When deploying Rublon MFA for Windows using Microsoft Endpoint Configuration Manager (MECM), it is important to detect the version currently installed on client machines. This allows MECM to determine whether an installation or update is required and prevents the connector from being installed repeatedly.
You can detect the installed version using the Rublon MFA registry key, an EXE-specific Windows uninstall registry key, or the MSI Product Code. Select the method that corresponds to your deployment.
Locating Rublon MFA for Windows Version Information
Option 1: Rublon MFA Custom Registry Key
This is the recommended method if you want to detect the connector version independently of whether it was installed using the EXE or MSI installer.
Registry path:
HKEY_LOCAL_MACHINE\SOFTWARE\Rublon\WindowsLogon\Data
• Value name: Version
• Data type: Version
• Description: The Version value contains the complete installed version of Rublon MFA for Windows.
• Usage in MECM: Configure the detection method to check the Version value and compare it with the version you want to deploy.
Because this value belongs to the connector rather than to a specific installer, you can use it for deployments involving either the EXE or MSI installer.
Option 2: Windows Uninstall Registry Key for the EXE Installer
Use this method when Rublon MFA for Windows was installed using the EXE installer.
Registry path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF8E23F0-68F5-4ED9-9B09-67DA991736CF}_is1
GUID information:
• {FF8E23F0-68F5-4ED9-9B09-67DA991736CF} is the fixed identifier used by the EXE installer.
• The _is1 suffix is part of the registry key name created by the EXE installer.
• This registry key is created regardless of whether the EXE installer is run in GUI or Silent Mode.
Relevant values:
• DisplayVersion: Contains the complete version number as a string.
• VersionMajor: Contains the major part of the version number.
• VersionMinor: Contains the minor part of the version number.
Windows uses this registry key to display the EXE installation in Apps & Features or Control Panel.
Usage in MECM:
Configure the detection method to check DisplayVersion, VersionMajor, or VersionMinor and compare the value with the version you want to deploy.
This method applies only to installations performed using the EXE installer. If the connector was installed or updated using the MSI installer, use Option 1 or Option 3.
Option 3: Windows Installer Detection for the MSI Installer
Use this method when Rublon MFA for Windows is deployed using the MSI installer.
MECM can read the Product Code directly from the MSI package and use it to determine whether the package is installed.
To configure this detection method:
1. Set Setting type to Windows Installer.
2. Select Browse and choose the RublonForWindows-6.7.0.msi file.
3. MECM will automatically read the Product Code from the MSI package.
4. To check only whether the MSI package is installed, use the Product Code existence rule.
5. To detect a specific version, add a Product Version rule and compare it with the version you are deploying.
This method applies only to installations performed using the MSI installer. When deploying a newer MSI version, select the MSI file for that version and verify the Product Code and Product Version used by the detection rule.
Configuring the MECM Detection Method
Follow these steps to configure version detection in MECM.
1. Open the MECM console.
2. Go to Software Library → Application Management → Applications.
3. Select the existing Rublon MFA for Windows application or create a new application.
4. Open the application’s deployment type properties and go to the Detection Method tab.
5. Select Add Clause and configure one of the following detection methods.
Method 1: Rublon MFA Custom Registry Key
Use this method for either EXE or MSI deployments:
Method 2: EXE Installer Registry Entry
Use this method only for deployments using the EXE installer:
Method 3: MSI Product Code
Use this method only for deployments using the MSI installer:
Configure the appropriate method for each deployment type. Do not require both the EXE-specific registry entry and the MSI Product Code within the same detection rule, because an endpoint may contain only the entry corresponding to the installer currently in use.
7. Apply the changes and save the application configuration.
Helpful Links
Rublon MFA for Windows Logon and RDP – Documentation
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article