Secure access
Welcome back
Enter your credentials to access the BDR security console.
◆ Protected by encrypted authentication
Secure access
Enter your credentials to access the BDR security console.
◆ Protected by encrypted authentication
Security Overview
Last 24 Hours · HKT
Fleet
Policy Analytics
Alert Queue
Policy
DLP Analytics
DLP Analytics
Browser Context
Alert Queue
Identity Provider
Provision, update and disable tenant users from Microsoft Entra ID, Okta or another SCIM 2.0 provider. The bearer token is shown once only.
Policy
Policy
Identity Source
Assign telemetry user IDs and devices to real company people. Managed groups and roles are used by policy scope matching.
Bulk Mapping
Download the template, fill only the fields you have, then upload the saved CSV to match people with extension device IDs.
Browser Context
Inventory shows the latest Chrome endpoint snapshot per device, user, and profile. New snapshots replace older rows in this view; deleting a row clears the stored snapshots for that endpoint, not the actual Chrome extensions.
Notifications
Delivery control for newly created HIGH and MEDIUM security alerts.
Recipient list
Checking the saved recipient and delivery configuration.
Portal Admin
Manage local portal accounts for this dashboard. Browser extension ingestion and policy sync are separate from portal login.
Access
Access
Create a local account with a temporary password.
Account Security
Set a temporary password. The user must change it after their next sign-in.
Identity Provider
Configure a tenant IdP such as Keycloak, Microsoft Entra ID or Okta. Enforce SSO only after testing and assigning a protected local break-glass Admin.
Platform Administration
Create and manage customer tenants and their initial Super Admin accounts. This page is restricted to tenant_demo Admins and Super Admins.
Tenant Directory
Disabling a tenant blocks its access without deleting its users, policies, or history.
Platform Administration
Create the customer workspace and its first Super Admin in one step.
Subscription
License usage counts unique devices seen within the last 30 days. Online is tracked separately using a 30-minute check-in window; exceeding the assigned limit raises a warning without interrupting endpoint protection.
Account Security
Protect your account with a TOTP authenticator app. There is no SMS or recurring fee.
Use a time-based one-time password from your authenticator app when signing in. No email or SMS code is sent.
Step 1
Google Authenticator, Microsoft Authenticator, 1Password and other TOTP apps are supported.
Step 2
Only you can scan and confirm your authenticator.
Admins can disable 2FA, never enable it for you.
One-time codes provide an emergency sign-in path.
Audit
Review administrative changes, policy edits, extension package activity, and operator actions in one dedicated audit view.
Extension Security
Choose a browser to manage its developer package and company deployment. Each browser keeps its own extension identity, release files, and deployment settings.
Selected browser
Token
Chrome
Tokens
Private Distribution
Generate a tenant-specific ZIP with two explicit controls: force installation and tenant configuration. Employees receive the signed CRX silently; the selected token assigns every deployed browser to the correct tenant.
Release
Customer IT handoff
This ZIP is a confidential, tenant-specific policy pack—not a universal one-click installer. Customer IT chooses one managed-Chrome method below and uses only the matching artifact. The same pack must never be shared with another tenant.
Google Admin Console · viewguard-google-admin-…jsonUpload the JSON under Policy for extensions, or paste its complete contents if Upload is unavailable. It supplies only apiBaseUrl and the tenant apiToken; OU/group, custom extension, Extension ID, update manifest URL, Force install and Save remain manual Admin Console steps.
Windows GPO · viewguard-chrome-….regUse the registry file as the exact Chrome policy source. Customer IT should translate or push those HKLM values through its managed Group Policy process; it is not a GPO backup and employees should not double-click it.
Windows Intune · viewguard-chrome-….regUse the registry file as the authoritative values for a customer-approved PowerShell, Win32 app or remediation deployment. A .reg file cannot be imported directly as an Intune configuration profile.
macOS MDM · viewguard-chrome-….mobileconfigUpload and assign the configuration profile through the customer's MDM at device/system scope. Pilot it first; do not ask employees to install the profile manually.
deployment-pack.json and README.txtReference metadata, release URLs, validation checks and rollback notes for customer IT. deployment-pack.json is not uploaded to Google Admin, Intune or MDM.
