Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

NinjaOne Browser Management: Extension Risk & Control

NinjaOne
10/04/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


a Product Manager, the man of the hour, at least this hour anyway, probably many hours. Daniel, thanks for taking time to join us. Thank you everybody, jumping in the chat already. You can tell folks are excited about this, Daniel. You've been here at NinjaOne for how long now? Oh, going on my second year now. I've lost track of time, though, in space while here. Oh yeah, time is weird regardless, but certainly in NinjaLand too. And so you're here a year or two. You've been working hard, maybe not solely on this, but this has been your baby for a long time. And so before we get into it, yes, everybody, we're going to be talking about browser management. It's the latest new product offering in the NinjaOne platform. We're going to get into, Daniel is going to show you live what all entails, the features and capabilities that we're rolling out with at launch. To answer a couple of questions right off the bat before we get into it, I want to ask you, Daniel, about the context of moving into this lane and providing this and why we thought it was important and how it works, how it fits into the rest of what Ninja's providing. But before we do, a couple of things you guys are going to have questions on right out of the bat that I'm anticipating. So this is going to be a paid additional add-on product. And so there is another cost associated with it. So I wanted to get that clear out of the gate. And in order to get access to it, same thing with a lot of new features and products, best course of action is to reach out to your account manager. If you don't know who your account manager is, we can help you find that out. You can also reach out, do a support ticket and find out that way. But if you're a member of our Discord, you can ping me or if you want to even leave a comment here in the chat too, I can connect with you offline. How much is a great question. I don't know if we've got ballpark figures we can toss at you, but the account manager is going to be the best person to ask. This has been available with people testing it out, early access and everything for a little while, but it is as of 15.0, the release is going to be GA, which means it's available for anyone who wants to try it to take a look. And a lot of you who are watching, if you're in Europe or if you're in APAC, Australia, New Zealand, Oceania, Canada, you're going to have access to that already. And US, it's actually going to be rolling out, if you're on the US2 instance, it's going to be this, along with the rest of what's included in 15. It's going to be available overnight, tomorrow night. So you'll wake up on Thursday, you'll be available. And then the rest of everybody on the NA instance, which is the largest, it'll be October 1st. Robert's just confusing me. Thank you for doing that, Robert. And Shriker's got some wheeling dealing things. I mean, whenever we first launch things, I think the interest is in getting a lot of people involved. So definitely worth the conversation. Okay. With me setting all that groundwork, Daniel, why don't you tell us a little about, first of all, yourself and then also let's talk about browser management and kind of how we got to here. Yeah. So if you don't know me, I'm one of the product managers here. And as Jonathan alluded to, there's more than one product that I'm working on. Browser management is the first of the things that I have lined up. This is an extension of what we've been chasing as a company for building something for protection, kind of hardening. And I'm reluctant to say security outright, but yeah, I mean, it has a security focus to it. And you'll see some of that as we talk about the product. Some of you that have seen the product, one of the biggest attack vectors right now that we see is extensions. I know even talking with Red Teamers, it's become like one of their chief exploit paths now for credential and identity theft stuff. So we'll have a lot of attention paid there. By the way, I got to call this out. Robert and I do have the same hairdresser. So if you are interested in this hairstyle, you can reach out to him and he'll get you the number to the hairdresser. But anyway, yeah. So I'm based in Nashville, Tennessee. Like I said, I've been here for about going on two years. But I am very excited about talking about this product. This has been something that's been sort of quiet while we've been working on it. So as you can imagine, there's a lot of things I want to say about it. Because Netherlands is a lovely place to get your haircut. But the goal here is to give control to the browser spaces. It's a fragmented space that we have to deal with. It should be easy. But it is not. As all of you know, browsers are these containerized things. So we may control the end point, may control policy. But we don't always have insight. We're chasing a lot of different things to try to manage these. And the goal here is for us to just put that into a single place and to try to build a unified area for control. In my mind, browser problems have become sort of the BYOD problems that we had back in late 2016, if you can remember that far back, where everybody's bringing a new device. Work and everything is starting to happen in a place that's not a homogenized space. And we've got homogenized platforms where they're accessing things. But there's still this gap in visibility. There's a gap in control. Couple that with things that are happening, emerging technologies through AI, et cetera. This is just becoming a complex