Most workstations should be configured to allow pushing out the Argent USB monitoring agent from the Main Engine.
In order to do so, the service account of the Main Engine must have access to administrative shares (C$, D$ etc) of monitored workstations. Normally this means the service account should be a member of local administrators group. This is typically the case when the service account is a member of Domain Admin, but should be confirmed.
Note: The pushed out Argent USB monitoring agent runs under Local System Account.
In case that the above accessibility cannot be arranged, the Argent USB monitoring agent can be installed manually. In this case, the service account of the USB agent must have write access to share