Update and Manage CSE Desktop App Versions

Update the desktop app across your devices and keep it up to date
Updated On: Oct 02, 2026

Overview

This doc explains how to keep the Cloud Secure Edge (CSE) desktop app up to date across your fleet, including a fleet that was built up over time and now runs a mix of app versions and installation methods.

Update the CSE Windows app to v4.5.1 or later. Earlier versions do not reliably renew device registration on their own. End users have to open the app and renew manually before registration expires, and devices that miss that window have to be re-registered. Enable App Auto Update, or deploy v4.5.1 manually: x86 EXE, x86 MSI, ARM EXE, ARM MSI.

There are two ways to keep the app up to date. We recommend App Auto Update.

ApproachHow it worksWho it suits
App Auto Update (recommended)CSE updates the app on each device silently, with no action from you or the end user.Most orgs.
Manual updatesYou deploy each version yourself, through a Device Manager, a remote monitoring and management (RMM) platform, or by hand.Orgs that need to approve and schedule every version.
{:.table.table-bordered.table-responsive}

You can also combine the two: deploy a specific version manually when you need a fleet on it immediately, then leave App Auto Update on to carry the fleet forward.


Terminology

TermWhat it means
Legacy Banyan installDesktop app v3.28.x or earlier, installed from a Banyan-branded installer.
CSE EXE installDesktop app v4.0.0 or later, installed from the .exe installer, either by hand or through the zero touch script.
CSE MSI installDesktop app v4.3.0 or later, installed from the Windows .msi package. See Installing the CSE Desktop App for Windows (MSI).
App Auto UpdateThe org-level setting in the CSE Command Center that lets CSE update the app on end user devices silently. See App Auto Update.
{:.table.table-bordered.table-responsive}

Legacy Banyan installs and CSE installs are the same application under two names. No product migration is required between them.


App Auto Update requires desktop app v4.2.0 or later. Whether a device needs anything done first depends only on its version:

Installed versionAction required before enabling
Any MSI installNone. The MSI was released at v4.3.0, so every MSI install already meets the requirement.
CSE EXE v4.2.0 or laterNone.
CSE EXE v4.0.0 to v4.1.xUpdate the device once. See Update Methods.
Legacy Banyan, v3.28.x or earlierUpdate the device once. See Update Methods.
{:.table.table-bordered.table-responsive}

Devices below v4.2.0 need one manual update to become eligible. After that, CSE keeps them up to date.

Enable App Auto Update

In the CSE Command Center, go to Settings > SonicWall CSE Client > the Deployment tab, and turn on App Auto Update. For full steps, and for how this setting interacts with the per-device MDM flag, see App Auto Update.

App Auto Update is an org-level setting, so enable it separately in each org. If you are a managed service provider (MSP), no single control turns it on across every org you administer. Orgs provisioned after the April 2026 release have it on by default. Orgs provisioned before that release do not, so turn it on by hand.


Manual Updates #

Choose this approach to approve and schedule every version yourself. Leave App Auto Update off and deploy each version using Update Methods on your own schedule.

With App Auto Update off, end users on desktop app v4.2.0 and later receive an update notification and can apply the update themselves. To prevent those prompts, set mdm_disable_auto_update to true. See Customizing desktop app functionality.


Update Methods #

These methods apply to both approaches. Use them to deploy a version manually, whether as the one-time update that makes a device eligible for App Auto Update or as your ongoing update process.

The method depends on whether the app was installed from an EXE or an MSI. The installed version does not affect which method to use, and no path requires an intermediate upgrade: any version can be updated directly to the current release.

Each method preserves the device's org registration, device certificate, tokens, mdm-config.json, and user settings. End users are not asked to re-register or to re-enter an invite code.

We do not provide a script that detects which installer is on a device and selects the update path. Determine the installation method from your own deployment records before updating.



Update a Single Device

To update one device outside of a fleet rollout, use either of the following:

  • The in-app update. When a new version is available and the end user receives an update notification in the app, they can apply the update by selecting it. Notifications appear when App Auto Update is off, or on devices earlier than v4.2.0. See How auto update works.
  • The installer. Download the current installer from the CSE desktop app download page and run it over the existing install, using the installation method already on the device.

Installing an older version over a newer one is blocked. See Register the Desktop App.