one-time password gate.
Enrollment happens once. MetaDefender Drive does not enroll again on later boots, so the authenticator your approver registered stays valid.
After enrollment, scans, file copies, and report deletion require a one-time password.
MetaDefender Drive creates the secret itself, so nobody holds it yet. Central Management supplies the real approver and secret afterwards. This is why MetaDefender Drive enrolls only when Central Management answers.
After boot
MetaDefender Drive deletes
mdd_ignition.inionce every step has been attempted. The file holds the registration code, the activation key, and the Wi-Fi password in clear text, so it does not stay on MetaDefender Drive.MetaDefender Drive applies the file once and then removes it, so there is nothing to read on the next boot. To apply the settings again, write the file again and reboot.
A failed Central Management enrollment and a rejected license key are shown as notifications, not dialogs. Wi-Fi and Centralize Profile failures are only written to the log.
Troubleshooting
Symptom | Cause and fix |
|---|---|
The file was not applied and is gone. | Either MetaDefender Drive consumed it on the previous boot, or the file name was not exactly |
MetaDefender Drive does not enroll with Central Management. | Check that |
MetaDefender Drive is not enrolled for Centralize Profile. | Check that |
MetaDefender Drive does not join Wi-Fi. | Check the password and |