area to have to deal with. So we had a bit of a roadmap here. I do want to talk about the roadmap a bit while we're on here. I know some of you will be interested in that, that have some awareness of the product already. But yeah, I'm ready to jump into it. All right. Awesome. Well, thanks for the background and context. Before we jump in, just one last thing. I'm going to add a little bit of... I'm going to add a couple links here for folks so they can have these open. But yeah, you can follow along with what Daniel's going to show. But I'm also adding a link there to the public documentation. This mirrors, I think, pretty directly what's in the dojo. And I'm also going to... Well, I guess that's all I'll provide for now. Yeah, let's switch over and, Daniel, let's go at it. All right. So browser management. As of 15, you should all see the browser management app tile. For enabling it, as same as always, you'll have a disable enable button here. Under general settings, configuration for block messages. And I want to clarify something here. This is block messages for extension installs. We do currently do URL policy. I'm going to talk more about that on the roadmap. But I don't want to confuse that. This is for block messages on extension installs. And in this 15 release, we have added browser extension risk. This is being done through AI. And I'm going to talk a little bit about that when we actually look at it in flight. But once I have this enabled, on my dashboard, I will get browsers, extensions, and if configured by policy, URL history. I'm going to call something out about URL history. This is not on by default. This is something that you do have to request to be turned on. This is because for a lot of people, this can be a bit of a data privacy concern. And they just don't want it enabled for their instance at all. So we keep that compartmentalized completely. So it can be separated as a feature flag. Once this is enabled, you would enable it through policy. And we'll talk more about the policy editor as I go through this. So here we go. Extensions are added. I can come in here and look. This is collecting extensions. Oh, I will zoom in happily. Is that good? Eyeballs out there in chat? All right. We get extension inventory. This is inventorying for Chrome, Edge, and Firefox where installed. We are doing this discovery via the agent. So we are looking at the manifests for each browser under the user profiles. That's where that information is coming from. That includes built-in extensions so that you're also aware of things that might be included in a browser that aren't necessarily visible right away like inside of the browser itself. We get the extension ID back, the browser that it's associated with, and source URL so you can actually follow these links out to stores. So like in this case, this would take me to the actual Google Chrome store page for this. You get version breakouts. And then, of course, if we're at this system view, we can see our total devices, installed devices, how many of these we have blocked, and what organizations these are associated with. So I can also look into each of these extensions and to get a breakdown of what permissions are being requested. And these are not AI generated. These are static. So we are looking for what these permissions are. We have given these risk scales. And for all of you that are already versed in this world, these are going to be not always the one permission that's the problem. It's usually the sum of all parts. And like RL URLs, for instance, if you're familiar with this, we give you a breakout here. But if you're not familiar with this, we give a breakout here. But this is access to everything inside of a session. Same thing for unlimited storage, a little less risk. But if we were to see cookies or scripting or something else in there, we start to get more elevated in terms of risk factors. Version, when you are on the system view, and this will be a fun one because we do see which devices we are installed on. If I have multiple devices, we will always show on the system view information page the version with the highest risk score. And that's not always going to be true. So if I've got multiple devices, multiple versions, they can be in different areas. Can we force uninstall extensions from the table? So currently, we are not doing force uninstalls. We are doing block only. And the reason behind that, and this is something I know is a bit of a feature request and something that we are going to pursue. But in the current state, the thinking is, if I have something that's been installed, if I force uninstall it by default, I have the risk of missing potential impact when I'm going back to do cleanup or to do some investigation. This becomes a little more important when we start talking about additional payloads that might have been installed, and it can mask problems. Default behaviors for the browser when you block those extensions, there's sort of two paths, and the path that we're choosing right now is to do blocks, not force blocks, which would cause the uninstall to trigger. Hopefully that answered your question there, Coco. Critical risk. So I do want to dive into this, though. This is what the AI is giving us. So we get our risk score, and then we get an actual breakout here. And we are looking at multiple things as we do these scores. If we're looking for quick summary, you know, critical risk is kind of the high level, and then jumping down to score rationale, we can get a breakout of what exactly and why, right? But individually within the parts, we're identifying, like, the permissions. We give you a breakout and explaining