Use this policy to manage Microsoft Edge extensions on Windows devices and control extension installation, usage, and permissions. By configuring this policy, you can enhance browser security, improve user productivity, and maintain a standardized browser environment across devices. You can control which extensions are allowed, blocked, or force installed.
This is a device level policy that applies system-wide to the device and all of its users. You can bind this policy to individual devices or device groups. For policies that apply to a specific user's profile across devices, see Get Started: Policies and Learn More section of this article.
Prerequisites
- Devices must be enrolled in Windows Mobile Device Management (MDM).
- Target devices must be running Windows 10 (1809 and later) or any version of Windows 11. This policy is supported on the following Windows editions:
- Windows Pro
- Windows Enterprise
- Windows Education
- Windows SE
- IoT Enterprise
- IoT Enterprise LTSC
- See Agent Compatibility, System Requirements, and Impacts to learn more.
Considerations
- You must restart the Microsoft Edge browser on target devices to enforce the configured settings.
Creating the Policy
To create a MS Edge Extensions policy for Windows devices, do the following:
Selecting the Policy Template
- Log in to the JumpCloud Admin portal.
If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.
- Go to Device Management > Policy Management. The Policy Management page is displayed.
- On the Policy Management page, click +Add New.
- Select Device Policy to assign the policy to devices and device groups. On the New Device Policy page:
- Select the Windows tab.
- Search and select the policy name and click Configure. The Details tab of the policy is displayed.
- On the Details tab, configure the required policy configuration settings.
- (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
- (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.
Configuring the Policy
- Under Settings, configure the following options:
- Block External Extensions - Selecting this checkbox prevents users from adding external extensions to Microsoft Edge, except for those from the Microsoft Edge Add-ons store. Edge should block attempts to install extensions from local files (.crx) or other external sources and display a relevant error message. This setting also blocks the developer mode extensions.
- Extension Allowed Types - Specify one or multiple types of extensions users are allowed to install. Select from following Edge extension categories: extension, theme, user script, hosted app, legacy packaged app, platform app.
- Disable Developer Mode Setting - Select this to prevent users from activating developer mode in Microsoft Edge, disabling options to load or pack extensions and use developer tools, and deactivating any extensions previously installed through developer mode. When the policy is disabled, users can freely enable developer mode to load unpacked extensions, pack extensions, and access developer tools. By default, this option is not enabled.
- Browser Extensions - Use the following options to allow or block extensions:
- Allow All - Enabling this option allows users to download and install all kinds of extensions. By default, all extensions are allowed.
- Allowlist - Specifies which extensions are not subject to the blocklist. Enter the name of extensions to allow that bypass the blocklist.
- Blocklist - Specifies which extensions users are prohibited from installing. Enter the name of extensions to allow that bypass the allowlist. Any extensions that are already installed will be automatically disabled and cannot be re-enabled by the user. An extension will be automatically re-enabled if it is later removed from the blocklist.
- Extension Force Install - Specifies a list of apps and extensions for silent installation.
- Extensions Install Sources - Enter URLs of sites that contain extensions and themes that users can install. For example:
https://corp.contoso.com/* - Blocklist for Extension Install Type - The blocklist prevents specific types of extensions from being installed.
Applying the Policy
- (Optional) Select the Policy Groups tab. Select one or more policy groups where you want to add this policy.
- Select the Device Groups tab. Select one or more device groups where you want to apply this policy to. For device groups with multiple OS member types, the policy only applies when a user logs into a supported Windows device that is enrolled in MDM.
- Or, select the Devices tab. Select one or more devices where you want to apply this policy.
- Click Create Policy. A success message is displayed indicating the completion of policy creation.
Viewing Policy Status
- Select the Status tab.
- To see the last Result Log for a device where this policy is applied, click view.
- If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.
