intense_username Posted December 29, 2023 Posted December 29, 2023 Hi all. We're a Windows based district -- currently on-prem joined systems using Securly with SmartPAC/certificate GPOs. It's worked well for us. As time progresses, we're focusing on Intune for Windows management in the future. In general, testing has gone well, but I keep revisiting one last item: managing and enforcing a Securly+Chrome combo via Intune management. Based on my conversations with Securly, there's no approachable way to go about the SmartPAC method with Intune. I can push the extension to the managed Chrome install via Intune, but it doesn't seem to filter anything. I found the behaviors kind of odd. For example, the Chrome policy enforces student login with a Google account (to the browser itself) to continue -- I punch in my test student account and I'm in the default Chrome window. I check extensions within Chrome and I can see Securly listed there, but nothing is filtered as I check random blocked sites. If I go to Google Drive and finish the sign-in there, suddenly all of my search results return a non-secure website (sort of like if you push the SmartPAC to on-prem systems but don't have the cert installed). I have a separate policy in Intune which contains the Securly certificate and puts it in the local computer store -- now websites work without the non-secure warning, but yet, no filtering seems to be active. Okay... so it's as if I have some of the puzzle pieces, but not all of them. While I continue to try and troubleshoot this, part of me keeps looking back at Edge and wondering if we should put our focus on Edge as the official (and only) browser for student devices. I mean, it auto logs in, auto installs the Securly extension in Edge, and everything seems to work seamlessly. Edge and Chrome sharing the same technical base via Chromium admittedly helps with compatibility concerns as well. Being a Microsoft shop, maybe there's an argument to be had there... If anybody has any suggestions for the Chrome piece I would greatly appreciate it (or, if perhaps you could offer your 2c about the Edge-sanity-check I certainly wouldn't turn it down). Thank you all!
rogerdnixon Posted December 29, 2023 Posted December 29, 2023 We have largely moved to Google's own Advanced Desktop Security now, but still have a handful of devices on InTune and use Securly. We use SmartPAC: The OMA-URI to do this is (so what we now apply in Googleland): ./Vendor/MSFT/NetworkProxy/SetupScriptUrl String - your SmartPAC URL (as http not https) Works fine in Chrome.
intense_username Posted December 29, 2023 Author Posted December 29, 2023 Interesting... thank you for this info! I think I'm going to build this out and test it, but the more I think about this the more I feel I may position this as a backup plan. In other words, push Edge as the default/only browser for students, but say that knowing I have confidence in a backup plan should Chrome be absolutely required for some reason I have yet to discover. I can always roll that out after the fact... but it just puts my mind at ease that there's a method to lean into should it come to that. Appreciate the info! I'm going to whip this up and see how it all works out. Appreciate it!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now