Deploying the Browser Defender extension to your company's users is done from the Setup Checklist tab, in Browser Defender > Setup. Two deployment paths are available: managed deployment, using a device management tool, or manual deployment, with a configuration email for each user. The managed path is the default; you can switch to the other path at any time using the dedicated link.
Prerequisites
- Browser Defender must be active for your company: otherwise, the tab shows "Activate Browser Defender" instead of the deployment module.
- Platform Administrator role in the LibraCyber console.
- For the managed path: administrative permissions required by your device management tool (Intune, GPO, or Jamf) to publish a configuration.
- For the manual path: no device management tool is necessary — each user installs and configures the extension independently, starting from the email they receive.
Detailed procedure
Managed deployment
- In the Setup Checklist tab, keep the managed deployment path selected (default).
If your company's identity provider is Google Workspace: no module appears — select the deployment method directly, Google Workspace or Jamf, and confirm with Confirm.
For any other provider (for example, Microsoft 365): fill in the deployment configuration form, one field at a time:
- Operating system: macOS or Windows.
- Endpoint management tool: on Windows, Intune or GPO; on macOS, Intune or Jamf.
- Environment: based on the combination you choose, you will be asked how to retrieve user identity (for GPO) and whether users work on physical workstations, shared/remote desktops, or a mix of both; for some combinations you also need to specify which browsers to configure (Chrome, Edge, Firefox, Brave, Vivaldi).
NOTE: each field locks as soon as it is filled in. If you make a mistake, the only way to correct it is to click Reset form and start over — you cannot modify a single field that is already locked. The Confirm button remains disabled until all displayed fields have been filled in.
- If you selected Intune on Windows with an environment other than "physical workstations", a downloadable package is not available on your own: in these cases, configuration completion is handled by the support team, which you can contact directly using the Send email to CSM button shown on the page.
- In all other cases, click Download now to download the ZIP package, with the README file and scripts or configuration files for your chosen combination.
- Follow the instructions in the downloaded README (or the tutorial linked for your specific combination) together with your device management tool to complete the deployment on devices.
WARNING: the downloaded package includes the company token in plain text. Never share it with end users: anyone who obtains it can register a device as belonging to your company.
Manual deployment
Switch to manual deployment if you prefer not to use a device management tool: each user receives a personal email with a configuration link.
NOTE: switching from one path to the other resets any configuration already in progress in the managed deployment module.
This path covers the current generation of the extension. Path not covered here: if the extension in use is from a previous generation, contact support for an update.
- Go to Browser Defender > Users and select the users to whom you want to send the invitation.
- Send the configuration emails: each user receives a personal one-time link, valid for 24 hours.
- If a user does not complete the configuration within 24 hours, or has already used the link, you need to send them a new invitation from the same page.
- You can invalidate a link already sent, before it is used, directly from the Users page.
Deployment verification
At this point the extension has been deployed (managed path) or invitations have been sent (manual path); you can proceed to configure company protections in Setup > Preferences. The Setup Checklist page does not maintain a completion status: for verification, use the channels in the dedicated section below. To check the outcome:
- On a single device, deployment is successful when the extension icon appears in the browser and the confirmation screen shows the detected work email address.
- In the Setup Checklist tab, once at least one configuration email has been sent, a counter of the number of emails sent appears — this only confirms that the invitation was sent, not that the user completed the configuration.
- For each user's status, see the Users page.
- For a company-wide overview, see the Users with active extension box in the Dashboard.
Troubleshooting
| Symptom | Probable cause | Solution | Escalation |
| The Confirm button remains disabled | A required field for your chosen combination is still empty | Fill in all displayed fields: which ones are required depends on the answers you have already given | — |
| Download now does not appear, only a message to contact support | The combination you chose (Intune + Windows + an environment other than physical workstations) is not self-service | Use the Send email to CSM button shown on the page | Contact the support team. |
| The Setup Checklist tab shows "Activate Browser Defender" instead of the module | Browser Defender is not active for your company | Contact support to verify your plan and activation | Contact support. |
| The downloaded file, or a received link, shows an unfamiliar address or domain | This is not an error | Still use the usual LibraCyber support channel | — |
| The link in a configuration email has stopped working | The link has expired (24 hours) or has already been used | Send a new configuration email from the Users page | — |