Install and remove the Sophos Protected Browser extension
The Sophos Protected Browser extension can be installed manually on individual Windows and Mac devices or centrally via Active Directory GPO, Google Enterprise Core, Microsoft Intune and Jamf Pro. The appropriate installer is obtained from Sophos Central. For Chrome, check both the enforced policy and the visible extension afterwards.
This guide covers the extension for existing browsers. Deploying and updating the full Sophos Protected Browser is a separate task.
Choose the appropriate deployment method
- Manual: for a small pilot or individual Windows and Mac devices. This method also includes the rollback steps documented by Sophos.
- Active Directory GPO: for domain-joined Windows devices with Google Chrome.
- Google Enterprise Core: for registered Chrome browsers on Windows and macOS.
- Microsoft Intune: for managed Windows and Mac devices with Google Chrome or Microsoft Edge.
- Jamf Pro: for managed Macs with Google Chrome or Microsoft Edge.
Start with a few devices and exactly the browser that will be used later. The ZIP files contain policy, profile, script and utility files depending on the deployment path. Do not mix files from different deployment paths.
Requirements, licence and roles
Before downloading, Meine Produkte > Protected Browser and the area Browser-Erweiterung under Meine Umgebung > Installer or Meine Umgebung > Installers > Protected Browser must be available in the correct Sophos Central tenant. No separate licence designation is specified for these procedures. Therefore, do not infer any further licence or role assumptions from the visibility of a menu. The required roles differ depending on the procedure:
- Manual on Windows: The Windows device is enrolled in an MDM solution; administrator access to the Windows device and Sophos Central is required. This method supports Google Chrome, Comet, and Microsoft Edge; the downloaded ZIP file also includes Atlas.
- Manual on macOS: The Mac is enrolled in an MDM solution; administrator access to both the Mac and Sophos Central is required. Sophos lists Google Chrome, Atlas, Comet and Microsoft Edge as supported browsers, however the current download package may only include profiles for Chrome, Atlas and Edge. If the profiles for Comet are missing in the current package, profiles for another browser must not be used. Download the package again and clarify the missing Comet files with Sophos Support before proceeding. Existing MDM configurations for
ExtensionForceinstallListmust be removed before manual installation: macOS does not merge a managed and a locally installed profile, it only applies one of them. - Active Directory GPO: Required are an AD administrator account for the Group Policy Editor, a Sophos Central admin account, local administrator rights on the target devices, the Chrome ADMX template, and permission to install extensions from external sources. The GPO is already linked to the target OU. An SMB share is available for the extension, which domain computers can access in read-only mode.
- Google Enterprise Core: The Chrome browsers are registered and assigned to the designated organisational unit. Administrator access to target devices, the Google Admin console and Sophos Central is required.
- Microsoft Intune: An account for Intune and Sophos Central is required, as well as administrator access to the target devices. Chrome and Edge may install extensions from external sources.
- Jamf Pro: A Jamf Pro admin account, a Sophos Central admin account and administrator access to the target devices are required. Chrome and Edge may install extensions from external sources.
The additional extension utility is only necessary if device status policy objects are to be used in web policies. It is called ExtensionUtility.exe on Windows and ExtensionUtility.pkg on macOS. Do not install this additional component as a precaution if you do not use the feature.
Download installation files in Sophos Central
Depending on the distribution method, Sophos refers to this step as Download installation files from Sophos Central or Download the installer from Sophos Central. In both cases, it refers to the ZIP package associated with the chosen procedure.
- In Sophos Central, open Meine Umgebung > Installer. In the manual method and for Google Enterprise Core, Sophos specifies the more precise path as Meine Umgebung > Installers > Protected Browser.
- Under Browser-Erweiterung, select the intended path and the operating system:
- Manuell > Windows or Manuell > Mac
- Active Directory (GPO) > Windows
- Google Enterprise with the appropriate operating system
- Microsoft Intune with the appropriate operating system
- JAMF > Mac.
- Unpack the downloaded ZIP file into a controlled working folder. Use only the files and values contained therein for the pilot.
