--- title: "How To | Deploy the Client Key by Policy" canonical: "https://ai-docs.certero.com/space/CXSM/341344283/How%20To%20%7C%20Deploy%20the%20Client%20Key%20by%20Policy" format: markdown --- --- ## Summary This guide walks you through delivering the CerteroX client key to your users' browsers by enterprise policy, so they never have to enter it themselves — and confirming it has worked. --- ## Before you Start - You have your organisation's **CerteroX client key**. - You have administrative access to your **browser policy management** (group policy, Intune, Jamf or equivalent). - For Safari on macOS, you have the **CerteroX **`.mobileconfig` configuration profile and the ability to deploy it through your MDM. - The **CerteroX Browser Extension** is deployed, or is being deployed alongside this configuration. > ⚠️ **Handle the client key as sensitive.** It identifies your tenant. Do not circulate it in tickets, screenshots or shared documents. --- ## Deploy to Chrome, Edge and Firefox 1. In your policy management tool, locate the **managed configuration** settings for the CerteroX extension. 2. Set the **client key** value to your organisation's key. 3. Target the policy at the devices or user groups in scope. 4. Allow the policy to apply, then have a target device refresh policy. --- ## Deploy to Safari on macOS Safari uses **managed app configuration** bridged through to the extension, rather than browser policy, a different mechanism from the other three browsers. 1. Obtain the `.mobileconfig` configuration profile from Certero. 2. Deploy the profile through your MDM to the macOS devices in scope. 3. On a target device, confirm the profile has landed: **System Settings → Privacy & Security → Profiles**. The profile should be listed and applied. --- ## Confirm It Has Worked On a device with the policy applied: 1. Open the extension popup while **logged out**. The **login view** opens. 2. Check the **client key** field. It should be **hidden**, the key has been supplied by policy. 3. Enter a valid **email address** and complete the login with the code. 4. Confirm the session is against the **correct tenant**. Repeat on each browser you have targeted, including Safari. --- ## Confirm the Fallback Behaviour On a device with **no** policy applied: 1. Open the extension popup while logged out. 2. The **client key field is visible and required**. 3. Begin typing a key. It should **auto-format to the UUID template** as you type. This is the expected behaviour where policy has not been deployed, and it is also a quick way to prove whether policy has reached a given device. --- ## Troubleshooting | <span style="color: #ffffff">**Problem**</span> | <span style="color: #ffffff">**What to Check**</span> | | --- | --- | | The client key field is still visible. | The policy has not reached that device. Confirm policy targeting and force a refresh. On macOS, check the profile is listed under **Profiles**. | | Chrome works but Safari does not. | Expected failure mode, Safari uses a different mechanism. Confirm the `.mobileconfig` is installed, not just the browser policy. | | Login fails against the wrong tenant. | The deployed key is incorrect. Verify it against the key shown in the companion app or supplied by Certero. | | A user cannot receive their login code. | They may have no Exchange mailbox. | | I need to read the full client key for a support call. | The **companion Mac / iOS app** displays it in full. Read it only to Certero support, and do not record it in a ticket. | --- © 2026 Certero Company Confidential. All rights reserved.