FAQ's | Browser Extension & Client Key Deployment
Summary
Below are a list of FAQ's which may help you answer a question or gain further insight on this feature.
Q. What does zero-touch client key deployment mean in practice?
Your users never see or enter the client key. It arrives with the extension by policy, the field is pre-filled and hidden, and the user only enters their email address.
Q. Which browsers support it?
Chrome, Edge and Firefox via managed configuration in browser policy. Safari on macOS via managed app configuration, bridged to the extension by a supplied .mobileconfig profile deployed through your MDM.
Q. Why is Safari different?
Safari does not take the key through browser policy, it takes it through managed app configuration, bridged to the extension. Because the mechanism differs, test Safari separately. A working Chrome deployment does not prove the Safari path.
Q. What happens if a device has no policy?
The client key field is visible and required, as before. Manual entry is easier now, the field auto-formats to the UUID template as you type, which removes most transcription errors.
Q. The key field is still visible when it should be hidden.
The policy has not reached that device. Check your policy targeting and force a refresh. On macOS, confirm the profile appears under System Settings → Privacy & Security → Profiles.
Q. Where can I see our full client key?
The companion Mac / iOS app now shows it in full, specifically so it can be read out during a support call. Treat it as sensitive, it identifies your tenant. Do not record it in full in a ticket, screenshot or document.
Q. Some of our staff never receive their login code. Why?
They may exist in Entra but hold no Exchange mailbox, so the code is sent somewhere it can never arrive. CerteroX now detects this during the Entra sync and prompts those users to nominate an alternate address.
Q. How is the mailbox check made?
From each user's Exchange Online service plans during the Entra sync, with a safeguard for hybrid and on-premises mailboxes so that people who do have a mailbox are not wrongly flagged.
Q. Can a user nominate any address?
No. The nominated address must belong to a known user in your organisation. Anything else is rejected, it cannot be a personal or external address.
Q. Does the user then log in as the nominated person?
No. The logged-in identity is always the original email. The nominated address is a delivery channel only, and reporting and attribution are unaffected.
Q. What if the mailbox flag is wrong?
The code-entry screen offers "Send the code to a different email" as a safety valve. This matters most where a user's licensing has changed but no Entra sync has run since, the flag is only as current as your last sync.
Q. Are users with a mailbox affected?
No. They see no change at all, including those on hybrid or on-premises Exchange.
Q. A user with a mailbox is being prompted to nominate an address.
That is a false positive and worth reporting, it interrupts a working user and reroutes their code to someone else's inbox. First, confirm an Entra sync has run since that user's licensing last changed; a stale sync is the most common cause.
Q. What has changed visually?
The extension popup, login, code entry, logged-in view and applications list, has been redesigned with a consistent dark theme and CerteroX branding. The blocked page keeps its content under the same theme. The companion app is restyled to match and now also shows client status and the privacy policy.
© 2026 Certero Company Confidential. All rights reserved.