Skip to main content

Deploying the desktop app

IT admins can install the desktop app on managed devices so people find Langdock in the Start menu or Applications folder without installing it themselves. Use it when you want to roll Langdock out to a whole department, keep versions under IT control, or pre-approve permissions before the first launch.

Which file do I need?

Don’t deploy the regular Langdock Setup.exe through an MDM. It installs for one user only, so when an MDM runs it as SYSTEM, your users won’t get the app. Use the MSIX packages on this page for managed Windows installs.

Windows

  • Windows version: Requires 64-bit Windows 10 version 1809 or later. Automatic updates require Windows 10 version 2004 or later. On older versions, the app doesn’t update itself, so push each new release through your MDM.
  • Sideloading: Langdock isn’t installed from the Microsoft Store, so Windows must allow apps from other sources. This is on by default since Windows 10 version 2004. On older versions, or if your organization turned it off, enable the AllowAllTrustedApps policy, called Allow all trusted apps to install in Group Policy.
  • AppLocker: only if you enforce Packaged app Rules. Add a publisher rule and select Langdock on a reference device. AppLocker fills in the publisher and package name.
Windows installs MSIX packages per user. Each tab provisions Langdock for the whole device, so every user gets it at their next sign-in, including standard users. Pick the tab for your tool:
Use the ready-made Win32 package to install Langdock for every user of a device.

Intune Win32 package (x64)

.intunewin for most Windows PCs

Intune Win32 package (ARM64)

.intunewin for Windows on ARM PCs
The .intunewin wraps the signed Langdock MSIX with install and uninstall scripts. Intune provisions Langdock for every user of the device, including standard users, and doesn’t reinstall it after the app updates itself. To package it yourself, download the plain MSIX for x64 or ARM64.
To test on one device first, run Add-AppxPackage -Path .\Langdock-x64.msix. It installs for the signed-in user only.
1

Add the app

In the Intune admin center, go to Apps > Windows > Add, select Windows app (Win32), and upload the .intunewin. For details, see Microsoft’s guide to Win32 apps in Intune.
2

Fill in the app information

Name is prefilled from the package. You can use these values for the rest:
3

Set the program

Set Install command to Deploy.cmd Install, Uninstall command to Deploy.cmd Uninstall, and Install behavior to System. Return codes are 0 success, 3010 soft reboot, and 1 failed.
4

Set the requirements

Set Check operating system architecture to Yes. Create a separate app for each package:Never select x86, because there’s no 32-bit build. If you rely on automatic updates, choose Windows 10 2004 instead.
Want only one app? Select x64 and ARM64 on the x64 package and skip the ARM64 package. ARM devices then run Langdock through x64 emulation on Windows 11, which is slower. One app per architecture stays the recommended setup. Never deploy both packages to the same ARM device.
5

Set the detection rule

After the install, Intune checks whether Langdock is on the device. If it doesn’t find it, it reports the install as failed and tries again. Built-in file and registry rules don’t fit here. The MSIX install folder and its registry entries contain the version, which changes with every self-update. The detection script checks the provisioned package by name instead, so it works for every version.Run this command in a PowerShell window. No admin rights needed; the file is saved to your Desktop as Detect-Langdock.ps1.
Under Detection rules, select Use a custom detection script and upload Detect-Langdock.ps1. Set Run script as 32-bit process on 64-bit clients and Enforce script signature check to No.Don’t want to create the script yourself? Download the deployment kit for x64 or ARM64 and upload its Deploy.ps1 as the detection script. It checks for the kit’s version or newer.
Turned off automatic updates? Create the script with this command instead. Set $MinVersion to the version you upload. Raise it each time you upload a new version to the same app, or add the new version as a new app with Supersedence.
The script prints Installed when Langdock is provisioned on the device. Intune treats output plus exit code 0 as detected. Without output, Langdock counts as not installed.
With $MinVersion, it only prints Installed for that version or newer:
6

Assign the app

Assign it as Required to a device group. Start with a pilot group.
Use this if you don’t want the .intunewin wrapper or a detection script, and you control versions yourself.Upload the x64 or ARM64 MSIX as a Line-of-business app. Assign it as Required to a device group and change Install Context to Device. Intune then provisions Langdock for every user.Turn off automatic updates first. Intune’s built-in detection expects the version you uploaded. Upload each new version to the app yourself.
Windows installs every MSIX to C:\Program Files\WindowsApps, and you can’t change that location.

Network requirements

The desktop app loads the same Langdock web app as your browser, so allow the same domains you allow for Langdock in the browser. It also needs: The app uses the Windows system proxy settings, including PAC files.

Shared devices and VDI

Each user gets their own copy of Langdock with their own sign-in and app data. Updates run per user, so different users on one device can be on different versions for a while. On non-persistent VDI, provision Langdock in the base image (golden image) your virtual desktops start from. Turn off automatic updates in the base image too. For each new Langdock version, update the base image and roll it out. Per-user app data lives in %LOCALAPPDATA%\Packages\com.langdock.desktop.msix_b9czaxkzpqt8m. Keep that folder in your profile container, or people have to sign in again in every session. Langdock hasn’t been validated on Windows multi-session hosts or Remote Desktop Session Host yet.

