The Sastrify Browser Extension is a lightweight browser add-on designed to enhance visibility into SaaS usage across your organization. It seamlessly supports the discovery of shadow IT and provides actionable insights—such as SaaS utilization trends and usage patterns—directly within your Sastrify platform. The extension operates only when users interact with SaaS applications using their company email, ensuring relevance and data accuracy while respecting user privacy.


All collected data is securely transmitted to your Sastrify platform, where Sastrify admins can:

  • View detailed usage data under the Usage tab of each tool.

  • Discover and manage new tools through the Shadow IT Radar feature.


IN THIS ARTICLE


Data Collection and Privacy Safeguards


The extension strictly tracks access to and activity within approved SaaS applications accessed via the organization’s work email. It collects the following data points:

  • Website hostnames of approved SaaS tools
  • User interaction metrics (e.g., click counts, keystroke counts, file upload events)
  • Session duration and timestamps (access and exit times)
  • Configuration data, such as approved product URLs
  • Work email address from the Edge work profile, which serves as an Employee/User ID


In doing so, we maintain a strict privacy-first approach to data handling:

  • User identifiers are cryptographically hashed to ensure anonymization.
  • Only whitelisted business SaaS applications are monitored—personal websites and content are never tracked.
  • Automatic exclusion of certain domains, including career sites, job boards, and non-business application URLs.
  • Data is transmitted securely via HTTPS, using OAuth for authentication.
  • Minimal data collection principle: Only essential usage metrics are gathered to support organizational analytics.

How to Install the Sastrify Browser Extension via Microsoft Intune

  1. Log into your Sastrify platform and go to Integrations > Discovery.
  2. Under "Browser Extension Integrations", find the Microsoft Edge connection card and click "Enable".


  3. If you haven’t connected an HRIS integration yet, you’ll be prompted to set one up.
     If an HRIS is already connected, deployment options will appear immediately.
  4. Choose Admin Install Instructions.




Using the steps below, you can deploy the Sastrify browser extension to all devices or to a specific group using Microsoft Intune for Microsoft Edge browsers.


Step 1: Create an Azure AD Group (Optional)

Skip this step if you plan to deploy the extension to all devices.


  1. Navigate to Microsoft Intune > Groups > New Group.

  2. Choose "Security" as the group type.

  3. Enter a meaningful group name (e.g., Sastrify Shadow IT).

  4. Set "Membership type" to Assigned.

  5. After creating the group, go to the "Members" section to add devices (e.g., using device serial numbers).



Step 2: Create the Configuration Profile

  1. Go to Intune > Devices > Windows > Configuration profiles.

  2. Click "Create profile".

  3. Use the following settings:

    • Platform: Windows 10 and later

    • Profile type: Settings catalog

  4. Click "Add settings", then search for Microsoft Edge.

  5. Browse for "Microsoft Edge\Extensions".
  6. Enable "Control which extensions are installed silently".
  7. Add the following extension ID: mkeifknkbhmlkdbgjnkedncjhhfllhih




Step 3: Assign the Policy

  1. Proceed to the Assignments step of the profile wizard.

  2. Choose:

    • The group you created in Step 1, or

    • All devices, if you want universal deployment.

  3. Complete the wizard to deploy the policy.


This configuration profile will automatically install the Sastrify browser extension in the background on Microsoft Edge for the targeted devices.


How to Uninstall the Sastrify Browser Extension

  1. Open Microsoft Endpoint Manager by going to the Intune Admin Center.
  2. Navigate to Apps or Devices > Configuration Profiles, and locate the profile used to deploy the Sastrify extension.
  3. Open the profile and go to the "Assignments" section.
  4. Remove the user or device group that was assigned the extension.
  5. Save and confirm. Changes will propagate automatically, and Intune will trigger the uninstall on the next policy sync.


Frequently Asked Questions


Please refer to the Browser Extension FAQ page for a complete list of frequently asked questions.