Follow the complete method-specific steps in Documentation: Windows GPO, Windows Intune, macOS MDM, or Google Admin Console.
Signing key is never generated or stored in Portal. Sign every CRX release offline with the same protected key to preserve the Extension ID.
ViewGuard documentation
Use these guides to operate every item in the Portal sidebar. Each feature has its own page with purpose, access requirements, operating steps, expected results, and safety notes.
Network · Security · IT
Permit the minimum outbound destinations below before deploying ViewGuard. Configure rules by FQDN, protocol and port; do not pin cloud or CDN services to resolved IP addresses.
| Destination | Protocol / port | Required by | Purpose |
|---|---|---|---|
bdr.prosfinity.com | HTTPS / TCP 443 | Portal browsers | Portal sign-in, application content, API requests and audit or administration workflows. |
bdr.prosfinity.com | HTTPS / TCP 443 | Chrome, Edge and Firefox extensions | Tenant enrolment, policy retrieval, inventory check-in, telemetry and alert delivery. |
bdr.prosfinity.com | HTTPS / TCP 443 | Managed browsers and deployment systems | Private CRX, XPI and update-manifest download paths under /extension/. |
challenges.cloudflare.com | HTTPS / TCP 443 | Portal sign-in browsers | Cloudflare Turnstile verification required by the interactive login page. |
| Destination | Protocol / port | When needed | Purpose |
|---|---|---|---|
Customer IdP hostname | HTTPS / TCP 443 | Company SSO is enabled | OIDC discovery, authorisation, token and signing-key traffic. Use the exact issuer hostname configured for the tenant. |
Customer SCIM client → bdr.prosfinity.com | HTTPS / TCP 443 | Directory Sync is enabled | Outbound SCIM provisioning from the customer identity platform to the tenant-specific BDR SCIM endpoint. |
bdr.prosfinity.com if extension certificate validation or update downloads fail.*.prosfinity.com rule is not required.https://bdr.prosfinity.com/dashboard, complete Turnstile and sign in from the target user network.https://bdr.prosfinity.com/health responds without a proxy block page or certificate warning.apiBaseUrl and apiToken, then confirm the browser appears in Inventory with a recent check-in./extension/.Overview
Alerts
Policies
Users
Inventory
Settings · General · Admin only
IdP · OpenID Connect · Admin only
Use this runbook to onboard a customer IdP, validate the complete sign-in flow, and enable SSO enforcement without locking administrators out. Company SSO protects Portal access only; browser extension deployment tokens remain separate.
https://bdr.prosfinity.com/scim/v2/<tenant-id>.Multi Authentication
Audit · Admin only
Data Retention · Logs and operational records
BDR provides short-term operational visibility. It is not a long-term log archive, evidence vault, backup service, or SIEM. The limits below apply separately to each tenant.