For GPO and Intune, the extension URL from this package is required. Google Enterprise Core requires the extension ID, extension URL and ExtensionSettings.json. Jamf and the manual Mac method use browser-dependent .mobileconfig files. In the manual Mac method, the package must include profiles belonging to the intended browser. If Comet profiles are missing, this is a stop condition and not a reason to rename or reuse Chrome, Atlas or Edge profiles.
Install extension manually
Install the extension on Windows devices
- Open the unpacked folder on the target device.
- Double-click on the browser installation file. For Chrome, this is
ChromeForceInstallExtension.reg; confirm Ausführen and Ja. This will write the extension details into the Windows registry. - Double-click on the file with the extension settings. For Chrome, this is
ChromeExtensionSettings.reg; confirm again Ausführen and Ja. - Only if device status policy objects are required: start
ExtensionUtility.exeand confirm Ja.
After setup, the extension prompts the user to log in with their credentials.
Install the extension on Mac devices
Important: Before this step, check whether
ExtensionForceinstallListis already managed via MDM. Remove this MDM configuration first. Without this cleanup, macOS may continue to apply only the managed profile instead of the local profiles.
- Double-click the browser’s force install file in the unzipped folder, for Chrome for example
ChromeForceInstallExtension.mobileconfig. - Open Systemeinstellungen, search for Profiles and install the downloaded profile. For Chrome, the sample profile is called Install Island Extension Chrome. Confirm Installieren with the administrator password.
- Double-click on the file with the extension settings, for Chrome for example
ChromeExtensionSettings.mobileconfig. - Install the configuration profile under Profile > Heruntergeladen. The Chrome example is called Setup Island Extension on Chrome.
- Only if device status policy objects are required: start
ExtensionUtility.pkg, click on Weiter and Installieren and enter the administrator password.
After completion, the extension prompts the user to log in.
Deploy the extension centrally
Configure Group Policy Object for installing the extension
- Open the prepared GPO and go to Computerkonfiguration > Richtlinien > Administrative Vorlagen > Google > Google Chrome > Erweiterungen.
- Open Liste der automatisch installierten Apps und Erweiterungen konfigurieren, select Aktiviert and click on Anzeigen under Optionen.
- Under Inhalte anzeigen, paste the extension URL copied from Sophos Central. Confirm and save the setting.
- Copy the contents of the downloaded
ChromeExtensionSettings.xml. - In the same GPO, go to Computerkonfiguration > Einstellungen > Windows-Einstellungen > Registry. Right-click on Registry, paste the XML content, name the registry entry, and save it.
Install the extension utility: The browser extension can be deployed using the above GPO settings. For the optional ExtensionUtility.exe, Sophos additionally describes a startup script via Computerkonfiguration > Richtlinien > Windows-Einstellungen > Skripte (Start/Herunterfahren) > Start and an SMB share. However, the verification path used is not clearly described as a local installation indicator. Therefore, do not use the script as an executable template. If device status policy objects require the utility, stop at this point and have Sophos Support or an approved, tested internal packaging process confirm the verification path, execution context, and pre- and post-installation checks for your environment. The extension policy can be validated initially on a pilot OU regardless.
Google Enterprise Core
For the step Installieren Sie die Protected Browser-Erweiterung auf Ihren Geräten., the extension ID, custom URL and settings file are stored together in the Google Admin console:
- Open Chrome-Browser > Anwendungen und Erweiterungen > Benutzer und Browser in the Google Admin console and select the intended organisational unit.
- Click the plus symbol at the bottom right and then on Chrome-App oder -Erweiterung anhand der ID hinzufügen.
- Enter the Erweiterungs-ID copied from Sophos Central.
- Select Von einer benutzerdefinierten URL aus and enter the copied extension URL. Save.
- Under Installationsrichtlinie, first select Installation zulassen and then Installation erzwingen.
- Open Richtlinien für Erweiterungen, upload
ExtensionSettings.jsonfrom the Sophos ZIP file and save again. - Install
ExtensionUtility.exeorExtensionUtility.pkgon the target devices only if web policies use device status policy objects.
The organisational unit determines the scope. For the pilot, therefore, choose a limited OU with few registered browsers rather than enforcing the setting tenant-wide immediately.
