VeridentiDocs
ChangelogFor BusinessContact
Docs Admin guide Deploying the extension (MDM)

Deploying the extension (managed / MDM)

Two ways to get Veridenti onto your team's browsers: let people install it themselves, or push it silently with your device-management tool.

Option A — Self-service (small teams)

Send the store link; users install and sign in with SSO.

Option B — Managed deployment (MDM)

Force-install the extension with browser enterprise policy, pushed through your MDM. Users get it automatically — nothing to click, nothing to uninstall.

The force-install policy

Every major browser force-installs an extension via an extension force-list policy. Set it to Veridenti's extension ID:

BrowserPolicyExtension ID
ChromeExtensionInstallForcelistolcbmkkoibpoimhjkhgllokikajccknn
EdgeExtensionInstallForcelist (Edge)available once the Edge listing is approved; until then deploy the Chrome-store ID above — Edge accepts it
FirefoxExtensionSettings (installation_mode: force_installed)masked-autofill@cappfamily.org, install_url from AMO

Push it through your MDM

Joining the organization

Installing is step one; the device also has to join your org so policies apply and posture reports flow in. Two paths:

  1. SSO (automatic) — the user signs in with your identity provider and the device associates with your tenant. This is the default for SCIM-provisioned users.
  2. Enrollment code (no-SSO / demos) — in the console, Settings → Connect the browser extension generates a one-time code. In the extension, the user opens Settings → Connect your organization, enters your console URL and the code. The device picks up your org's policies and shared vaults.

Why joining matters — management + analytics

Once a device has joined, and only then:

TipRoll out in one motion: force-install via MDM and enable SSO. The extension appears automatically and self-associates on the first SSO sign-in — zero user steps.
Last updated August 26, 2026 · Docs v1.3
Enter to open · Esc to close
Veridenti