Managed deployment using Microsoft Endpoint Manager (Intune)
Overview
Deploy the Push browser extension for Google Chrome, Microsoft Edge, Firefox, and Brave using Microsoft Endpoint Manager (Intune).
Because the installation requires creating policies and deploying a PowerShell script, we recommend you implement the changes first in a test environment.
Note: If you are deploying the Push browser extension for multiple browsers, review each section of this documentation to avoid missing settings that need to be applied in each instance.
Deploying to Google Chrome
Generate the extension config
The first step is to generate a config file in the Push admin console. Skip to the next step if you've already done so.
1. In the Push admin console, go to Browsers > Enrollment options.
data:image/s3,"s3://crabby-images/441b5/441b5a8293918c2772bf843b98e4536b450c6d7a" alt="Push app browser enrollment options: KB 10052/3/4/5/6/8"
2. Then select a Managed enrollment.
data:image/s3,"s3://crabby-images/fbe85/fbe85383bcf598994cda651613caafb459994852" alt="Managed browser enrollment screen - docs - showing Arc"
3. Select Device Management Software, choose Chrome as the browser, and Windows as the OS. Then click Generate config. This will allow you to download a config file specific to your team.
data:image/s3,"s3://crabby-images/fabb6/fabb634fb3a9f4078e2b404ce05f79147513361e" alt="Push app - Device Management Software Chrome: KB 10054"
4. Download and extract the zip file.
Create a configuration profile
In Microsoft Endpoint Manager, select Devices (1) > Configuration (2) > Create (3) > New Policy (4).
Select Windows 10 and later (5) as your target platform and Settings catalog (6) as the Profile type. Then click the Create (7) button.
data:image/s3,"s3://crabby-images/2783f/2783f77dd03a62bb32186d9b0e6c048a55ea2dd2" alt="InTune - Create Configuration Profile: KB 10054 10055"
Enter a descriptive name for the profile (8), and a description if required, then click Next (9).
data:image/s3,"s3://crabby-images/67842/67842fe76a6e8be37bb95f1daf2d70f1a3079a48" alt="InTune - Device Management Profile Creation Chrome: KB 10054"
In the Setting picker, search for Chrome, select Google Chrome Extensions, and select Configure the list of force-installed apps and extensions. Then click the X at the top right.
Note: If you prefer to deploy the policies as user-scoped, you can do so by configuring the policies under Configure the list of force-installed apps and extensions (User) instead.
data:image/s3,"s3://crabby-images/d624b/d624b1eb7ff30d37057040062f57d089e294548d" alt="Intune MDM instructions for Chrome - docs - settings picker"
Toggle the Configure the list of force-installed apps to Enabled. Paste the following string into the value field:
dljjddkmmcminffjbcmeccgfbjlhmhlm;https://clients2.google.com/service/update2/crx
Click Next at the bottom of the page and set any scope tags you require.
On the following page, assign target groups (15), or set it to apply to all users and groups, if required. Click Next (16).
data:image/s3,"s3://crabby-images/53c3a/53c3af27109baa569dad3309723f581885acbbb0" alt="InTune - Device Management Profile Creation Assignments: KB 10054 10055"
On the final page, review the profile for any errors and finally click Create (17).
data:image/s3,"s3://crabby-images/11123/111238afa043ae002c1abae14fe9c0b7ebf86b97" alt="InTune - Device Management Profile Creation Chrome Review: KB 10054"
Create a PowerShell script
A few settings can't be configured via configuration profiles, so you'll need to create a PowerShell script that will run on each endpoint to finalize the configuration.
The script will create registry keys and values containing policy settings for the Push browser extension. It is not possible to create those values using administrative templates in Intune.
In Microsoft Endpoint Manager, click on Devices (1) > Scripts and remediations (2) > Platform scripts (3), Add (4) and then select Windows 10 and later (5) on the dropdown menu.
data:image/s3,"s3://crabby-images/c01ee/c01eeed5fb842256cdea62592e479768d4fb2f0b" alt="InTune - Create PowerShell script step 0: KB 10054 10055"
On the Add PowerShell script screen, provide a Name (5) for the script and an optional description. Then click Next (6).
data:image/s3,"s3://crabby-images/1571b/1571b74ff26da3d490ff180dd520b1f8407a7ead" alt="InTune - Device Management Powershell Chrome step 1: KB 10054"
Next, upload (8) chrome_push_security.ps1. This is included in the config.zip file you generated in the Push admin console.
