Skip to main content
Certified BuildRequires the governance package. Available September 2026.

Administrative Templates (Intune & GPO)

NVM for Windows certified governance builds come with ADMX/ADML templates. Use them in on-premises Group Policy or Microsoft Intune configuration profiles.

ResourceGuidance
ADMX fileControls the technical registry settings. Available at portal.author.io.
ADML fileProvides the language text for the settings. Available at portal.author.io.
Target pathHKLM\Software\Policies\Author Software\nvm

Download the ADMX/ADML from the customer portal. For Win32 app installation through Intune, see Install → Intune.


Intune policy configuration​

After NVM for Windows is installed, enforce settings with the imported administrative template.

1. Import ADMX and ADML​

  1. In Intune admin center, go to Devices > Windows > Configuration.
  2. Open the Import ADMX tab and select Import.
  3. Upload NVMWindows.admx and en-US\NVMWindows.adml from your deployment pack. No Windows.admx prerequisite is required.
error 131329 (0x20101)
  1. On the device, run certified\enhanced\policy\Get-NvmAdmxIngestDiagnostics.ps1 and note the HRESULT on ADMX Ingestion events (for example 0x8007000D invalid ADMX data, 0x80070005 blocked registry path).
  2. Delete the prior NVM ADMX import in Intune, then re-import the updated template.
  3. Clear stale ingest state on the device, then sync again:
Remove-Item -Recurse -Force "$env:ProgramData\Microsoft\PolicyManager\ADMXIngestion\*nvm*" -ErrorAction SilentlyContinue
Get-ChildItem 'HKLM:\SOFTWARE\Microsoft\PolicyManager\AdmxInstalled' -Recurse |
Where-Object { $_.Name -match 'nvm' } |
Remove-Item -Recurse -Force

Until ADMX ingest succeeds, deploy values with a Custom configuration profile (Registry CSP OMA-URIs). Value names and types are in the Central Registry Reference.

alt text

2. Create a configuration profile​

  1. Go to Devices > Configuration > Create > New policy.
  2. Platform: Windows 10 and later (covers Windows 11 and Windows Server 2019 and later).
  3. Profile type: Templates → Imported Administrative templates.
  4. Navigate to Author Software > NVM for Windows and configure policies.

alt text

Policy names match the GPO tree below. Registry value names are in the Central Registry Reference.

Registry CSP alternative

You can also deploy individual registry values with a Settings catalog or Custom configuration profile using Registry CSP OMA-URIs. Prefer ADMX import when available; use Registry CSP as a fallback or for one-off keys. See the Central Registry Reference.


Group Policy (GPO) Deployment​

Domain Controller Access

You will need access to your domain controller to perform the tasks in this section.

On your domain controller:

  1. Copy NVMWindows.admx to \\domain\sysvol\domain\Policies\PolicyDefinitions.
  2. Copy en-US\NVMWindows.adml to \\domain\sysvol\domain\Policies\PolicyDefinitions\en-US.
  3. Open the Group Policy Management Editor (Windows Key + R, type gpedit.msc and press Enter.)
  4. Locate the Group Policy Object (or create a new one) used to manage Node.js policies. Right click and select Edit.
  5. Navigate to Computer Configuration > Policies > Administrative Templates > Author Software > NVM for Windows.

GPO

Policy names below match the Administrative Templates tree in Group Policy Management Editor and Intune after ADMX import.

Computer Configuration
└── Policies
└── Administrative Templates
└── Author Software
└── NVM for Windows
├── Disable Node.js version management
├── Configure Node.js storage directory
├── Allow users to change the Node.js storage directory
├── Configure local Node.js installation mirror source directory
├── Use local mirror for all Node.js installations
├── Network
│ ├── Configure proxy server address
│ ├── Configure proxy authentication type
│ ├── Configure proxy authentication value
│ ├── Configure Node.js download mirror(s)
│ ├── Configure npm registry mirror(s)
│ ├── Always cache downloads
│ ├── Disable removal of cached downloads
│ ├── Disable NVM for Windows upgrades
│ └── Disable project and release announcements
├── Environment
│ ├── Set operating mode
│ ├── Configure custom version aliases
│ ├── Configure auto-installed global npm modules
│ └── Shim mode
│ ├── Configure automatic version detection files (e.g. .nvmrc)
│ ├── Configure default auto-detect file
│ ├── Disable automatic version detection
│ ├── Disable automatic version installation
│ ├── Always prompt before automatic installation
│ ├── Disable native tool installation
│ └── Configure package manager mismatch action
└── Security
├── Skip live license JWKS (air-gapped JWT verify)
├── Configure allowed Node.js versions
├── Configure blocked Node.js versions
├── Disable insecure downloads
├── Include verbose identity metadata in mirror license tokens
├── Configure approved vendors (trusted code signers)
└── Shim mode
├── Enable audit logging
├── Enforce Node.js permission model
├── Prevent modification of global JavaScript prototypes
├── Disallow dynamic code generation from strings
└── Configure npm package minimum release age
Language Support

Contact [email protected] to request a language other than English.