| Record type | Retention period | Record limit | Deletion rule |
|---|---|---|---|
| General telemetry events | 7 days | Up to 1,000 events per tenant | Includes routine browser activity and historical inventory snapshots. The oldest record is permanently removed when either limit is reached. |
| Security, DLP and blocked-response events | 30 days | Included in the 1,000-event tenant limit | Security event classification extends the time window, but the shared event record limit still applies. |
| Open, Investigating or Acknowledged alerts | Until the alert is Closed | Not included in the closed-alert limit | Active alerts are not deleted by age. Close an alert only after the investigation and required notes are complete. |
| Closed alerts | 30 days after the last status change | Up to 2,000 closed alerts per tenant | The oldest Closed alert is permanently removed when either limit is reached. |
| Case comments and response actions | Same as the associated alert | Follow the associated tenant and alert | They remain while the alert remains and are permanently removed with that alert, preventing orphan case data. |
| Audit logs | 90 days | Up to 5,000 records per tenant | Includes sign-in, policy, user, alert-status, token and other administrative actions. The oldest record is permanently removed when either limit is reached. |
| Data category | Examples | How long it remains |
|---|---|---|
| Policy and detection configuration | Policies, custom rules, policy overrides and deleted-rule state | Until an authorised administrator changes or deletes it. |
| Tenant and user state | Tenant records, Portal users, managed users, archived user state and user mappings | Until changed or deleted through an authorised lifecycle action. |
| Current device inventory | The current managed-browser device registry and latest device state | Until the device is explicitly removed. Historical inventory snapshot events remain subject to the 7-day event policy. |
| Extension security configuration | Active extension tokens, default token mapping and current package configuration | Until rotated, revoked, replaced or deleted by an authorised administrator. |
| Identity configuration | OIDC and SCIM configuration | Until changed or deleted by an authorised administrator. |
Extension Security · Admin only
ViewGuard documentation
Choose the browser-management method already used by the customer. Customer IT is responsible for enrolling and managing Chrome; Prosfinity provides the signed ViewGuard extension, tenant policy pack, deployment values, and end-to-end validation steps.
Before you begin
inalpegloaagicplciefkhpdilbaeelihttps://bdr.prosfinity.com/extension/updates.xmlhttps://bdr.prosfinity.comForce installapiBaseUrl + tenant-specific apiTokenThe same signed CRX is used by every customer. The tenant-specific apiToken assigns browsers to the correct tenant and must never be reused across customers. Do not paste a token into a ticket, email thread, or public chat.
Method 1
Use this method when Windows computers are domain joined and customer IT manages Chrome through Active Directory GPO.
inalpegloaagicplciefkhpdilbaeeli;https://bdr.prosfinity.com/extension/updates.xml.HKLM\Software\Policies\Google\Chrome\3rdparty\extensions\inalpegloaagicplciefkhpdilbaeeli\policy, create string values apiBaseUrl and apiToken using the values from that tenant's ZIP. Do not ask end users to double-click the confidential .reg file.gpupdate /force on a pilot device, open chrome://policy, select Reload policies, fully quit Chrome, and reopen it..reg file provides the exact force-install and managed-policy registry values. Review it before applying through GPO.Method 2
Use this method when Windows devices are Entra joined or registered and enrolled in Microsoft Intune.
inalpegloaagicplciefkhpdilbaeeli;https://bdr.prosfinity.com/extension/updates.xml.Software\Policies\Google\Chrome\3rdparty\extensions\inalpegloaagicplciefkhpdilbaeeli\policy. Use the customer's approved Intune method, such as a reviewed PowerShell/Win32 package or remediation. A .reg file is a reference artifact; it is not directly importable as an Intune configuration profile.chrome://policy, reload policies, fully quit Chrome, and reopen it..reg as the source of truth for registry paths and values. Convert or wrap it only through the customer's approved Intune deployment process.Method 3
Use this method when customer Macs are enrolled in Jamf, Kandji, Microsoft Intune, Mosyle, or another MDM that can deploy configuration profiles.
chrome://management reports that the browser is managed. Remove or reconcile any old local com.google.Chrome plist/profile or cloud policy for the same extension before testing.viewguard-chrome-<extension-id>.mobileconfig. It contains both Chrome force installation and tenant managed configuration..mobileconfig, and assign it at device/system scope to the pilot group.chrome://policy, select Reload policies, verify the production Extension ID and extension policy, then fully quit and reopen Chrome..mobileconfig. For a pilot only, it can also be reviewed in System Settings → General → Device Management; production deployment should remain MDM controlled.Method 4
Use this method when customer IT already manages Chrome browsers or managed Google users from Google Admin Console.
