Roll out PhishTriage by browser policy
Install the PhishTriage extension on managed Chrome, Edge and Firefox browsers, set or lock its settings, and join each browser to your team with an enrolment key, without anyone signing in.
Managed rollout is offered with Enterprise (see pricing), and we can set it up with you: contact us. This page is the technical reference. What each setting sends, and how long it is kept, is in Data handling.
Before you start
- A team. Create one in the portal and be its owner; only owners can create enrolment keys. See Set up PhishTriage for a team.
- The version. The browser stores serve version 1.0.0. Every setting below works in that version unless its row says otherwise.
- The order. PhishTriage reads the enrolment key when it registers, which it does as soon as it is installed, and again when someone presses Sign out or Leave team. Put the key in policy before PhishTriage is installed on a browser: a browser that has already registered does not pick up a key added later. On Chrome and Edge even that may not be enough, because a browser may hand an extension its settings a moment after it installs it, and a browser that registers in between stays outside the team. That is a possibility, not a confirmed fault, so check one browser through each way you deliver policy before the whole fleet. See Browsers that already had PhishTriage.
- Forcing a switch is not granting a permission. Background protection, Send full URLs and File protection, forced on by policy, run only where the browser permission they need has been accepted on that browser, and PhishTriage does not ask for it. Read the permission rule before you force any of them.
- Firefox 142 or later. That is PhishTriage’s minimum, so Firefox ESR 140 cannot run it.
- A welcome tab. On its first install PhishTriage opens its welcome page in a new tab, on every browser. Tell people before the rollout.
- Many browsers behind one address. Registration is limited to 10 an hour from one network address. In an office where many computers share one internet address, the rest wait: a browser whose registration was refused registers, and joins the team, the next time someone on it presses Analyze or Log in. Roll out in batches if you need every browser in the team at once.
- Not covered here: Brave and other Chromium-based browsers, and Safari (see Safari).
What you can set by policy
These are PhishTriage’s own settings, delivered as the extension’s managed configuration (how,
per browser, is under Configure the extension). Leave a key out to let each
person decide. Where a key has a switch, a value that is set wins over the person’s own setting
both ways: true forces the switch on, false forces it off, and either way
it is locked and marked Managed in PhishTriage’s settings. An empty string counts as not set. Write
true and false as booleans, not as text in quotes, and every address with
https://.
| Key | What it does | Locks a switch, marked Managed | Version |
|---|---|---|---|
proxyUrltext |
The backend everything goes to: scans, visit checks, evidence, registration. Not set: https://api.phishtriage.com. There is no user setting for it. Change it only for a self-hosted backend. |
No switch. Shown read-only under Advanced, Backend, with the badge | 1.0.0 and later |
enrolmentTokentext |
An enrolment key from the portal. Joins the browser to your team when PhishTriage registers, which it does at install and again when someone presses Sign out or Leave team. A key added to policy later is not picked up by a browser that is already registered. No email address is collected. A key that is wrong, expired, revoked or used up leaves the browser registered outside the team, working normally. Anyone who can see a computer’s browser policy can read the key: see Join browsers to your team. | No. PhishTriage does not show it, but the computer’s policy store holds it | 1.0.0 and later |
trackDomainstrue / false |
Background protection: the name of each site visited is checked, and a site flagged as dangerous gets a full-page warning. Default off. Needs a browser permission. | Yes: Background protection | 1.0.0 and later |
trackVisitstrue / false |
Sends the full address of every page opened, query string included. Default off. Do not force it on without reading Choose your settings. Needs a browser permission. | Yes: Send full URLs, under Advanced | 1.0.0 and later |
cacheDomainVisitstrue / false |
With Background protection on, checks each site’s name at most once an hour. Default off. Does nothing without trackDomains or the person’s own switch. |
Yes: Cache domains for 1 hour, under Advanced | 1.0.0 and later |
evidenceCapturetrue / false |
After a check that comes back phishing or suspicious, uploads a screenshot and the page’s HTML so the site can be reported. Default on: only false turns it off for everyone. |
Yes: Keep evidence of phishing | 1.0.0 and later |
fileProtectiontrue / false |
File protection: each download’s fingerprint, file name and size (not the file) are sent to filescan.phishtriage.com, or to your filescanUrl, to be checked. Default off. Needs a browser permission. The Firefox store build of 1.0.0 offers no File protection switch, so do not rely on forcing fileProtection there. |
Yes: File protection | 1.0.0 and later |
fileBlockingtrue / false |
true: block mode, which holds a file a page builds and asks before saving it. false: warn mode, the default. Needs File protection on. |
Yes: Block, don’t just warn, shown only while File protection is on | 1.0.0 and later |
deepScanAlwaystrue / false |
Sends every downloaded file for a full malware scan, not only the files a person asks about. Default off. Needs File protection on. | Yes: Deep scan every file, shown only while File protection is on | 1.0.0 and later |
filescanUrltext |
The file-scan service. Not set: https://filescan.phishtriage.com. Used only by File protection. Change it only for a self-hosted backend. |
No. Not shown anywhere | 1.0.0 and later |
feedbackUploadtrue / false |
From 1.1.0, a press of Looks safe to me or Looks dangerous is sent to PhishTriage by default. false keeps it on the device; nothing else turns it off. Version 1.0.0 sends no feedback and does not read this key. |
No. Not shown anywhere | 1.1.0 and later |
When proxyUrl, trackDomains, trackVisits or
cacheDomainVisits is set, PhishTriage’s Settings also shows the
notice “Some settings are managed by your organization and can’t be changed here.” What each switch
sends, where it goes and how long it is kept is in
Data handling.
