Kavanati — deploying to a team
Last updated: 6 October 2026 · applies from version 1.12.0 · describes version 1.12.0
1. Windows: the file
Kavanati-windows.exe is a single self-contained file (about 50 MB). It needs no installer and no admin
rights, and it runs per user: the first run registers "Start with Windows" for that user (HKCU\…\Run) and
adds a Start Menu shortcut. Download the current build from kavanati.com and keep it on a share or in
your deployment tool.
- Where to put it: a folder the user can write to, for example
%LOCALAPPDATA%\Kavanati\Kavanati.exe. The built-in updater replaces the file in place, so a read-only location such asProgram Filesworks only when you also turn self-update off (section 3) and ship new versions yourself. - How to start it: run it once per user (a logon script, an Intune PowerShell script in user context, or your RMM). From then on it starts with Windows by itself.
- SmartScreen: the Windows build is not code-signed yet, so SmartScreen may warn the first time it runs on a computer. A deployment tool that launches it does not see the prompt. The file names, paths and endpoints to allow-list in antivirus and EDR tools are in the security overview.
2. The license key, without typing it anywhere
From version 1.12.0 the app looks for a managed license key at start-up. The first place that has one wins:
| Where | Value | Use it when |
|---|---|---|
HKLM\SOFTWARE\Policies\Kavanati | LicenseKey (REG_SZ) =
KAV-XXXX-XXXX-XXXX-XXXX | Group Policy, Intune or RMM for the whole computer (recommended). |
HKCU\SOFTWARE\Policies\Kavanati | same value | A per-user policy or a logon script without admin rights. |
Kavanati.license next to the exe | a text file whose first line is the key; lines starting
with # are comments | You copy a folder and nothing else. Handy for RMM tools and small offices. |
At start-up each computer activates itself against the license server and takes one seat (section 6). The user sees "License: KAV-… · managed by your organization" in the Plan menu, and the "Disconnect this device" item is hidden — a managed key would simply come back at the next start. If the computer is offline at logon, the app retries every few hours; "Check for updates…" in the menu forces a retry right away. When the key has no free seat left, the user gets one short message and the app keeps working on the free plan until IT adds computers to the license.
A personal Pro key that a user had entered before is replaced by the organization's key on a managed computer. Removing the policy value does not remove the license from computers that already activated; to move a seat, release the old computer from the key (write to support@kavanati.com) or let it free itself after 45 days unseen.
3. Updates: self-update or managed
By default the app downloads a new version in the background, verifies its SHA-256 against the published value and asks the user to restart. If you deploy software centrally, turn that off:
HKLM\SOFTWARE\Policies\Kavanati→SelfUpdate(REG_DWORD) =0(HKCUworks too).- The app then only shows "v1.x available — updates are managed by your organization" in its menu and never downloads or replaces anything. You ship the new exe the same way you shipped the first one.
- The app still reads
kavanati.com/version.jsonevery 6 hours: that is where the signed plan policy and the "minimum supported version" live. It carries no identifier (see the security overview).
4. Sample: one script for a logon task, Intune or RMM
User context, no admin rights. Adjust the share path and the key. The copy runs only when the file is missing, so a self-updated newer build is not overwritten; when you turn self-update off, copy unconditionally on each new release.
# Kavanati rollout (per user) — PowerShell 5.1+
$key = "KAV-XXXX-XXXX-XXXX-XXXX"
$dir = Join-Path $env:LOCALAPPDATA "Kavanati"
$exe = Join-Path $dir "Kavanati.exe"
New-Item -ItemType Directory -Force $dir | Out-Null
if (-not (Test-Path $exe)) { Copy-Item "\\server\software\Kavanati-windows.exe" $exe -Force }
$pol = "HKCU:\SOFTWARE\Policies\Kavanati"
New-Item -Path $pol -Force | Out-Null
Set-ItemProperty -Path $pol -Name LicenseKey -Value $key
# Set-ItemProperty -Path $pol -Name SelfUpdate -Value 0 -Type DWord # only if IT ships updates
if (-not (Get-Process Kavanati -ErrorAction SilentlyContinue)) { Start-Process $exe }
With Group Policy Preferences, create the two registry values under HKLM\SOFTWARE\Policies\Kavanati
instead of the HKCU lines, and use a user logon script just to copy and start the exe. An ADMX template is
on the list (section 8).
5. Mac
Kavanati-mac.zip contains Kavanati.app, Developer-ID signed and notarized by Apple. Place it in
/Applications with your MDM or a script. Each user must approve Accessibility and Input
Monitoring once; the app opens the right System Settings pane and starts working the moment they are granted.
