phishtriage

For security teams · 20 minutes

Roll out PhishTriage by browser policy

Install the PhishTriage extension on managed Chrome, Edge and Firefox browsers, set or lock its settings, and join each browser to your team with an enrolment key, without anyone signing in.

Managed rollout is offered with Enterprise (see pricing), and we can set it up with you: contact us. This page is the technical reference. What each setting sends, and how long it is kept, is in Data handling.

Before you start

What you can set by policy

These are PhishTriage’s own settings, delivered as the extension’s managed configuration (how, per browser, is under Configure the extension). Leave a key out to let each person decide. Where a key has a switch, a value that is set wins over the person’s own setting both ways: true forces the switch on, false forces it off, and either way it is locked and marked Managed in PhishTriage’s settings. An empty string counts as not set. Write true and false as booleans, not as text in quotes, and every address with https://.

Key What it does Locks a switch, marked Managed Version
proxyUrl
text
The backend everything goes to: scans, visit checks, evidence, registration. Not set: https://api.phishtriage.com. There is no user setting for it. Change it only for a self-hosted backend. No switch. Shown read-only under Advanced, Backend, with the badge 1.0.0 and later
enrolmentToken
text
An enrolment key from the portal. Joins the browser to your team when PhishTriage registers, which it does at install and again when someone presses Sign out or Leave team. A key added to policy later is not picked up by a browser that is already registered. No email address is collected. A key that is wrong, expired, revoked or used up leaves the browser registered outside the team, working normally. Anyone who can see a computer’s browser policy can read the key: see Join browsers to your team. No. PhishTriage does not show it, but the computer’s policy store holds it 1.0.0 and later
trackDomains
true / false
Background protection: the name of each site visited is checked, and a site flagged as dangerous gets a full-page warning. Default off. Needs a browser permission. Yes: Background protection 1.0.0 and later
trackVisits
true / false
Sends the full address of every page opened, query string included. Default off. Do not force it on without reading Choose your settings. Needs a browser permission. Yes: Send full URLs, under Advanced 1.0.0 and later
cacheDomainVisits
true / false
With Background protection on, checks each site’s name at most once an hour. Default off. Does nothing without trackDomains or the person’s own switch. Yes: Cache domains for 1 hour, under Advanced 1.0.0 and later
evidenceCapture
true / false
After a check that comes back phishing or suspicious, uploads a screenshot and the page’s HTML so the site can be reported. Default on: only false turns it off for everyone. Yes: Keep evidence of phishing 1.0.0 and later
fileProtection
true / false
File protection: each download’s fingerprint, file name and size (not the file) are sent to filescan.phishtriage.com, or to your filescanUrl, to be checked. Default off. Needs a browser permission. The Firefox store build of 1.0.0 offers no File protection switch, so do not rely on forcing fileProtection there. Yes: File protection 1.0.0 and later
fileBlocking
true / false
true: block mode, which holds a file a page builds and asks before saving it. false: warn mode, the default. Needs File protection on. Yes: Block, don’t just warn, shown only while File protection is on 1.0.0 and later
deepScanAlways
true / false
Sends every downloaded file for a full malware scan, not only the files a person asks about. Default off. Needs File protection on. Yes: Deep scan every file, shown only while File protection is on 1.0.0 and later
filescanUrl
text
The file-scan service. Not set: https://filescan.phishtriage.com. Used only by File protection. Change it only for a self-hosted backend. No. Not shown anywhere 1.0.0 and later
feedbackUpload
true / false
From 1.1.0, a press of Looks safe to me or Looks dangerous is sent to PhishTriage by default. false keeps it on the device; nothing else turns it off. Version 1.0.0 sends no feedback and does not read this key. No. Not shown anywhere 1.1.0 and later

When proxyUrl, trackDomains, trackVisits or cacheDomainVisits is set, PhishTriage’s Settings also shows the notice “Some settings are managed by your organization and can’t be changed here.” What each switch sends, where it goes and how long it is kept is in Data handling.