Choose your settings
Start from the portal’s snippet, which holds only proxyUrl and
enrolmentToken. It is configuration only: the force-install policy, further down, is
what installs PhishTriage. With the force-install, and the snippet in policy before it,
each browser joins your team as PhishTriage is
installed on it, and every switch is left to the person using it. Then decide each of these
on purpose:
trackVisits: leave it out. Forced on, the full address of every page each person opens goes to the backend and is stored there: search terms, links to shared documents, and any token a site carries in its addresses.trackDomainssends only the site’s name. The portal offers to add it to the snippet with the box Force full-URL visit tracking on every device, under the warning “Overrides each person’s own setting, and they cannot turn it off. The extension then sends the full address of every page they visit.” Leave the box unticked. To make sure nobody turns it on, set it tofalserather thantrue.trackDomains: your organisation’s choice. On, it shows a full-page warning on a site flagged as dangerous, and sends the name of every site people visit. Read the permission rule before you force it on.evidenceCapture: on unless you setfalse. Captures can show what was on screen, including anything typed that is still visible; see Data handling.- File protection (
fileProtection,fileBlocking,deepScanAlways): your organisation’s choice, under the same permission rule. The Firefox store build offers no File protection switch, so do not rely on File protection there. proxyUrlandfilescanUrl: keep the defaults unless you run your own backend (offered with Enterprise, on request).
Force-install the extension
Each store’s copy of PhishTriage has its own ID. Use the copy from the browser’s own store, and use the same ID again for its settings.
| Browser | Extension ID | Update or install URL |
|---|---|---|
| Chrome (Chrome Web Store) | gjlaknelkbocikcnjebmigaeenagdapl |
https://clients2.google.com/service/update2/crx |
| Edge (Edge Add-ons) | cgohfopcndeliihonajifpfibocendjn |
https://edge.microsoft.com/extensionwebstorebase/v1/crx |
| Firefox (Firefox Add-ons) | phishtriage@phishtriage.com |
https://addons.mozilla.org/firefox/downloads/latest/phishtriage@phishtriage.com/latest.xpi |
All three are store listings, so the computers do not need to be joined to a domain. Chrome and Edge restrict force-installing extensions from outside their own store to domain-joined or managed computers; that is one more reason to give Edge the Edge Add-ons copy.
Chrome
Use one of two policies, not both: ExtensionSettings overrides
ExtensionInstallForcelist for the same extension. Either one installs PhishTriage
without asking and stops people removing or turning it off. Google documents for
ExtensionInstallForcelist that taking an extension out of the list uninstalls it, and
that the list does not apply in Incognito.
ExtensionInstallForcelist is a list; PhishTriage’s entry is:
gjlaknelkbocikcnjebmigaeenagdapl;https://clients2.google.com/service/update2/crx
ExtensionSettings holds one entry per extension. If you already set it, add
PhishTriage’s entry to your existing value rather than replacing it:
{
"gjlaknelkbocikcnjebmigaeenagdapl": {
"installation_mode": "force_installed",
"update_url": "https://clients2.google.com/service/update2/crx"
}
}
Optionally add "toolbar_pin": "force_pinned" to the entry to keep PhishTriage’s icon
in the toolbar.
