Registry Policy Reference
This reference contains the registry keys and values used to manage, secure, and configure NVM for Windows in enterprise environments.
All administrative policies should be enforced within the HKEY_LOCAL_MACHINE (HKLM) hive. Settings applied here are mandatory and will override any conflicting preferences configured by individual users within the local application interface.
The application evaluates settings in the following order of priority:
HKLM\Software\Policies\Author Software\nvm(Enforced Admin Policy)HKCU\Software\Author Software\Preferences\nvm(User-defined Preferences)
Available Registry Keys
See Administrative Templates for GPO and Intune deployment. Download ADMX/ADML from the customer portal. ADMX/ADML ship with the Governance pack; Distro/Audit can still set shared keys via Registry CSP/OMA-URI or .reg.
Overridable in a description means users may also set the equivalent preference (nvm config / HKCU). Machine policy under HKLM\Software\Policies\Author Software\nvm always wins.
| Name | Key | Description |
|---|---|---|
| Air-gapped license verify | AirGapped | Edition: Distro+. Skip live JWKS fetch from licensing.author.io. Verify AccessToken only against the COSE-signed offline JWKS store (JwksCose or nvm-jwks.cose next to nvm.exe). Independent of LocalInstallOnly.- 0 = off- 1 = onDefault: 0REG_DWORD |
| Version aliases | Aliases | Overridable. Centrally managed aliases (e.g. stable=24.9.0). Blocks user-defined aliases when set by policy.alias=version per entryREG_MULTI_SZ |
| Allow cache deletion | AllowDownloadCacheDelete | Overridable (allow_download_cache_removal). Whether cached downloads may be removed (nvm cache remove).- 0 = blocked- 1 = allowedDefault: 1REG_DWORD |
| Allow insecure downloads | AllowInsecureDownloads | Overridable (allow_insecure_downloads). Permit downloads when TLS certificates are expired or invalid.- 0 = blocked- 1 = allowedDefault: 0REG_DWORD |
| Allow install root change | AllowRootDirChange | Overridable. Whether users may change the install root. - 0 = blocked- 1 = allowedDefault: 1REG_DWORD |
| Allow native tool install | AllowToolInstall | Overridable. Allow nvm install native-tools (Python, VS Build Tools, etc.) (shim-only).- 0 = blocked- 1 = allowedDefault: 1REG_DWORD |
| Allowed code signers | AllowedSigners | Overridable (allowed_signers). Additional trusted node.exe signers. OpenJS Foundation, Node.js Foundation, and Author Software are always trusted (shim-only). One signer name per entry.REG_MULTI_SZ |
| Allowed thumbprints | AllowedThumbprints | Overridable (allowed_thumbprints). Optional SHA-1 Authenticode leaf thumbprints (hex; separators optional). When non-empty, node.exe must match a pin after org allowlist. Empty disables pinning.REG_MULTI_SZ |
| Authenticode revocation | AuthenticodeRevocation | Overridable (authenticode_revocation). CRL/OCSP mode for Authenticode:- online = network retrieval (install/sign/seed only; default)- cached = local URL cache only- disabled = no revocation checksShim runtime never uses online (clamped to cached). AirGapped forces cached when online would apply.Default: onlineREG_SZ |
| Auto-detect files | AutoDetect | Overridable (auto_detect). Project files scanned for version pins (shim-only). Overrides defaults.Default: .nvmrc.node-versionpackage.jsonREG_MULTI_SZ |
| Auto-install missing version | AutoInstall | Overridable (auto_install). Auto-install missing detected versions (shim mode).- 0 = off- 1 = onDefault: 0REG_DWORD |
| Auto-install global modules | AutoInstallModuleList | Overridable (auto_installed_modules). Global npm modules installed with each new Node.js version. One module name per entry.REG_MULTI_SZ |
| Prompt before auto-install | AutoInstallPrompt | Overridable (auto_install_prompt). Confirm before auto-installing (shim mode).- 0 = no prompt- 1 = promptDefault: 1REG_DWORD |
| Auto-use detected version | AutoUse | Overridable (auto_use). Auto-switch to detected version when running commands (shim mode).- 0 = off- 1 = onDefault: 1REG_DWORD |
| Cache downloads | CacheDownloads | Overridable (cache_downloads). Cache downloaded Node.js versions for offline reuse.- 0 = off/false- 1 = on/trueDefault: 0REG_DWORD |
| Default detect file | DefaultDetectFile | Overridable (default_detect_file). File written when pinning a version (nvm pin) (shim-only).Default: .nvmrcREG_SZ |
| Disable announcements | DisableAnnouncements | Overridable (disable_announcements). Suppress project and release announcements.- 0 = shown- 1 = hiddenDefault: 0REG_DWORD |
| Disallow eval/string code gen | DisableEvalAndStringExecution | Overridable (disable_eval_and_string_execution). Shim prepends --disallow-code-generation-from-strings, blocking eval() and new Function() (shim-only). Does not affect node:vm.- 0 = off- 1 = onDefault: 0REG_DWORD |
