SafeToOpen Browser Security
Android, unmanaged devices and activation emails
Where no policy channel exists: Edge on Android, BYOD, contractors, and the activation-email and Azure AD routes
Not every browser can be told what to do. This guide covers the devices where the person has to install or click once, and the console features that keep that to a minimum.
1. What has no policy channel#
| Device | Situation | What to do |
|---|---|---|
| Android (Edge) | Edge for Android runs extensions, but Microsoft’s extension policies do not apply on Android and Intune app configuration has no extension keys. | Install Edge from managed Google Play, then the person adds SafeToOpen from Edge’s extension menu and clicks the activation email once. |
| Android (Chrome) | Chrome for Android has no extensions. | No coverage. Consider network-level filtering through your MDM. |
| BYOD laptops | No MDM rights. | Activation email. The person installs from the store link in the email and clicks the link. |
| iOS without supervision | MAM-only or personal devices. | App Store install, enable in Settings → Safari → Extensions, activation email (guide 5, section 5). |
| ChromeOS | Force-install works, per-device values do not. | Activation email after force-install (guide 6). |
Important Do not promise unattended Android coverage to customers. It does not exist in any browser today.
2. Activation emails#
The activation email carries a link that registers the browser it is opened in, valid for as long as the plan is active and reusable on up to five browsers per person. Three ways to send it:
2a. Add people manually or by CSV#
- Console → People → Invite. One address, or a CSV with a column of addresses; pick the workspace for the batch.
- Leave “Send activation email” ticked. Untick it when the extension is deployed by policy and you only want the seat assigned; you can send the email later from the member’s row.
- The People list shows an “emailed / not emailed” indicator per member, so you can see who still has to act.
2b. Import from Azure AD#
- Console → People → Azure AD → Connect; sign in with a Global Administrator or Application Administrator account and consent once.
- Map groups to workspaces. Members of mapped groups are added, moved and removed automatically as the groups change.
- Choose whether imports send activation emails. Switch it off when devices enrol unattended (guides 2 to 5): the import then only assigns seats and workspaces, and enrolment supplies the sessions. Removal emails are a separate switch.
2c. Resend#
People → the member’s row → Resend activation. Reinviting invalidates the previous link.
3. Combining unattended enrolment with emails#
- Enrolment and invitation are the same member record. An enrolled person who also receives an email uses no extra seat.
- Turn email sending off for Azure AD and CSV imports on fleets that enrol unattended; keep it on for the BYOD workspace.
- Removing a member revokes every session, enrolled or emailed. Azure AD removals do the same and can send a removal email.
4. Instructions to give end users#
For the devices in section 1, this is all a person needs:
1. Install SafeToOpen for your browser:
Chrome https://chromewebstore.google.com/detail/ekfkopmgnijagfmjgcjkbffcnmggekec
Edge https://microsoftedge.microsoft.com/addons/detail/bbgoikmidjfiaaadlgkpdlppilhkjfke
Firefox https://addons.mozilla.org/addon/safetoopen-online-security/
iPhone/iPad https://apps.apple.com/us/app/safetoopen/id1588042602 (then Settings → Safari → Extensions → SafeToOpen → On)
2. Open the email “Activate SafeToOpen Browser Security” from your organisation and click Activate.
3. The SafeToOpen icon shows your organisation’s name. You are done.