Once uploaded, locate the option Run script in 64 bit PowerShell Host (8) and click Yes. This is an important step to make sure that the registry keys are created in the correct location on 64-bit hosts. Click Next (9).
data:image/s3,"s3://crabby-images/19c72/19c725922c4be164d6b96a81a03bea98fdee8da4" alt="InTune - Device Management Powershell Chrome step 2: KB 10054"
Click Add groups (10) to specify the group or groups you wish to deploy the settings to, or set it to apply to all users and groups. Click Next (11).
data:image/s3,"s3://crabby-images/f70ea/f70eafdd5ffeb9175ca5430b077d0fb6497f5995" alt="InTune - Device Management Powershell step 3: KB 10054 10055"
On the final page, review the profile for any errors and finally click Create (12).
data:image/s3,"s3://crabby-images/3dd9d/3dd9dd1a5b5c8cb8568b441c2c1c949233cd6166" alt="InTune - Device Management Powershell Chrome step 4: KB 10054"
Deploying to Microsoft Edge
Generate the extension config
The first step is to generate a config file in the Push admin console. Skip to the next step if you've already done so.
1. In the Push admin console, go to Browsers > Enrollment options.
data:image/s3,"s3://crabby-images/441b5/441b5a8293918c2772bf843b98e4536b450c6d7a" alt="Push app browser enrollment options: KB 10052/3/4/5/6/8"
2. Then select a Managed enrollment.
data:image/s3,"s3://crabby-images/fbe85/fbe85383bcf598994cda651613caafb459994852" alt="Managed browser enrollment screen - docs - showing Arc"
3. Select Device Management Software, choose Edge as the browser, and Windows as the OS. Then click Generate config. This will allow you to download a config file specific to your team.
data:image/s3,"s3://crabby-images/b446d/b446da40009c0a8820fa2c1b3d846ab34b70d65e" alt="Push app - Device Management Software Edge: KB 10055"
4. Download and extract the zip file.
Create a configuration profile
In Microsoft Endpoint Manager, select Devices (1) > Configuration profiles (2) > Create profile (3).
Select Windows 10 and later (4) as your target platform and Templates (5) as the Profile type. Then select Administrative Templates (6) then click the Create (7) button.
data:image/s3,"s3://crabby-images/2783f/2783f77dd03a62bb32186d9b0e6c048a55ea2dd2" alt="InTune - Create Configuration Profile: KB 10054 10055"
Enter a descriptive name for the profile (8), and a description if required, then click Next (9).
data:image/s3,"s3://crabby-images/89652/89652747378437ea6f49b6a6535fe2cab9286d27" alt="InTune - Device Management Profile Creation Edge: KB 10055"
In the Setting picker, search for Edge, select Microsoft Edge\Extensions, and select Control which extensions are installed silently. Then click the X at the top right.
Note: If you prefer to deploy the policies as user-scoped, you can do so by configuring the policies under Control which extensions are installed silently (User) instead.
data:image/s3,"s3://crabby-images/bd54b/bd54b8a771120fd56780defa87910f75c998af0c" alt="Intune MDM instructions for Edge - settings picker"
Toggle the Configure the list of force-installed apps to Enabled. Paste the following string into the value field:
dljjddkmmcminffjbcmeccgfbjlhmhlm;https://clients2.google.com/service/update2/crx
Note: The URL following the extension is one associated with Google Chrome. This is intentional and should be configured as defined in this documentation for the extension to be successfully rolled out to Microsoft Edge browsers.
Click Next at the bottom of the page and set any scope tags you require.