| Disable NVM upgrades | DisableUpgrade | Overridable. Block in-app NVM upgrades (does not block AD/GPO package deployment). - 0 = allowed- 1 = blockedDefault: 0REG_DWORD |
| Disable version management | Enabled | Overridable (nvm on/nvm off). Forces version management on or off. When off, NVM does not manage or redirect Node.js commands.- 0 = off (nvm off)- 1 = onDefault: 1REG_DWORD |
| Enforce permission model | EnforcePermissionModel | Overridable (enforce_permission_model). Shim prepends Node permission-model flag on every node.exe launch (shim-only). Default-deny FS/network unless the process passes --allow-* at runtime. NVM does not inject --allow-* grants.- Node 23+: --permission- Node 20–22: --experimental-permission- Node <20: no flag (unsupported) - 0 = off- 1 = onDefault: 0REG_DWORD |
| Freeze V8 global objects | FreezeV8GlobalObjects | Overridable (freeze_v8_global_objects). Shim prepends --frozen-intrinsics so built-in prototypes cannot be patched (shim-only; Node.js 12+). Adds measurable startup cost.- 0 = off- 1 = onDefault: 0REG_DWORD |
| Install root | InstallRoot | Overridable (root). Directory where Node.js versions are stored. Overrides machine and user preferences.Default: %LOCALAPPDATA%\Author Software\nvm\installsREG_SZ |
| Local install source | LocalInstallDir | Overridable (local_dir). Alternate local directory for Node.js archives (air-gapped mirrors). Overrides cache.REG_SZ |
| Local install only | LocalInstallOnly | Overridable (local_install_only). Restrict installs to LocalInstallDir only.- 0 = off- 1 = onDefault: 0REG_DWORD |
| Audit logging | LogExecutions | Overridable (log_executions). Log every Node.js invocation to the Windows Event Log (shim-only). Most useful on Audit+ (structured ETW).- 0 = off- 1 = onDefault: 0REG_DWORD |
| Node.js download mirrors | MirrorNode | Overridable (node_mirror). Ordered mirror list; first successful response wins. See Download Mirrors. Author *.author.io mirrors need Governance licensing — see Version Firewall + Author Mirror.Default: https://nodejs.org/distREG_MULTI_SZ |
| npm registry mirrors | MirrorNpm | Overridable (npm_mirror). Ordered npm registry list. Used as shim registry fallback.Default: https://registry.npmjs.orgREG_MULTI_SZ |
| Operating mode | OperatingMode | Overridable (mode). How NVM for Windows manages Node.js versions.Shim (recommended) uses signed shims to intercept node, npm, npx, yarn, and pnpm. Required for runtime policies (audit logging, auto-detect, ACL).Link uses NTFS junctions/symlinks on PATH. Default: shimREG_SZ |
| Package manager mismatch action | PackageManagerMismatchAction | Overridable (pm_mismatch_action). Behavior when npm/pnpm/yarn version mismatches Node during install or use (shim-only).- ignore- warn- errorDefault: errorREG_SZ |
| Proxy URL | Proxy | Overridable (proxy). Proxy for downloads. Basic and Bearer work on all certified editions. See Download Mirrors.REG_SZ |
| Proxy auth value | ProxyAuth | Overridable (proxy_auth). Credentials or bearer token (stored in plain text).- user:pass- Bearer YOUR_TOKENREG_SZ |
| Proxy auth type | ProxyAuthType | Overridable (proxy_auth_type). Authentication scheme for the configured proxy.- basic, bearer — all certified editions- ntlm, negotiate, ntlm,negotiate — Governance only (IWA); PAC/WPAD also Governance-onlyREG_SZ |
Governance Keys
These keys are part of the Governance feature set. They appear in the Governance ADMX pack.
| Name | Key | Description |
|---|---|---|
| Verbose mirror license metadata | ApplyVerboseLicenseMetadata | When on, Author mirror license JWTs include identity claims (idp_username, idp_machine_name, idp_machine_id). Does not set AccessToken/AccessKey.- 0 = omit claims- 1 = include claimsDefault: 0REG_DWORD |
| npm module minimum age | NpmModuleMinimumAge | Minimum package publish age (cooldown), in minutes, for package manager installs (shim mode). Auto-converts for npm/pnpm/yarn. Default: 0 (disabled)REG_DWORD |
| Allowed Node.js versions | VersionAllowList | Allow list for installs. Invalid entries fail enforcement. Allow wins over block. Also feeds Author-mirror JWT version claims (magic tokens such as EOL, ALPHA, MAINTENANCE, ALL).Supports exact semver, wildcards (e.g. 20.x), aliases, and NOT/! negation (one rule per line).REG_SZ |
| Blocked Node.js versions | VersionBlockList | Block list for installs. Same rule formats as VersionAllowList.REG_SZ |
AccessToken, AccessKey, and JwksCose are not ADMX policies. Deploy with portal scripts (Set-NvmWindowsAccessToken.ps1 on stock certified build; Set-NvmWindowsLicensing.ps1 for governance builds, which also sets AccessKey for Author mirrors) or nvm license.