Accessibility can be pre-approved through a PPPC profile. Apple does not let MDM pre-approve Input Monitoring, so the
user clicks that one.
The license key and the update switch are read from the app's preferences domain, com.melogix.langguard
(the app's original internal name, kept for compatibility):
| Where | Keys | Use it when |
|---|---|---|
A configuration profile (Jamf, Intune, Kandji, Mosyle…), payload type com.melogix.langguard |
LicenseKey (string), SelfUpdate (boolean) | Managed Macs. Wins over everything below. |
sudo defaults write /Library/Preferences/com.melogix.langguard LicenseKey "KAV-…" |
same keys | A script for all users on the Mac. |
defaults write com.melogix.langguard LicenseKey "KAV-…" | same keys | One user, no admin rights. |
/Library/Application Support/Kavanati/Kavanati.license | a text file whose first line is the key | Tools that push files rather than preferences. |
Minimal profile payload (inside a standard .mobileconfig):
<dict>
<key>PayloadType</key><string>com.melogix.langguard</string>
<key>PayloadIdentifier</key><string>com.example.kavanati.license</string>
<key>PayloadUUID</key><string>6F0C4A2E-1B2D-4C3E-9F8A-7E6D5C4B3A21</string>
<key>PayloadVersion</key><integer>1</integer>
<key>LicenseKey</key><string>KAV-XXXX-XXXX-XXXX-XXXX</string>
<key>SelfUpdate</key><false/>
</dict>
Everything in section 2 about silent activation, retries, the managed label and seats applies to Macs the same way. The app adds itself as a login item on the first run.
6. Seats: how computers are counted
- A Business license covers the number of computers you bought (5 to 1,000). One key, Windows and Mac mixed.
- Each computer takes one seat, identified by a one-way hash of its machine ID. All Windows users on the same computer share that seat, and reinstalling does not take a new one.
- When the key is full, computers not seen for 45 days free their seat automatically. We can also release a specific computer on request.
- Add computers any time: the checkout quantity can be raised, and the key grows immediately. Nothing is charged automatically after a pilot.
7. Measuring a pilot
The app keeps a counter on each computer, never sent anywhere: the menu header reads "Corrections: 1,284 · This month: 212". For a 30-day pilot, ask the participants for that line (or a screenshot of the menu) on day 21 or 30. Request a pilot key on the teams page; it covers up to the number of computers you name, for 30 days, and simply expires.
8. What isn't ready yet
- A code-signed Windows build (planned through the Microsoft Store) and an MSI for silent, machine-wide installs.
- An ADMX template; today the two registry values are set directly.
- Central control of the user-facing menu (hiding "Report a problem", locking settings).
- VDI and roaming profiles have not been tested; the seat is tied to the machine, not the user.
Questions from IT, procurement or security: support@kavanati.com. See also the security & IT overview and Kavanati for teams.
כוונתי — פריסה בארגון
עדכון אחרון: 6 באוקטובר 2026 · תקף מגרסה 1.12.0 · מתאר את גרסה 1.12.0
1. Windows: הקובץ
Kavanati-windows.exe הוא קובץ אחד עצמאי (כ‑50 MB). לא צריך התקנה ולא הרשאות מנהל, והוא רץ לכל משתמש
בנפרד: ההפעלה הראשונה רושמת "הפעלה עם Windows" לאותו משתמש (HKCU\…\Run) ומוסיפה קיצור בתפריט התחל. מורידים
את הגרסה הנוכחית מ‑kavanati.com ושומרים אותה בשיתוף רשת או בכלי הפריסה שלכם.
- איפה לשים: בתיקייה שהמשתמש יכול לכתוב אליה, למשל
%LOCALAPPDATA%\Kavanati\Kavanati.exe. מנגנון העדכון המובנה מחליף את הקובץ במקומו, ולכן מיקום לקריאה בלבד כמוProgram Filesמתאים רק אם גם מכבים את העדכון העצמי (סעיף 3) ומפיצים גרסאות חדשות בעצמכם. - איך מפעילים: מריצים פעם אחת לכל משתמש (סקריפט כניסה, סקריפט PowerShell של Intune בהקשר משתמש, או ה‑RMM שלכם). מכאן והלאה הוא עולה עם Windows לבד.
- SmartScreen: גרסת Windows עדיין לא חתומה בחתימת קוד, ולכן SmartScreen עשוי להזהיר בהרצה הראשונה במחשב. כלי פריסה שמפעיל את הקובץ לא רואה את ההודעה. שמות הקבצים, הנתיבים והכתובות שצריך לאשר באנטי‑וירוס וב‑EDR מופיעים בסקירת האבטחה.