inalpegloaagicplciefkhpdilbaeeli, choose From a custom URL, enter https://bdr.prosfinity.com/extension/updates.xml, and save.viewguard-google-admin-<extension-id>.json from that tenant's ZIP. Otherwise open the file and paste its complete valid JSON into the text field. Confirm there is no validation error and that it contains apiBaseUrl and that tenant's apiToken.chrome://policy, select Reload policies, fully quit Chrome, and reopen it.viewguard-google-admin-<extension-id>.json from the correct tenant pack. Upload that JSON where the Admin panel offers Upload, or paste its complete contents into Policy for extensions. Never upload the whole ZIP. Older packs should be regenerated before deployment.ViewGuard documentation
Generate an Edge Company Deployment pack and use only the Edge artifacts. The signed Edge CRX, Extension ID, update manifest and managed-policy paths are different from Chrome.
Before you begin
pgnnnpinccfeldgmimjkhjdeikokgpkmhttps://bdr.prosfinity.com/extension/edge-updates.xmlhttps://bdr.prosfinity.comapiBaseUrl + tenant-specific apiTokenviewguard-edge-<extension-id>.reg, viewguard-edge-<extension-id>.mobileconfig, release details, validation checks and rollback notes. It contains a tenant token and must be handled as confidential.The Chrome and Edge extensions have different IDs, signed CRX files, update manifests and policy roots. Do not reuse a Chrome registry file, mobileconfig or Extension ID for Edge.
Edge · Method 1
Use this method for domain-joined Windows devices managed through Active Directory.
Group Policy provides the most consistent deployment model for a traditional Windows domain because the extension installation policy and its tenant configuration can be applied at computer scope. ViewGuard is installed silently from the Prosfinity update service, while the managed values bind that installation to the correct customer tenant. End users do not need local administrator access and cannot remove a force-installed extension.
Keep both controls in one computer GPO wherever possible. Splitting installation and configuration across unrelated GPOs makes scope, precedence and troubleshooting harder to audit, particularly when devices move between organisational units.
MSEdge.admx and matching language ADML files to the domain Central Store, then open Group Policy Management.pgnnnpinccfeldgmimjkhjdeikokgpkm;https://bdr.prosfinity.com/extension/edge-updates.xml.apiBaseUrl and apiToken as string values under HKLM\Software\Policies\Microsoft\Edge\3rdparty\extensions\pgnnnpinccfeldgmimjkhjdeikokgpkm\policy. Copy the exact values from the Edge tenant .reg; do not ask users to import the confidential file.gpupdate /force, open edge://policy, select Reload policies, fully quit every Edge process and reopen Edge.ExtensionInstallForcelist, both managed values, tenant connectivity, inventory and a monitor-mode test alert before expanding the GPO.A successful result has two independently verifiable parts: Edge reports ViewGuard as installed by enterprise policy, and the Portal reports the pilot device Online in the intended tenant. Do not expand the GPO if only one of those checks succeeds.
viewguard-edge-<extension-id>.reg is the exact reference for both Edge force-install and tenant managed-storage paths.Edge · Method 2
Use this method for Entra joined or registered Windows devices enrolled in Microsoft Intune.
Intune deployment uses the native Microsoft Edge policy catalog for silent installation and a separately managed Windows delivery for the tenant values. This separation is expected: the catalog controls browser behaviour, whereas the tenant configuration is stored in Edge's extension-managed policy registry path.
Treat the two assignments as one release. They should use the same device-based pilot and production groups, the same change window and the same rollback decision. This prevents an apparently healthy CRX installation from remaining unregistered or reporting to the wrong tenant.
pgnnnpinccfeldgmimjkhjdeikokgpkm;https://bdr.prosfinity.com/extension/edge-updates.xml.apiBaseUrl and apiToken string values from the Edge tenant .reg under HKLM\Software\Policies\Microsoft\Edge\3rdparty\extensions\pgnnnpinccfeldgmimjkhjdeikokgpkm\policy. Use an approved PowerShell script, Win32 package or remediation; a .reg file is not directly importable as an Intune configuration profile.edge://policy and restart Edge completely.edge://extensions, both policies in edge://policy, Portal inventory and a monitor-mode test alert before production assignment.Intune reporting confirms that a policy reached Windows; it does not by itself prove that Edge loaded the policy or that ViewGuard authenticated successfully. Browser-side and Portal-side verification remain mandatory.
viewguard-edge-<extension-id>.reg as the source of truth when implementing the registry values through the customer's approved Intune method.Edge · Method 3
Use this method for Macs enrolled in Jamf, Kandji, Intune, Mosyle or another MDM that supports custom configuration profiles.
