Back to home

Fleet Management

Policy Enforcement

Define risk thresholds and an approved extension list. We enforce both automatically, through the MDM tools you already have deployed.

Supported MDM platforms

Google Admin Console

Push Chrome policies directly from Workspace Admin. Block or restrict extensions by ID or by risk score threshold - no additional agent required.
In development

Microsoft Intune

Deploy Chrome extension policies via Intune device configuration profiles. In development - register your interest and we will notify you when it ships.
In development

Jamf and Kandji

Support for Apple MDM platforms is planned. Register interest and we will factor your setup into the build prioritisation.

What you can enforce

Block
  • Extensions above your defined risk threshold
  • Extensions not on your approved list
  • Specific extension IDs regardless of score
  • Extensions from publishers you have flagged
Warn
  • Extensions in a review-pending state
  • Extensions with a risk increase since last scan
  • New extensions installed in the last 7 days
  • Extensions matching specific risk categories

Policy actions are logged

Enforcement events - block, warn, override, and exemption - are written to your audit log with a timestamp, device identifier, authenticated actor, and the policy that triggered them. The downstream MDM action (the actual install block on the device) is attested by your MDM's own logs; AIBP records the policy decision that drove it.

See how enforcement works with your MDM.

Talk to us about your setup.