SafeToOpen Browser Security
Deployment Guides
Install and register SafeToOpen Browser Security on every platform, device and browser your organisation uses, with nothing for the user to do.
Overview and Enrolment Key
How install and registration work, the four policy values, the enrolment key, workspaces, verification. Start here.
Windows: Edge and Chrome with Intune
Force-install through the Settings Catalog and push the enrolment values with a platform script. Zero user action.
Windows: Group Policy and registry
On-premises AD, RMM tools or hand-built images: ADMX templates, a .reg file and a logon script.
macOS: Chrome, Edge and Safari
Managed preferences via Intune or Jamf, a root script for per-user values, and Safari through the Mac app plus DDM.
iPhone and iPad: Safari
Apple Business Manager, Intune VPP, app configuration for the enrolment values, and Safari extension DDM.
Chrome Enterprise (Google Admin)
Chrome Browser Cloud Management and ChromeOS: force-install and the extension policy JSON from the Admin console.
Android, unmanaged devices and activation emails
Where no policy channel exists: Edge on Android, BYOD, contractors, and the activation-email and Azure AD routes.
Apple MDMs: Jamf, Kandji, Mosyle, Addigy, SimpleMDM
The same profile, script and app-configuration payloads in each Apple MDM, with the menu paths and variables each one offers.
Windows RMM and UEM tools
NinjaOne, Datto RMM, ConnectWise, Kaseya, Atera, Action1, PDQ, ManageEngine, MECM and Workspace ONE: where to run the script or push the registry.
Linux: Chrome and Edge
JSON policy files under /etc, delivered by Ansible, Puppet, Landscape or any package: force-install and the enrolment values.
Cross-platform UEMs: ManageEngine MDM Plus, SOTI MobiControl, Hexnode
One console for Windows, macOS, iOS and Android: where each of the three puts scripts, custom profiles, app configuration and Android app push.
Which guide do I need?#
- Everyone — Read the Overview first: how install and registration work, the enrolment key, the four policy values, workspaces and troubleshooting.
- Windows — Guide 2 (Intune) or guide 3 (Group Policy, RMM, images).
- macOS — Guide 4: Chrome and Edge via Intune or Jamf, and Safari through the Mac app.
- iPhone and iPad — Guide 5: Apple Business Manager, Intune app configuration and Safari DDM.
- Google Admin — Guide 6: Chrome Browser Cloud Management and ChromeOS.
- Everything else — Guide 7: Android, BYOD, contractors and the activation-email and Azure AD routes.
- Other Apple MDMs — Guide 8: Jamf Pro, Kandji, Mosyle, Addigy and SimpleMDM.
- Windows RMM and UEM tools — Guide 9: NinjaOne, Datto RMM, ConnectWise, Kaseya, Atera, Action1, PDQ, ManageEngine, MECM and Workspace ONE.
- Linux — Guide 10: policy files for Chrome and Edge via Ansible, Puppet or a package.
- Cross-platform UEMs — Guide 11: ManageEngine MDM Plus, SOTI MobiControl and Hexnode across Windows, macOS, iOS and Android.
What can be made unattended, and what cannot#
- Windows, macOS and Linux with Chrome or Edge: install and registration are both enforced by policy. The user does nothing and cannot remove it.
- Safari on macOS 15+ and iOS 18+: install and the on/off switch are enforced; registration is one click on an activation link until the Apple apps pass managed configuration through.
- ChromeOS: install enforced from Google Admin; registration by activation link because no per-device script can supply the user and device names.
- Edge on Android: the user installs the extension and clicks the activation link. Microsoft’s extension policies do not apply on Android and Edge’s mobile app configuration has no extension keys, so no MDM can do it for them. Other Android browsers do not run extensions at all.
- BYOD and contractors: activation link, and the person can remove the extension. The People page shows who was emailed and who has never checked in.
Guide 1 has the full matrix with the reason for each limit and what the user can still change after enrolment.
Before you start#
You need an Owner or Co-administrator login to https://plus.safetoopen.com/business-console#/settings, where the enrolment key is generated and the copy-ready Intune, registry, macOS and iOS payloads are shown with your key filled in.