How To | Deploy the Client Key by Policy
Summary
This guide walks you through delivering the CerteroX client key to your users' browsers by enterprise policy, so they never have to enter it themselves — and confirming it has worked.
Before you Start
You have your organisation's CerteroX client key.
You have administrative access to your browser policy management (group policy, Intune, Jamf or equivalent).
For Safari on macOS, you have the CerteroX .mobileconfig configuration profile and the ability to deploy it through your MDM.
The CerteroX Browser Extension is deployed, or is being deployed alongside this configuration.
Handle the client key as sensitive. It identifies your tenant. Do not circulate it in tickets, screenshots or shared documents.
Deploy to Chrome, Edge and Firefox
In your policy management tool, locate the managed configuration settings for the CerteroX extension.
Set the client key value to your organisation's key.
Target the policy at the devices or user groups in scope.
Allow the policy to apply, then have a target device refresh policy.
Deploy to Safari on macOS
Safari uses managed app configuration bridged through to the extension, rather than browser policy, a different mechanism from the other three browsers.
Obtain the .mobileconfig configuration profile from Certero.
Deploy the profile through your MDM to the macOS devices in scope.
On a target device, confirm the profile has landed: System Settings → Privacy & Security → Profiles. The profile should be listed and applied.
Confirm It Has Worked
On a device with the policy applied:
Open the extension popup while logged out. The login view opens.
Check the client key field. It should be hidden, the key has been supplied by policy.
Enter a valid email address and complete the login with the code.
Confirm the session is against the correct tenant.
Repeat on each browser you have targeted, including Safari.
Confirm the Fallback Behaviour
On a device with no policy applied:
Open the extension popup while logged out.
The client key field is visible and required.
Begin typing a key. It should auto-format to the UUID template as you type.
This is the expected behaviour where policy has not been deployed, and it is also a quick way to prove whether policy has reached a given device.
Troubleshooting
Problem | What to Check |
|---|
Problem | What to Check |
|---|---|
The client key field is still visible. | The policy has not reached that device. Confirm policy targeting and force a refresh. On macOS, check the profile is listed under Profiles. |
Chrome works but Safari does not. | Expected failure mode, Safari uses a different mechanism. Confirm the .mobileconfig is installed, not just the browser policy. |
Login fails against the wrong tenant. | The deployed key is incorrect. Verify it against the key shown in the companion app or supplied by Certero. |
A user cannot receive their login code. | They may have no Exchange mailbox. |
I need to read the full client key for a support call. | The companion Mac / iOS app displays it in full. Read it only to Certero support, and do not record it in a ticket. |
© 2026 Certero Company Confidential. All rights reserved.