Choose your settings

Start from the portal’s snippet, which holds only proxyUrl and enrolmentToken. It is configuration only: the force-install policy, further down, is what installs PhishTriage. With the force-install, and the snippet in policy before it, each browser joins your team as PhishTriage is installed on it, and every switch is left to the person using it. Then decide each of these on purpose:

Force-install the extension

Each store’s copy of PhishTriage has its own ID. Use the copy from the browser’s own store, and use the same ID again for its settings.

Browser Extension ID Update or install URL
Chrome (Chrome Web Store) gjlaknelkbocikcnjebmigaeenagdapl https://clients2.google.com/service/update2/crx
Edge (Edge Add-ons) cgohfopcndeliihonajifpfibocendjn https://edge.microsoft.com/extensionwebstorebase/v1/crx
Firefox (Firefox Add-ons) phishtriage@phishtriage.com https://addons.mozilla.org/firefox/downloads/latest/phishtriage@phishtriage.com/latest.xpi

All three are store listings, so the computers do not need to be joined to a domain. Chrome and Edge restrict force-installing extensions from outside their own store to domain-joined or managed computers; that is one more reason to give Edge the Edge Add-ons copy.

Chrome

Use one of two policies, not both: ExtensionSettings overrides ExtensionInstallForcelist for the same extension. Either one installs PhishTriage without asking and stops people removing or turning it off. Google documents for ExtensionInstallForcelist that taking an extension out of the list uninstalls it, and that the list does not apply in Incognito.

ExtensionInstallForcelist is a list; PhishTriage’s entry is:

gjlaknelkbocikcnjebmigaeenagdapl;https://clients2.google.com/service/update2/crx

ExtensionSettings holds one entry per extension. If you already set it, add PhishTriage’s entry to your existing value rather than replacing it:

{
  "gjlaknelkbocikcnjebmigaeenagdapl": {
    "installation_mode": "force_installed",
    "update_url": "https://clients2.google.com/service/update2/crx"
  }
}

Optionally add "toolbar_pin": "force_pinned" to the entry to keep PhishTriage’s icon in the toolbar.

Edge

The same two policies, with Edge’s names and paths. Microsoft documents for ExtensionInstallForcelist that it installs PhishTriage without asking, stops people removing or turning it off, uninstalls it if you take it out of the list again, and does not apply in InPrivate. Its entry:

cgohfopcndeliihonajifpfibocendjn;https://edge.microsoft.com/extensionwebstorebase/v1/crx

Or for ExtensionSettings, added to any value you already have:

{"cgohfopcndeliihonajifpfibocendjn":{"installation_mode":"force_installed","update_url":"https://edge.microsoft.com/extensionwebstorebase/v1/crx"}}

Firefox

Firefox takes ExtensionSettings in its own policy file, policies.json, keyed by PhishTriage’s ID. force_installed installs it and stops people removing it:

{
  "policies": {
    "ExtensionSettings": {
      "phishtriage@phishtriage.com": {
        "installation_mode": "force_installed",
        "install_url": "https://addons.mozilla.org/firefox/downloads/latest/phishtriage@phishtriage.com/latest.xpi"
      }
    }
  }
}

Configure the extension

Start from the snippet the portal shows when you create an enrolment key (see Join browsers to your team). With your key in place of the placeholder, it is:

{
  "proxyUrl": "https://api.phishtriage.com",
  "enrolmentToken": "YOUR-ENROLMENT-KEY"
}

These keys are PhishTriage’s, not the browser’s, so each browser takes them in a place set aside for one extension’s settings, under the same ID you force-installed. Add any other key from the table beside them. Deliver them through the same management tool as the force-install, to the same browsers, and before the force-install, because PhishTriage reads the enrolment key when it registers, straight after it is installed (see Browsers that already had PhishTriage).

