Skip to main content
Certified BuildRequires the governance package. Available September 2026.

Registry Policy Reference

This reference contains the registry keys and values used to manage, secure, and configure NVM for Windows in enterprise environments.

All administrative policies should be enforced within the HKEY_LOCAL_MACHINE (HKLM) hive. Settings applied here are mandatory and will override any conflicting preferences configured by individual users within the local application interface.

Policy Override Behavior

The application evaluates settings in the following order of priority:

  1. HKLM\Software\Policies\Author Software\nvm (Enforced Admin Policy)
  2. HKCU\Software\Author Software\Preferences\nvm (User-defined Preferences)

Available Registry Keys​

See Administrative Templates for GPO and Intune deployment. Download ADMX/ADML from the customer portal. ADMX/ADML ship with the Governance pack; Distro/Audit can still set shared keys via Registry CSP/OMA-URI or .reg.

Overridable in a description means users may also set the equivalent preference (nvm config / HKCU). Machine policy under HKLM\Software\Policies\Author Software\nvm always wins.

NameKeyDescription
Air-gapped license verifyAirGappedEdition: Distro+. Skip live JWKS fetch from licensing.author.io. Verify AccessToken only against the COSE-signed offline JWKS store (JwksCose or nvm-jwks.cose next to nvm.exe). Independent of LocalInstallOnly.

- 0 = off
- 1 = on

Default: 0

REG_DWORD
Version aliasesAliasesOverridable. Centrally managed aliases (e.g. stable=24.9.0). Blocks user-defined aliases when set by policy.

alias=version per entry

REG_MULTI_SZ
Allow cache deletionAllowDownloadCacheDeleteOverridable (allow_download_cache_removal). Whether cached downloads may be removed (nvm cache remove).

- 0 = blocked
- 1 = allowed

Default: 1

REG_DWORD
Allow insecure downloadsAllowInsecureDownloadsOverridable (allow_insecure_downloads). Permit downloads when TLS certificates are expired or invalid.

- 0 = blocked
- 1 = allowed

Default: 0

REG_DWORD
Allow install root changeAllowRootDirChangeOverridable. Whether users may change the install root.

- 0 = blocked
- 1 = allowed

Default: 1

REG_DWORD
Allow native tool installAllowToolInstallOverridable. Allow nvm install native-tools (Python, VS Build Tools, etc.) (shim-only).

- 0 = blocked
- 1 = allowed

Default: 1

REG_DWORD
Allowed code signersAllowedSignersOverridable (allowed_signers). Additional trusted node.exe signers. OpenJS Foundation, Node.js Foundation, and Author Software are always trusted (shim-only). One signer name per entry.

REG_MULTI_SZ
Allowed thumbprintsAllowedThumbprintsOverridable (allowed_thumbprints). Optional SHA-1 Authenticode leaf thumbprints (hex; separators optional). When non-empty, node.exe must match a pin after org allowlist. Empty disables pinning.

REG_MULTI_SZ
Authenticode revocationAuthenticodeRevocationOverridable (authenticode_revocation). CRL/OCSP mode for Authenticode:

- online = network retrieval (install/sign/seed only; default)
- cached = local URL cache only
- disabled = no revocation checks

Shim runtime never uses online (clamped to cached). AirGapped forces cached when online would apply.

Default: online

REG_SZ
Auto-detect filesAutoDetectOverridable (auto_detect). Project files scanned for version pins (shim-only). Overrides defaults.

Default:
  .nvmrc
  .node-version
  package.json

REG_MULTI_SZ
Auto-install missing versionAutoInstallOverridable (auto_install). Auto-install missing detected versions (shim mode).

- 0 = off
- 1 = on

Default: 0

REG_DWORD
Auto-install global modulesAutoInstallModuleListOverridable (auto_installed_modules). Global npm modules installed with each new Node.js version. One module name per entry.

REG_MULTI_SZ
Prompt before auto-installAutoInstallPromptOverridable (auto_install_prompt). Confirm before auto-installing (shim mode).

- 0 = no prompt
- 1 = prompt

Default: 1

REG_DWORD
Auto-use detected versionAutoUseOverridable (auto_use). Auto-switch to detected version when running commands (shim mode).

- 0 = off
- 1 = on

Default: 1

REG_DWORD
Cache downloadsCacheDownloadsOverridable (cache_downloads). Cache downloaded Node.js versions for offline reuse.

- 0 = off/false
- 1 = on/true

Default: 0

REG_DWORD
Default detect fileDefaultDetectFileOverridable (default_detect_file). File written when pinning a version (nvm pin) (shim-only).

Default: .nvmrc

REG_SZ
Disable announcementsDisableAnnouncementsOverridable (disable_announcements). Suppress project and release announcements.