Several ADMX policies use inverted GPO labels (e.g. Disable automatic version detection writes AutoUse=0 when enabled). The tables document the registry value admins should deploy via GPO, Intune (imported ADMX or Registry CSP), or Entra custom OMA-URI.
Registry Import Example
Save as nvm-policy.reg, replace placeholder paths and URLs for your environment, then double-click or run reg import nvm-policy.reg from an elevated command prompt.
REG_MULTI_SZ keysMirrorNode, MirrorNpm, Aliases, AutoDetect, AutoInstallModuleList, AllowedSigners, and AllowedThumbprints are REG_MULTI_SZ (one string per entry). A .reg line like "MirrorNode"="url1,url2" creates a wrong REG_SZ. Set those with ADMX, Registry CSP, or PowerShell (below) — not comma-joined REG_SZ values.
Windows Registry Editor Version 5.00
; =============================================================================
; NVM for Windows — machine policy (HKLM)
; Path: HKLM\SOFTWARE\Policies\Author Software\nvm
; =============================================================================
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Author Software\nvm]
; --- Core / environment ---
"OperatingMode"="shim"
"Enabled"=dword:00000001
"InstallRoot"="%LOCALAPPDATA%\\Author Software\\nvm\\installs"
"AllowRootDirChange"=dword:00000000
"LocalInstallDir"="D:\\Node\\local_mirror"
"LocalInstallOnly"=dword:00000000
"AirGapped"=dword:00000000
; --- Version ACL (Governance) ---
"VersionAllowList"="20.x\r\n22.x"
"VersionBlockList"="!20.17.0"
; --- Network / downloads (SZ / DWORD only here; MULTI_SZ via PowerShell below) ---
"Proxy"="http://proxy.example.corp:8080"
"ProxyAuthType"="ntlm"
; "ProxyAuth"="service-account:password"
; "ProxyAuth"="Bearer YOUR_TOKEN_HERE"
"CacheDownloads"=dword:00000001
"AllowDownloadCacheDelete"=dword:00000000
"AllowInsecureDownloads"=dword:00000000
"ApplyVerboseLicenseMetadata"=dword:00000000
"DisableUpgrade"=dword:00000001
"DisableAnnouncements"=dword:00000001
; --- Shim runtime (requires OperatingMode=shim) ---
"DefaultDetectFile"=".nvmrc"
"AutoUse"=dword:00000001
"AutoInstall"=dword:00000000
"AutoInstallPrompt"=dword:00000001
"AllowToolInstall"=dword:00000000
"PackageManagerMismatchAction"="error"
"LogExecutions"=dword:00000001
"EnforcePermissionModel"=dword:00000001
"FreezeV8GlobalObjects"=dword:00000001
"DisableEvalAndStringExecution"=dword:00000001
"NpmModuleMinimumAge"=dword:000005a0
After importing the .reg (or instead of it for list values), set multi-string keys elevated:
$policy = 'HKLM:\SOFTWARE\Policies\Author Software\nvm'
New-ItemProperty -Path $policy -Name MirrorNode -PropertyType MultiString -Force -Value @(
'https://mirror.author.io/runtime/nodejs'
'https://nodejs.org/dist'
) | Out-Null
New-ItemProperty -Path $policy -Name MirrorNpm -PropertyType MultiString -Force -Value @(
'https://npm.example.corp'
'https://registry.npmjs.org'
) | Out-Null
New-ItemProperty -Path $policy -Name Aliases -PropertyType MultiString -Force -Value @(
'stable=24.9.0'
'lts=22.17.0'
) | Out-Null
New-ItemProperty -Path $policy -Name AutoDetect -PropertyType MultiString -Force -Value @(
'.nvmrc'
'.node-version'
'package.json'
) | Out-Null
New-ItemProperty -Path $policy -Name AutoInstallModuleList -PropertyType MultiString -Force -Value @(
'typescript'
'eslint'
'prettier'
) | Out-Null
New-ItemProperty -Path $policy -Name AllowedSigners -PropertyType MultiString -Force -Value @(
'Contoso Ltd.'
) | Out-Null