# Install Muniment Desktop on Windows

Signed Windows release installers are available: MSI per user, MSI per machine, and NSIS per user. Choose one download for the local app, which will need no account. The paid console will hold the organization’s sign-in, sharing, and routing rules, so a fleet install will carry no company key.

## Choose a package

The default `muniment.msi` package installs under `%LocalAppData%` for the current user without administrator rights. The `-machine.msi` package installs under `%ProgramFiles%`, requires administrator rights, and serves every user of the computer. The `muniment-nsis.exe` executable installs under `%LocalAppData%`, requires no administrator rights, and serves only the current user.

## Verify the per-machine MSI

Windows release packages have Azure Trusted Signing signatures under Green Kangaroo, LLC. The commands below verify the signed per-machine MSI, `muniment-machine.msi`. The site publishes no verification procedure for the per-user NSIS executable today. Before fleet deployment, require both checks to pass. SignTool must report a successful signature check. PowerShell must report the signer as `CN=Green Kangaroo LLC`.

**SignTool signature verification**

```
signtool verify /pa /v muniment-machine.msi
```

**PowerShell publisher verification**

```
(Get-AuthenticodeSignature .\muniment-machine.msi).SignerCertificate.Subject
```

## Per-user MSI

Run the per-user MSI in the target user’s session. Use the MSI whose name does not end in `-machine.msi`.

**silent per-user MSI install**

```
msiexec.exe /i "muniment.msi" /qn /norestart
```

**silent per-user MSI uninstall**

```
msiexec.exe /x "muniment.msi" /qn /norestart
```

## Per-machine MSI

Run the MSI from an elevated Command Prompt or a deployment agent with administrator rights. Use the artifact whose name ends in `-machine.msi`. Do not set `ALLUSERS` on another MSI to change its scope.

**silent MSI install**

```
msiexec.exe /i "muniment-machine.msi" /qn /norestart
```

**silent MSI uninstall**

```
msiexec.exe /x "muniment-machine.msi" /qn /norestart
```

`/qn` displays no interface and `/norestart` prevents Windows Installer from restarting the computer. The calling system should handle a restart if `msiexec.exe` returns 3010.

## Per-user NSIS

Run both commands in the target user’s session so `%LocalAppData%` and the per-user registration refer to that user. The installer does not require administrator rights. The `/S` switch is case-sensitive.

**silent NSIS install**

```
muniment-nsis.exe /S
```

**silent NSIS uninstall**

```
"%LocalAppData%\muniment\uninstall.exe" /S
```

## Upgrade and removal support

The per-machine MSI has a stable Windows Installer upgrade identity, so a newer muniment MSI upgrades an installed copy in place. The verified package contract does not promise upgrade-in-place behavior for the per-user NSIS installer. Use the MSI where supported fleet upgrades are required.