- 0 = shown
- 1 = hidden

Default: 0

REG_DWORD
Disallow eval/string code genDisableEvalAndStringExecutionOverridable (disable_eval_and_string_execution). Shim prepends --disallow-code-generation-from-strings, blocking eval() and new Function() (shim-only). Does not affect node:vm.

- 0 = off
- 1 = on

Default: 0

REG_DWORD
Disable NVM upgradesDisableUpgradeOverridable. Block in-app NVM upgrades (does not block AD/GPO package deployment).

- 0 = allowed
- 1 = blocked

Default: 0

REG_DWORD
Disable version managementEnabledOverridable (nvm on/nvm off). Forces version management on or off. When off, NVM does not manage or redirect Node.js commands.

- 0 = off (nvm off)
- 1 = on

Default: 1

REG_DWORD
Enforce permission modelEnforcePermissionModelOverridable (enforce_permission_model). Shim prepends Node permission-model flag on every node.exe launch (shim-only). Default-deny FS/network unless the process passes --allow-* at runtime. NVM does not inject --allow-* grants.

- Node 23+: --permission
- Node 20–22: --experimental-permission
- Node <20: no flag (unsupported)

- 0 = off
- 1 = on

Default: 0

REG_DWORD
Freeze V8 global objectsFreezeV8GlobalObjectsOverridable (freeze_v8_global_objects). Shim prepends --frozen-intrinsics so built-in prototypes cannot be patched (shim-only; Node.js 12+). Adds measurable startup cost.

- 0 = off
- 1 = on

Default: 0

REG_DWORD
Install rootInstallRootOverridable (root). Directory where Node.js versions are stored. Overrides machine and user preferences.

Default: %LOCALAPPDATA%\Author Software\nvm\installs

REG_SZ
Local install sourceLocalInstallDirOverridable (local_dir). Alternate local directory for Node.js archives (air-gapped mirrors). Overrides cache.

REG_SZ
Local install onlyLocalInstallOnlyOverridable (local_install_only). Restrict installs to LocalInstallDir only.

- 0 = off
- 1 = on

Default: 0

REG_DWORD
Audit loggingLogExecutionsOverridable (log_executions). Log every Node.js invocation to the Windows Event Log (shim-only). Most useful on Audit+ (structured ETW).

- 0 = off
- 1 = on

Default: 0

REG_DWORD
Node.js download mirrorsMirrorNodeOverridable (node_mirror). Ordered mirror list; first successful response wins. See Download Mirrors. Author *.author.io mirrors need Governance licensing — see Version Firewall + Author Mirror.

Default: https://nodejs.org/dist

REG_MULTI_SZ
npm registry mirrorsMirrorNpmOverridable (npm_mirror). Ordered npm registry list. Used as shim registry fallback.

Default: https://registry.npmjs.org

REG_MULTI_SZ
Operating modeOperatingModeOverridable (mode). How NVM for Windows manages Node.js versions.

Shim (recommended) uses signed shims to intercept node, npm, npx, yarn, and pnpm. Required for runtime policies (audit logging, auto-detect, ACL).

Link uses NTFS junctions/symlinks on PATH.

Default: shim

REG_SZ
Package manager mismatch actionPackageManagerMismatchActionOverridable (pm_mismatch_action). Behavior when npm/pnpm/yarn version mismatches Node during install or use (shim-only).

- ignore
- warn
- error

Default: error

REG_SZ
Proxy URLProxyOverridable (proxy). Proxy for downloads. Basic and Bearer work on all certified editions. See Download Mirrors.

REG_SZ
Proxy auth valueProxyAuthOverridable (proxy_auth). Credentials or bearer token (stored in plain text).

- user:pass
- Bearer YOUR_TOKEN

REG_SZ
Proxy auth typeProxyAuthTypeOverridable (proxy_auth_type). Authentication scheme for the configured proxy.

- basic, bearer — all certified editions
- ntlm, negotiate, ntlm,negotiate — Governance only (IWA); PAC/WPAD also Governance-only

REG_SZ

Governance Keys​

These keys are part of the Governance feature set. They appear in the Governance ADMX pack.

NameKeyDescription
Verbose mirror license metadataApplyVerboseLicenseMetadataWhen on, Author mirror license JWTs include identity claims (idp_username, idp_machine_name, idp_machine_id). Does not set AccessToken/AccessKey.

- 0 = omit claims
- 1 = include claims

Default: 0

REG_DWORD
npm module minimum ageNpmModuleMinimumAgeMinimum package publish age (cooldown), in minutes, for package manager installs (shim mode). Auto-converts for npm/pnpm/yarn.

Default: 0 (disabled)

REG_DWORD
Allowed Node.js versionsVersionAllowListAllow list for installs. Invalid entries fail enforcement. Allow wins over block. Also feeds Author-mirror JWT version claims (magic tokens such as EOL, ALPHA, MAINTENANCE, ALL).