- Windows, Group Policy (with Google’s Chrome templates): Administrative
Templates → Google → Google Chrome → Extensions → “Configure the list of force-installed apps and
extensions”, or “Extension management settings” for
ExtensionSettings, which takes the JSON on one line. - Windows registry: under
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist, a string value named with the next free number (1,2, …) holding the entry above. Do not reuse a number another extension has: replacing its entry uninstalls it. Or one string value,ExtensionSettings, underHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome, holding the JSON on one line:{"gjlaknelkbocikcnjebmigaeenagdapl":{"installation_mode":"force_installed","update_url":"https://clients2.google.com/service/update2/crx"}} - macOS: a configuration profile for the preference domain
com.google.Chrome, from your device management, with:<key>ExtensionSettings</key> <dict> <key>gjlaknelkbocikcnjebmigaeenagdapl</key> <dict> <key>installation_mode</key> <string>force_installed</string> <key>update_url</key> <string>https://clients2.google.com/service/update2/crx</string> </dict> </dict> - Linux: a JSON file of your choosing in
/etc/opt/chrome/policies/managed/, containing{"ExtensionSettings": …}with the entry above. The same file can carry PhishTriage’s settings; see Configure the extension. - Google Admin console (browsers enrolled in Chrome Enterprise Core, or people signed in with a managed Google Account): Menu → Devices → Chrome → Apps & extensions (with Chrome Enterprise Core: Menu → Chrome browser → Apps & extensions) → Users & browsers. Pick the organisational unit or group, add PhishTriage from the Chrome Web Store or by its ID, and set Installation policy to Force install, or Force install + pin to browser toolbar.
Edge
The same two policies, with Edge’s names and paths. Microsoft documents for
ExtensionInstallForcelist that it installs PhishTriage without asking, stops people
removing or turning it off, uninstalls it if you take it out of the list again, and does not apply
in InPrivate. Its entry:
cgohfopcndeliihonajifpfibocendjn;https://edge.microsoft.com/extensionwebstorebase/v1/crx
Or for ExtensionSettings, added to any value you already have:
{"cgohfopcndeliihonajifpfibocendjn":{"installation_mode":"force_installed","update_url":"https://edge.microsoft.com/extensionwebstorebase/v1/crx"}}
- Windows, Group Policy (
MSEdge.admx): Administrative Templates → Microsoft Edge → Extensions → “Control which extensions are installed silently” (ExtensionInstallForcelist), or “Configure extension management settings” (ExtensionSettings). - Windows registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist, a string value named with the next free number, holding the entry. Or the string valueExtensionSettingsunderHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge, holding the JSON. - Intune, Windows: Devices → Configuration → Create → platform Windows 10 and later, profile type Settings catalog. Add settings, search for “Control which extensions are installed silently” in the Microsoft Edge category, enable it and add the entry. Microsoft treats this as equivalent to Group Policy.
- macOS: the preference domain
com.microsoft.Edge. In Intune, a macOS device configuration profile of type Preference file for that domain, uploading a plist that holds only the key and its value; in Jamf, a Custom Settings payload:<key>ExtensionInstallForcelist</key> <array> <string>cgohfopcndeliihonajifpfibocendjn;https://edge.microsoft.com/extensionwebstorebase/v1/crx</string> </array>
Firefox
Firefox takes ExtensionSettings in its own policy file, policies.json,
keyed by PhishTriage’s ID. force_installed installs it and stops people removing it:
{
"policies": {
"ExtensionSettings": {
"phishtriage@phishtriage.com": {
"installation_mode": "force_installed",
"install_url": "https://addons.mozilla.org/firefox/downloads/latest/phishtriage@phishtriage.com/latest.xpi"
}
}
}
}
- Keep
install_url. Firefox 153 and later can do without it for an extension on Firefox Add-ons; Firefox 142 to 152 need it. - Where the file goes: on Windows, in a folder named
distributionnext to the Firefox program file; on macOS, inFirefox.app/Contents/Resources/distribution; on Linux, indistributioninside the Firefox installation folder, or system-wide in/etc/firefox/policies. Save it as UTF-8. - Flatpak Firefox cannot read
/etc/firefox/policies. Put the file at/var/lib/flatpak/extension/org.mozilla.firefox.systemconfig/<arch>/<branch>/policies/policies.json(for examplex86_64andstable). - Windows, Group Policy: with Mozilla’s Firefox templates, the same policy is
the multi-string registry value
ExtensionSettingsunderSOFTWARE\Policies\Mozilla\Firefox, holding the JSON without the outer"policies"object. - macOS profile: the preference domain
org.mozilla.firefox, which works only withEnterprisePoliciesEnabledset to true. The full example is under Configure the extension.
