Frequently Asked Questions (FAQ)
General
Endpoint Central MSP secures Google Chrome, Mozilla Firefox, Microsoft Edge, Internet Explorer, and Chromium-based browsers such as Brave, Yandex, Naver Whale, Vivaldi, and Coc Coc.
The Browsers' module in Endpoint Central MSP is your one stop solution to manage and secure enterprise browsers from all browser based threats. Endpoint Central MSP helps detect the potentially harmful add-ons, isolate untrusted sites away from your default browser, harden browser settings, map browsers and java versions to web applications. You can also establish security standards that need to be followed in an enterprise and detect the computers that are not compliant with the established standards.
Mobility has enabled users to access work from outside the network. Once the user leaves the network, a traditional firewall solution will not be able to protect enterprise devices from threats that can be contacted outside the network.
Extensions are similar to mobile applications that we download on mobile phones. Extensions ask the users permissions to access various aspects of the browsers. Once these permissions are given to the extensions, they can get complete hold of the browser. Based on the permissions given, they can read content present in webpages, the credentials entered, browsing history etc. If the reliability of the extension is questionable, the safety of data can not be guaranteed. Endpoint Central MSP classifies such extensions making use of permissions that could lead to data leaks, as potentially harmful extensions.
To prevent plugins from questionable sources from being used, plugin vendors introduced the concept of signature. Plugins that are signed by the developer can be considered reliable. Endpoint Central MSP classifies unsigned plugins to be harmful. In addition to unsigned plugins, plugins that aren't up to date has more chances of having vulnerabilities. Endpoint Central MSP classifies plugins that aren't signed and those plugins that aren't up to date to be potentially harmful in nature.
The Browser Security module is included in the Security Edition and can be accessed after purchasing the Security license. For the trial version of browser security, kindly contact msp-endpointcentral-support@manageengine.com . It is also available in the Professional, UEM, and Enterprise editions as an add-on.
Navigate to Manage → Groups & Computers → Computers . Select the specific computer and go to Extensions . The browsers managed will be listed under the Browser column.
Extensions deployed via Browser Security can be uninstalled as follows:
Go to Manage → Extension Repository . Select the associated computer count displayed next to the relevant extension to view all devices where it has been deployed. For a specific device, click the Action button next to it and choose Remove . The extension will then be uninstalled from that computer.
To remove the extension from a custom group, navigate to Distributed Groups within the same section and click Remove next to the appropriate custom group.
Go to Insights → Browser Add-ons → Extensions . Search for the Browser Security extension and select its Installation Count. This will display the list of computers where the Browser Security add-on is installed.
Browser extensions deployed through Endpoint Central MSP do not currently work in incognito mode (Chrome/Edge) or private mode (Firefox). This is a limitation of how browsers handle extensions in private browsing sessions.
Workarounds:
- Block Incognito/Private Mode: If you need to prevent users from accessing incognito or private browsing entirely, you can deploy a policy to block these modes on managed machines. This ensures all browsing sessions go through your standard browser configuration where extensions are active.
- Use Standard Browsing: Educate users that extensions and certain security policies only apply in standard (non-private) browsing mode. Private mode is intended for temporary sessions without extensions or policies.
Limitation:Endpoint Central MSP does not provide built-in scripts to manage this behavior. Any custom solution would require manual script creation and testing.
This error indicates that the Endpoint Central MSP server cannot access the browser extension web store (Chrome Web Store, Firefox Add-ons, etc.) to download the extension. Follow these troubleshooting steps:
Step 1: Verify Proxy & Firewall Settings- Proxy Configuration: Ensure the Endpoint Central MSP server's proxy settings (if used) allow traffic to:
- Chrome Web Store:
https://chrome.google.com,https://clients2.google.com - Firefox Add-ons:
https://addons.mozilla.org - Edge Add-ons:
https://microsoftedge.microsoft.com
- Chrome Web Store:
- Firewall Rules: Verify that firewall policies allow outbound HTTPS (port 443) traffic from the Endpoint Central MSP server to the web stores listed above.
- Network Connectivity: Test direct connectivity from the server to the web store URLs. Use
curlorpingto verify access.
- Open the Endpoint Central MSP console in Chrome incognito mode or Firefox private mode.
- Try to add the same extension again to the repository.
- Observe if the error still occurs. Screenshot the result for troubleshooting.
- If your network uses SSL/TLS inspection or certificate interception, ensure the web store certificates are trusted by the server.
- Invalid or expired certificates can block extension downloads.
- Ensure the extension exists in the web store and is available in the region where your server is located.
- Some extensions may be restricted geographically.
If Error Persists: Contact support with a full-page screenshot of the error message and confirmation that the server can reach the web store URLs.
No. Endpoint Central MSP only supports .crx file format for distributing custom extensions. XML files are not supported.
File Formats:- .CRX (Chromium Extension): Supported — This is the compiled binary format for Chrome, Edge, and Chromium-based browsers. You must provide a .crx file to distribute custom Chrome extensions.
- .XPI (Firefox Extension): Supported — This is the format for Firefox extensions. Use the direct download URL pointing to an .xpi file.