Supports exact semver, wildcards (e.g. 20.x), aliases, and NOT/! negation (one rule per line).

REG_SZ
Blocked Node.js versionsVersionBlockListBlock list for installs. Same rule formats as VersionAllowList.

REG_SZ
License secrets

AccessToken, AccessKey, and JwksCose are not ADMX policies. Deploy with portal scripts (Set-NvmWindowsAccessToken.ps1 on stock certified build; Set-NvmWindowsLicensing.ps1 for governance builds, which also sets AccessKey for Author mirrors) or nvm license.

GPO vs registry values

Several ADMX policies use inverted GPO labels (e.g. Disable automatic version detection writes AutoUse=0 when enabled). The tables document the registry value admins should deploy via GPO, Intune (imported ADMX or Registry CSP), or Entra custom OMA-URI.

Registry Import Example​

Save as nvm-policy.reg, replace placeholder paths and URLs for your environment, then double-click or run reg import nvm-policy.reg from an elevated command prompt.

REG_MULTI_SZ keys

MirrorNode, MirrorNpm, Aliases, AutoDetect, AutoInstallModuleList, AllowedSigners, and AllowedThumbprints are REG_MULTI_SZ (one string per entry). A .reg line like "MirrorNode"="url1,url2" creates a wrong REG_SZ. Set those with ADMX, Registry CSP, or PowerShell (below) — not comma-joined REG_SZ values.

Windows Registry Editor Version 5.00

; =============================================================================
; NVM for Windows — machine policy (HKLM)
; Path: HKLM\SOFTWARE\Policies\Author Software\nvm
; =============================================================================

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Author Software\nvm]

; --- Core / environment ---
"OperatingMode"="shim"
"Enabled"=dword:00000001
"InstallRoot"="%LOCALAPPDATA%\\Author Software\\nvm\\installs"
"AllowRootDirChange"=dword:00000000
"LocalInstallDir"="D:\\Node\\local_mirror"
"LocalInstallOnly"=dword:00000000
"AirGapped"=dword:00000000

; --- Version ACL (Governance) ---
"VersionAllowList"="20.x\r\n22.x"
"VersionBlockList"="!20.17.0"

; --- Network / downloads (SZ / DWORD only here; MULTI_SZ via PowerShell below) ---
"Proxy"="http://proxy.example.corp:8080"
"ProxyAuthType"="ntlm"
; "ProxyAuth"="service-account:password"
; "ProxyAuth"="Bearer YOUR_TOKEN_HERE"
"CacheDownloads"=dword:00000001
"AllowDownloadCacheDelete"=dword:00000000
"AllowInsecureDownloads"=dword:00000000
"ApplyVerboseLicenseMetadata"=dword:00000000
"DisableUpgrade"=dword:00000001
"DisableAnnouncements"=dword:00000001

; --- Shim runtime (requires OperatingMode=shim) ---
"DefaultDetectFile"=".nvmrc"
"AutoUse"=dword:00000001
"AutoInstall"=dword:00000000
"AutoInstallPrompt"=dword:00000001
"AllowToolInstall"=dword:00000000
"PackageManagerMismatchAction"="error"
"LogExecutions"=dword:00000001
"EnforcePermissionModel"=dword:00000001
"FreezeV8GlobalObjects"=dword:00000001
"DisableEvalAndStringExecution"=dword:00000001
"NpmModuleMinimumAge"=dword:000005a0

After importing the .reg (or instead of it for list values), set multi-string keys elevated:

$policy = 'HKLM:\SOFTWARE\Policies\Author Software\nvm'

New-ItemProperty -Path $policy -Name MirrorNode -PropertyType MultiString -Force -Value @(
'https://mirror.author.io/runtime/nodejs'
'https://nodejs.org/dist'
) | Out-Null

New-ItemProperty -Path $policy -Name MirrorNpm -PropertyType MultiString -Force -Value @(
'https://npm.example.corp'
'https://registry.npmjs.org'
) | Out-Null

New-ItemProperty -Path $policy -Name Aliases -PropertyType MultiString -Force -Value @(
'stable=24.9.0'
'lts=22.17.0'
) | Out-Null

New-ItemProperty -Path $policy -Name AutoDetect -PropertyType MultiString -Force -Value @(
'.nvmrc'
'.node-version'
'package.json'
) | Out-Null

New-ItemProperty -Path $policy -Name AutoInstallModuleList -PropertyType MultiString -Force -Value @(
'typescript'
'eslint'
'prettier'
) | Out-Null

New-ItemProperty -Path $policy -Name AllowedSigners -PropertyType MultiString -Force -Value @(
'Contoso Ltd.'
) | Out-Null