On the following page, assign target groups (15), or set it to apply to all users and groups, if required. Click Next (16).
data:image/s3,"s3://crabby-images/53c3a/53c3af27109baa569dad3309723f581885acbbb0" alt="InTune - Device Management Profile Creation Assignments: KB 10054 10055"
On the final page, review the profile for any errors and click Create (17).
data:image/s3,"s3://crabby-images/52cee/52cee7c67d7636819f83c71c836b87c667ea15ce" alt="InTune - Device Management Profile Creation Edge Review: KB 10055"
Create a PowerShell script
A few settings can't be configured via configuration profiles, so you'll need to create a PowerShell script that will run on each endpoint to finalize the configuration.
The script will create registry keys and values containing policy settings for the Push browser extension. It is not possible to create those values using administrative templates in Intune.
In Microsoft Endpoint Manager, click on Devices (1) > Scripts and remediations (2) > Platform scripts (3), Add (4) and then select Windows 10 and later (5) on the dropdown menu.
data:image/s3,"s3://crabby-images/c01ee/c01eeed5fb842256cdea62592e479768d4fb2f0b" alt="InTune - Create PowerShell script step 0: KB 10054 10055"
On the Add PowerShell script screen, provide a Name (5) for the script and an optional description. Then click Next (6).
data:image/s3,"s3://crabby-images/706e0/706e0fd64dd9611c8f821dd03ba1054415db43d0" alt="InTune - Device Management Powershell Edge step 1: KB 10055"
Next, upload (8) chrome_push_security.ps1. This is included in the config.zip file you generated in the Push admin console.
Once uploaded, locate the option Run script in 64 bit PowerShell Host (8) and click Yes. This is an important step to make sure that the registry keys are created in the correct location on 64-bit hosts. Click Next (9).
data:image/s3,"s3://crabby-images/b2493/b249342efcbaf4b0271c448f876dbecf46f15602" alt="InTune - Device Management Powershell Edge step 2: KB 10055"
Click Add groups (10) to specify the group or groups you wish to deploy the settings to, or set it to apply to all users and groups if required. Click Next (11).
data:image/s3,"s3://crabby-images/f70ea/f70eafdd5ffeb9175ca5430b077d0fb6497f5995" alt="InTune - Device Management Powershell step 3: KB 10054 10055"
On the final page, review the profile for any errors and finally click Create (12).
data:image/s3,"s3://crabby-images/a2191/a21918541c7abc6ae0c3a9aa41c3288cc9c61023" alt="InTune - Device Management Powershell Edge step 4: KB 10055"
Deploying to Firefox
Generate the extension config
The first step is to generate a config file in the Push admin console. Skip to the next step if you've already done so.
1. In the Push admin console, go to Browsers > Enrollment options.
data:image/s3,"s3://crabby-images/441b5/441b5a8293918c2772bf843b98e4536b450c6d7a" alt="Push app browser enrollment options: KB 10052/3/4/5/6/8"
2. Then select a Managed enrollment.
data:image/s3,"s3://crabby-images/fbe85/fbe85383bcf598994cda651613caafb459994852" alt="Managed browser enrollment screen - docs - showing Arc"
3. Select Device Management Software, choose Firefox as the browser, and Windows as the OS. Then click Generate config. This will allow you to download a config file specific to your team.
data:image/s3,"s3://crabby-images/1d602/1d602e533d91d54f21dd745ea0e01288f31db75f" alt="Intune - Firefox - config generation screen in Push - docs"
4. Download and extract the zip file.
Import the Firefox ADMX templates
Intune includes ADMX templates for Google Chrome and Microsoft Edge by default. However, for Firefox, we’ll need to import the templates before we can apply any of the deployment settings.
1. To begin, get the required files from Mozilla. Download the policy_templates_vX.YY.zip file associated with the latest release.
2. Extract the policy files. Remember the location of these files as you'll be importing them into Intune in the next step.
3. In Microsoft Endpoint Manager, select Devices (1) > Configuration Profiles (2) > Import ADMX (3) > Import (4).
data:image/s3,"s3://crabby-images/d4420/d442025777d5338482a828912a727a7bd8f5f7eb" alt="Intune - Firefox - import admx screen - docs"
4. Import the ADMX templates. This is a two-part process because you need to import both the mozilla.* and firefox.* templates.
