Overview
Download templates
Upload templates
Configure templates
Deploy templates to devices/users/groups
Adding Policy Files to Intune
Downloading Policy Templates
Microsoft Policy Template
Download and run this file
After finished installing policies, navigate to the Intune Configuration profile upload page and click the
Import ADMXtab.Click the
+ ImportbuttonIn the selection window navigate to
C:\Windows\Policy Definitions\Locate the
Windows.admxfile and select it.Add the
Windows.admlfile located atC:\Windows\Policy Definitions\en-US\Click the blue
Nextbutton.Verify the displayed info is correct and then click the blue
Createbutton.
Edge Policy Template
Navigate to Microsoft Edge for Business
Scroll down and locate the archetype of windows your systems are on and click the blue text that should read
Download Windows XX-bit PolicywhereXXis64,32, orARM64NOTEMost people will choose the64option if you're unsure which you should get.
Locate the file you downloaded, it should have a name similar to
MicrosoftEdgePolicyTemplates.cabExtract the
MicrosoftEdgePolicyTemplates.zipfileExtract the
MicrosoftEdgePolicyTemplatesfolder
Uploading Policy Templates to Intune
Open your browser of choice and navigate to Intune Admin Center webpage and login as an administrator
On the left side click
DevicesOn the new side bar that appears scroll down to the
Policysection and clickConfiguration profilesClick the
Import ADMXtab and then clickImportIn the field labeled
ADMX fileclick the blue folder icon to the right of itNavigate to where you exported that folder in step 5 and then go to the following:
Windows->ADMX->msedge.admxClick the
Openbutton to confirm the file.In the field labeled
ADML fileclick the blue folder icon to the right of itNavigate to where you exported the folder in step 5 and then go to the following subfolder:
Windows->ADMX->en-US->msedge.admlClick the
Openbutton to confirm the file.Click the blue
NextbuttonCheck that you have the two correct files added, it should read
ADMX file:msedge.admxandADML file for the default langeuage:msedge.admlIf everything looks correct, click
CreateWait for the profile to upload, typically takes a few minutes.
NOTEYou cannot close or refresh the tab that you started the upload on or it will fail. Please leave the tab open until the status showsCompleted. You may need to click theRefreshbutton on top of the table for it to update to show completed.
Setting up the Edge/Chrome Policy in Intune
NOTE: You must have completed the Adding Policy Files to Intune steps before you proceed. If you don't see the settings mentioned in the next steps make sure you've completed the Adding Policy Files to Intune steps.
Edge Force Install
Navigate to Intune Device Configuration Profiles
Click the
+ Create profilebuttonSet the
Platformdrop down toWindows 10 and laterSet the
Profile typedrop down toSettings catalogClick the blue
Createbutton.Give your profile a name such as
Edge Force Install ExtensionGive the profile a description if you wish
Click the blue
NextbuttonClick the blue text that read
+ Add settingsIn the field labeled
Search for a settinginputMicrosoft EdgeScroll through the list until you locate
Microsoft Edge\Extensionsand click itThen scroll through the bottom list and look for the option named
Control which extensions are intalled silentlyClick the checkbox on the leftDo another search from step 10 and input
Microsoft Edgeand look for an option calledMicrosoft EdgeLook for the option
Allow managed extensions to use the Enterprise Hardware Platform APIand click the checkboxLook for the option
Browser sign-in settingsand click the checkboxLook for the option
Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain accountLook for the option
Configure InPrivate mode availabilityClick the X in the top right of the
Settings Pickermenu.Enable all of the policies and configure the following:
Browser sign-in settings: "Force users to sign-in to use the browser"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account: "Sign in and make domain account non-removable"Configure InPrivate mode availability: "InPrivate Mode Disabled"Enter in the app name into "Control which extensions are installed silently" :
npnkndcccppmijoadmlaacmfbolcfppp;https://storage.googleapis.com/mm-cf-download.managedmethodsdev.com/main/updates.xml
Click the blue
Nextbutton at the bottomSet any
Scope Tagsif you have any you'd like to setClick the blue
Nextbutton at the bottomSet which users, groups or devices you'd like to have this policy enforced on by clicking the
Add Groups,Add All UsersorAdd All Devices.Alternatively you can add all users or devices and then add groups to the exclude list.
Click the blue
NextbuttonReview all the options and ensure they look correct and then click the blue
Createbutton at the bottom to create the policy
Chrome Force Install (Windows OS)
NOTE: This will only apply to Chrome on Windows OS and not Chrome OS or Mac OS
Navigate to Intune Device Configuration Profiles
Click the
+ Create profilebuttonSet the
Platformdrop down toWindows 10 and laterSet the
Profile typedrop down toSettings catalogClick the blue
Createbutton.Give your profile a name such as
Edge Force Install ExtensionGive the profile a description if you wish
Click the blue
NextbuttonClick the blue text that read
+ Add settingsIn the field labeled
Search for a settinginputMicrosoft EdgeDo a search for
ChromeLocate the field called
Google Google Chrome Extensionsand click itIn the table below locate the
Configure the list of force-installed apps and extensionsoption and check the box next to it.In the search field from step 11, do another search for
Chromeand click the row calledGoogle Google ChromeLook for an option called
Browser sign-in settingsand click the checkboxLook for an option called
Enables managed extensions to use the Enterprise Hardware Platform APIand click the checkboxLook for an option called
Incognito mode availabilityand click the checkboxLook for an option called
Add restrictions on managed accountsand click the checkboxClick the X in the top right of the
Settings PickermenuLook for the section labeled
Google Chrome > Extensionsand check the toggle to enable that policy.Input the following into the field that should have appeared
npnkndcccppmijoadmlaacmfbolcfppp;https://storage.googleapis.com/mm-cf-download.managedmethodsdev.com/main/updates.xml
Click the toggle for each option to enable it and configure the following settings after:
Add restrictions on managed accounts: "A Managed Account Must be a primary account"Browser sign in settings: "Force-users to sign-in to use the browser"Incognito mode availability: "Incognito Mode Disabled"
Click the blue
Nextbutton at the bottomSet any
Scope Tagsif you have any you'd like to setClick the blue
Nextbutton at the bottomSet which users, group or devices you'd like to have this policy enforced on by clicking the
Add Groups,Add All UsersorAdd All Devices.Alternatively you can add all users or devices and then add groups to the exclude list.
Click the blue
NextbuttonReview all the options and ensure they look correct and then click the blue
Createbutton at the bottom to create the policy
