---
title: "How To | Deploy the Client Key by Policy"
canonical: "https://ai-docs.certero.com/space/CXSM/341344283/How%20To%20%7C%20Deploy%20the%20Client%20Key%20by%20Policy"
format: markdown
---
---

## Summary

This guide walks you through delivering the CerteroX client key to your users' browsers by enterprise policy, so they never have to enter it themselves — and confirming it has worked.

---

## Before you Start

- You have your organisation's **CerteroX client key**.
- You have administrative access to your **browser policy management** (group policy, Intune, Jamf or equivalent).
- For Safari on macOS, you have the **CerteroX **`.mobileconfig` configuration profile and the ability to deploy it through your MDM.
- The **CerteroX Browser Extension** is deployed, or is being deployed alongside this configuration.

> ⚠️ **Handle the client key as sensitive.** It identifies your tenant. Do not circulate it in tickets, screenshots or shared documents.

---

## Deploy to Chrome, Edge and Firefox

1. In your policy management tool, locate the **managed configuration** settings for the CerteroX extension.
2. Set the **client key** value to your organisation's key.
3. Target the policy at the devices or user groups in scope.
4. Allow the policy to apply, then have a target device refresh policy.

---

## Deploy to Safari on macOS

Safari uses **managed app configuration** bridged through to the extension, rather than browser policy, a different mechanism from the other three browsers.

1. Obtain the `.mobileconfig` configuration profile from Certero.
2. Deploy the profile through your MDM to the macOS devices in scope.
3. On a target device, confirm the profile has landed: **System Settings → Privacy & Security → Profiles**. The profile should be listed and applied.

---

## Confirm It Has Worked

On a device with the policy applied:

1. Open the extension popup while **logged out**. The **login view** opens.
2. Check the **client key** field. It should be **hidden**, the key has been supplied by policy.
3. Enter a valid **email address** and complete the login with the code.
4. Confirm the session is against the **correct tenant**.

Repeat on each browser you have targeted, including Safari.

---

## Confirm the Fallback Behaviour

On a device with **no** policy applied:

1. Open the extension popup while logged out.
2. The **client key field is visible and required**.
3. Begin typing a key. It should **auto-format to the UUID template** as you type.

This is the expected behaviour where policy has not been deployed, and it is also a quick way to prove whether policy has reached a given device.

---

## Troubleshooting

| <span style="color: #ffffff">**Problem**</span> | <span style="color: #ffffff">**What to Check**</span> |
| --- | --- |
| The client key field is still visible. | The policy has not reached that device. Confirm policy targeting and force a refresh. On macOS, check the profile is listed under **Profiles**. |
| Chrome works but Safari does not. | Expected failure mode, Safari uses a different mechanism. Confirm the `.mobileconfig` is installed, not just the browser policy. |
| Login fails against the wrong tenant. | The deployed key is incorrect. Verify it against the key shown in the companion app or supplied by Certero. |
| A user cannot receive their login code. | They may have no Exchange mailbox. |
| I need to read the full client key for a support call. | The **companion Mac / iOS app** displays it in full. Read it only to Certero support, and do not record it in a ticket. |

---

© 2026 Certero Company Confidential. All rights reserved.