Deploy with Active Directory
What you'll need:
- The NVM for Windows MSI installer and MST patch1 (available in the customer portal).
- Administrative access to your domain controller to create group policies.
Prepare the file server
GPO software installation reads the MSI and MST from a network share. Domain Computers must be able to reach that share when the policy applies.
Upload the NVM for Windows MSI and MST files from your deployment package to a file server accessible to Domain Computers and any users in the GPO scope. Grant read access to those principals.
1. Open the Group Policy Management Console
- Using Run Command: Press Windows Key + R, type
gpmc.msc, and hit OK. - Using Start Menu: Click Start, type Group Policy Management, and select the top application result.
- Using Server Manager: Open the Microsoft Server Manager Console, click Tools in the upper right-hand corner, and click Group Policy Management.
2. Create Group Policy
- Right-click on the organizational unit containing the computer(s) where NVM for Windows will be installed. Select "Create a GPO in this domain, and link it here.".
- Click on the GPO. In the right-hand pane, select the "Scope" tab.
- Under "Security Filtering", click "Add". In the "Enter object name to select" section, add
Domain Computers. If you have any security groups you wish to limit the installation to, add them as well. Click "Check Names" to assure they are all recognized. Click OK to proceeed. - If "Authenticated Users" is present under "Security Filtering", remove it.
- Click the "Delegation" tab. Assure
Domain Computersand any groups you specified are in the list.
3. Configure Group Policy Installation Package
- Right-click the GPO and select "Edit".
- Navigate to Computer Configuration > Policies > Software Settings > Software installation. Make sure to select the Computer Configuration and not the user configuration. Unlike the public edition, NVM for Windows certified builds are installed at the machine level2.
- Right-click "Software installation", then select "New > Package". This will open a file selection dialog.
- Navigate to the location on your file server where the NVM for Windows installation media was uploaded. Select the
.msifile and press "Open". This will present a "Deploy Software" dialog. - Select
Advancedon the "Deploy Software" dialog, then "OK". - Click on the "Deployment" tab and choose "Assigned" as the deployment type. Check "Uninstall this application when it falls out of the scope of management" if you wish to remove NVM for Windows when it no longer applies to users.
Automatically uninstalling NVM for Windows when the application falls out of the scope of management may have an unintended critical impact on users erroneously removed from the installation scope as descrribed below.
Uninstalling NVM for Windows removes all Node.js versions managed by NVM for Windows. This includes any global modules users have installed in these Node.js versions. It is possible to backup the Node.js storage directory before removing. This folder can be manually restored if NVM for Windows needs to be reinstalled later.
Default storage directory: %LOCALAPPDATA%\Author Software\nvm\installs
- Click the "Modifications" tab, then click the "Add" button.
- Navigate to the file server and select the
.mstfile1. By doing this, you're agreeing to the EULA on behalf of any user the application is installed for (required). - Press "OK" to close the window.
- In the GPO manager, navigate to Computer Configuration > Policies > Administrative Templates > System > Group Policy.
- Double-click to open the policy, choose "Enabled", and choose Merge or Replace.
- Click "OK".
Congratulations, you've created a group policy that will install NVM for Windows on user computers.
Run gpupdate /force in a terminal on the client device to immediately apply the policy.
It is also possible to create the installer under the user configuration by elevating user privileges for the installation.
This method moves the deployment to User Configuration so it triggers at logon, but configures Active Directory to temporarily bypass user restriction rules to execute the MSI with administrative authority.
- Create or Edit a GPO: Link it to the OU containing your target Users.
- Configure Software Installation: Add your MSI under User Configuration > Policies > Software Settings > Software Installation. Select Advanced, and you will now be able to check Install this application at logon.
- Elevate Installer Privileges:
- Navigate to Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer.
- Double-click Always install with elevated privileges.
- Set it to Enabled, click Apply, and click OK.
- Navigate to User Configuration > Policies > Administrative Templates > Windows Components > Windows Installer.
- Double-click Always install with elevated privileges there as well and set it to Enabled.
Enabling Always install with elevated privileges allows standard users to run any Windows Installer package with elevated privileges, which can be exploited by malicious actors.