The Sastrify Browser Extension is a lightweight browser add-on designed to enhance visibility into SaaS usage across your organization. It seamlessly supports the discovery of shadow IT and provides actionable insights—such as SaaS utilization trends and usage patterns—directly within your Sastrify platform. The extension operates only when users interact with SaaS applications using their company email, ensuring relevance and data accuracy while respecting user privacy.


All collected data is securely transmitted to your Sastrify platform, where Sastrify admins can:

  • View detailed usage data under the Usage tab of each tool.

  • Discover and manage new tools through the Shadow IT Radar feature.


The browser extension can be installed using one of the following methods:

  • Admin Installation (Recommended): This centralized method allows an administrator to remotely deploy the extension across the entire organization in a single action. It ensures a seamless, company-wide rollout without requiring any action from individual users.

  • Manual Installation: This decentralized approach requires your Sastrify admin to send installation notifications to selected users. Each notified employee must then manually install the browser extension on their own work browser.


IN THIS ARTICLE


Data Collection and Privacy Safeguards


The extension strictly tracks access to and activity within approved SaaS applications accessed via the organization’s work email. It collects the following data points:

  • Website hostnames of approved SaaS tools
  • User interaction metrics (e.g., click counts, keystroke counts, file upload events)
  • Session duration and timestamps (access and exit times)
  • Configuration data, such as approved product URLs
  • Work email address from the Edge work profile, which serves as an Employee/User ID


The extension collects data and sends it to the server every 15 minutes.


In doing so, we maintain a strict privacy-first approach to data handling:

  • User identifiers are cryptographically hashed to ensure anonymization.
  • Only whitelisted business SaaS applications are monitored—personal websites and content are never tracked.
  • Automatic exclusion of certain domains, including career sites, job boards, and non-business application URLs.
  • Data is transmitted securely via HTTPS, using OAuth for authentication.
  • Minimal data collection principle: Only essential usage metrics are gathered to support organizational analytics.

How to Install the Sastrify Browser Extension via Microsoft Intune


Locate the Edge Extension in Sastrify



  1. Log into your Sastrify platform.
  2. Navigate to Integrations > Discovery.
  3. Under Browser Extension Integrations, locate the Microsoft Edge connection card.
  4. Click "Enable".


Set Up the User List (via HRIS Integration or Manual Input)


Why is this step required? The browser extension requires a verified user list—a list of employees within your organization that the extension will target. No action is needed from the users themselves. However, the extension only collects data from these verified users, so this step is essential for proper tracking functionality.



  1. If your HRIS integration is not connected, you’ll be prompted to either connect HRIS or manually add employees.
  2. Click "Connect HRIS Integration" to proceed to the HRIS setup page. Follow this guide for detailed instructions.
  3. Alternatively, choose to "Add employees manually".


Once the user list is created, it can be found under the "Employee" tab on the browser extension connection page. Only the users listed here will have their usage interactions—such as click counts, keystroke counts, and file upload events—tracked and collected after a successful admin installation of the browser extension.




Open Admin Installation Instructions



  1. In the setup screen, click Admin Install Instructions to open the installation guide for Microsoft Edge browsers via Microsoft Intune.

Step 1: Create an Azure AD Group (Optional)

Skip this step if you plan to deploy the extension to all devices.

  1. Navigate to Microsoft Intune > Groups > New Group.

  2. Choose "Security" as the group type.

  3. Enter a meaningful group name (e.g., Sastrify Shadow IT).

  4. Set "Membership type" to Assigned.

  5. After creating the group, go to the "Members" section to add devices (e.g., using device serial numbers).



Step 2: Create the Configuration Profile

  1. Go to Intune > Devices > Windows > Configuration profiles.

  2. Click "Create profile".

  3. Use the following settings:

    • Platform: Windows 10 and later

    • Profile type: Settings catalog

  4. Click "Add settings", then search for Microsoft Edge.

  5. Browse for "Microsoft Edge\Extensions".
  6. Enable "Control which extensions are installed silently".
  7. Add the following extension ID: mkeifknkbhmlkdbgjnkedncjhhfllhih



Step 3: Assign the Policy

  1. Proceed to the Assignments step of the profile wizard.

  2. Choose:

    • The group you created in Step 1, or

    • All devices, if you want universal deployment.

  3. Complete the wizard to deploy the policy.


This configuration profile will automatically install the Sastrify browser extension in the background on Microsoft Edge for the targeted devices, when users log into their work-managed browser profile.


How to Uninstall the Sastrify Browser Extension


  1. Open Microsoft Endpoint Manager by going to the Intune Admin Center.
  2. Navigate to Apps or Devices > Configuration Profiles, and locate the profile used to deploy the Sastrify extension.
  3. Open the profile and go to the "Assignments" section.
  4. Remove the user or device group that was assigned the extension.
  5. Save and confirm. Changes will propagate automatically, and Intune will trigger the uninstall on the next policy sync.


Frequently Asked Questions


Please refer to the Browser Extension FAQ page for a complete list of frequently asked questions.