Microphone access

The first time Langdock uses the microphone, Windows asks “Let Langdock access your microphone?” once per user. To approve microphone access up front, configure the LetAppsAccessMicrophone policy through the Intune Settings Catalog or the Group Policy Let Windows apps access the microphone. Add the Langdock package family name to the force allow list:

Inventory and uninstall

Langdock appears under Settings > Apps, not in Programs and Features or the classic Uninstall registry key. To check which devices have it, use the kit’s detection scripts or run these commands from an elevated PowerShell:
Deploy.cmd Uninstall as SYSTEM removes Langdock for all users. Remove-AppxPackage removes only the current user’s install. Windows deletes each user’s app data with the package. Policy keys you set stay in place.

macOS

1

Deploy the DMG (required)

The DMG is signed and notarized. It works on Apple silicon and Intel Macs.

macOS DMG

Apple silicon and Intel Macs
  • Intune: add a macOS app (DMG).
  • Jamf Pro and Kandji: upload the DMG as a custom app that installs Langdock.app to /Applications.
2

Add a configuration profile (optional)

You only need a profile to turn off automatic updates. It sets the boolean disableAutoUpdates to true in the com.langdock.desktop domain. Langdock then stops all update checks and downloads, and you deploy each new version.Deliver the setting through your MDM: Application & Custom Settings in Jamf Pro, a preference file in Intune, or a custom profile in Kandji. A user’s own defaults write is ignored. The setting applies after Langdock restarts.
Langdock in /Applications is owned by root, so standard users can’t update it without admin rights. On those Macs, set disableAutoUpdates and push each update yourself.
Users approve microphone access at the first macOS prompt. They don’t need admin rights for that. Accessibility, used for the dictation shortcut and media pause, needs a one-time admin approval in System Settings on Macs where users are standard users.

Automatic updates

The desktop app updates itself by default. To ship each version through your MDM instead, turn automatic updates off with the disableAutoUpdates policy. Pick one owner before you deploy, so the updater and your MDM don’t work against each other. See Manage desktop app updates.

Troubleshooting

The detection script doesn’t find Langdock. Upload the detection script from the Intune steps as a .ps1 file and set Run script as 32-bit process on 64-bit clients to No.
Sideloading or an app install policy blocks the package. Allow sideloading of trusted apps on the device and check AppLocker or WDAC.
Windows doesn’t install an older version over a newer one. Deploy the current version, or remove Langdock first if you need to roll back.
Windows can’t replace a package that’s running. Deploy.cmd Uninstall closes Langdock first. For updates you deploy yourself, ask people to quit Langdock and retry.
The device can’t build the certificate chain. Make sure the GlobalSign Code Signing Root R45 is in the machine’s trusted root store. Windows usually adds it through its automatic root updates.
The kit failed and wrote the reason to its error output. Common causes: the kit files come from different releases (“The MSIX does not match this deployment script”), or it didn’t run as SYSTEM or admin in 64-bit PowerShell. Run Deploy.cmd instead of calling Deploy.ps1 directly.
Provisioning registers the app at the next sign-in. Ask existing users to sign out and back in.
Add the Packaged app Rules rule for Langdock. The kit scripts also fall under Script Rules. Check the AppLocker event logs Packaged app-Deployment, Packaged app-Execution, and MSI and Script for blocks.
Win32 apps can take up to about an hour to arrive. To speed it up, click Sync in Company Portal under Settings or restart the Microsoft Intune Management Extension service.
  • Intune: C:\ProgramData\Microsoft\IntuneManagementExtension\Logs, mainly AppWorkload.log and IntuneManagementExtension.log.
  • Package installs: Event Viewer under Applications and Services Logs > Microsoft > Windows > AppXDeployment-Server > Microsoft-Windows-AppXDeploymentServer/Operational.
  • Langdock app: main.log in %LOCALAPPDATA%\Packages\com.langdock.desktop.msix_b9czaxkzpqt8m\LocalCache\Roaming\com.langdock.desktop.msix\logs for each user.

FAQ

No. Langdock ships an MSIX, which Intune, Configuration Manager, Matrix42 Empirum, ACMP, baramundi, and Group Policy startup scripts can all deploy silently and machine-wide. MSIX apps have no MSI product code or Uninstall registry key, so use the kit’s detection scripts or Get-AppxProvisionedPackage instead of MSI-based detection.
No. Download the MSIX from this page. Devices don’t need Microsoft Store access.
Run Add-AppxProvisionedPackage or Deploy.cmd Install as SYSTEM, the same way you run other install commands in your tool. For Empirum, follow the Matrix42 Empirum steps in the Other tools tab under Windows. For ACMP, copy the extracted kit to the client with a Client Command and run Deploy.cmd Install in the system context.
No. With a machine-wide deployment, standard users get Langdock at sign-in without admin rights. Only the provisioning step needs SYSTEM or admin rights. If your policies restrict app installs by standard users, turn off automatic updates and ship each version through your MDM.
Yes. See Microphone access. Without the policy, each user answers the Windows prompt once.
Only if your MDM manages versions. If Langdock manages versions, you deploy once and Langdock updates itself. Windows doesn’t install an older version over a newer one. To roll back, remove Langdock and deploy the older version.
Both can be installed on one device. They’re separate apps with their own sign-in. Langdock doesn’t remove the EXE install. Uninstall it under Settings > Apps if you standardize on the MSIX.
Not yet. The MSIX on this page connects to Langdock cloud at app.langdock.com. Desktop apps for dedicated deployments aren’t available yet.