First, click on the ADMX file selector and browse to the location where the policy templates were extracted. Select and import mozilla.admx.
Next, in the ADML file selector, locate the mozilla.adml file underneath the language locale policy templates folder.
Finally, click Next.
data:image/s3,"s3://crabby-images/4288e/4288ebbef183c77c6de7a2126caafdd2c8eea8a0" alt="Intune - Firefox - admx import settings screen - docs"
On the following screen, select Create.
data:image/s3,"s3://crabby-images/7e2be/7e2be1ec923b5f0a5b7c3e64d970b157d53c2e5d" alt="Intune - Firefox - import settings for Mozilla admx - docs"
Note: Before proceeding, wait for Intune to finish importing the template. This is an important step because the Firefox templates are dependent on these being imported.
data:image/s3,"s3://crabby-images/c741c/c741c7105e1b3a1dc5b0289a842a615fe94b4133" alt="Intune - Firefox - Mozilla admx upload confirmed - docs"
Next, repeat the previous steps, but import the firefox.admx and firefox.adml template files instead.
Once complete, the page should show that both templates have been successfully imported.
data:image/s3,"s3://crabby-images/77898/77898101b2071c1455eda4b107bb6156618b3253" alt="Intune - Firefox - mozilla and firefox admx imported - docs"
You're now ready to create a configuration profile for Firefox.
Create a configuration profile
In Microsoft Endpoint Manager, select Devices (1) > Configuration profiles (2) > Create profile (3).
Select Windows 10 and later (4) as your target platform and Templates (5) as the Profile type. Then select Imported Administrative Templates (Preview) (6) then click the Create (7) button.
data:image/s3,"s3://crabby-images/acacc/acacc8726a67e3df2abbdbd004cdf34e4f4edb47" alt="Intune - Firefox - create a profile screen - docs"
Enter a descriptive name for the profile (8), and a description if required, then click Next (9).
data:image/s3,"s3://crabby-images/29f05/29f05049ea8f7326b14f79dbfa49a421053cecb4" alt="Intune - Firefox - administrative template profile name - docs"
On the next screen, make sure Computer Configuration is selected (10).
Note: If you prefer to deploy the policies as user-scoped, you can do so by configuring the policies under User Configuration instead.
In the Setting name listing, click on Mozilla, then Firefox, then Extensions, and finally Extensions to Install (11).
When a page opens on the right side of your screen, scroll down, click the Enabled radio button (12), and paste the following string into the value field (13):
https://addons.mozilla.org/firefox/downloads/latest/push-security/latest.xpi
Finally, click OK (14).
data:image/s3,"s3://crabby-images/aa82d/aa82de94eb979db53c83b44bfcac1b1a946fb816" alt="Intune - Firefox - create profile config settings - docs"
Click Next at the bottom of the page and set any scope tags you require.
On the following page, assign target groups (15), or set it to apply to all users and groups, if required. Click Next (16).
data:image/s3,"s3://crabby-images/50edf/50edf4a4f869d10bf313cdd9229abb5f8110859b" alt="Intune - Firefox - create profile group assignments - docs"
On the final page, review the profile for any errors and finally click Create (17).
data:image/s3,"s3://crabby-images/b4477/b44775143147ce69f673adaea32b58cbee9b753f" alt="Intune - Firefox - create profile review included groups - docs"
Create a PowerShell script
A few settings can't be configured via configuration profiles, so you'll need to create a PowerShell script that will run on each endpoint in order to finalize the configuration.
The script will create registry keys and values containing policy settings for the Push browser extension. It is not possible to create those values using administrative templates in Intune.
In Microsoft Endpoint Manager, click on Devices (1) > Scripts (2) > Add (3), and then from the dropdown menu, select Windows 10 and later (4).
data:image/s3,"s3://crabby-images/4872a/4872a49b45769d207bb0194417d6701b943f6cd8" alt="Intune - Firefox - script configuration - docs"
On the Add PowerShell script screen, provide a Name (5) for the script and an optional description. Then click Next (6).
data:image/s3,"s3://crabby-images/b5c2b/b5c2b5b03e47374e2d3a709c8ba913c53be155ba" alt="Intune - Firefox - PowerShell script name screen - docs"
Next, upload firefox_push_security.ps1 (7). This is included in the config.zip file you generated in the Push admin console.