The supplied configuration profile contains two coordinated payloads: Microsoft Edge receives the force-install instruction, and the extension-specific managed preference domain receives the tenant connection values. Deploying the complete profile at system scope keeps both controls under MDM ownership and applies them consistently to every user of the Mac.
Do not copy individual keys into an existing browser profile unless the customer has reviewed payload identifiers, precedence and removal behaviour. Uploading the generated tenant profile as a distinct managed object gives administrators a clearer audit trail and a safer rollback path.
edge://management reports the browser as managed. Resolve any existing com.microsoft.Edge profiles that set conflicting extension policies.viewguard-edge-<extension-id>.mobileconfig, never the Chrome profile. It contains an ExtensionInstallForcelist payload for com.microsoft.Edge and a tenant managed-storage payload for com.microsoft.Edge.extensions.pgnnnpinccfeldgmimjkhjdeikokgpkm.edge://policy, reload policies, confirm the force-install entry plus apiBaseUrl/apiToken, then fully quit and reopen Edge.Removing the MDM profile withdraws the managed settings and force-install requirement. Follow the documented rollback order so the tenant token is removed from endpoints before it is revoked in the Portal.
viewguard-edge-<extension-id>.mobileconfig through MDM; production users should not install it manually.ViewGuard documentation
Firefox uses a Mozilla-signed XPI and Firefox Enterprise Policies. Generate a Firefox Company Deployment pack and use its policies.json, Windows registry or macOS MDM artifact.
Before you begin
viewguard-bdr@prosfinity.comhttps://bdr.prosfinity.com/extension/viewguard-firefox.xpihttps://bdr.prosfinity.comMozilla Enterprise Policiesviewguard-firefox-<extension-id>-policies.json, a Windows .reg, a macOS .mobileconfig, release details and validation notes. All three deliver both forced XPI installation and tenant managed configuration.Only deploy the Mozilla-signed XPI. The add-on ID inside the XPI and the ID used by ExtensionSettings and 3rdparty.Extensions must all be viewguard-bdr@prosfinity.com.
Firefox · Method 1
Use this method for domain-joined Windows devices where Firefox is managed by Active Directory.
Firefox Enterprise Policies provide the equivalent of a browser force-install policy, but the policy names and storage model differ from Chromium browsers. ExtensionSettings installs and locks the Mozilla-signed XPI, while 3rdparty.Extensions supplies the managed values that connect ViewGuard to the customer's tenant.
Use the registry artifact as a reviewed source for centrally managed computer policy, not as an end-user installer. Keeping the settings in Active Directory ensures they are reapplied, auditable and removable through the customer's normal change process.
distribution/policies.json, local registry, GPO or MDM policy for the same add-on before testing..reg writes the JSON ExtensionSettings policy to HKLM\Software\Policies\Mozilla\Firefox. It force-installs viewguard-bdr@prosfinity.com from https://bdr.prosfinity.com/extension/viewguard-firefox.xpi.HKLM\Software\Policies\Mozilla\Firefox\3rdparty\Extensions\viewguard-bdr@prosfinity.com, deploy string values apiBaseUrl and apiToken exactly as supplied in the tenant .reg.gpupdate /force, fully restart Firefox, then open about:policies. The Active tab must show ExtensionSettings and 3rdparty without errors.Firefox must show both policy branches under about:policies without an Errors entry. An installed add-on alone is incomplete because it may not yet have received its tenant configuration.
viewguard-firefox-<extension-id>.reg for Windows GPO. The supplied policies.json is a readable cross-platform reference, not a substitute for centrally managed GPO unless customer IT deliberately manages Firefox's distribution directory.Firefox · Method 2
Use this method for Intune-enrolled Windows devices running Mozilla Firefox.