the permissions that we're seeing. This is being pulled from the manifest. We're evaluating this through the AI. Known threats. This, of course, is going to be based off web scraping, other intelligence things that we find, like, how is this being used, or just generally what's security sentiment on this. Publisher reputation. So we're not actually looking at the store, but we are looking at the publisher. And if the publisher has, like, low trust value, we're obviously going to call that out. There may be instances where this could be a potentially trusted thing, or it could be an open source project of sorts. But we're going to call those things out. It does impact the score. If I look at things like a GitHub project would be a great example of that. If I have a greater or lesser volume of contributors, number of stars on it, whatever, whatever, that's all going to be reflected here in publisher reputation. And then user sentiment. User sentiment is, as you would expect, it's reviews that we're seeing. It's also the GitHub stars. It's does this thing align to purpose? And so as we look at all of these things together, from the manifest to known threats to publisher reputation, user sentiment, we pit all those things against each other with weighted values, and then that's where we draw our conclusion from. And you'll see this played out, and to sort of answer a question that may be on your mind, as new versions are installed or released or updated, it does trigger a rescan of that extension. So one of the biggest issues that you see in terms of attacks today with extensions is silent updates, where you already have a stated trusted extension, and then things flip. This gets called out as we grade these. Yes, Corey, yeah, we covered that. It's a whole new product that we're introducing, and it's going to continue to grow over time. Also with this, so I don't like this one here, so I'm going to go ahead and block this. I'm going to add this to our policy here. Go ahead and put a block in place, and there we go. URL history. As I said, this is an optional feature that can be requested to be turned on. This does not come with additional cost, but this gives a running record of URLs that have been visited. We are holding this for seven days in its current state. We are only pulling back domain name. This course is, again, back to data privacy concerns. I know there's some ask for us to get to full URL paths. That's something that we plan on introducing in the future, but we need to put some more guardrails in before we do that. Now, seeing here, breakdown policy status, this is a live column, so this reflects what is going on currently, how this is set. So, for instance, pyrobay.org, we have a blocked policy status, and we see an activity status of attempted. It means it was actually blocked. But if I come down here, I can see blocked attempted, and then I have an allowed attempted for is it DNS.com, right? That means at the time that this happened, we actually had a blocked policy in place. Same as we had with the extensions, taking control here. When I'm ready, block anything I want, add it to my policy. And that leads us over to the policy itself. And what we have in here, extension management. Enabling extension management enables the inventory. Block list is the default value. Nothing is added to block. This is a safe path, so block list is active. I can take control. I can add values when I'm ready, but nothing is being enforced. We're just grabbing inventory. URL management, this same thing. We are enabling this, but this is not enabling history collection. History collection happens here. If this is enabled for the account, turning this on will install a Ninja 1 extension. The Ninja 1 extension is how we are collecting history. So, unlike the extension collection where we're doing that by agent, this is happening inside the session. That is then sent to the server, right? So, caveat here, this is a feature that requires systems to be managed because the Ninja 1 extension is being sideloaded at this time. That's something that will be changing in the future, but for now, that means unmanaged devices won't be able to push this because of browser protections against policy controls, certain policy types. And then lastly, incognito mode. The whole reason for disabling incognito mode or allowing that is, as some of you may already know that have done browser management in the past, incognito mode offers or requires end user consent for things. That would mean extensions, different policy settings I might set might not play as I would expect in incognito mode. So, when under management, it's usually a good idea to disable this, but that is an optional thing. Hey, Daniel. Yeah, this is great. And lots of good questions here. Also, I like that mug. We actually had a call out later or earlier, I think last week, people will be like, man, you got to bring that one back. Anyway, quick point sermons. Great comments here. Asking about the blocking of extensions and whether basically there can be kind of like a pending state. And so, that makes me curious about what is the end user experience with this, if any. And then I think what he's asking too is, basically, would like to use to block all extensions from installing, but then they get put in a list of pending. So, he's able to go in or he or she is able to go in and review after the fact. No, right now, these are being set as policy items. And the way that installs typically happen with extensions, we are allowing the browser to manage those installs. So, we're writing the policy to set the extension for install. And I know there's some mechanisms that we're