Once uploaded, locate the option Run script in 64 bit PowerShell Host (8) and click Yes. This is an important step to make sure that the registry keys are created in the correct location on 64-bit hosts. Click Next (9).
data:image/s3,"s3://crabby-images/8b4a8/8b4a8a898d3e1698478c374ac8269ded2121df4e" alt="Intune - Firefox - add powershell script - docs"
Click Add groups (10) to specify the group or groups you wish to deploy the settings to, or set it to apply to all users and groups. Click Next (11).
data:image/s3,"s3://crabby-images/43e7a/43e7a5c9d9e708613172589daf3d3d75a9a55bb5" alt="Intune - Firefox - create powershell script assignments - docs"
On the final page, review the profile for any errors and finally click Create (12).
data:image/s3,"s3://crabby-images/2f76d/2f76db32774fb02a9197b74fa12fe5fdd00d7bf9" alt="Intune - Firefox - review settings and add powershell script - docs"
Deploying to Brave
Generate the extension config
The first step is to generate a config file in the Push admin console. Skip to the next step if you've already done this.
In the Push admin console, go to Browsers > Enrollment options.
Select the Managed enrollment option.
Select Device Management Software, choose Brave as the browser, and Windows as the OS. Then select Generate config. This downloads a config file specific to your team and contains some required ADMX templates.
Download and extract the zip file.
Import the Brave ADMX templates
Intune includes ADMX templates for Google Chrome and Microsoft Edge by default. However, for Brave, we’ll need to import the templates before we can apply any of the deployment settings.
1. To begin, get the required files from Brave. Download the policy_templates.zip file.
2. Extract the policy files. Remember the location of these files as you'll be importing them into Intune in the following steps.
Note: At the time of writing, importing the Brave ADMX files results in an error. To resolve this, we included a few files that you need to import prior to importing the Brave policy files downloaded in step 1.
4. In Microsoft Endpoint Manager, select Devices (1) > Configuration (2) > Import ADMX (3) > Import (4).
data:image/s3,"s3://crabby-images/bf8f2/bf8f24d455444846f27001865cfdc94dc9db6ba8" alt="Intune MDM instructions for Edge - device config"
5. Import the ADMX templates. This is a two-part process because you first need to import the files you extracted following the generation of the Push app config, then import the Brave ADMX templates.
First, click on the ADMX file selector and browse to the location where the files from Push were saved. Select and import google.admx.
Next, in the ADML file selector, locate and import google.adml.
Finally, click Next.
data:image/s3,"s3://crabby-images/997ec/997ecc1ab710bd59cbb393595e3c43fbb00b70a0" alt="Intune MDM instructions for Brave - import settings"
On the next screen, select Create.
data:image/s3,"s3://crabby-images/48202/48202343b223970b4b450b0f9cb3c5247c10a766" alt="Intune MDM instructions for Brave - import settings - create"
Important! Wait for Intune to finish importing the template, or you may get an error.
data:image/s3,"s3://crabby-images/2a118/2a11809903b772cb4a52938e16979b116ec48789" alt="Intune MDM instructions for Brave - template upload 1"
Next, repeat the previous steps for the remaining templates. You must import the templates in this order, one step at a time:
1. google.admx and google.adml
2. bravesoftware.admx and bravesoftware.adml
3. windows.admx and windows.adml
Wait for each template import to complete before proceeding with the next one. Your imported templates page should resemble the following screenshot.
data:image/s3,"s3://crabby-images/0e1fc/0e1fc3eb279a37ce7a99c1272b0e117a6bb25cbc" alt="Intune MDM instructions for Brave - template upload 2"
Once all three templates have successfully been imported, you can proceed with the Brave policy files. These are located in the folder containing the extracted policy_templates.zip file from step 1. The files are located at windows\admx\brave.admx and windows\admx\en-US\brave.adml respectively.
