Is My Apps Secure Sign-in Extension safe?
My Apps Secure Sign-in Extension scans form fields on all websites during admin SSO capture and sends opt-in diagnostics to Microsoft.
When an administrator activates metadata capture mode, the extension polls every page every 500ms to collect input element attributes (IDs, names, types, HTML structure) across all HTTP and HTTPS sites, storing this data for SSO login replay. A content script also reports the current page URL to the extension's background worker on each navigation, though the URL stays within the browser and is not sent to any server. On user opt-in, diagnostic session logs (session ID, browser info, action type, extension version) are transmitted to Microsoft's Azure AD endpoint; choosing opt-out triggers the extension to uninstall itself.
Who publishes itMicrosoft - 1 other listing from the same operator, none carrying a finding
Microsoft - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 36.0M+ users between them, none of them carrying a finding.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 8.2.1.196. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 8.2.1.252, which we have not unpacked yet.
Read and change your data on every secure site you visit
https://*/*
Read and change your data on every site you visit
http://*/*
See the address and title of every tab you have open
tabs
Run its own code inside the pages you visit
scripting
Add items to the right-click menu
contextMenus
Store an unlimited amount of data in your browser
unlimitedStorage
See every page you navigate to, as you navigate to it
webNavigation
Store data in your browser
storage
Act on the current tab, but only after you click the extension
activeTab
Block and redirect the requests your browser makes
declarativeNetRequest
Where it sends data
Destinations our analysis observed My Apps Secure Sign-in Extension contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- appmanagement.activedirectory.microsoft.com
My Apps Secure Sign-in Extension sends data to appmanagement.activedirectory.microsoft.com. No other extension we have analysed sends data here.