SafeToOpenBrowser Security Docs

SafeToOpen Browser Security

iPhone and iPad: Safari

Apple Business Manager, Intune VPP, app configuration for the enrolment values, and Safari extension DDM

Guide 5 of 11 · April 2026

On iOS the extension is part of the SafeToOpen app. Three pieces make it silent on iOS 18 and later: the app is installed as a required app, a declarative Safari extension setting turns it on and keeps it on, and an app configuration policy hands it the enrolment values. The user opens Safari and is protected.

What you will need#

1. Buy and assign the app#

  1. Apple Business Manager → Apps and Books → search “SafeToOpen” (https://apps.apple.com/us/app/safetoopen/id1588042602) → buy the number of licences you need for the location linked to Intune.
  2. Intune → Apps → iOS/iPadOS → the app appears after the next VPP sync (Tenant admin → Connectors and tokens → Apple VPP tokens → Sync).
  3. Assign as Required to your device groups with licence type Device licensing, so no Apple ID is needed on the device.

2. Turn the Safari extension on, permanently#

  1. Devices → iOS/iPadOS → Configuration → Create → Settings catalog.
  2. Add settings → Declarative Device Management → Safari Extension Settings.
  3. Managed Extensions → add the SafeToOpen extension identifier (bundle id (team id); from the Mac command in guide 4 section 4, or from [email protected]). State AlwaysOn, Private Browsing AlwaysOn, Allowed Domains *.
  4. Assign to the same groups. On iOS 18 and later the extension is enabled without the user visiting Settings, and the toggle is greyed out for them.
Note Devices below iOS 18 ignore the declaration. There the user has to enable the extension once in Settings → Safari → Extensions; everything else still works.

3. Hand over the enrolment values#

Managed app configuration reaches the container app, which shares it with the extension. Intune substitutes the per-device tokens at delivery time, so one policy covers the fleet.

  1. Apps → App configuration policies → Add → Managed devices. Platform iOS/iPadOS, targeted app SafeToOpen.
  2. Configuration settings format: Use configuration designer. Add four keys, all String:
KeyValue
enrol_keyYour enrolment key
user_name{{userprincipalname}}
asset_name{{devicename}}
domain_nameWorkspace name, or leave the value empty
  1. Assign to the same groups. The values arrive with the app install; the extension enrols the first time Safari loads it.
Important The current App Store build enrols with these keys only from the version that ships managed-configuration support; check the release notes or ask [email protected] before relying on zero-touch iOS registration. Until then, users on iOS register with the activation email (guide 7), and steps 1 and 2 still remove every other manual step.

4. Verify#

  1. On a test device: Settings → Safari → Extensions shows SafeToOpen on, with “managed by your organisation”.
  2. Open a page in Safari; the SafeToOpen icon appears in the address bar menu.
  3. Console → Settings → Unattended enrolment → Enrolled devices shows the device name from {{devicename}}.

5. BYOD iPhones#

Personal devices in Intune app protection (MAM without enrolment) cannot receive declarative Safari settings or device app configuration. Let people install the app from the App Store and send them an activation email from the People page (guide 7). The extension has to be enabled once in Settings → Safari → Extensions.