SafeToOpen Browser Security
iPhone and iPad: Safari
Apple Business Manager, Intune VPP, app configuration for the enrolment values, and Safari extension DDM
On iOS the extension is part of the SafeToOpen app. Three pieces make it silent on iOS 18 and later: the app is installed as a required app, a declarative Safari extension setting turns it on and keeps it on, and an app configuration policy hands it the enrolment values. The user opens Safari and is protected.
What you will need#
- Supervised devices enrolled in Intune (Automated Device Enrollment through Apple Business Manager is the normal route).
- Apps and Books (VPP) location linked to Intune, with licences for the SafeToOpen app.
- Your enrolment key (guide 1).
1. Buy and assign the app#
- Apple Business Manager → Apps and Books → search “SafeToOpen” (
https://apps.apple.com/us/app/safetoopen/id1588042602) → buy the number of licences you need for the location linked to Intune. - Intune → Apps → iOS/iPadOS → the app appears after the next VPP sync (Tenant admin → Connectors and tokens → Apple VPP tokens → Sync).
- Assign as Required to your device groups with licence type Device licensing, so no Apple ID is needed on the device.
2. Turn the Safari extension on, permanently#
- Devices → iOS/iPadOS → Configuration → Create → Settings catalog.
- Add settings → Declarative Device Management → Safari Extension Settings.
- Managed Extensions → add the SafeToOpen extension identifier (
bundle id (team id); from the Mac command in guide 4 section 4, or from [email protected]). State AlwaysOn, Private Browsing AlwaysOn, Allowed Domains*. - Assign to the same groups. On iOS 18 and later the extension is enabled without the user visiting Settings, and the toggle is greyed out for them.
3. Hand over the enrolment values#
Managed app configuration reaches the container app, which shares it with the extension. Intune substitutes the per-device tokens at delivery time, so one policy covers the fleet.
- Apps → App configuration policies → Add → Managed devices. Platform iOS/iPadOS, targeted app SafeToOpen.
- Configuration settings format: Use configuration designer. Add four keys, all String:
| Key | Value |
|---|---|
enrol_key | Your enrolment key |
user_name | {{userprincipalname}} |
asset_name | {{devicename}} |
domain_name | Workspace name, or leave the value empty |
- Assign to the same groups. The values arrive with the app install; the extension enrols the first time Safari loads it.
4. Verify#
- On a test device: Settings → Safari → Extensions shows SafeToOpen on, with “managed by your organisation”.
- Open a page in Safari; the SafeToOpen icon appears in the address bar menu.
- Console → Settings → Unattended enrolment → Enrolled devices shows the device name from
{{devicename}}.
5. BYOD iPhones#
Personal devices in Intune app protection (MAM without enrolment) cannot receive declarative Safari settings or device app configuration. Let people install the app from the App Store and send them an activation email from the People page (guide 7). The extension has to be enabled once in Settings → Safari → Extensions.