Skip to main content
Deploy the extension to managed devices with the ingest key pre-configured. Pick a method below; the browser support and configuration reference follow.
Deploying Velatir for Desktop? It handles all of this for you. Use this guide only if you manage browser extensions through your own Group Policy or MDM.

Deployment methods

Windows (Group Policy / registry)

Force-install via GPO, PowerShell, manual registry, or the Intune Settings Catalog. Chrome, Edge, Firefox, Vivaldi, and Brave.

macOS (Jamf / MDM)

A single .mobileconfig profile for Chrome, Firefox, Vivaldi, and Brave.

Vendor-managed & other browsers

Island, Prisma Access, Surf, and browsers with no policy surface.

Extension IDs

Vivaldi, Brave, and Atlas install the Chrome Web Store build (same extension ID, same managed-storage schema), so no separate listing is needed.

Supported browsers

The deployment methods cover every browser with an enterprise policy surface.

Managed configuration

The extension reads its configuration from managed storage: It fetches your organisation’s display name from the platform, so that is not configured through managed storage.

Vendor-managed browsers

Island, Prisma Access Browser (formerly Talon), and Surf Security run their own management plane and do not honour host-OS Chromium policy keys or preference plists. Force-install and pre-configure the extension from each vendor’s admin console using these values:

Browsers without a policy surface

Comet, Arc, Dia, and Opera / Opera GX publish no framework to force-install an extension. Users install it manually:
  1. Open the Chrome Web Store listing.
  2. Click Add to browser (on Opera, via Opera’s “Install Chrome Extensions” add-on).
  3. Open the Velatir popup and enter the ingest key.
We will add these to the MSI / mobileconfig if and when the vendors publish a policy reference.

Verify

After the profile or policy applies:
  • Open the browser’s policy page and confirm the Velatir extension ID is force-installed with your apiToken: chrome://policy, edge://policy, vivaldi://policy, brave://policy, or about:policies (Firefox shows velatir@velatir.com set to force_installed).
  • Open the extensions page and confirm Velatir is present: chrome://extensions, edge://extensions, about:addons (Firefox: “Installed by enterprise policy”), vivaldi://extensions, brave://extensions. For Atlas, use the extensions panel in the Atlas menu.
  • On Windows, trigger an Intune sync first, then Reload policies on the policy page.
  • On macOS, confirm the managed-preference plist exists, e.g. ls /Library/Managed\ Preferences/com.google.Chrome.plist.

Troubleshoot

  • Extension not installing: confirm the browser was installed before the policy applied, and check the policy page for errors. Windows: confirm the device synced with Intune (Devices > Monitor > Device configuration status). macOS: confirm the profile is installed under System Settings > Privacy & Security > Profiles. Firefox (macOS): set EnterprisePoliciesEnabled to true, or Firefox ignores all policies.
  • Configuration not appearing: restart the browser after policy changes. Windows: run scripts in 64-bit PowerShell with administrator / SYSTEM rights, or registry writes land under WOW6432Node. macOS: match the preference domain exactly. Firefox (Windows) with policies.json: confirm the file is at C:\Program Files\Mozilla Firefox\distribution\policies.json, which Firefox updates can remove.
  • Policy conflicts (Windows): if multiple Intune profiles set ExtensionInstallForcelist, use the PowerShell script instead of the Settings Catalog. It writes to a high value name (1000) that does not collide with MDM-managed entries.

Browser Extension Overview

Features and manual installation

Get your ingest key

Set up your account and get your ingest key