Force-install the browser extension by browser policy (Edge or Chrome ExtensionInstallForcelist). The desktop agent has its own guide: Deploying the desktop agent with Microsoft Intune.
Before you start
- Devices are Microsoft Entra joined (or Entra hybrid joined).
- An Entra device group of the engagement's endpoints exists.
- You know the default browser on the fleet.
Microsoft Edge
In the Microsoft Intune admin center: Devices → Manage devices → Configuration → Create → New policy, platform Windows 10 and later, profile type Settings catalog, Create.
Step 1 · Basics
Name → Edge - flowscope extension. Next.
Step 2 · Configuration settings
+ Add settings, search "Control which extensions are installed silently" (under Microsoft Edge \ Extensions), tick it, close the picker. Set it to Enabled and add:
opjfphaanmoegpfopnheechjekegaelb;https://stflowscopeextrel.blob.core.windows.net/extension-releases/extension/updates.xml
Next.
Step 3 · Scope tags
Skip. Next.
Step 4 · Assignments
Add the device group (or All devices). Next.
Step 5 · Review + create
Create.
If you filter outbound traffic, allow stflowscopeextrel.blob.core.windows.net. Full egress list: Network and security requirements.
Google Chrome
Only if Chrome is in use. Same five-step wizard, with one change on Step 2: search "Configure the list of force-installed apps and extensions" under Google \ Google Chrome \ Extensions, set Enabled, add the same value:
opjfphaanmoegpfopnheechjekegaelb;https://stflowscopeextrel.blob.core.windows.net/extension-releases/extension/updates.xml
If you already lock extensions down
If ExtensionInstallBlocklist is ["*"], also add opjfphaanmoegpfopnheechjekegaelb to the corresponding allowlist. Force-install otherwise overrides a blocklist on its own.
Self-serve, where browsers are not managed centrally
If the engagement runs in self-serve mode, or some browsers are not centrally managed, participants add the extension themselves from the flowscope listing on the Chrome Web Store (works in Chrome and Edge). They are walked through it, alongside the desktop app, in Installing flowscope yourself, so there is no policy to push in that case.
Confirming it landed
The extension shows in edge://extensions (or chrome://extensions) as managed by your organization, enabled, with no remove button. Pairing is automatic on participant sign-in, with a manual fallback for the cases it is not: Pairing the browser extension.