Deploy and Configure with Group Policy
OPSWAT File Security for Browser can be force-installed and centrally configured on managed devices using browser enterprise policies. This page covers Microsoft Edge, Google Chrome, and Chromium on Windows and Linux. Examples use Microsoft Edge; substitute the path for your browser where indicated.
Prerequisites
The device must be centrally managed: domain-joined, Microsoft Entra ID-joined, or enrolled in an MDM such as Intune. Browsers ignore force-install policies on unmanaged devices.
The extension is distributed through the Chrome Web Store. Microsoft Edge installs Chrome Web Store extensions through the policies below; no Edge Add-ons listing is required.
Extension ID:
fjampemfhdfmangifafmianhokmpjbcjUpdate URL:
https://clients2.google.com/service/update2/crx
Force-install the extension
Use either policy. ExtensionSettings is recommended, as it also lets you block user removal and manage other extensions from one policy.
Option A — ExtensionInstallForcelist
Browser | GPO path |
|---|---|
Microsoft Edge | Computer Configuration › Administrative Templates › Microsoft Edge › Extensions › Control which extensions are installed silently |
Google Chrome | Computer Configuration › Administrative Templates › Google › Google Chrome › Extensions › Configure the list of force-installed apps and extensions |
Value:
Option B — ExtensionSettings
Browser | GPO path |
|---|---|
Microsoft Edge | Computer Configuration › Administrative Templates › Microsoft Edge › Extensions › Configure extension management settings |
Google Chrome | Computer Configuration › Administrative Templates › Google › Google Chrome › Extensions › Extension management settings |
Value:
json
Linux
Place a JSON file in the managed policies directory for your browser:
Browser | Directory |
|---|---|
Microsoft Edge |
|
Google Chrome |
|
Chromium |
|
json
Configure managed settings
The extension reads its configuration from the browser's managed storage. All settings are supplied as a single JSON string under a key named settings. Do not supply a nested JSON object.
Settings template
json
Windows
Create a REG_SZ value named settings under the key for your browser, containing the JSON template above as a single-line string.
Browser | Registry key |
|---|---|
Microsoft Edge |
|
Google Chrome |
|
Chromium |
|
Example (Edge):
Linux
Add a file (for example opswat-file-security.json) to the managed policies directory listed above. Note the escaped inner quotes: settings is a string, not an object.
json
Settings reference
Key | Type | Default | Description |
|---|---|---|---|
| boolean |
| Scan every downloaded file. |
| boolean |
| Produce a Deep CDR-sanitized copy of supported file types. Ignored when |
| boolean |
| Submit suspicious files for dynamic analysis. Ignored when |
| string |
| MetaDefender Cloud Workflow ID. When set, the workflow's configuration replaces |
| boolean |
| Check download URLs, IPs, and domains against MetaDefender Cloud reputation data. |
| boolean |
| Share scan results with the MetaDefender Cloud community. |
| boolean |
| Show browser notifications for scan verdicts. |
| boolean |
| Open the scan status page during analysis. |
| boolean |
| Keep only files with a clean verdict; discard the rest. |
| integer or string |
| Maximum size in MB of a download held in browser memory while scanning. Larger files are not held. |
| boolean |
| Check the download URL before the file is fetched. |
| integer or string |
| Skip scanning files from regular links larger than this size in MB. |
| integer or string |
| Skip scanning files from one-time links larger than this size in MB. |
| string |
| MetaDefender Cloud API key used for all scans. Overrides the user's own key and any Core configuration. Empty string disables. |
| string |
| URL of a private MetaDefender Core server. Requires |
| string |
| API key for the MetaDefender Core server. Requires |
| string |
| Name of a workflow rule on the Core server (for example |
| array of strings |
| Domains for which downloads are not scanned. Empty array disables. |
Precedence and interactions
Situation | Behaviour |
|---|---|
| Used for all scans. Core settings and the user's own key are ignored. |
| Files are scanned by the Core server. |
Neither set | Files are scanned by MetaDefender Cloud using the signed-in user's key. |
| Workflow configuration overrides |
File exceeds | File is still scanned. |
File exceeds both limits | Scan is skipped. |
| Scanning does not run. |
Security considerations
Managed-storage values, including
custom_apikeyandcore_apikey, are stored in plaintext in the Windows registry underHKLMand in/etcon Linux. Both locations are readable by local users.Use a dedicated API key for browser deployments. Scope it to the minimum required permissions and rotate it on your normal credential schedule.
Do not use an administrator or organization-owner API key in a browser policy.
Verify the deployment
Open
edge://policy(orchrome://policy). ConfirmExtensionSettingsorExtensionInstallForcelistappears with no errors, and that thesettingsvalue appears under the extension's ID.Open
edge://extensions(orchrome://extensions). The extension should show as installed by your administrator and cannot be removed by the user.Restart the browser after applying policy if the extension does not appear.
Limitations
Allow access to file URLs cannot be set by policy on Chrome or Edge. Each user must enable it manually in
edge://extensionsorchrome://extensions, per device and per profile, if scanning of localfile://downloads is required.The extension is not published to the Microsoft Edge Add-ons store. Edge deployments install from the Chrome Web Store via the policies on this page.