SafeToOpenBrowser Security Docs

SafeToOpen Browser Security

Android, unmanaged devices and activation emails

Where no policy channel exists: Edge on Android, BYOD, contractors, and the activation-email and Azure AD routes

Guide 7 of 11 · April 2026

Not every browser can be told what to do. This guide covers the devices where the person has to install or click once, and the console features that keep that to a minimum.

1. What has no policy channel#

DeviceSituationWhat to do
Android (Edge)Edge for Android runs extensions, but Microsoft’s extension policies do not apply on Android and Intune app configuration has no extension keys.Install Edge from managed Google Play, then the person adds SafeToOpen from Edge’s extension menu and clicks the activation email once.
Android (Chrome)Chrome for Android has no extensions.No coverage. Consider network-level filtering through your MDM.
BYOD laptopsNo MDM rights.Activation email. The person installs from the store link in the email and clicks the link.
iOS without supervisionMAM-only or personal devices.App Store install, enable in Settings → Safari → Extensions, activation email (guide 5, section 5).
ChromeOSForce-install works, per-device values do not.Activation email after force-install (guide 6).
Important Do not promise unattended Android coverage to customers. It does not exist in any browser today.

2. Activation emails#

The activation email carries a link that registers the browser it is opened in, valid for as long as the plan is active and reusable on up to five browsers per person. Three ways to send it:

2a. Add people manually or by CSV#

  1. Console → People → Invite. One address, or a CSV with a column of addresses; pick the workspace for the batch.
  2. Leave “Send activation email” ticked. Untick it when the extension is deployed by policy and you only want the seat assigned; you can send the email later from the member’s row.
  3. The People list shows an “emailed / not emailed” indicator per member, so you can see who still has to act.

2b. Import from Azure AD#

  1. Console → People → Azure AD → Connect; sign in with a Global Administrator or Application Administrator account and consent once.
  2. Map groups to workspaces. Members of mapped groups are added, moved and removed automatically as the groups change.
  3. Choose whether imports send activation emails. Switch it off when devices enrol unattended (guides 2 to 5): the import then only assigns seats and workspaces, and enrolment supplies the sessions. Removal emails are a separate switch.

2c. Resend#

People → the member’s row → Resend activation. Reinviting invalidates the previous link.

3. Combining unattended enrolment with emails#

4. Instructions to give end users#

For the devices in section 1, this is all a person needs:

1. Install SafeToOpen for your browser:
   Chrome  https://chromewebstore.google.com/detail/ekfkopmgnijagfmjgcjkbffcnmggekec
   Edge    https://microsoftedge.microsoft.com/addons/detail/bbgoikmidjfiaaadlgkpdlppilhkjfke
   Firefox https://addons.mozilla.org/addon/safetoopen-online-security/
   iPhone/iPad https://apps.apple.com/us/app/safetoopen/id1588042602  (then Settings → Safari → Extensions → SafeToOpen → On)
2. Open the email “Activate SafeToOpen Browser Security” from your organisation and click Activate.
3. The SafeToOpen icon shows your organisation’s name. You are done.