Unlike Microsoft Edge, Firefox settings may not be available as native entries in every Intune tenant and service release. Customer IT therefore chooses one supported delivery pattern—imported Mozilla administrative templates or a managed script/package—and uses it consistently for both forced installation and tenant configuration.
The generated registry and JSON artifacts describe the same intended Firefox policy in different forms. They are reference inputs for the customer's chosen Intune implementation; assigning the raw files without an appropriate configuration or packaging workflow is not a complete deployment.
policies.json that could conflict.ExtensionSettings JSON for viewguard-bdr@prosfinity.com, with installation_mode set to force_installed and install_url set to the signed ViewGuard XPI URL.apiBaseUrl and apiToken from viewguard-firefox-<extension-id>.reg under HKLM\Software\Policies\Mozilla\Firefox\3rdparty\Extensions\viewguard-bdr@prosfinity.com.3rdparty values is not a completed deployment.about:policies.Record which Intune delivery method owns these settings. Two overlapping methods can report success independently while repeatedly overwriting each other on the endpoint.
.reg is the exact Windows value reference; policies.json shows the complete expected ExtensionSettings and 3rdparty structure. Neither file is directly importable as an Intune configuration profile without the customer's chosen packaging method.Firefox · Method 3
Use this method for MDM-enrolled Macs running Mozilla Firefox.
Firefox reads managed macOS preferences from the org.mozilla.firefox payload. The tenant-specific profile combines the enterprise policy that installs the signed XPI with the third-party extension values required for portal registration, allowing MDM to manage the full deployment as one configuration object.
Apply the profile at device scope so its behaviour does not depend on which user is signed in. A dedicated pilot smart group should receive the profile first, giving administrators time to confirm Firefox policy parsing, add-on installation and Portal connectivity before broad assignment.
org.mozilla.firefox profile or local distribution/policies.json that sets conflicting extension policy.viewguard-firefox-<extension-id>.mobileconfig; Chrome and Edge profiles are not interchangeable. The profile uses payload type org.mozilla.firefox and enables enterprise policies.ExtensionSettings for forced installation and 3rdparty → Extensions → viewguard-bdr@prosfinity.com with apiBaseUrl and apiToken.about:policies.MDM installation status proves that macOS accepted the profile, not that Firefox parsed every key. Always check about:policies and the Portal before promoting the profile beyond the pilot group.
viewguard-firefox-<extension-id>.mobileconfig at device/system scope. Do not distribute the profile or its embedded tenant token to end users.Required for every method
inalpegloaagicplciefkhpdilbaeeli, Edge pgnnnpinccfeldgmimjkhjdeikokgpkm, or Firefox viewguard-bdr@prosfinity.com.chrome://policy, edge://policy, or about:policies shows the browser-specific policy without errors.apiBaseUrl and apiToken.Extension is missing or blockedCheck device/browser enrollment, policy scope, the browser-specific Extension ID and package URL, and errors in chrome://policy, edge://policy, or about:policies. Remove conflicting cloud, registry, plist, GPO, MDM, or local policies before retesting.
HTTP 401 or tenant unknownThe tenant managed policy is missing, incorrect, or revoked. Reapply the pack generated for the correct tenant.
Installed but no Portal deviceConfirm apiBaseUrl and apiToken appear under the production extension policy, then fully restart the selected browser.
RollbackRemove the force-install assignment and tenant managed policy from the same scope. Confirm the browser removes the extension, then revoke the old tenant token only after all devices have migrated.
Official references: Chrome ExtensionInstallForcelist · Google Admin apps & extensions · Chrome Windows registry policies · Microsoft Edge ExtensionInstallForcelist · Manage Edge extensions · Mozilla policy templates · Firefox Group Policy · Apple device management profiles