Configure Microsoft Intune to install the extension
Windows
- In the Microsoft Intune Admin Center, go to Geräte > Windows > Konfigurationsprofile > Erstellen > Neue Richtlinie.
- Select Windows 10 und höher as the platform and Einstellungskatalog as the profile type. Create and name the profile.
- Under Konfigurationseinstellungen, click on Einstellungen hinzufügen.
- For Chrome, open Google > Google Chrome > Erweiterungen, enable Liste der automatisch installierten Apps und Erweiterungen konfigurieren and enter the extension URL from Sophos Central. For Edge, use Microsoft Edge > Erweiterungen accordingly.
- Confirm with OK and Anwenden.
- Go to Geräte > Windows > PowerShell-Skripte and upload the script obtained from Sophos Central for the browser, for Chrome for example
ChromeExtensions.ps1. - Under Zuordnungen, first select only the pilot devices. Check Überprüfen + Erstellen and click on Erstellen.
macOS
- Go to Geräte > macOS > Konfigurationsprofile and click on Profil erstellen.
- Select Vorlagen, then Benutzerdefiniert and Erstellen. Name the profile and select Gerätekanal as the deployment channel.
- Upload the Force installation file from the Sophos ZIP file under Konfigurationsprofildatei, for example
ChromeForceInstallExtension.mobileconfigfor Chrome. - First assign the profile to the pilot devices and create it.
- Repeat the process with a second profile for the extension settings, in Chrome with
ChromeExtensionSettings.mobileconfig.
If device status policy objects are required, also run the ExtensionUtility.exe or ExtensionUtility.pkg installer included in the package on the devices where the extension is installed.
Jamf Pro
The Jamf process here includes the two configuration profiles:
- Erstellen Sie ein Konfigurationsprofil für die Einstellungen zur Erzwingung der Installation. Open Computer > Konfigurationsprofile, click on Hochladen and upload the force install file:
ChromeForceInstallExtension.mobileconfigorEdgeForceInstallExtension.mobileconfig. - Assign a name and description, select Browser as category, Computerebene as level, and Automatisch installieren as distribution method. Initially limit to the pilot devices under Umfang and save.
- Konfigurationsprofil für die benutzerdefinierten Erweiterungseinstellungen erstellen: Repeat the process for
ChromeExtensionSettings.mobileconfigorEdgeExtensionSettings.mobileconfig.
If the web policies also require the optional ExtensionUtility.pkg, stop after these two configuration profiles. Set packaging, policy, triggers and rollback in a separate, approved and tested Jamf procedure; do not adopt the Intune or manual installation steps for this. The two browser profiles can initially be tested on the pilot devices without this additional component.
Validate installation
For a Chrome deployment with GPO or Google Enterprise Core the check is straightforward:
- Open Chrome on a pilot device.
- Call
chrome://policyand click on Richtlinien neu laden. - Check in Chrome Policies whether
ExtensionInstallForcelistexists and has the status OK. - Call
chrome://extensionsand check if the Protected Browser extension is visible. The message Sophos extension is installed and managed by the organization. may be displayed.
In a manual installation, the login prompt is also an expected outcome. For Intune and Jamf, there is no equivalent, accurate status display available. The rollout therefore remains limited to the pilot until the intended profiles or scripts have reached the device and the expected browser result is visible. A successful assignment in the management console alone does not prove the local installation.
If the extension programme is required, check separately whether its installer has completed on the pilot device. Do not assume that the utility is also installed just because a browser extension is visible.
Troubleshooting by symptom
ExtensionInstallForcelist is missing or does not have the status OK
First, check whether the device is really in the assigned OU or pilot group. Then verify that exactly the extension URL from the current Sophos package has been entered. For GPO, this includes the installed Chrome ADMX template, the GPO link, and the registry entries imported from ChromeExtensionSettings.xml. Afterwards, reload the policies in chrome://policy and repeat the check.
The policy is present, but the extension is not visible
Open chrome://extensions and check there again. For Google Enterprise Core, in addition to the ID and custom URL, Installation erzwingen as well as the uploaded ExtensionSettings.json must be present. For GPO, Liste der automatisch installierten Apps und Erweiterungen konfigurieren must be enabled. Do not change multiple levels at the same time; first correct the missing part on a pilot device and validate again.