Once complete, the page should show that all four templates have been successfully imported.
data:image/s3,"s3://crabby-images/dff3f/dff3f1c7438f32cd8b2550be856c57ec627a5ad4" alt="Intune MDM instructions for Brave - template upload complete"
Create a configuration profile
In Microsoft Intune, select Devices (1) > Configuration (2) > Create (3).
Select Windows 10 and later (4) as your target platform and Templates (5) as the Profile type. Then select Imported Administrative templates (6) and click the Create button.
data:image/s3,"s3://crabby-images/9a443/9a44391ab28cf6204540dc150ab9f8c2b461a66c" alt="Intune MDM instructions for Brave - create a profile"
Enter a descriptive name for the profile and a description if required, then click Next.
data:image/s3,"s3://crabby-images/18450/18450f3956188f812805c33bd049effc6269e642" alt="Intune MDM instructions for Brave - add profile name and desc"
On the next screen, select Computer Configuration.
Note: If you prefer to deploy the policies as user-scoped, you can do so by configuring the policies under User Configuration instead.
In the Setting name list, go to Brave > Brave > Extensions > Configure the list of force-installed apps and extensions. If a page opens on the right side of your screen, scroll down, click the Enabled radio button, and paste the following string into the value field:
dljjddkmmcminffjbcmeccgfbjlhmhlm;https://clients2.google.com/service/update2/crx
Then select OK.
data:image/s3,"s3://crabby-images/de912/de91278921855b81c164ce27f949d74a6591d31b" alt="Intune MDM instructions for Brave - config force-installed apps"
Note: The URL following the extension is one associated with Google Chrome. This is intentional and should be configured as defined in this documentation for the extension to be successfully rolled out to Brave browsers.
Click Next at the bottom of the page and set any scope tags you require.
On the following page, assign target groups, or set it to apply to all users and groups, if required. Click Next.
data:image/s3,"s3://crabby-images/e86e0/e86e00dd0cde77caac57bc9d597729d5d5c76ca3" alt="Intune MDM instructions for Brave - add groups"
On the final page, review the profile for any errors and click Create.
data:image/s3,"s3://crabby-images/6a771/6a77178d380550c63a53d59d83f542717e39db24" alt="Intune MDM instructions for Brave - review and create profile"
Create a PowerShell script
A few settings can't be configured via configuration profiles, so you'll need to create a PowerShell script that will run on each endpoint to finalize the configuration.
The script will create registry keys and values containing policy settings for the Push browser extension. It is not possible to create those values using administrative templates in Intune.
In Microsoft Intune, click on Devices (1) > Scripts and remediations (2) > Platform scripts (3) > Add (4).
data:image/s3,"s3://crabby-images/d75df/d75dfb24eaa4df4d6dd49e948732408a5ea31327" alt="Intune MDM instructions for Brave - add powershell script"
On the Add PowerShell script screen, provide a Name for the script and an optional description. Then click Next.
data:image/s3,"s3://crabby-images/a971d/a971d0befd977302bcaeb89e4343e40dad8008dc" alt="Intune MDM instructions for Brave - name the powershell script"
Next, upload brave_push_security.ps1. This is included in the config file downloaded from the Push admin console.
Once uploaded, ensure that the Run this script using the logged on credentials and Enforce script signature check options are set to No, and set Run script in 64 bit PowerShell Host to Yes. This is necessary to make sure that the registry keys are created in the correct location on 64-bit hosts. Click Next.
data:image/s3,"s3://crabby-images/0546f/0546f837ce365f3dde820a7d8440002a493aa6d3" alt="Intune MDM instructions for Brave - powershell script settings"
Click Add groups to specify the group or groups you wish to deploy the settings to, or set it to apply to all users and groups if required. Click Next.
data:image/s3,"s3://crabby-images/d0cf8/d0cf86ec6f478fa5de70128fbda2ad3f1e5f3991" alt="Intune MDM instructions for Brave - powershell add groups"
On the final page, review the profile for any errors and finally click Add.
data:image/s3,"s3://crabby-images/63125/6312536c56689d6f11ee0dc06719f59b0a05aaee" alt="Intune MDM instructions for Brave - review and add powershell script"