> ## Documentation Index
> Fetch the complete documentation index at: https://docs.langdock.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage desktop app updates

> The desktop app updates itself by default. IT admins can turn automatic updates off by policy on Windows and macOS and ship each version through their MDM instead.

## Managing desktop app updates

The desktop app updates itself by default, so people get fixes without IT. If IT owns the rollout, you can turn automatic updates off by policy and ship each new version through your MDM. Use it when you test every release before rollout, run non-persistent VDI from a base image (golden image), or manage Macs where standard users can't update apps.

## Before you begin

Choose one owner for versions before you deploy, so the app's updater and your MDM don't work against each other:

* **Langdock manages versions**: leave the policy unset and deploy Langdock once. In Intune, use the [default detection script](/en/admin/desktop-app/deploy#intune). It only checks that Langdock is there, so Intune keeps reporting **Installed** after the app updates itself.
* **Your MDM manages versions**: turn automatic updates off and upload each new version yourself. In Intune, use the detection script with `$MinVersion`. The [plain MSIX alternative](/en/admin/desktop-app/deploy#intune) also needs automatic updates off.

On Windows, self-updates need Windows 10 version 2004 or later. On older versions, your MDM always manages versions.

## Turn off automatic updates

<Warning>
  With automatic updates off, Langdock doesn't install security fixes on its own. IT is responsible for deploying every new version, including security updates, promptly.
</Warning>

| Platform | Where | Value |
| - | - | - |
| Windows | `HKLM\SOFTWARE\Policies\Langdock` or `HKCU\SOFTWARE\Policies\Langdock` | `disableAutoUpdates`, `REG_DWORD`, `1` |
| macOS | Configuration profile, domain `com.langdock.desktop` | `disableAutoUpdates`, boolean, `true` |

On Windows, the HKLM value wins over HKCU, including an explicit `0`. Set the value with Intune, Group Policy registry preferences, or PowerShell:

```powershell theme={null}
New-Item -Path 'HKLM:\SOFTWARE\Policies\Langdock' -Force
New-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Langdock' -Name disableAutoUpdates -PropertyType DWord -Value 1 -Force
```

In Matrix42 Empirum, add this line to the `[Reg:Product]` section of the package:

```ini theme={null}
HKLM,"SOFTWARE\Policies\Langdock","disableAutoUpdates",0x00010001,1
```

On macOS, only values an MDM profile writes count: **Application & Custom Settings** in Jamf Pro, a preference file in Intune, or a custom profile in Kandji. A per-user profile wins over a device profile, and a user's own `defaults write` is ignored. Standard users can't update an app that an MDM installed to `/Applications`, so turn updates off for those devices. The [sample configuration profile](/en/admin/desktop-app/deploy#macos) sets this policy.

Keep these in mind:

* The app reads the policy at launch. Restart it after you change the policy.
* Set the policy before the first launch.
* An invalid value turns updates off.
* The policy doesn't undo an update that's already downloaded, and it can't point the app at a different update source.

## Verify the setting

Restart Langdock and open **Check for Updates**. With updates off, it shows "Updates are managed by your organization." and the app doesn't check for or download updates.

To check the value on a Windows device, run:

```powershell theme={null}
reg query HKLM\SOFTWARE\Policies\Langdock /v disableAutoUpdates /reg:64
```

## Deploy approved versions

Download the new version from the [Enterprise Guide for Langdock Desktop](/en/admin/desktop-app/deploy#which-file-do-i-need) and roll it out like the first one:

* **Intune**: add a new Win32 app with the newer `.intunewin`. Under **Supersedence**, add the previous app and set **Uninstall previous version** to **No**, so people keep their app data. Create its detection script with `$MinVersion` set to the new version and upload it.
* **Intune with the plain MSIX**: upload the new MSIX to the same line-of-business app.
* **Configuration Manager, Empirum, ACMP, and baramundi**: create a new application or package version with the newer MSIX or kit. You don't need to uninstall the old version first.

Ask people to quit Langdock before the update, because Windows can't replace a running package.

## Turn updates back on

Delete the `disableAutoUpdates` value, or set it to `0`, and restart Langdock. On Windows, check both HKLM and HKCU: a `1` in HKCU still turns updates off when HKLM has no value. On macOS, remove the key from the configuration profile.

In Intune, upload the [default detection script](/en/admin/desktop-app/deploy#intune) again, which doesn't check the version. In other tools, detect the deployed version or newer, as the [commands for other tools](/en/admin/desktop-app/deploy#other-tools) do.

Updates run per user, so different users on one device can be on different versions for a while.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.