- .XML (Manifest): Not Supported — XML manifest files alone cannot be uploaded. You must provide the compiled extension package (.crx or .xpi).
- Contact the extension developer to obtain the compiled .crx or .xpi package file.
- Alternatively, if developing a custom extension, compile it to the appropriate format (.crx for Chrome, .xpi for Firefox) before uploading to Endpoint Central MSP.
- Share the compiled extension file (as .crx or .xpi) instead of the XML manifest.
Troubleshooting Upload Errors: If you're getting an error when uploading an extension, verify that you're uploading the correct file type (.crx or .xpi), not an XML or other format.
No, Browser Security cannot monitor or inspect email content or detect sensitive data within emails. It operates at the browser level, focusing on access control and usage restrictions rather than analyzing data inside web applications. For monitoring sensitive content in emails, refer to the Endpoint DLP module.
The Browsers module visibility in Endpoint Central MSP depends on your license edition and add-on entitlements. If the module is not visible, it may be due to one of the following:
1. License Edition Check
- Security Edition: Browser Security is included. The Browsers module should be visible.
- Professional, UEM, or Enterprise Edition: Browser Security is available as a separate add-on and is NOT included by default.
- Free/Trial Edition: Browser Security is not included. Purchase the Security Edition or add Browser Security as an add-on.
To check your license: Go to Profile icon on the top right and click License and review your current edition and any purchased add-ons.
2. If You Have Purchased Browser Security Add-on but Module is Still Not Visible
- License Synchronization: After purchasing the add-on, it may take up to 24 hours for the license to sync with your Cloud tenant. Wait and refresh the console.
- Cache Issue: Log out completely and log back in. Clear browser cache (Ctrl+Shift+Delete or Cmd+Shift+Delete) and reload the console.
- Admin Role Permissions: Verify your user account has Full Administrator role. Limited roles may not expose the Browsers module. Contact your full administrator to verify entitlements.
- Organization-level Feature Flag: In rare cases, the module may need to be activated at the organization level. Contact ManageEngine support if the above steps don't resolve the issue.
3. Purchase Browser Security Add-on
If you need Browser Security and don't have it, submit a purchase request for the Browser Security add-on. Go to Admin → Subscription → Get Add-ons or contact your sales representative.
Yes. Endpoint Central MSP's Web Filter allowlist mode (using the Allow option in URL Filter) is supported across all managed browsers: Chrome, Firefox, Edge, Internet Explorer, and Chromium-based browsers.
How it works: When you configure Web Filter with Allow rules and specify only approved websites, all other websites are blocked by default on those managed browsers, regardless of browser type.
Note: Web Filter enforcement does NOT apply in Incognito or Guest mode. To enforce allowlist mode completely, disable these modes under Browsers → Policies → Browser Customization.
Restriction Policies
Managing browser extensions is crucial for security, compliance, and productivity. Unapproved extensions can introduce vulnerabilities, lead to data breaches, and affect browser performance.
Endpoint Central MSP provides a centralized platform to manage browser extensions, add-ons, and plugins across all user devices. It allows you to enforce policies, distribute approved extensions, detect outdated plugins, monitor extension permissions, and block unauthorized extensions, ensuring a secure and compliant browsing environment for the entire organization.
Browser lockdown is a security measure that restricts and controls web browsing by limiting access to specific websites, features, and settings to implement safe browsing.
The need to lockdown a browser arises to enhance security, prevent unauthorized access to inappropriate or harmful websites, maintain productivity, and ensure compliance with company policies in both public and enterprise settings.
Web filter is a browser security policy that allows organizations to restrict access to different aspects of the web like URLs and web applications. Web filter can be used to create a fortified boundary that protects networks from unexpected cyberattacks.
Enterprise web filtering software is essential because it helps to protect against a variety of cyber threats, including malware, phishing, and ransomware. It also helps to enforce internet usage policies by blocking access to sites that are deemed inappropriate or non-work-related. Additionally, web filtering can help to increase productivity by reducing the amount of time employees spend on non-work-related websites.
The web is filled with malware and other attack vectors laying low, waiting to take advantage of users' slip-ups and distractions. While browsing the web, users sometimes accidentally land on a malicious website infected with malware, leading to the compromise of sensitive enterprise data.
With the Browsers module in Endpoint Central MSP , you can filter out the malicious websites from being accessed by users across your network. Once a web filter policy has been deployed, the user will not be able to open the specific website/website groups in any of the browsers.
To ensure consistent application of web filtering policies across devices, use Endpoint Central MSP to centrally manage and deploy web filtering policies to all endpoints. This allows you to apply the same rules uniformly, regardless of the device type or location, and monitor compliance to maintain a secure browsing environment. Before deploying the web filter policy, select all the custom groups for the web filter policy to be applied to all endpoints.
No, Safari browser on macOS cannot be restricted using Browser Security. The Browser Restriction policy can block several other browsers such as Google Chrome, Mozilla Firefox, and so on. The Safari application can also be blocklisted using the Application Control module.
Browser Security alone cannot enforce managed-device-only access to Google Workspace. This requires integration with Google Workspace Context-Aware Access or a similar identity-verification mechanism.