exploring with extension installs. But I'll point out for those of you that are aware of this too, or maybe not, extensions as a tech are really expected to be a rolling technology in terms of releases. So, putting controls in there, we run certain risks for actually breaking a functionality and causing additional headaches, rather than just doing the block or allow or install. So, I'd be curious to know more about more on this from a pending state conversation, like kind of what you have in mind around that. Well, if I'm reading it correctly, I think it's blocking is great, but then maintaining a list to be able to go back and see, okay, this is the number of extensions that have attempted to be installed. They've been blocked. If you go and review those things, you can actually say, okay, yeah, we can improve it. Okay. I'm with you. No, not today. There's definitely some things that we have in mind for that. And I can't talk about those right now because they have other implications, but that is something we're exploring. I think about this too. Yeah. It's sort of like an application control mechanism. Yeah. Yeah. Yes. That is something we were exploring, but that's not here today. But you can see, yeah, you can see the list of the block extensions, but in terms of having a button that then would be say, okay, actually this is approved, go ahead and install it. That's not what's going to be available. Yeah. And that's, there's, yes, I will tell you that is something we were exploring. There are some other items that are already on roadmap ahead of that, but those sort of control mechanisms are part of roadmap right now. But that's probably a private conversation. A couple more, just because this is great. Thank you everybody for watching this and for asking questions and everything. Because there's definitely some good ones, especially since this is a new area Ninja's going into. So, okay. Oh, and Janice, well, I've got a point about that in a second, about your comment there. Okay. What about extensions loaded locally in developer mode? Yeah. So this is, again, Daniel kind of going back into how is this actually kind of working under the hood maybe? Yeah. So, to your point, Robert, those should be discovered because they should end up showing up on a manifest. We are crawling that profile directory and doing lookups. So there's iteration through multiple extension manifests for the browser. So if it's a supported browser, unless it's like a hidden folder somewhere, somebody would have to go really far out of their way to build a profile of sorts that's hiding these. But we are doing discovery. So I would expect a loaded local. The only kicker with that is that for the install source, it would show as other. We wouldn't be able to necessarily pull back that install source to identify it. But any time you see other, it's either built in or it's been something that's side loaded. It's not coming from a first party store. Okay. And then I know you got lots more you want to show. Just one other question here really quickly. And then I've got a note for the pricing conversation for MSPs. How does the URL blocking work at the agent PC side? Does the agent intercept all web traffic then? But you're saying the URL blocking is the actual extension, the Ninja 1 extension that's installed. Is that right? No. So this is loaded. And this is a roadmap item. So for the URL policy management right now, it is browser policy management. So we are doing direct URL policy rights for the browser. We are working on URL categorization. URL categorization moves enforcement into the extension. So when we actually move to that version with that release, which we have a pretty good fix on when that's going to be released. But I want to be careful about stating any actual time frame. But with URL categorization, that enforcement moves into the web extension itself. And that will be categorical blocked along with exception patterns. This is not agent side. This is not DNS filtering. This is none of that. Now, when it comes to why blocking the browser versus the agent, there's a lot of DNS-based solutions. There's perimeter solutions for doing these blocks. Catching things in transit or transition within the browser is sort of the key here. It's also for dynamically shifting targets, which is the whole purpose for URL categorization. And we're expecting some level of reputation in that as well. So it's adding more dynamic blocking and then to be able to do that outside of perimeter. I almost think of it more of last mile of defense for URL management. But yeah, we're not doing this on the agent side, at least not today. Okay, cool. And then before we move on here, just to address the... Absolutely here, you guys. Anything that's an additional cost for you, you don't want to take on that burden yourself, right? Ideally, that goes on to the clients because it's a service for them. Totally makes sense. And I think what I would say with a couple of these things. First, what Daniel is saying is this is the initial rollout of something, an area that's going to be iterated on and built up quite a bit. And so even if this doesn't fully hit all of your needs or justifications for the price increase yet, it's something to keep an eye on because it may allow you to display some things in the future, some other costs in the near future. And then in addition to that, anytime that you have your annual renewals, things like that, I don't know with your cost increases, there's a whole element of that where maybe this fits in with some additional things that you've maybe been eating the costs on for security anyways. But as with a lot of things, there