I just thought I’d post this handy link for installing an Agent on a WORKGROUP Computer without a Gateway. The process is slightly different, but very similar.
The OpsMgr Agent must be able to establish a security communication channel to the management server using the correct certificate. Agents in the workgroup must be able to use the Kerberos protocol for mutual authentication. In otherwords, certificates should most likely be used in an environment in which Kerberos protocol is not used (untrusted domains or workgroups).
Give this link a read!