Skip to main content
Certified BuildAvailable September 2026.

Deploy with Active Directory

What you'll need:

  • The NVM for Windows MSI installer and MST patch1 (available in the customer portal).
  • Administrative access to your domain controller to create group policies.

Prepare the file server​

GPO software installation reads the MSI and MST from a network share. Domain Computers must be able to reach that share when the policy applies.

Upload the NVM for Windows MSI and MST files from your deployment package to a file server accessible to Domain Computers and any users in the GPO scope. Grant read access to those principals.

Source Files

1. Open the Group Policy Management Console​

  • Using Run Command: Press Windows Key + R, type gpmc.msc, and hit OK.
  • Using Start Menu: Click Start, type Group Policy Management, and select the top application result.
  • Using Server Manager: Open the Microsoft Server Manager Console, click Tools in the upper right-hand corner, and click Group Policy Management.

2. Create Group Policy​

  1. Right-click on the organizational unit containing the computer(s) where NVM for Windows will be installed. Select "Create a GPO in this domain, and link it here.".
  2. Click on the GPO. In the right-hand pane, select the "Scope" tab.
  3. Under "Security Filtering", click "Add". In the "Enter object name to select" section, add Domain Computers. If you have any security groups you wish to limit the installation to, add them as well. Click "Check Names" to assure they are all recognized. Click OK to proceeed.
  4. If "Authenticated Users" is present under "Security Filtering", remove it.
  5. Click the "Delegation" tab. Assure Domain Computers and any groups you specified are in the list.
Create GPO

3. Configure Group Policy Installation Package​

  1. Right-click the GPO and select "Edit".
  2. Navigate to Computer Configuration > Policies > Software Settings > Software installation. Make sure to select the Computer Configuration and not the user configuration. Unlike the public edition, NVM for Windows certified builds are installed at the machine level2.
Find the GPO Software Installation Path
  1. Right-click "Software installation", then select "New > Package". This will open a file selection dialog.
  2. Navigate to the location on your file server where the NVM for Windows installation media was uploaded. Select the .msi file and press "Open". This will present a "Deploy Software" dialog.
  3. Select Advanced on the "Deploy Software" dialog, then "OK".
  4. Click on the "Deployment" tab and choose "Assigned" as the deployment type. Check "Uninstall this application when it falls out of the scope of management" if you wish to remove NVM for Windows when it no longer applies to users.
Automatic Uninstallation via GPO Consequences

Automatically uninstalling NVM for Windows when the application falls out of the scope of management may have an unintended critical impact on users erroneously removed from the installation scope as descrribed below.

Uninstalling NVM for Windows removes all Node.js versions managed by NVM for Windows. This includes any global modules users have installed in these Node.js versions. It is possible to backup the Node.js storage directory before removing. This folder can be manually restored if NVM for Windows needs to be reinstalled later.

Default storage directory: %LOCALAPPDATA%\Author Software\nvm\installs

  1. Click the "Modifications" tab, then click the "Add" button.
  2. Navigate to the file server and select the .mst file1. By doing this, you're agreeing to the EULA on behalf of any user the application is installed for (required).
  3. Press "OK" to close the window.
  4. In the GPO manager, navigate to Computer Configuration > Policies > Administrative Templates > System > Group Policy.
Enable Loopback Processing
  1. Double-click to open the policy, choose "Enabled", and choose Merge or Replace.
  2. Click "OK".

Congratulations, you've created a group policy that will install NVM for Windows on user computers.

Update Client Device

Run gpupdate /force in a terminal on the client device to immediately apply the policy.

Alternative User Configuration with Elevated Privileges

It is also possible to create the installer under the user configuration by elevating user privileges for the installation.

This method moves the deployment to User Configuration so it triggers at logon, but configures Active Directory to temporarily bypass user restriction rules to execute the MSI with administrative authority.

  1. Create or Edit a GPO: Link it to the OU containing your target Users.
  2. Configure Software Installation: Add your MSI under User Configuration > Policies > Software Settings > Software Installation. Select Advanced, and you will now be able to check Install this application at logon.
  3. Elevate Installer Privileges:
    1. Navigate to Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer.
    2. Double-click Always install with elevated privileges.
    3. Set it to Enabled, click Apply, and click OK.
    4. Navigate to User Configuration > Policies > Administrative Templates > Windows Components > Windows Installer.
    5. Double-click Always install with elevated privileges there as well and set it to Enabled.
Temporary Security Risk

Enabling Always install with elevated privileges allows standard users to run any Windows Installer package with elevated privileges, which can be exploited by malicious actors.

Footnotes​

  1. The MST patch must be applied to automatically accept the EULA. ↩ ↩2

  2. If you are upgrading your fleet of computers from public builds to certified builds, the certified build MSI installer will automatically migrate existing Node.js installations and user preferences. ↩