Deploy Flowstate Desktop for Windows with Intune
This guide is for IT. Flowstate Desktop for Windows works with or without device management. This page covers Intune. People who install it themselves follow Set up Flowstate Desktop for Windows.
What gets installed
| Item | Location | Notes |
|---|---|---|
| Flowstate service | C:\Program Files\Flowstate\Service | Windows service Flowstate. Runs as LocalSystem, starts automatically and restarts on failure. Listens on 127.0.0.1:47820 only. |
| Flowstate tray app | C:\Program Files\Flowstate\App | Starts when someone signs in. |
| Service state | %ProgramData%\Flowstate | The local certificate authority and logs. Access is limited to SYSTEM and Administrators. |
| Per-user state | %LocalAppData%\Flowstate | The person’s session and a copy of the public certificate. |
The installer is per-machine and self-contained, so devices need no .NET runtime.
1. Download the installer
2. Add the app in Intune
-
In the Intune admin centre, go to Apps → Windows → Add.
-
Choose Line-of-business app and upload the MSI.
-
Set the install command:
msiexec /i Flowstate-x.y.z-x64.msi /qn MANAGEDROUTING=1Use the name of the file you downloaded.
-
Assign the app to a device group, with the install context set to System.
Intune fills in the uninstall command for MSI apps. It’s msiexec /x "{product code}" /qn.
Install properties
| Property | What it does |
|---|---|
MANAGEDROUTING=1 | Writes HKLM\SOFTWARE\Policies\Flowstate\ManagedRouting as 1. The app treats Turn on routing as done and hides the pause switch. You then apply the routing settings yourself. |
It’s optional. Without it, people turn on routing themselves. Everyone signs in with their own Flowstate account.
If you prefer a policy to install properties, set the same two values with a custom OMA-URI profile or a PowerShell remediation script. Policy values win over anything a person types.
Managed routing
With MANAGEDROUTING=1, Flowstate doesn’t change proxy settings. Apply these for each user with an Intune Settings catalog profile or a PowerShell script:
- Proxy auto-config URL. Set it to
http://127.0.0.1:47820/proxy.pac. It’s theAutoConfigURLvalue underHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings. - User environment variables. Set
HTTPS_PROXYtohttp://127.0.0.1:47820andNO_PROXYtolocalhost,127.0.0.1. Do this only if you want terminal tools such as Claude Code and Codex covered. - Certificate trust. Each device generates its own local certificate authority. For silent trust, export the public certificate once from a pilot device (
%LocalAppData%\Flowstate\ca.pem) and push it as a trusted certificate profile. Otherwise leave trust to the app’s third setup step.
The auto-config file always ends with a direct connection, so a stopped service never blocks browsing.
Updates
New versions install over the old one. The service restarts during an upgrade. For detection, use the MSI product code or the file version of C:\Program Files\Flowstate\App\Flowstate.exe.
Uninstall
Uninstalling removes the program files, the service and the policy keys. It doesn’t edit anything inside user profiles.
Ask people to choose Pause routing or Quit in the tray app, or to sign out, before you uninstall. That restores their proxy settings. If a person keeps a stale HTTPS_PROXY pointing at 127.0.0.1:47820, command-line tools fail until it’s removed. Signing out and in, or a remediation script that deletes the value, clears it.