The manual installation on the Mac does not work
Check whether ExtensionForceinstallList is already managed by MDM. Remove the managed configuration before the local profile. Then check under Systemeinstellungen > Profiles > Heruntergeladen if both the Force-Install profile and the profile with the extension settings have been installed. macOS does not merge these local profiles with a conflicting MDM configuration.
The extension is visible, but device status objects do not work
The browser extension and the extension programme are two separate components. Check whether ExtensionUtility.exe or ExtensionUtility.pkg has been installed on this specific device. For GPO, read access of the computer account to the designated SMB share alone is not sufficient: use the startup script only when the verification path, execution context and pre-/post-checks are approved and tested. For Jamf, packaging, policy, trigger and rollback must also be defined in a separate, approved and tested procedure. Then check again on the same pilot device before expanding the scope.
A central rollout cannot be reliably rolled back
Do not extend the assignment and leave the pilot group unchanged. Do not attempt any local partial uninstallation while a central force-install policy is active. The mandatory limits and further procedures for centrally managed uninstallations are outlined in the following offboarding section.
Uninstall extension and complete offboarding
Document the browser, installation path and existing profiles or registry files before the rollback. Users will then lose the functionality provided by the extension. Therefore, start the rollback on a test device and check it before a wide-scale removal.
Manual on Windows
- Use the
uninstallfolder from the same Sophos ZIP file as for the installation. - Double-click on
ExtensionUninstaller.regto remove the extension. - If the extension programme has been installed, open PowerShell with the required administrator rights and execute the command documented by Sophos.
powershell.exe -Command "& { msiexec /q /x $((New-Object -ComObject 'WindowsInstaller.Installer').RelatedProducts('{B0D532EB-39A8-497B-8DD8-6A3ACCE97532}')); }"
Then open the browser on the test device and check that the extension is no longer displayed. If it is still present, stop the broad rollback and check whether a GPO, Intune, or other MDM policy is enforcing it again.
Manual under macOS
- Open Systemeinstellungen and search for Profiles.
- Remove both the force-install profile and the profile with the custom extension settings. Confirm each with the administrator password.
- If
ExtensionUtility.pkghas been installed, open a terminal with an administrator account and run the uninstaller documented by Sophos.
sudo /usr/local/island/island-nmh/uninstall
Then check on the test device that both profiles have been removed and that the extension no longer appears in the browser. If a profile is still assigned via MDM, stop the local removal and first remove the managed assignment through the responsible MDM process.
For Google Enterprise Core, Intune and Jamf Pro, there is no complete, tested uninstallation procedure available. While the GPO method does include steps for rollback, there is no comprehensive procedure for the joint removal of assignment, registry entries, Force-Install policy and, if applicable, the utility. Allow Sophos Support or an internally approved and tested process to determine the rollback based on the profiles, policies and packages actually created. Until then, do not expand the assignment and keep the pilot group unchanged. Do not remove local files or individual profiles, registry entries, policies or the utility on suspicion while a central Force-Install policy is active.
Operations and lifecycle
Do not keep an old unpacked ZIP file as a supposed reference installation permanently. Download the files again via the Sophos Central path intended for the chosen method before any planned changes and record which file was distributed to which pilot group. After changes in GPO, OU assignment, Intune profiles or Jamf scope, check the policy and extension again on a pilot device.
Regular operational checks include:
- does the assigned scope still match the intended devices and browsers;
- whether competing local and MDM profiles exist on Macs;
- whether the extension utility is used only where device status policy objects are required;
- the documented manual rollback still works on a test device;
- whether owners and an escalation path for centrally managed uninstallations are defined.
Plan migration or decommissioning dates only based on current product information from Sophos. If there is a change in the deployment method, first validate the new pilot configuration and only then decommission the old method in a controlled manner.
Related existing guides
This guide covers the extension, its distribution methods and safe manual removal. Licensing, identities, DNS, ZTNA and general Sophos Central roles are not part of the extension installation. Likewise, deploying the complete Sophos Protected Browser is a separate lifecycle and update process described in Deploy and keep Sophos Protected Browser up to date.