Deploy the desktop application with its Windows installer when the fleet is not on Intune: through another deployment tool (an RMM, PDQ Deploy, Configuration Manager or a Group Policy script), by hand, or on virtual desktops. Intune takes the packaged app instead: Deploying the desktop application with Microsoft Intune. The browser extension is a separate guide: Rolling out the browser extension.
Before you start
- You have
flowscope-<version>.exefrom the dashboard's admin setup checklist (Download → Windows installer (.exe)). - The fleet reaches the desktop application's two hosts,
app.flowscope.comandstflowscopeagentrel.blob.core.windows.net, over HTTPS. The full list, with the extension's host: Network and security requirements.
Install
The installer installs for one user, into that user's profile (%LOCALAPPDATA%\flowscope), with no administrator rights. Run it as the person who uses the machine:
- By hand: the person double-clicks the installer, or runs
flowscope-<version>.exe /Sfor a silent install. - With a deployment tool: run
flowscope-<version>.exe /Sin the signed-in user's context. A tool that runs it as SYSTEM or under another account installs it into that account's profile instead.
The desktop application starts when the user signs in to Windows and updates itself. While an organization's fleet is held on a version from the dashboard, no device of that organization moves to a newer one.
If a Defender attack-surface-reduction rule blocks low-prevalence apps, add the exclusion in the Intune guide; it applies to this installer too.
First sign-in
When you add people to the engagement, each person gets a pairing email that points at the app on their machine. They sign in with their work account, accept the agreement, and pair the device. The steps are in Pairing the flowscope app.
Uninstall
Run "%LOCALAPPDATA%\flowscope\uninstall.exe" /S as the same user.
Virtual desktops
The desktop application runs inside each person's desktop session like any per-user app. Its program files are in %LOCALAPPDATA%\flowscope, and its sign-in, settings and queued activity are in %APPDATA%\com.flowscope.agent, both in the user's profile. The device the dashboard shows is that paired install, so a profile that moves between hosts stays one device.
- Persistent desktops (one virtual machine per person): install it as on a physical machine.
- Golden images: install it per user at sign-in instead of in the image, for example with a logon script that runs
flowscope-<version>.exe /Sas the user. An install made while building the image lands in the image builder's profile. - Non-persistent desktops: keep the whole user profile, local and roaming, across sessions, for example with FSLogix profile containers. Without it, the app, its sign-in and any activity not yet uploaded are gone at sign-out, and each new install pairs as a new device.
- Multi-session hosts: each signed-in person runs their own copy in their own profile and pairs it.