are very few things in an MSP stack that I would consider this is something that you would add as a bullet item on your costs, a line item on the invoices and that you would have to justify on its own. It's always going to be better to say, hey, we're providing additional security services in X, Y, and Z ways. Also, things are changing. And also, hopefully you've developed kind of an anticipation that prices are going to be increasing on a pretty regular annual, if not longer, basis. So anyway, just some thoughts there. I know it's not the best answer. It's always a sensitive subject. But you guys provide a lot of good services that are very important. And I think in general, the same for MSPs is you should probably be asking for a little bit more. Okay. Daniel, please continue. So hopefully I solved the question about which browsers are supported today. It is Chrome Edge and Firefox. So I'll pick that up. But I was trying to sort of silently announce that for you. As far as the policy management itself, obviously driving things with the dashboard is one way to do it. But actually constructing policies, especially ones that I need to build as like a base policy or apparent policy of sorts, being able to do extensions from inventory, so building a reference target and establishing that based off of imports from inventory, selecting the browsers I want to control, if it's going to be an install, a block, continuing, and then shopping in here for whatever extension it is that I'm looking for. Similarly, when those are set, the ability to do CSVs, so building external policies that I can just import when ready to rapidly set up a new policy. And then also for installation of extensions, being able to also do side loaded extensions, custom URLs, if I've got like a third party extension that I'm paying for or something like that, using this as a way to orchestrate those installs. URL listings are pretty straightforward. Block URL, or again, URL from inventory where you can actually look through domains that have been visited, things that you know you need to block. So maybe I don't want chat GPT allowed. I can put that policy block in place right away. Now, let me see. Yes, yes. Oh, and I'm glad you're bringing that up because this is exactly part of roadmap. So one of the things that's going to follow, we have expanded browser policy, configuration items, URL history export, risk score versioning, so in answers to what we have now. In development is the URL categories and category blocking. I do not have it posted here yet, but Mac OS, Brave, Opera, Safari, and DuckDuckGo are all on the table. Chromium specifically, I would be interested if that's not already managed, capable through Chrome, I'll have to test that. But I'll look at that. But as we are expanding the footprint for OS support, that is a future that follows behind URL categories. And with that, I want to jump into what's changing in the 16th version. And I know some of you haven't even accessed the 15 yet. So this is probably a bit crazy to be looking at this right now. But what is coming in the near future is also expanding the initial policy controls. So for us, pushing the policy down is almost instantaneous. Browsers are in control of when they do policy ingestion. So this is also one of those things where browser restarts are one way to force that. The other would be building notification channels. We don't have a mechanism there from forcing it today. But with Chrome and Edge, for instance, if it's on a Windows device, average it's going to reevaluate policy every 90 minutes. For Firefox, it only happens on restart events. So 15 has been a rolling release for a while now, Robert. But coming in here, browser settings, startup pages, home page button configuration, bookmark toolbar control, quick links control, being able to build custom bookmarks for pinned bookmarks. So for setting up internal links or things that you want, that's coming in the 16 release. Opening up some of the popular security controls that people like to configure within the browser. So safe browsing and smart screen. Forcing secure connections or the HTTPS TLS connections. Incognito mode has been moved into here. Third party cookie control and browser notifications, which is another exploit path that gets used for malware. Password, disabling passwords, payments, fixing a download directory, and the built-in browser AI controls. So for Chrome, Edge, and Firefox, that is something we have on 16. So when you see that in the roadmap, know that this is what is coming in that v16. And then we've simplified some of the view here for extension and URL management. So this is all a single pager now. So yeah. But yeah, I appreciate your time. I kind of want to go back. Jonathan, we have any more questions that we want to hit before we close out? Oh, yeah. All right, folks. You got Daniel held captive here for a little bit longer. Let's just final round, final ask for questions. And then also going back to the cost too, I know that there's some interesting things with the Verizon DBIR, the latest report, calling specifically browser out as being kind of a new front in a lot of the intrusions that have come out. And so maybe we can help out with that too. Something I'm definitely taking into heart. And I'm going to think through what other materials we can help to help you all make the case. But while we're doing that, okay, here we go. Let's see. Any ideas? Matt, thanks for asking this question. Any ideas if you're going to introduce account management, folks adding their own Google accounts to Chrome, for example? Yeah. Profile controls and things like that, there's an awareness