Getting Started

Deploy InputGuard to devices

Roll InputGuard out across a managed fleet using per-OS deployment packages generated from your organization’s deployment profile.

Individual installation vs. organization deployment

These are two different paths. Individual users install InputGuard themselves; organizations deploy it to devices with a deployment package — admins do not ask each user to install the extension first.

Individual users

Individuals install InputGuard directly from the Chrome Web Store (launching soon).

  • No account required
  • No organization required
  • Local detection
  • Local audit history

Organization deployment

Each deployment package is designed to:

  • Configure device enrollment
  • Configure browser policies
  • Force-install the InputGuard extension
  • Connect the device to the organization

Organization deployment

InputGuard deployment packages install the extension and enroll devices for you. Users do not need to visit the Chrome Web Store or install the extension manually.

How deployment works

From a deployment profile in the portal, open Deploy… and download a deployment package — one ZIP per operating system. Each package contains a managed profile/policy artifact and a generic enrollment script. On each device the admin installs the profile or policy, then runs the enrollment script; together they:

  • Force-install the InputGuard extension (production packages).
  • Apply your organization’s static configuration — org, deployment key, and API endpoint.
  • Give the device a stable identity and capture its hostname and OS.
  • Connect the device to the organization so it appears in the portal.

The result is a hands-off flow for the end user:

  1. 1

    Admin installs the profile/policy and runs the enrollment script

    Run both on the device, or push the package through management tooling.
  2. 2

    Chrome installs InputGuard automatically

    Production packages force-install the extension — no manual Chrome Web Store visit is required.
  3. 3

    Device enrolls into the organization

    The enrollment script establishes the device identity and connects it to your org.
  4. 4

    Device appears in the portal

    Confirm it on the Devices page, then assign policy.

Management platforms

The package’s profile/policy artifact is exactly what device management platforms consume — distribute it through Jamf, Microsoft Intune, Kandji, Mosyle, and similar. See MDM deployment.

Choose your platform

The installation mechanics differ slightly per operating system. Follow the guide that matches your fleet:

Before you start

Deployment assumes you’ve already created an organization and a deployment profile. If you haven’t, start with Create an organization. For the concepts behind profiles, enrollment keys, and device registration, see Device enrollment.