Deploying Velatir for Desktop? It handles all of this for you. Use this guide only if you manage browser extensions through your own Group Policy or MDM.
Deployment methods
Windows (Group Policy / registry)
Force-install via GPO, PowerShell, manual registry, or the Intune Settings Catalog. Chrome, Edge, Firefox, Vivaldi, and Brave.
macOS (Jamf / MDM)
A single .mobileconfig profile for Chrome, Firefox, Vivaldi, and Brave.
Vendor-managed & other browsers
Island, Prisma Access, Surf, and browsers with no policy surface.
Extension IDs
Vivaldi, Brave, and Atlas install the Chrome Web Store build (same extension ID, same managed-storage schema), so no separate listing is needed.
Supported browsers
The deployment methods cover every browser with an enterprise policy surface.Managed configuration
The extension reads its configuration from managed storage:
It fetches your organisation’s display name from the platform, so that is not configured through managed storage.
Vendor-managed browsers
Island, Prisma Access Browser (formerly Talon), and Surf Security run their own management plane and do not honour host-OS Chromium policy keys or preference plists. Force-install and pre-configure the extension from each vendor’s admin console using these values:Browsers without a policy surface
Comet, Arc, Dia, and Opera / Opera GX publish no framework to force-install an extension. Users install it manually:- Open the Chrome Web Store listing.
- Click Add to browser (on Opera, via Opera’s “Install Chrome Extensions” add-on).
- Open the Velatir popup and enter the ingest key.
Verify
After the profile or policy applies:- Open the browser’s policy page and confirm the Velatir extension ID is force-installed with your
apiToken:chrome://policy,edge://policy,vivaldi://policy,brave://policy, orabout:policies(Firefox showsvelatir@velatir.comset toforce_installed). - Open the extensions page and confirm Velatir is present:
chrome://extensions,edge://extensions,about:addons(Firefox: “Installed by enterprise policy”),vivaldi://extensions,brave://extensions. For Atlas, use the extensions panel in the Atlas menu. - On Windows, trigger an Intune sync first, then Reload policies on the policy page.
- On macOS, confirm the managed-preference plist exists, e.g.
ls /Library/Managed\ Preferences/com.google.Chrome.plist.
Troubleshoot
- Extension not installing: confirm the browser was installed before the policy applied, and check the policy page for errors. Windows: confirm the device synced with Intune (Devices > Monitor > Device configuration status). macOS: confirm the profile is installed under System Settings > Privacy & Security > Profiles. Firefox (macOS): set
EnterprisePoliciesEnabledtotrue, or Firefox ignores all policies. - Configuration not appearing: restart the browser after policy changes. Windows: run scripts in 64-bit PowerShell with administrator / SYSTEM rights, or registry writes land under
WOW6432Node. macOS: match the preference domain exactly. Firefox (Windows) withpolicies.json: confirm the file is atC:\Program Files\Mozilla Firefox\distribution\policies.json, which Firefox updates can remove. - Policy conflicts (Windows): if multiple Intune profiles set
ExtensionInstallForcelist, use the PowerShell script instead of the Settings Catalog. It writes to a high value name (1000) that does not collide with MDM-managed entries.
Browser Extension Overview
Features and manual installation
Get your ingest key
Set up your account and get your ingest key