What Browser Security CAN Do
- Block or allow google.com/Gmail/Drive via Web Filter policies
- Monitor access to Google services via Web Activity reports
- Restrict file uploads/downloads related to Google services
- Enforce browser security settings on managed devices
What Browser Security CANNOT Do
- Verify that a login originated from an Endpoint Central-managed device
- Block or allow users based on device management status
- Integrate with Google Workspace's access control decisions
Recommended Approach
To enforce managed-device-only access to Google Workspace:
- Enable Google Workspace Context-Aware Access in your Google Admin console
- Configure access policies to trust only devices enrolled in your MDM (Endpoint Central)
- Users accessing Google Workspace from non-managed devices will be required to complete additional verification or will be denied access
- Use Browser Security as a complementary control to enforce other browser policies
Restricting Personal Email Accounts on Corporate Devices
Similarly, blocking personal Gmail accounts while allowing corporate Gmail on the same device is beyond Browser Security's current capabilities, as it cannot distinguish between account authentication status. Consider:
- Using Google Workspace's multiple-account sign-in restrictions
- Implementing app-level controls through MDM policies
- Education and policy enforcement at the user level
Policy Deployment
Policies are applied to the computers/machines on which the agent has been installed on. Inventory details of the current user logged into the machine and the browser will be displayed.
Once deployed, a browser security policy will be effective under the following scenarios:
- When a 90-minute refresh cycle is completed (during which, the computer should be active).
- During the computer startup.
- The first 100 computers on demand, amongst the group of computers.
Web activity takes place online through a web browser. This activity can include browsing websites, downloading media, playing online games, or engaging in social media.
A web/internet activity tracker is a tool used to monitor users' online activity. This can include tracking of web browsing, emails, downloads, and other online activities.
No. This message is displayed by the browser whenever a policy is applied and cannot be disabled from Endpoint Central MSP . Once browser policies are deployed, the browser automatically shows the message: "Your browser is managed by your organization."
You can deploy Chrome extensions using the Extension Repository feature. Add the required extension to the in-house extension repository and deploy it to the target machines.
This behavior occurs because the website restriction is bypassed through Incognito mode. To prevent this, disable Incognito mode using the following policy setting:
Policies → Browser Customization → Security Restrictions → Privacy & Safety → Incognito Mode and select Disable from the dropdown.
To view and export Web Activity reports:
- Navigate to Insights → Web Activity .
- Apply filters for the required domains, if needed.
- Click the Export button on the right to generate the report.
Continuous Maintenance
Web activity must be monitored across the enterprise network to understand user behavior, track trends, and achieve both productivity and security. It can enhance security by identifying potential security risks or detecting fraudulent activity. It can improve productivity by identifying usage of non-work related websites and by blocking them with web filters.
Methods include cookies, analytics tools, tracking pixels, session recording, and user accounts.
It is always better to watch out for insider threats and prevent productivity loss in enterprises. With the Browsers' module in Endpoint Central MSP , you can track user activity on the internet to understand why users have frequently visited certain web applications or websites, and based on this, you can improve productivity and security by deploying web filtering policies.
Endpoint Central MSP provides three predefined compliance standards: STIG, CIS and Default Compliance. Default compliance has all the 30 standards provided by Endpoint Central MSP . IT admins can check the compliance of computers with these predefined standards. It can also be used to create a new compliance policy with standards that his organization mandates and check compliance of computers with the standards defined.
The Browser extension export report may contain numeric codes in the Browser column. These codes represent the following browsers:
| Numeric Code | Browser |
|---|---|
| -1 | Unknown Browser |
| -2 | Internet Explorer |
| -3 | Google Chrome |
| -4 | Mozilla Firefox |
| -5 | Microsoft Edge |
These numeric identifiers may appear in CSV exports. When viewing reports in the console directly (not exported), browser names are displayed in human-readable format.
If Browser Security extension is being enforced but you cannot find the associated policy in the console, follow these steps:
Step 1: Check Extension Repository
- Go to Browsers → Manage → Extension Repository
- Look for Browser Security Plus extension in the list
- If found, remove it:
- Select the extension
- Click Remove from Repository
- Distribute the removal policy to the target groups
Step 2: Check Add-on Settings
- Go to Browsers → Add-on Settings
- Verify Install Browser Security extension automatically is Disabled
- Click Save
- This prevents automatic installation in future, but won't remove existing installations
Step 3: Manual Extension Removal via Script
If the above steps don't remove the extension, use the provided script:
- Contact ManageEngine support to obtain the extension removal script
- Run the script on each affected machine (either via deployment or manually)
- The script will uninstall Browser Security Plus from all browsers on that machine
If Still Enforced After Above Steps
- Check with your IT department for any organization-level browser management policies (Group Policy, Mobile Device Management)
- Some browsers (particularly Chromium-based) may have enterprise policies that override Endpoint Central settings
- Contact ManageEngine support with:
- Screenshot from Browsers → Add-on Settings
- Screenshot from Extension Repository
- Confirmation that the script has been run
- Which browsers show the extension (Chrome, Edge, Firefox, etc.)