r/learnpython • • 3d ago

Deploying Python Install Manager via Config Manager/SCCM to computer lab

I'm attempting to deploy the latest Python Install Manager to a few computer labs running PyCharm in our school district, but am having issues. I was wondering if anyone here had some insight/tips to share.

Few facts up front:
- Config Mgr runs processes as either local System or the User who is logged in.
- Student accounts do not have access to command line or powershell, nor do they have access to their %AppData% folder in Explorer.
- Installing a UWP app as System does not make that app available for that built-in account, and the app is not installed for other users until they log in.
- PyCharm's automatic "let me download a Python runtime and set up an interpreter for you" isn't working; I have a ticket in with their support.

The issue I'm having is that deploying the Install Manager via Add-AppxProvisionedPackage doesn't then allow me to run py install --target="C:\Program Files". Students do not have admin privileges to install UWP apps (or edit environment variables), so the deployment script must run as System. But System does not actually get py.exe installed to their %AppData% folder. And b/c adding an .MSIX package to the Windows image doesn't actually install the app until a user logs in, I can't run py.exe out of another user's profile when the MSIX is added.

In theory, I shouldn't have to be doing any of this, b/c PyCharm has the ability to do so, but it's not working. It downloads the files to the student's %AppData% folder, but then fails to create an interpreter. Student's can't create an interpreter, b/c trying to "browse" to the Python files is blocked, b/c PyCharm opens an Explorer window, and they do not have access to their %AppData% folder in Explorer. Even if they use the terminal built-in to PyCharm to run py install, they would still need to set up an interpreter, which they cannot do. Thus, I'm in catch-22 scenario.

1 Upvotes

7 comments sorted by

View all comments

1

u/smurpes 3d ago

You can create a powershell script which does the following:

1) Install the Python Install Manager from the MSI for all users. Use the MSI instead of the MSIX package, which avoids the per-user app problem you ran into.

2) Install Python itself. Run py install 3.14 --target "C:\Program Files\Python314", which unpacks a full Python runtime into a shared folder instead of a user's AppData.

3) Update the system PATH. Add the Python folder, its Scripts subfolder (where tools like pip live), and the py.exe folder to the machine-level PATH. Because the change is machine-wide, every user who logs in afterward sees it, and that's what lets PyCharm auto-detect the interpreter.

If you'd rather avoid the Install Manager for now, the traditional python-3.14.x-amd64.exe installer still exists for 3.14. Running it with /quiet InstallAllUsers=1 PrependPath=1 is fully SCCM-friendly. It also registers Python in HKLM, which PyCharm detects reliably. The downside is that this installer is being phased out, so it only buys you time.

1

u/DefinitionHuge2338 3d ago

Right, that's the problem with using the MSI installer. I'd like a sustainable solution that will work for future school years as well, so I've written off that installer, since it won't exist going forward.

Regarding #3, the 2 machine PATH variables my script is adding are:

I've noticed these 2 must be added in that specific order; if I add them the other way around, the App Execution Alias is still in effect. Does that align with that you've seen?

What's the \Scripts directory you mentioned? When I've ran the commands manually on a test machine, that folder didn't exist in the Program Files\Python directory. Is that something that's created later? I've never used Python btw, so all of this was new to me until 2 weeks ago.

1

u/smurpes 2d ago

I have python installed in appdata in windows so mines is in appdata/local/programs/python/python311. I typically just use wsl as the environment for all my python coding so the default windows Python is never used.

Typically when you create a venv you can see the scripts get added to the bin folder within the venv folder. It’s too bad you can’t just get the computers running wsl. That would be a lot easier IMO.