Setup guide

QB-Flow NinjaOne setup.

Create a PowerShell automation in the NinjaOne script library and run it against the Windows devices you want to update.

1

Get your Customer ID

Use the Customer ID emailed to you when you subscribed to QB-Flow. It looks like cus_XXXXXXXXXXXXXXXX. Replace Your_Customer_ID in the script below with your assigned Customer ID.

2

Create the NinjaOne automation

  • Go to Administration > Library > Automation.
  • Click Add automation > New Script.
  • Set Name to QB-Flow Deployment, Language to PowerShell, Operating System to Windows, Architecture to All, and Run As to System.
  • Paste the script below into the script body and save.
  • Run it against a small test group before deploying broadly.
3

PowerShell deployment script

PowerShell
# QB-Flow Deployment for NinjaOne
# Run as a NinjaOne PowerShell automation (Run As: System)
$ErrorActionPreference = "Stop"

# Enter your Customer ID, which can be found in your Welcome Email after subscribing to QB-Flow
$CustomerId = "Your_Customer_ID"

# URL to download the QB-Flow executable
$Url  = "https://flowdevsblob.blob.core.windows.net/qbflow/QB-flow.exe"

# Destination path for the QB-Flow executable
$Dest = "C:\Windows\Temp\qb-flow.exe"

# Log file location
$Log  = "C:\Windows\Temp\qbflow_$(Get-Date -Format 'yyyyMMdd_HHmmss').log"

function Write-Log {
    param([string]$Message)
    $Line = "$(Get-Date -Format 'yyyy-MM-dd HH:mm:ss')  $Message"
    Write-Output $Line
    Add-Content -Path $Log -Value $Line
}

try {
    Write-Log "Starting QB-Flow deployment..."
    Write-Log "Customer ID: $CustomerId"
    Write-Log "Download URL: $Url"
    Write-Log "Destination: $Dest"

    [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12

    if (Test-Path $Dest) {
        Write-Log "Removing existing QB-Flow executable at $Dest"
        Remove-Item $Dest -Force
    }

    Write-Log "Downloading QB-Flow executable..."
    $WebClient = New-Object System.Net.WebClient
    $WebClient.DownloadFile($Url, $Dest)

    if (!(Test-Path $Dest)) {
        throw "Download failed. File was not found at $Dest"
    }
    Write-Log "Download complete."

    Write-Log "Executing QB-Flow..."
    Write-Log "Command: $Dest /customerid $CustomerId"

    $Output = & $Dest "/customerid" $CustomerId 2>&1
    $ExitCode = $LASTEXITCODE
    $Output | ForEach-Object { Write-Log $_ }

    Write-Log "QB-Flow exit code: $ExitCode"
    if ($ExitCode -ne 0) {
        throw "QB-Flow failed with exit code $ExitCode"
    }

    Write-Log "QB-Flow deployment complete."
    exit 0
}
catch {
    Write-Log "ERROR: $($_.Exception.Message)"
    exit 1
}
4

Run the automation

  • Go to Devices and select the devices you want to run QB-Flow on.
  • Click Run > Run Automation > Script and choose QB-Flow Deployment.
  • Confirm Run As: System and click Run Now, or schedule it.
  • Review the output in the device's Activities log.
  • For recurring runs, attach the script to a scheduled automation or policy with a maintenance window.

Deployment notes

  • We recommend running the automation against 1 to 3 test endpoints first before deploying to all devices.
  • The deployment log is written to C:\Windows\Temp\qbflow_[timestamp].log, for example C:\Windows\Temp\qbflow_20260505_143000.log.
  • The endpoint needs internet access and must be able to reach the FlowDevs download URL.
  • PowerShell must be allowed to run through NinjaOne.
  • Endpoint security or application control must not block execution from C:\Windows\Temp.
  • Confirm the correct Customer ID was entered in the script.

NinjaOne-specific notes

  • The NinjaOne agent does not support custom scripts that issue reboots. If you want to reboot endpoints after QB-Flow runs, use NinjaOne's native reboot script as a follow-up step.
  • NinjaOne does not allow the characters & | ; $ > < ` ! in script parameters. The script above avoids parameters and uses hardcoded variables instead, which sidesteps this restriction.
  • NinjaOne's local scripting working directory is C:\ProgramData\NinjaRMMAgent\scripting and is cleared after a run. QB-Flow's own log lives in C:\Windows\Temp\, which is what to check for verification.

Verifying a successful run

QB-Flow doesn't pop a "success" dialog when it finishes. There are two reliable signals you can check on the endpoint:

  • The log file exists. QB-Flow writes a log to C:\Windows\Temp\qbflow_<yyyyMMdd_HHmmss>.log on every run. If a recent log is there, it ran.
  • The QuickBooks installer folder is empty (or no longer contains the latest .msi / .cab files). This is intentional. The QuickBooks updater uses the presence of those files as its trigger to apply an update. QB-Flow removes them after applying the release so Intuit can't re-trigger the same update outside your scheduled window.

Do not open the QuickBooks Update window to verify a run

The QuickBooks Update window inside QuickBooks Desktop is not a passive status screen. Simply opening it can re-enable Intuit's automatic update service in the background, even if you never click "Update Now." That's the exact behavior QB-Flow is built to prevent. If you want to confirm QB-Flow ran, check the log file. That is the source of truth, not the in-app Update window.

Quick verification checklist

  • Recent log present at C:\Windows\Temp\qbflow_*.log
  • QuickBooks installer folder empty or pruned of latest installers
  • Nobody opened the QuickBooks Update window during or after the run

If the log is missing entirely, the script never executed. The usual culprits are AV blocking the signed executable, or a firewall blocking the download URL.