Deployment

MDM deployment

Deploy InputGuard through your existing device management platform.

Overview

InputGuard deployment packages distribute cleanly through device management platforms such as Jamf, Microsoft Intune, Kandji, and Mosyle. The package’s managed profile/policy artifact — a macOS .mobileconfig, a Windows .reg, or a Linux managed-policy JSON — is exactly what these platforms push, and it force-installs the extension and applies your organization’s configuration.

Download the deployment package from a deployment profile in the portal (Deploy… → Download deployment package), push its profile/policy through your MDM, and run the bundled enrollment script — as an MDM script step, or baked into your provisioning — to give each device a stable identity. The device then appears on the Devices page just like any other enrolled device.

Current support

  • Push the package’s managed profile/policy through your MDM platform.
  • Run the enrollment script to enroll devices, with no manual steps for the user.
  • Manage enrolled devices through the InputGuard portal.

Future improvements

Native browser-management profiles and stronger platform-level enforcement are planned for a future release. These will build on top of MDM deployment — they are not required to deploy and enroll devices through your MDM today.

Available today

MDM deployment works now. The future work is deeper platform-level enforcement, not basic MDM distribution or enrollment.