Configure the extension
Start from the snippet the portal shows when you create an enrolment key (see Join browsers to your team). With your key in place of the placeholder, it is:
{
"proxyUrl": "https://api.phishtriage.com",
"enrolmentToken": "YOUR-ENROLMENT-KEY"
}
These keys are PhishTriage’s, not the browser’s, so each browser takes them in a place set aside for one extension’s settings, under the same ID you force-installed. Add any other key from the table beside them. Deliver them through the same management tool as the force-install, to the same browsers, and before the force-install, because PhishTriage reads the enrolment key when it registers, straight after it is installed (see Browsers that already had PhishTriage).
Chrome
- Windows: the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\gjlaknelkbocikcnjebmigaeenagdapl\policy, with one value per setting: text as a string value, andtrueorfalseas a DWORD of 1 or 0. As a.regfile:Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\gjlaknelkbocikcnjebmigaeenagdapl\policy] "proxyUrl"="https://api.phishtriage.com" "enrolmentToken"="YOUR-ENROLMENT-KEY"
Push these values with whatever you already use to set registry values on managed computers. - macOS: the preference domain
com.google.Chrome.extensions.gjlaknelkbocikcnjebmigaeenagdapl, in a configuration profile whose preferences payload (com.apple.ManagedClient.preferences) targets that domain. Its keys are PhishTriage’s settings, as they are:<key>proxyUrl</key> <string>https://api.phishtriage.com</string> <key>enrolmentToken</key> <string>YOUR-ENROLMENT-KEY</string>
A switch is<true/>or<false/>. A plain.plistimported withdsclis laid out differently: there each value is wrapped instateandvaluekeys. - Linux: in the same folder as the force-install,
/etc/opt/chrome/policies/managed/, under3rdparty→extensions→ the ID. One file can hold both:{ "ExtensionSettings": { "gjlaknelkbocikcnjebmigaeenagdapl": { "installation_mode": "force_installed", "update_url": "https://clients2.google.com/service/update2/crx" } }, "3rdparty": { "extensions": { "gjlaknelkbocikcnjebmigaeenagdapl": { "proxyUrl": "https://api.phishtriage.com", "enrolmentToken": "YOUR-ENROLMENT-KEY" } } } } - Google Admin console: on PhishTriage’s entry in
Apps & extensions, Users & browsers, the field
Policy for extensions takes JSON. Chromium’s administrator documentation gives
its format as each setting wrapped in an object with a
Valuemember; Google’s own help page shows no format, so confirm on a test browser atchrome://policy:{ "proxyUrl": { "Value": "https://api.phishtriage.com" }, "enrolmentToken": { "Value": "YOUR-ENROLMENT-KEY" } }
Edge
The portal labels its snippet “Managed policy (Chrome/Edge):”, but Microsoft’s Edge documentation does not say where an extension’s own settings go. Microsoft support staff have given the Chromium layout under Edge’s policy key. Try it on one computer and check it as described under Checking it worked before you roll it out:
- Windows: the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\cgohfopcndeliihonajifpfibocendjn\policy, with the same values as for Chrome. - macOS: the preference domain
com.microsoft.Edge.extensions.cgohfopcndeliihonajifpfibocendjn, with the same keys as for Chrome.
Firefox
In policies.json, under 3rdparty → Extensions (capital
E) → PhishTriage’s ID, beside the force-install:
{
"policies": {
"ExtensionSettings": {
"phishtriage@phishtriage.com": {
"installation_mode": "force_installed",
"install_url": "https://addons.mozilla.org/firefox/downloads/latest/phishtriage@phishtriage.com/latest.xpi"
}
},
"3rdparty": {
"Extensions": {
"phishtriage@phishtriage.com": {
"proxyUrl": "https://api.phishtriage.com",
"enrolmentToken": "YOUR-ENROLMENT-KEY"
}
}
}
}
}
- Windows: Mozilla says an extension’s settings need an administrative template
from the extension’s maker to be set through Group Policy or Intune. PhishTriage has none, so use
policies.jsonon Windows too. - macOS: in the
org.mozilla.firefoxprofile, besideEnterprisePoliciesEnabled:<key>EnterprisePoliciesEnabled</key> <true/> <key>ExtensionSettings</key> <dict> <key>phishtriage@phishtriage.com</key> <dict> <key>installation_mode</key> <string>force_installed</string> <key>install_url</key> <string>https://addons.mozilla.org/firefox/downloads/latest/phishtriage@phishtriage.com/latest.xpi</string> </dict> </dict> <key>3rdparty</key> <dict> <key>Extensions</key> <dict> <key>phishtriage@phishtriage.com</key> <dict> <key>proxyUrl</key> <string>https://api.phishtriage.com</string> <key>enrolmentToken</key> <string>YOUR-ENROLMENT-KEY</string> </dict> </dict> </dict>
Join browsers to your team
In the portal at https://portal.phishtriage.com, open Team, then the Devices tab. At the bottom is Enrolment keys. Press New key.