there. We don't have a fixed plan for it, but that is something that I want to address in the product. But that's way too early for me to say specifically on what or how we're going to handle that. Daniel, I saw you pulled up product board and I can grab that link and post it here to you or post it in the description after the fact. But yeah, I mean, this is the best way to, this is a brand new basically lane for Ninja. And as you mentioned, we're actively devoting your time into it and others. And so it's going to be built on pretty rapidly and you've got some things already in the works. But in case people have other requests like that, what's the best way? How do you guys prioritize? It's through looking through product report and feature requests, right? Yes. So there's a lot of ways to get feature requests to us. One would be emailing on the feedback specifically, but the best route, the two best routes are usually going through your account manager and having them put a feature request in for us. We have a very fixed pipeline for how we manage feature requests. And then the other, and I will, now that this product has been released, I will start being more forward about a lot of things that are under consideration, planned and in development. Anything under consideration, definitely something that if you see that it's a need that you have, like these are things that we're fishing. Like this is a crazy idea we had. What do you think about this? Right. Coming into something like that or any of these, you have these not important, nice to have, important or critical. I mean, these are as you would expect. Like if this is something that you need as a definite driver for your own business, like Mark, this is critical for us, right? If it's something that you really, quality of life stuff, even to me could fall into important categories, but nice to have is usually your quality of life, but important to stuff that I really needed to do this. I can get by with workarounds, but I really needed to do this. But hitting us there, that feedback goes to us. It gets weight applied to what we are planning and it helps us with our prioritization. Because as you would imagine, there's way more of you than there are of us. And we absolutely want to build stuff you guys need, but it can be hard sometimes for us to determine which, reading the tea leaves. And this is a way for you to basically write on the tea leaves for us, right? Yeah, totally. And when you're having those discussions with your account manager, like, Hey, I was just on this browser management stream. I'm interested in checking it out. Tell me about pricing. And then also say, Hey, I really needed to have X, Y, or Z before we can move forward with those conversations. That would certainly help get attention to it too. Okay. This is another one we got. Dustin, thanks for being on, watching this. I may have missed this, but did the dashboard for other infrastructure users when an extension was installed? So let me drill into one of these. We'll pick dark reader here. When 11 tech extensions. So at the device level, I do get an install date. Obviously at the system level of the dashboard, pick your install date, right? But yeah, at the device level, we do, we do have more granular information about things like that. So, so I can see that. And these can also be exported as reports like CSVs. I need to work with this offline. I didn't call that out earlier, but part of the benefit of this is, is so you can actually build importable or portable CSVs of policy sets because building policies for extensions can be a bit of a nightmare because extensions are crazy. Like their extension ID is their name, right? We would love for it to be this, but it's really this, right? So any more? Just one. And I'll switch down to this view. Okay. Okay. Okay. It is not a unicorn. It is a quadricorn, right? So it's not good enough to be a unicorn. It needs more horns. And honestly, this is a bit of self depreciating humor. If you're in the software game, everybody's a unicorn. Everybody's a unicorn. It's like, it's not enough to be a unicorn anymore. You gotta be a quadricorn. So it's my quasi spirit animal. Oh man. And Daniel did mention that he sometimes likes to open calls, Zoom calls with that on to get people's reactions. So if you're going to get involved in the development of browser management and you get calls with Daniel, just brace yourself. All right, guys. Thank you so much for taking time for joining. Thanks for being active and all the questions. The convo doesn't have to stop here, obviously. Jump in the Discord. I think a lot of you are already members of it, but there's a little QR code that you can blindly scan. Also, we can drop a link in the description to join. Daniel is active in there. You can join. I think we have browser management as a channel that's going to be moved up from early access into GA. So it's an official channel. You can connect with other users, ask more questions. And as always, everybody, we appreciate you. This is how we build Ninja with your feedback and everything. So lots of cool new stuff coming your way. We have two other streams. Well, one of which was based around 15 new features. We're going to push it back to October 1st. That's the stream that was scheduled for tomorrow with Greg Smith, the PM behind Ninja One Remote. He's got some cool things to share about some screen recording and things like that, some really good updates to remote. But in order to make sure everything is working properly and also that everyone has access, we're going to push that to next Thursday, October 1st. By that point, everyone watching, including