2. מפתח הרישיון, בלי להקליד אותו בשום מקום
מגרסה 1.12.0 האפליקציה מחפשת בהפעלה מפתח רישיון מנוהל. המקום הראשון שבו יש מפתח קובע:
| איפה | הערך | מתי משתמשים |
|---|---|---|
HKLM\SOFTWARE\Policies\Kavanati | LicenseKey (REG_SZ) =
KAV-XXXX-XXXX-XXXX-XXXX | Group Policy, Intune או RMM לכל המחשב (מומלץ). |
HKCU\SOFTWARE\Policies\Kavanati | אותו ערך | מדיניות למשתמש או סקריפט כניסה בלי הרשאות מנהל. |
Kavanati.license ליד ה‑exe | קובץ טקסט שהשורה הראשונה בו היא המפתח; שורות שמתחילות
ב‑# הן הערות | מעתיקים תיקייה וזהו. נוח לכלי RMM ולמשרדים קטנים. |
בהפעלה כל מחשב מפעיל את הרישיון מול שרת הרישוי ותופס מושב אחד (סעיף 6). המשתמש רואה בתפריט Plan את השורה "License: KAV-… · managed by your organization", והפריט "Disconnect this device" מוסתר — מפתח מנוהל פשוט היה חוזר בהפעלה הבאה. אם המחשב לא מחובר לרשת בזמן הכניסה, האפליקציה מנסה שוב כל כמה שעות; "Check for updates…" בתפריט מכריח ניסיון מיידי. כשלמפתח אין מושב פנוי, המשתמש מקבל הודעה קצרה אחת והאפליקציה ממשיכה לעבוד במסלול החינמי עד ש‑IT מוסיף מחשבים לרישיון.
מפתח Pro אישי שמשתמש הזין קודם מוחלף במפתח הארגון במחשב מנוהל. הסרת ערך המדיניות לא מסירה את הרישיון ממחשבים שכבר הופעלו; כדי להעביר מושב, משחררים את המחשב הישן מהמפתח (כתבו ל‑support@kavanati.com) או נותנים לו להשתחרר לבד אחרי 45 יום בלי פעילות.
3. עדכונים: עצמיים או מנוהלים
כברירת מחדל האפליקציה מורידה גרסה חדשה ברקע, מאמתת את ה‑SHA‑256 שלה מול הערך שפורסם ומבקשת מהמשתמש להפעיל מחדש. אם אתם מפיצים תוכנה מרכזית, כבו את זה:
HKLM\SOFTWARE\Policies\Kavanati←SelfUpdate(REG_DWORD) =0(גםHKCUעובד).- האפליקציה תציג אז בתפריט רק "v1.x available — updates are managed by your organization", ולא תוריד ולא תחליף שום דבר. את ה‑exe החדש מפיצים כמו את הראשון.
- האפליקציה ממשיכה לקרוא את
kavanati.com/version.jsonכל 6 שעות: שם נמצאים מדיניות המסלולים החתומה ו"הגרסה המינימלית הנתמכת". הבקשה לא נושאת שום מזהה (ראו סקירת האבטחה).
4. דוגמה: סקריפט אחד למשימת כניסה, ל‑Intune או ל‑RMM
הקשר משתמש, בלי הרשאות מנהל. התאימו את נתיב השיתוף ואת המפתח. ההעתקה רצה רק כשהקובץ חסר, כדי לא לדרוס גרסה חדשה שהתעדכנה לבד; אם כיביתם את העדכון העצמי, העתיקו תמיד בכל גרסה חדשה.
# Kavanati rollout (per user) — PowerShell 5.1+
$key = "KAV-XXXX-XXXX-XXXX-XXXX"
$dir = Join-Path $env:LOCALAPPDATA "Kavanati"
$exe = Join-Path $dir "Kavanati.exe"
New-Item -ItemType Directory -Force $dir | Out-Null
if (-not (Test-Path $exe)) { Copy-Item "\\server\software\Kavanati-windows.exe" $exe -Force }
$pol = "HKCU:\SOFTWARE\Policies\Kavanati"
New-Item -Path $pol -Force | Out-Null
Set-ItemProperty -Path $pol -Name LicenseKey -Value $key
# Set-ItemProperty -Path $pol -Name SelfUpdate -Value 0 -Type DWord # only if IT ships updates
if (-not (Get-Process Kavanati -ErrorAction SilentlyContinue)) { Start-Process $exe }
עם Group Policy Preferences יוצרים את שני ערכי הרישום תחת HKLM\SOFTWARE\Policies\Kavanati במקום שורות
ה‑HKCU, ומשתמשים בסקריפט כניסה רק כדי להעתיק ולהפעיל את ה‑exe. תבנית ADMX ברשימה (סעיף 8).