Chrome

Edge

The portal labels its snippet “Managed policy (Chrome/Edge):”, but Microsoft’s Edge documentation does not say where an extension’s own settings go. Microsoft support staff have given the Chromium layout under Edge’s policy key. Try it on one computer and check it as described under Checking it worked before you roll it out:

Firefox

In policies.json, under 3rdparty → Extensions (capital E) → PhishTriage’s ID, beside the force-install:

{
  "policies": {
    "ExtensionSettings": {
      "phishtriage@phishtriage.com": {
        "installation_mode": "force_installed",
        "install_url": "https://addons.mozilla.org/firefox/downloads/latest/phishtriage@phishtriage.com/latest.xpi"
      }
    },
    "3rdparty": {
      "Extensions": {
        "phishtriage@phishtriage.com": {
          "proxyUrl": "https://api.phishtriage.com",
          "enrolmentToken": "YOUR-ENROLMENT-KEY"
        }
      }
    }
  }
}

Join browsers to your team

  1. In the portal at https://portal.phishtriage.com, open Team, then the Devices tab. At the bottom is Enrolment keys. Press New key.

  2. Give the key a label, for example “Finance rollout”. Optionally set a maximum number of uses and an expiry of 1 to 365 days; left blank, the key has neither. If you set a maximum, read how to size it below. Press Create key.

  3. The portal shows “Enrolment key created” and the key, with “Copy it now — it is stored hashed and will not be shown again.” Copy it. Below, under “Managed policy (Chrome/Edge):”, is the snippet with proxyUrl set to https://api.phishtriage.com and enrolmentToken set to the key. Leave Force full-URL visit tracking on every device unticked (see Choose your settings).

  4. Put the snippet’s keys into your policy, as under Configure the extension; the same keys work for Firefox.

  5. Deploy the policy to the browsers first, then the force-install. Each browser joins the team when PhishTriage first registers, straight after it is installed there, if it has the key by then. Nobody signs in, and no email address is collected.

Browsers that already had PhishTriage

PhishTriage reads the key when it registers: straight after it is installed, and again when someone presses Sign out or Leave team. A browser that is already registered does not pick up a key you add to policy later, so it stays outside the team. The same goes for a browser that registered while the key was wrong, expired, revoked or used up, which does not try again when you fix the key. A Chrome or Edge browser that registers before its settings reach it may be in the same situation.

The reliable way to bring any such browser in is to remove PhishTriage and install it again, with the key already in policy. The fresh install registers again, this time with the key, and what PhishTriage kept on that device is gone. Do it on one browser first. Removing PhishTriage also removes the browser permissions people had accepted for it. After the reinstall, a feature you force on by policy does not run on that browser until the permission is accepted again, and its locked switch cannot ask for it: use the order under the permission rule. Sign out and Leave team, below, keep the permissions.

If none of this fits how you manage your browsers, write to support@phishtriage.com.

On a browser enrolled by key, Leave team registers it again at once, so it rejoins the team for as long as the key is valid. That spends another use of the key and adds a new device to the Devices tab; the old one stays on the list.

The permission rule

Forcing a switch on does not grant a permission. trackDomains, trackVisits and fileProtection, forced on by policy, still need a browser permission accepted on each browser, and PhishTriage does not ask for it. Until it is granted, the feature does not run, even though its switch shows on and Managed.

Checking it worked

Test on one browser of each kind, through each way you deliver policy, before the whole fleet. Test on a browser that has never had PhishTriage: one that already has it does not read a new key.

Safari

None of this applies to Safari. PhishTriage is not available for Safari, and its Safari build has no administrator policy: Safari gives extensions no managed storage, so none of the keys on this page can be set there, including the enrolment key. A configuration profile on a Mac reaches PhishTriage in Chrome, Edge and Firefox on that Mac, not in Safari.

The 1.1.0 update

The stores serve 1.0.0. The next version, 1.1.0, reads Outlook at outlook.cloud.microsoft as mail, a fifth mail host. On Chrome and Edge that is a new site permission. Chrome’s developer documentation says an update that adds a permission with a warning disables the extension until the person accepts it; Chrome’s and Edge’s policy references say a force-installed extension’s permissions are granted implicitly. Neither says in so many words what happens when an update to a force-installed extension adds one. So expect a permission change at 1.1.0: when it reaches a test browser, check at chrome://extensions or edge://extensions that PhishTriage is still turned on.

1.1.0 also sends feedback presses to PhishTriage by default. If you want them kept on the device, set feedbackUpload to false before the update reaches your browsers.

What each setting sends

For every switch above: what leaves the device, where it goes, how long it is kept and who in your team can see it, see Data handling and the privacy policy. Questions about a rollout: contact us.