Documentation Get help

Deploy Flowstate Desktop for Windows with Intune

This guide is for IT. Flowstate Desktop for Windows works with or without device management. This page covers Intune. People who install it themselves follow Set up Flowstate Desktop for Windows.

What gets installed

ItemLocationNotes
Flowstate serviceC:\Program Files\Flowstate\ServiceWindows service Flowstate. Runs as LocalSystem, starts automatically and restarts on failure. Listens on 127.0.0.1:47820 only.
Flowstate tray appC:\Program Files\Flowstate\AppStarts when someone signs in.
Service state%ProgramData%\FlowstateThe local certificate authority and logs. Access is limited to SYSTEM and Administrators.
Per-user state%LocalAppData%\FlowstateThe person’s session and a copy of the public certificate.

The installer is per-machine and self-contained, so devices need no .NET runtime.

1. Download the installer

2. Add the app in Intune

  1. In the Intune admin centre, go to Apps → Windows → Add.

  2. Choose Line-of-business app and upload the MSI.

  3. Set the install command:

    msiexec /i Flowstate-x.y.z-x64.msi /qn MANAGEDROUTING=1

    Use the name of the file you downloaded.

  4. Assign the app to a device group, with the install context set to System.

Intune fills in the uninstall command for MSI apps. It’s msiexec /x "{product code}" /qn.

Install properties

PropertyWhat it does
MANAGEDROUTING=1Writes HKLM\SOFTWARE\Policies\Flowstate\ManagedRouting as 1. The app treats Turn on routing as done and hides the pause switch. You then apply the routing settings yourself.

It’s optional. Without it, people turn on routing themselves. Everyone signs in with their own Flowstate account.

If you prefer a policy to install properties, set the same two values with a custom OMA-URI profile or a PowerShell remediation script. Policy values win over anything a person types.

Managed routing

With MANAGEDROUTING=1, Flowstate doesn’t change proxy settings. Apply these for each user with an Intune Settings catalog profile or a PowerShell script:

  • Proxy auto-config URL. Set it to http://127.0.0.1:47820/proxy.pac. It’s the AutoConfigURL value under HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings.
  • User environment variables. Set HTTPS_PROXY to http://127.0.0.1:47820 and NO_PROXY to localhost,127.0.0.1. Do this only if you want terminal tools such as Claude Code and Codex covered.
  • Certificate trust. Each device generates its own local certificate authority. For silent trust, export the public certificate once from a pilot device (%LocalAppData%\Flowstate\ca.pem) and push it as a trusted certificate profile. Otherwise leave trust to the app’s third setup step.

The auto-config file always ends with a direct connection, so a stopped service never blocks browsing.

Updates

New versions install over the old one. The service restarts during an upgrade. For detection, use the MSI product code or the file version of C:\Program Files\Flowstate\App\Flowstate.exe.

Uninstall

Uninstalling removes the program files, the service and the policy keys. It doesn’t edit anything inside user profiles.

Ask people to choose Pause routing or Quit in the tray app, or to sign out, before you uninstall. That restores their proxy settings. If a person keeps a stale HTTPS_PROXY pointing at 127.0.0.1:47820, command-line tools fail until it’s removed. Signing out and in, or a remediation script that deletes the value, clears it.