> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Install Formal Endpoint on Windows

> Install the Formal Endpoint MSI on Windows, sign in, and connect to Resources

## Overview

The Formal Endpoint for Windows ships as an MSI installer. It installs the `formal` CLI and the Endpoint's background agent, and adds a **Formal** shortcut to the Start menu.

On Windows, the Endpoint connects you to Resources through local listeners with `formal connect`. [Transparent Mode](/docs/guides/client-apps/desktop-app#transparent-mode) and [network rules](/docs/guides/network-rules) are not available on Windows yet.

## Prerequisites

* 64-bit Windows on an x86-64 (amd64) processor. There is no Arm64 package.
* Administrator rights. The MSI installs for all users of the machine.
* Windows Hello set up with a fingerprint, face, or PIN, if your policies use the [MFA action](/docs/guides/policies/enforcement#mfa-action).

## Install

<Steps>
  <Step title="Download the installer">
    In the [Control Plane](https://app.formal.ai), click **Download Formal Endpoint** at the bottom of the sidebar, then choose **Windows**. You can also download the latest MSI directly:

    ```text theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
    https://static-assets.formalcloud.net/desktop-app/windows/formal-desktop_latest_windows_amd64.msi
    ```
  </Step>

  <Step title="Run the installer">
    Open the MSI and follow the installer. To install silently, run this from an elevated command prompt:

    ```powershell theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
    msiexec /i formal-desktop_latest_windows_amd64.msi /qn
    ```

    The installer puts `formal.exe` under `Program Files\Formal` and adds that folder to the system `PATH`.
  </Step>

  <Step title="Start the Endpoint">
    Open the Start menu and select **Formal**. The shortcut starts the Endpoint agent in the background.
  </Step>

  <Step title="Sign in">
    Open a new terminal so it picks up the updated `PATH`, then sign in:

    ```powershell theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
    formal auth login
    ```

    A browser window opens for Formal sign-in.
  </Step>
</Steps>

## Verify

```powershell theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
formal auth whoami
formal ls
```

`formal auth whoami` shows your Formal user. `formal ls` lists the Resources available to you. Connect to one with `formal connect <resource-name>`. See the [CLI reference](/docs/guides/client-apps/cli).

## Upgrade

The Endpoint can't upgrade itself on Windows, and `formal upgrade` reports that it isn't supported. To move to a new version:

1. Uninstall **Formal** from the **Apps** section of Windows **Settings**.
2. Install the new MSI.

<Warning>
  Uninstall the current version before you install a new one. Installing a new
  MSI over an existing install registers a second copy of Formal, and
  uninstalling either copy later leaves the other's files behind.
</Warning>

## Deploy to a Fleet

Deploy the MSI with your Windows device management tool, such as Microsoft Intune, as a standard Windows app. Use the silent install command above. The [MDM Endpoint Rollout](/docs/guides/integrations/mdm#endpoint-rollout) files in the Control Plane are for macOS.

## Files and Logs

| Item | Location |
| - | - |
| Configuration | `%USERPROFILE%\.formal\config.toml`. See [Configuration](/docs/guides/client-apps/configuration). |
| Logs | `%LOCALAPPDATA%\Formal\Logs` |
| Endpoint data | `%LOCALAPPDATA%\Formal` |

## Troubleshooting

<AccordionGroup>
  <Accordion title="formal is not recognized as a command">
    **Cause:** The terminal started before the installer updated `PATH`. **Fix:** Open a new terminal. If the problem persists, sign out of Windows and back in.
  </Accordion>

  <Accordion title="The CLI cannot connect to the Formal app">
    **Cause:** The Endpoint agent isn't running. **Fix:** Start **Formal** from the Start menu, then retry the command.
  </Accordion>

  <Accordion title="MFA prompts fail">
    **Cause:** Windows Hello isn't set up, or you're connected over Remote Desktop, where Windows Hello is unavailable. **Fix:** Set up Windows Hello on the device and sign in locally.
  </Accordion>
</AccordionGroup>

## Next Steps

<CardGroup cols={2}>
  <Card title="Formal Endpoint" icon="desktop" href="/docs/guides/client-apps/desktop-app">
    Review authentication and connection options
  </Card>

  <Card title="CLI Reference" icon="terminal" href="/docs/guides/client-apps/cli">
    Connect to Resources from the terminal
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.