Give the key a label, for example “Finance rollout”. Optionally set a maximum number of uses and an expiry of 1 to 365 days; left blank, the key has neither. If you set a maximum, read how to size it below. Press Create key.
The portal shows “Enrolment key created” and the key, with “Copy it now — it is stored hashed and will not be shown again.” Copy it. Below, under “Managed policy (Chrome/Edge):”, is the snippet with
proxyUrlset tohttps://api.phishtriage.comandenrolmentTokenset to the key. Leave Force full-URL visit tracking on every device unticked (see Choose your settings).Put the snippet’s keys into your policy, as under Configure the extension; the same keys work for Firefox.
Deploy the policy to the browsers first, then the force-install. Each browser joins the team when PhishTriage first registers, straight after it is installed there, if it has the key by then. Nobody signs in, and no email address is collected.
- Anyone who can see a computer’s browser policy can read the key. It sits in the
policy store of every browser you deploy it to, and Chrome lists an extension’s settings, this one
included, at
chrome://policy. Anyone who has it can join a browser to your team until it expires, is used up or is revoked. Treat it like the rest of your deployment configuration: set an expiry and a maximum number of uses, sized as below, and revoke the key when the rollout is done. Browsers already enrolled with it stay in the team. - Size the maximum number of uses with room to spare. Every registration with the key spends one use and adds a device to the Devices tab; a registration the key refuses spends none. A browser registers again when someone presses Leave team or Sign out in PhishTriage, and when PhishTriage is removed and installed again; each browser profile counts as a browser of its own. The device that registration replaces stays on the list, unused. Allow for that, or leave the maximum blank and rely on the expiry.
- One shared key per rollout. Each device on the Devices tab shows the label of the key it joined with. The portal warns that a single-use key names one machine, so keys issued one per person make their labels identify individuals.
- The key list shows each key’s label, uses, devices, expiry and status: active, revoked, expired or exhausted. Revoke refuses new enrolments with that key only. Browsers already enrolled with it stay in the team. It cannot be undone.
- What the team sees of these browsers follows the team’s reporting mode, as for any other device; see Set up PhishTriage for a team.
Browsers that already had PhishTriage
PhishTriage reads the key when it registers: straight after it is installed, and again when someone presses Sign out or Leave team. A browser that is already registered does not pick up a key you add to policy later, so it stays outside the team. The same goes for a browser that registered while the key was wrong, expired, revoked or used up, which does not try again when you fix the key. A Chrome or Edge browser that registers before its settings reach it may be in the same situation.
The reliable way to bring any such browser in is to remove PhishTriage and install it again, with the key already in policy. The fresh install registers again, this time with the key, and what PhishTriage kept on that device is gone. Do it on one browser first. Removing PhishTriage also removes the browser permissions people had accepted for it. After the reinstall, a feature you force on by policy does not run on that browser until the permission is accepted again, and its locked switch cannot ask for it: use the order under the permission rule. Sign out and Leave team, below, keep the permissions.
- Chrome and Edge: stop
force-installing PhishTriage: take it out of
ExtensionInstallForcelist, or set itsExtensionSettingsentry’sinstallation_modetoremoved. Wait until the browser has uninstalled it, make sure the settings with the key are in place, then put the force-install back. - Firefox: set the entry’s
installation_modetoblocked, which Mozilla documents as removing an extension that is already installed, and restart Firefox. Then set it back toforce_installed, with the key already under3rdparty, and restart again. - Without a reinstall: if PhishTriage’s account row, under Settings, offers Sign out or Leave team, pressing it registers the browser again at once, this time with the key. If the row reads “Not signed in”, there is no such button. You can invite the person and have them press Log in (see Set up PhishTriage for a team), which joins the browser with their account rather than by key.
If none of this fits how you manage your browsers, write to support@phishtriage.com.
On a browser enrolled by key, Leave team registers it again at once, so it rejoins the team for as long as the key is valid. That spends another use of the key and adds a new device to the Devices tab; the old one stays on the list.
