# Add-on Restriction Last Updated On: 24 Jul 2026 4 minutes read Configure a policy to block risky browser add-ons and control the permissions the ones you keep can use. ## Browser add-ons Add-ons boost productivity, but unmanaged ones are also a direct security risk. ### What add-ons are, and why they need managing A **browser add-on** (plugin or extension) is a software module that adds specific capabilities to a web browser — features like ad blocking, password management, and integration with other applications. They can boost productivity, but they also pose security risks: a malicious add-on can steal personal information and compromise systems. Unauthorized add-ons can lead to data breaches and non-compliance, so effective add-on management matters for security, compliance, and performance alike. Limiting unnecessary add-ons also improves productivity and browser speed. ## Managing add-ons Build a policy that blocks specific add-ons or permissions, then control what the rest can access. ### Create an add-on restriction policy 1. Open the Endpoint Central MSP console and go to **Browsers → Policies → Add-on Management**. 2. Click **Create Policy** and select a browser. 3. Give the policy a name. 4. Choose **Yes** or **No** against **Allow users to install extensions**. 5. Block specific add-ons manually or by uploading a CSV file — or block specific permissions used by add-ons, such as Desktop capture. 6. Select **Remove selected extensions if already installed** to automatically remove the specified extensions from devices where they're already present. 7. Configure **Native Messaging Permissions** — allow or block communication between the browser and native applications on Windows devices. 8. Configure **Pin Extensions** to permanently fix add-ons to the browser's toolbar for easy access and visibility. 9. Configure **Manage Runtime Host Access** — allow or block a specific extension from running on specific websites by associating it with a website group. 10. **Save** and **publish** the policy, then [deploy](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) it with the computers or groups it should apply to. ![Add-on Management policy configuration screen.](https://www.manageengine.com/sites/meweb/images/desktop-central/help/browser-security/addon-management.png) Configuring the Add-on Management policy. ## Related - [Browser Security Overview](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-overview.html) - [Policy Deployment](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) - [Browser Security FAQ](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-faq.html#restrictfaq)