5. Mac
Kavanati-mac.zip מכיל את Kavanati.app, חתומה ב‑Developer ID ומאושרת (notarized) על ידי Apple.
שימו אותה ב‑/Applications דרך ה‑MDM או סקריפט. כל משתמש צריך לאשר פעם אחת Accessibility
ו‑Input Monitoring; האפליקציה פותחת את החלונית הנכונה בהגדרות המערכת ומתחילה לעבוד ברגע שההרשאות ניתנו. את
Accessibility אפשר לאשר מראש בפרופיל PPPC. את Input Monitoring Apple לא מאפשרת לאשר מראש דרך MDM, ולכן את זו המשתמש
מאשר בעצמו.
מפתח הרישיון ומתג העדכונים נקראים מדומיין ההעדפות של האפליקציה, com.melogix.langguard (השם הפנימי המקורי
של האפליקציה, שנשמר לתאימות):
| איפה | מפתחות | מתי משתמשים |
|---|---|---|
פרופיל תצורה (Jamf, Intune, Kandji, Mosyle…), payload מסוג com.melogix.langguard |
LicenseKey (string), SelfUpdate (boolean) | מחשבי Mac מנוהלים. גובר על כל מה שלמטה. |
sudo defaults write /Library/Preferences/com.melogix.langguard LicenseKey "KAV-…" |
אותם מפתחות | סקריפט לכל המשתמשים ב‑Mac. |
defaults write com.melogix.langguard LicenseKey "KAV-…" | אותם מפתחות | משתמש אחד, בלי הרשאות מנהל. |
/Library/Application Support/Kavanati/Kavanati.license | קובץ טקסט שהשורה הראשונה בו היא המפתח | כלים שדוחפים קבצים ולא העדפות. |
payload מינימלי לפרופיל (בתוך .mobileconfig רגיל):
<dict>
<key>PayloadType</key><string>com.melogix.langguard</string>
<key>PayloadIdentifier</key><string>com.example.kavanati.license</string>
<key>PayloadUUID</key><string>6F0C4A2E-1B2D-4C3E-9F8A-7E6D5C4B3A21</string>
<key>PayloadVersion</key><integer>1</integer>
<key>LicenseKey</key><string>KAV-XXXX-XXXX-XXXX-XXXX</string>
<key>SelfUpdate</key><false/>
</dict>
כל מה שבסעיף 2 על הפעלה שקטה, ניסיונות חוזרים, תווית "מנוהל" ומושבים תקף ל‑Mac באותה צורה. האפליקציה מוסיפה את עצמה כפריט כניסה בהפעלה הראשונה.
6. מושבים: איך סופרים מחשבים
- רישיון Business מכסה את מספר המחשבים שרכשתם (5 עד 1,000). מפתח אחד, Windows ו‑Mac יחד.
- כל מחשב תופס מושב אחד, לפי גיבוב חד‑כיווני של מזהה המכונה. כל המשתמשים באותו מחשב Windows חולקים את המושב, והתקנה מחדש לא תופסת מושב חדש.
- כשהמפתח מלא, מחשבים שלא נראו 45 יום משחררים את המושב שלהם אוטומטית. אפשר גם לבקש שחרור של מחשב מסוים.
- מוסיפים מחשבים בכל רגע: מעלים את הכמות ברכישה והמפתח גדל מיד. אחרי פיילוט לא מחויבים אוטומטית בכלום.
7. מדידת פיילוט
האפליקציה שומרת מונה בכל מחשב, שלא נשלח לשום מקום: כותרת התפריט מציגה "Corrections: 1,284 · This month: 212". בפיילוט של 30 יום בקשו מהמשתתפים את השורה הזאת (או צילום מסך של התפריט) ביום 21 או 30. מבקשים מפתח פיילוט בעמוד לעסקים; הוא מכסה עד מספר המחשבים שתציינו, ל‑30 יום, ופשוט פג.
8. מה עוד לא מוכן
- גרסת Windows חתומה בחתימת קוד (מתוכנן דרך Microsoft Store) ו‑MSI להתקנה שקטה לכל המחשב.
- תבנית ADMX; היום מגדירים את שני ערכי הרישום ישירות.
- שליטה מרכזית בתפריט למשתמש (הסתרת "Report a problem", נעילת הגדרות).
- VDI ופרופילים נודדים לא נבדקו; המושב קשור למכונה, לא למשתמש.
שאלות מ‑IT, רכש או אבטחה: support@kavanati.com. ראו גם את סקירת האבטחה וה‑IT ואת כוונתי לעסקים.