Skip to content
OpenAdminOS

Download

Download the local-first desktop app.

Download OpenAdminOS for Windows, macOS, or Linux, review release notes, and inspect the open-source Microsoft 365 admin agent runtime before running it against a tenant.

Current release

v0.6.4

macOS

Use the DMG for a normal workstation install. Use the PKG when you need a managed deployment package.

.dmg

DefaultApple Silicon · signed and notarized

Direct install for individual workstations

SHA-256

e687e510c38fdee2c0ac15bfa0de60bbed57db7b266129a4b68acfd05bedf15c
Download .dmg

.pkg

ManagedApple Silicon · signed and notarized

Installer package for Intune, Jamf, Munki, or MDM rollout

SHA-256

52d100924a6a2c0813c43597024ab845ccba11c4c36b01697ddd01e7bf85d7f8
Download .pkg

Linux x64

Linux packages are unsigned preview builds. Verify the SHA-256 hash before installing.

AppImage

PortableLinux x64 · unsigned

Runs on most desktop distributions

SHA-256

3d6c1394eb597c3733329d9424d952f8fc2e76c993c58d0541261cfa2fad14f4
Download AppImage

.deb

Linux x64 · unsigned

Ubuntu and Debian-family systems

SHA-256

e13fd6c0d08d6fa32ff01a112e0a1f2f39ef5cb6c2cee36856dce239fab955ed
Download .deb

.rpm

Linux x64 · unsigned

Fedora, RHEL, and compatible systems

SHA-256

79dc91cdfa0214f6568a04a20572ce449921587ede503687013e8ab90a0bf739
Download .rpm

Windows x64

Signed per-user installer, no administrator rights needed. If SmartScreen warns, confirm the publisher is Ugurlabs UG (haftungsbeschränkt) or verify the SHA-256 hash.

.exe

DefaultWindows x64 · signed

Per-user installer. Does not need local administrator rights.

SHA-256

6a2f3f7b207604b6ed131e3281ec066bf2097366681c97f3d417f59c17764954
Download .exe

Source

Inspect the code before connecting a tenant.

The app, runtime, registry contract, and SDK are open-source under the MIT License.

Inspect the repository

Before first run

Connect a tenant and choose a model provider.

OpenAdminOS uses MSAL for Microsoft 365 tenant consent and Microsoft Graph access. Local model providers keep prompts and tenant context on the workstation. Hosted providers are optional and labeled before tenant context leaves the device.

Read-only agents can run after consent. Write agents always stop at a diff confirmation screen before changing tenant state.

Read the trust model