Is My Apps Secure Sign-in Extension safe?

Clean risk

My Apps Secure Sign-in Extension scans form fields on all websites during admin SSO capture and sends opt-in diagnostics to Microsoft.

When an administrator activates metadata capture mode, the extension polls every page every 500ms to collect input element attributes (IDs, names, types, HTML structure) across all HTTP and HTTPS sites, storing this data for SSO login replay. A content script also reports the current page URL to the extension's background worker on each navigation, though the URL stays within the browser and is not sent to any server. On user opt-in, diagnostic session logs (session ID, browser info, action type, extension version) are transmitted to Microsoft's Azure AD endpoint; choosing opt-out triggers the extension to uninstall itself.

Microsoftv8.2.1.252Chrome Web Store
0Risk
Who publishes it

Microsoft - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Microsoft

Same store account

1 other listing published from this account, 36.0M+ users between them, none of them carrying a finding.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

login.sovcloud-identity.fr
Also called by 3 other listings, including CloudCapcha

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 8.2.1.196. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 8.2.1.252, which we have not unpacked yet.

  • Read and change your data on every secure site you visit

    https://*/*

  • Read and change your data on every site you visit

    http://*/*

  • See the address and title of every tab you have open

    tabs

  • Run its own code inside the pages you visit

    scripting

  • Add items to the right-click menu

    contextMenus

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Store data in your browser

    storage

  • Act on the current tab, but only after you click the extension

    activeTab

  • Block and redirect the requests your browser makes

    declarativeNetRequest

Where it sends data

Destinations our analysis observed My Apps Secure Sign-in Extension contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • appmanagement.activedirectory.microsoft.com

    My Apps Secure Sign-in Extension sends data to appmanagement.activedirectory.microsoft.com. No other extension we have analysed sends data here.

Updated 30 September 2026ggjhpefgjjfobnfoldnjipclpcfbgbhl