---
title: "FAQ's | Browser Extension & Client Key Deployment"
canonical: "https://ai-docs.certero.com/space/CXSM/341344323/FAQ's%20%7C%20Browser%20Extension%20%26%20Client%20Key%20Deployment"
format: markdown
---
---

## Summary

Below are a list of FAQ's which may help you answer a question or gain further insight on this feature.

---

## <span style="color: #6554c0">Q. What does zero-touch client key deployment mean in practice?</span>

Your users never see or enter the client key. It arrives with the extension by policy, the field is **pre-filled and hidden**, and the user only enters their email address.

---

## <span style="color: #6554c0">Q. Which browsers support it?</span>

**Chrome**, **Edge** and **Firefox** via managed configuration in browser policy. **Safari on macOS** via **managed app configuration**, bridged to the extension by a supplied `.mobileconfig` profile deployed through your MDM.

---

## <span style="color: #6554c0">Q. Why is Safari different?</span>

Safari does not take the key through browser policy, it takes it through managed **app** configuration, bridged to the extension. Because the mechanism differs, **test Safari separately**. A working Chrome deployment does not prove the Safari path.

---

## <span style="color: #6554c0">Q. What happens if a device has no policy?</span>

The client key field is **visible and required**, as before. Manual entry is easier now, the field auto-formats to the UUID template as you type, which removes most transcription errors.

---

## <span style="color: #6554c0">Q. The key field is still visible when it should be hidden.</span>

The policy has not reached that device. Check your policy targeting and force a refresh. On macOS, confirm the profile appears under **System Settings → Privacy & Security → Profiles**.

---

## <span style="color: #6554c0">Q. Where can I see our full client key?</span>

The **companion Mac / iOS app** now shows it in full, specifically so it can be read out during a support call. **Treat it as sensitive**, it identifies your tenant. Do not record it in full in a ticket, screenshot or document.

---

## <span style="color: #6554c0">Q. Some of our staff never receive their login code. Why?</span>

They may exist in Entra but hold **no Exchange mailbox**, so the code is sent somewhere it can never arrive. CerteroX now detects this during the Entra sync and prompts those users to **nominate an alternate address**.

---

## <span style="color: #6554c0">Q. How is the mailbox check made?</span>

From each user's **Exchange Online service plans** during the Entra sync, with a safeguard for **hybrid and on-premises** mailboxes so that people who do have a mailbox are not wrongly flagged.

---

## <span style="color: #6554c0">Q. Can a user nominate any address?</span>

No. The nominated address must belong to a **known user in your organisation**. Anything else is rejected, it cannot be a personal or external address.

---

## <span style="color: #6554c0">Q. Does the user then log in as the nominated person?</span>

**No.** The logged-in identity is **always the original email**. The nominated address is a delivery channel only, and reporting and attribution are unaffected.

---

## <span style="color: #6554c0">Q. What if the mailbox flag is wrong?</span>

The code-entry screen offers **"Send the code to a different email"** as a safety valve. This matters most where a user's licensing has changed but no Entra sync has run since, the flag is only as current as your last sync.

---

## <span style="color: #6554c0">Q. Are users with a mailbox affected?</span>

No. They see no change at all, including those on hybrid or on-premises Exchange.

---

## <span style="color: #6554c0">Q. A user with a mailbox is being prompted to nominate an address.</span>

That is a false positive and worth reporting, it interrupts a working user and reroutes their code to someone else's inbox. First, confirm an **Entra sync has run since that user's licensing last changed**; a stale sync is the most common cause.

---

## <span style="color: #6554c0">Q. What has changed visually?</span>

The extension popup, login, code entry, logged-in view and applications list, has been redesigned with a consistent dark theme and CerteroX branding. The blocked page keeps its content under the same theme. The companion app is restyled to match and now also shows client status and the privacy policy.

---

© 2026 Certero Company Confidential. All rights reserved.