Cyber Cloud Ops Logo
Microsoft Intune

Secure Your Environment: Blocking External Extension Installs with Intune

By Admin User
June 13, 2025
7 min
Secure Your Environment: Blocking External Extension Installs with Intune

Secure Your Environment: Blocking External Extension Installs with Intune

Hi everyone! Today, we’re going to explore how to allow or block external extensions from being installed in Microsoft Edge — using Microsoft Intune.

As many of you know, the Control the installation of external extensions policy is an important setting in Microsoft Edge, especially for organizations managing devices through Intune.

🎯 Why Blocking External Extensions Matters

In Microsoft Edge, administrators can enable settings such as “Block external extensions from being installed” and apply these configurations to specific user groups or devices.

This provides an easy and effective way to manage browser security and helps maintain data privacy and protection — especially in industries where compliance and security are critical.

By enabling this policy, organizations can ensure that extensions are only installed from official and trusted sources, such as the Microsoft Edge Add-ons store.

If this policy is enabled:

  • External extensions will be blocked from installation.

  • Only approved extensions from trusted sources can be used.

If this policy is disabled or not configured: ❌ Users will still be able to install extensions from unverified external sources, which introduces potential security risks to the organization.

Blocking unauthorized extensions helps reduce the chances of accidental data leakage or malicious code being introduced via third-party extensions.

🚀 What Happens When This Policy Is Enabled in Microsoft Edge via Intune?

When the “Control the installation of external extensions” setting is enabled in Microsoft Edge through Intune:

  • Users will be prevented from installing external extensions.

  • The organization gains greater control over the browsing environment.

  • It helps mitigate the risk of data leakage and security incidents caused by untrusted extensions.

🛠️ How to Deploy “Block External Extensions” Policy Using Intune

To deploy this policy, you first need to create a configuration profile in Intune.

Follow these steps:

Go to Microsoft Intune admin center.

  • In the left-hand menu, click Devices.

  • Select Windows Devices.

  • Click on Configuration.

  • Policies New Policy.

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 01

A new pane will open on the right side.

  • Under Platform, select Windows 10 and later.

  • Under Profile type, choose Settings catalog.

  • Click Create to begin configuring the policy.

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 02

Basic Information

In the Basics tab, enter a name for your policy in the Name field. If you’d like, you can also include a description to provide more details about the policy’s purpose. This helps in identifying the policy later. The policy name and its description will be visible as shown in the screenshot below.

  • Name: I named the policy that Block external extensions from being installed for user.

  • Description: Block external extensions from being installed for the user in MS Edge

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 03

Configuration Settings

The Next Step Configuration Settings Page On the Configuration Settings page, you will see an option labeled “Add Settings” in blue. Click on that to open the Settings window. In the Settings window, locate and select the Microsoft Edge category. Within that category, click on the Extensions subcategory.

  • In the Extensions section, look for the policy named: “Block external extensions from being installed for users” select the policy and close settings picker.

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 04

Block External Extensions from Being Installed — Default Behavior

By default, the “Block External Extensions from Being Installed” policy is set to Disabled.

After selecting the setting in the Configuration Settings page and closing the Settings window, you will return to the main Configuration Settings view. At this point, you will see that the policy is now listed and visible.

When the policy remains in the Disabled state, users can still install external extensions, which may introduce security risks.

👉 In our example, we will enable this policy by selecting Enabled. This ensures that only trusted extensions can be installed, improving the overall security posture of the organization.

Tip: Enabling this policy helps enforce corporate security standards by ensuring that only approved extensions from trusted sources can be installed — providing greater control and protection over browser usage across managed devices.

Define Scope (if applicable)

In this step, you can define scoping filters to target specific groups or conditions—this is useful in more complex environments where policies should only apply to a subset of devices or users. If you’re not using scoping filters, simply leave the default settings and click Next to proceed.

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 05

Assign the Policy

In the Assignments tab, choose who will receive this reboot policy. You can assign it to a specific group, or apply it broadly to All Users or All Devices, depending on your deployment strategy.

Once you've selected the appropriate target group, click Next to continue.

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 06

Review and Create

In the final step, review all the configurations you've made, including the platform, profile type, settings, scope, and assignments. If everything looks correct, click Create to deploy the policy. This will apply the scheduled reboot configuration to the assigned devices, ensuring they restart as planned without manual intervention.

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 07

Device and user Check-in Status

After creating the policy, the next step is to check if it was applied successfully. Always remember that it can take up to 8 hours for the policy to be fully deployed. If you’ve synced the policy through the Company Portal, you can check its status easily. Just go to Devices > Configuration, then search for the name of your policy in the list.

  • Click on the policy to see the check-in status for both devices and users.

  • In the screenshot below, you’ll see it says “Succeeded: 3” this means the policy was deployed successfully.

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 08

Client-Side Verification

After deploying the policy, you can verify whether it has been successfully applied on the client side using Event Viewer.

To do this:

  1. Open Event Viewer.

  2. Navigate to: Applications and Services Logs > Microsoft > Windows > Device Management > Enterprise Diagnostic Provider > Admin.

Within this log, you will see a list of policy-related events. To narrow down the results, use the “Filter Current Log” option on the right-hand panel.

👉 In this case, look specifically for Event ID 813 or Event ID 814, which indicate policy processing and application.

In my example, I found confirmation of the policy in Event ID 813.

The event details indicated that the following policy had been applied:

Policy Name: BlockExternalExtensions Policy Area: microsoft_edgePolicymicrosoft_edge~Extensions Enrollment ID: (unique identifier for the device enrollment) Current User: (SID of the user the policy was applied to) Enrollment Type: (shows the enrollment method — for example, MDM enrollment) Scope: (indicates the scope of the policy application)

Secure Your Environment: Blocking External Extension Installs with Intune - Fig. 09

This confirms that the Block External Extensions policy was successfully processed and applied to the device.

👉 Tip: Event ID 813 typically reflects successful policy application, while Event ID 814 may provide additional diagnostic information in case troubleshooting is required.

More Information

For additional guidance on managing Microsoft Edge extensions using Microsoft Intune, refer to the following Microsoft Learn resources:

These resources provide comprehensive guidance for configuring, managing, and optimizing extension policies using Microsoft Intune and Microsoft Edge.

Thank you!

🖥️ Ricardo Barbosa

📘 MCT Microsoft Certified Trainer | ☁️ Cloud Architect

🌐 Technology Director - https://altelix.com

Originally published on LinkedIn · June 13, 2025 · read the original article
Tags:
MicrosoftIntune
EndpointManagement
Windows11
DeviceManagement
ModernWorkplace
MEM
ITPro
ZeroTrust
MVPBuzz
Keep reading

The full Hardening Windows Endpoints series

One control at a time, with the exact policy paths, the detection and remediation scripts, and the reporting to prove it worked across the fleet.

Browse all articles
Need a hand

Rolling this out across a real fleet?

Reading the guide is the easy part. Designing it for thousands of devices, piloting it without breaking production and proving compliance afterwards is the hard part. That is what we do at ISolutions CloudX.

Talk to ISolutions CloudX

Written by Ricardo Barbosa, Microsoft MVP and MCT. New guide every Wednesday and Friday. Follow on LinkedIn to get the next one.

Posts Sugeridos

Secure Your Environment: Blocking External Extension Installs with Intune | CyberCloudOps Blog