The permission rule
Forcing a switch on does not grant a
permission. trackDomains, trackVisits and
fileProtection, forced on by policy, still need a browser permission accepted on each
browser, and PhishTriage does not ask for it. Until it is granted, the feature does not run, even
though its switch shows on and Managed.
- Which permission. Background protection (
trackDomains) and Send full URLs (trackVisits) needwebNavigation. File protection (fileProtection) needsdownloads. Each of the three also needs access to all sites. Background protection and Send full URLs share one grant: once someone has accepted it for either, it covers both. Forcing any of the three tofalseneeds no permission. - Where the prompt comes from. PhishTriage asks for the permission only when someone turns the switch on, in its settings or on its welcome page. A switch locked by policy cannot be turned, so on a browser that has never been granted the permission, nothing asks for it.
- An order that works for Background protection and
File protection. Leave
trackDomainsorfileProtectionout of the policy at first and ask people to turn the feature on themselves, accepting the browser’s prompt. Then set the key totrueto lock it on. Turning a switch off in PhishTriage does not give the permission back, so a later lock still finds it. - Send full URLs is not part of that order. This page recommends leaving
trackVisitsout (see Choose your settings). Because it shares Background protection’s grant, forcing it on where someone has already accepted that prompt starts sending full addresses at once, with no prompt of its own. - Not affected:
evidenceCapture,cacheDomainVisits,enrolmentToken,proxyUrl,filescanUrlandfeedbackUploadneed no extra permission.fileBlockinganddeepScanAlwaysact only once File protection runs.
Checking it worked
Test on one browser of each kind, through each way you deliver policy, before the whole fleet. Test on a browser that has never had PhishTriage: one that already has it does not read a new key.
- Chrome: open
chrome://policy, press Reload policies, tick Show policies with no value set, and check thatExtensionInstallForcelistorExtensionSettingshas the status OK. Extensions with managed settings are listed there too, with the values Chrome received for them. A change may need Chrome restarted. - Edge: open
edge://policyto see the policies applied. Close and reopen Edge if it was open when the policy changed; after a Group Policy change, rungpupdate /forcefirst. Microsoft does not say whether an extension’s own settings are listed there, so check PhishTriage itself as below. - Firefox: restart Firefox, open
about:policies, and check thatExtensionSettingsand3rdpartyare active and nothing is listed as an error. - In PhishTriage: click its icon, then Settings. With the
portal’s snippet in place, the notice “Some settings are managed by your organization and can’t be
changed here.” appears, and Advanced, Backend shows
https://api.phishtriage.comwith the Managed badge. Every switch you forced shows the badge and cannot be changed. The account row begins “Team ·” or reads “Part of a team”, with Leave team. - In the portal: Team, Devices lists each joined browser, with its browser, enrolment date, last check-in, Enrolled via (the key’s label) and status, in either reporting mode. A browser checks in only when it is used. A new one shows as Active, turns Idle after 7 days without use and Stale after 30, so an installed but unused browser can look stale. Under Enrolment keys, the key’s uses and devices go up.
- A browser missing from the list whose account row reads “Not signed in” registered without the key, or on Chrome and Edge may have registered before its settings reached it. See Browsers that already had PhishTriage, and check the order of your policies.
Safari
None of this applies to Safari. PhishTriage is not available for Safari, and its Safari build has no administrator policy: Safari gives extensions no managed storage, so none of the keys on this page can be set there, including the enrolment key. A configuration profile on a Mac reaches PhishTriage in Chrome, Edge and Firefox on that Mac, not in Safari.
The 1.1.0 update
The stores serve 1.0.0. The next version, 1.1.0,
reads Outlook at outlook.cloud.microsoft as mail, a fifth mail host. On Chrome and Edge
that is a new site permission. Chrome’s developer documentation says an update that adds a
permission with a warning disables the extension until the person accepts it; Chrome’s and Edge’s
policy references say a force-installed extension’s permissions are granted implicitly. Neither says
in so many words what happens when an update to a force-installed extension adds one. So expect a
permission change at 1.1.0: when it reaches a test browser, check at chrome://extensions
or edge://extensions that PhishTriage is still turned on.
1.1.0 also sends feedback presses to PhishTriage by default. If
you want them kept on the device, set feedbackUpload to false before the
update reaches your browsers.
What each setting sends
For every switch above: what leaves the device, where it goes, how long it is kept and who in your team can see it, see Data handling and the privacy policy. Questions about a rollout: contact us.