Contented Desktop App for Enterprise: Deployment, Network Requirements & Updates
Last updated: August 24, 2026
A guide for IT administrators deploying and managing the Contented desktop app across managed devices.
Who this guide is for
This guide is for IT teams deploying Contented centrally rather than having users install it themselves. It applies if:
Your users can't install software on their own machines
You deploy applications centrally (Intune, SCCM, Group Policy, etc.)
A user has landed on a screen asking for an email and password to download the app. That is usually a sign they should be on the MSI path instead.
What the MSI installer is
The MSI installer is a packaged version of the Contented desktop app built for centralised, IT-managed deployment. It lets your team install and maintain Contented on managed machines without individual users downloading anything.
One thing to know upfront: there is currently no automatic updater. Updates are distributed as new MSI links and need to be deployed manually across machines.
Network requirements (allowlisting)
If your organisation uses a firewall or web proxy, allowlist the domains below for the app to function correctly. All connections use HTTPS or WSS (WebSocket Secure) on port 443.
Domain | Protocol | Port | Purpose |
|---|---|---|---|
| HTTPS | 443 | Core application |
| HTTPS | 443 | API |
| HTTPS | 443 | Core application |
| HTTPS | 443 | App updates and downloads |
| HTTPS | 443 | In-app help and support |
| HTTPS | 443 | Authentication |
| HTTPS | 443 | Recording upload (cloud storage) |
| WSS | 443 | Real-time events (WebSocket) |
Notes for IT administrators
All traffic uses TLS encryption on port 443. No additional ports need to be opened.
If your organisation performs TLS inspection (SSL interception), the app relies on the Windows OS trust store and is compatible with corporate proxy certificates installed via Group Policy.
The two amazonaws.com domains are Contented's own AWS infrastructure (cloud storage and real-time API), hosted in the ap-southeast-2 (Sydney) region.
IP-based allowlisting is not recommended. Cloud infrastructure IPs change, so domain-based rules are more reliable.
Deployment
The MSI deploys like any standard Windows installer. Most teams push it through Intune, though SCCM and Group Policy work equally well.
Before rolling out to all machines:
Confirm the domains above are allowlisted on your firewall or proxy.
Test the install and login on one machine first.
Confirm a test user can log in and upload a recording. Login and upload rely on different domains, so a successful login alone doesn't confirm uploads will work.
Updates
Updates are currently manual. There is no automatic updater yet. New versions reach you two ways:
Self-serve changelog and download page. You can pull the latest MSI and read release notes at any time, so you can decide whether an update is worth deploying.
COMING SOON
Email notification. Your registered IT contact is emailed when a new version is available.
Cadence: because installs are manual, MSI updates are released less frequently than the standard app, roughly every month
Recommendation: We highly recommend keeping the app as up to date as possible for the best user experience.
We would love your feedback: how do you prefer to get MSI updates? Would you use an MSI auto-updater?
Troubleshooting
Symptom | Likely cause | Fix |
|---|---|---|
Can't log in / can't stay logged in | Firewall or proxy blocking the auth domains | Allowlist |
Can't upload recordings | Firewall blocking cloud storage or the WebSocket | Allowlist the two |
Uploads suddenly failing after previously working | Token issue, often on an outdated build | Log out and back in. If it persists, update to the latest MSI |
Login or upload works for some users but not others | Inconsistent proxy or VPN routing | Confirm the same allowlist rules apply to all affected users and any VPN split-tunnel config |
If an issue isn't resolved by the above, get in touch with the domains and steps you've already tried and we'll work through it directly.
Getting the smoothest experience
The single biggest predictor of a smooth deployment is having one named IT contact who owns the Contented technical relationship. Someone who can be emailed or called directly, and looped in when something needs resolving.
If your Contented deployment is managed by an external IT provider, please let us know who our point of contact should be.