those on the NA instance, will have access to all the new 15.0 features. But Thursday, we are going to hold this stream. We've got one with Phil who's going to be covering lots of new features around ticketing. So stay tuned for those. But everybody, thanks again. And Daniel, really appreciate your time. Yeah. I appreciate yours too. Actually, I did see one more question I wanted to answer. Yeah. Yeah. Let's do it. So the question about the password manager stuff. So this is a bit of a loaded question because it's going to be behaviorally dependent. But if you move this thing into an allow list, anything that's previously installed will get disabled. The allow list is going to have a hard enforcement on that. There's no grace period for anything previously installed. The configuration setting that I was showing coming in 16, that is for the browser's cache specifically. So it's just what's getting saved within there, which you typically want to disable if you can because that's an area where theft can happen for credentials. But also coming in v16 that we don't have currently in 15 is that we will have toggleable enforced states. So if I'm building an allow list and I need to protect these extensions, it will not go into an enforced state until I flip that toggle to sort of help accidentally cutting something off like that. So I know that's a bit of like a lot of answers to that. But behaviorally today, if you were to turn on allow list and you have extensions installed that are not in the allow list, they will be disabled. Right. I think that's a very important thing to bring up. And hopefully we know well in documentation and everything. I may revisit a little stuff around that. Yeah. And by the way, call out documentation stuff to me if we're missing stuff that you need, because I'm happy to get that stuff added. Documentation is something that matures along with the product. Yeah. And man, I know this is frustrating, guys, like the preliminary pricing. As with a lot of things with Ninja, there's kind of like a lot of it depends. And I just want to be careful to not to set the wrong expectations. And I know that's a frustrating answer. But let me do a little Dane and let me see what I can provide everybody that's a good, at least getting started way, because I'm totally with you. I don't want to go to the trouble of tracking down my account manager, setting up a time discussion and then be like, oh, this isn't even my ballpark. That was kind of like a waste of our time. So let me see what I can do. And if you're in the discord, let me follow up with you there, if you don't mind. Again, sorry, I know it's not the best answer for those watching, but yeah, we'll try to get better about that. Okay. There you go. For the low, low, yes, limited time. I mean, I think that there probably is some, to be honest with that, some early, it's in our best interest to get lots of people trying this out and telling us what it needs and what they like, what they don't like, et cetera. It would behoove you to have the conversations with your reps sooner rather than later. I will say that that's always true with any new product without throwing us under the bus. All right, everybody. Thanks. This is great. Daniel, thanks again. And we'll see everybody on Thursday or later. Take care, everybody.

TL;DR

  • NinjaOne Browser Management is a new paid add-on (GA in v15.0) that inventories Chrome, Edge, and Firefox extensions across a Windows fleet using agent-based manifest crawling, with no separate tool required.
  • An AI risk scoring engine evaluates each extension across four dimensions — permissions, known threats, publisher reputation, and user sentiment — and automatically rescans on version updates to catch silent update attacks.
  • URL policy management currently works via direct browser policy writes; browsing history collection is opt-in, domain-level only, and retained for seven days due to data privacy considerations.
  • Version 16 will add expanded browser settings controls (safe browsing, HTTPS enforcement, cookie controls, AI feature toggles), URL categorization with categorical blocking, and a toggleable enforced state for allow lists to prevent accidental lockouts.
  • Force-uninstall of extensions is not yet available by design — blocking without removal preserves forensic evidence; future roadmap items include application-control-style pending approval queues and support for macOS and additional browsers.

Browser Management as a New Security Layer

NinjaOne's Browser Management, released as a generally available paid add-on in platform version 15.0, addresses a visibility gap that most endpoint management tools leave open: what browser extensions are actually running across a fleet, and whether any of them pose a security risk. Product Manager Daniel Belcher frames the problem as analogous to the BYOD challenge of the mid-2010s — browsers have become fragmented, containerized environments where IT teams may control the endpoint but lack insight into what's happening inside the session. Extensions in particular have emerged as a primary attack vector, with red teamers increasingly exploiting them for credential and identity theft. The new module brings extension inventory, AI-driven risk scoring, URL policy management, and optional browsing history collection into the existing NinjaOne console, eliminating the need for a separate browser management tool. Supported browsers at launch are Chrome, Edge, and Firefox on Windows.

Extension Inventory and AI Risk Scoring

The extension inventory works by having the NinjaOne agent crawl browser profile directories and read extension manifests directly — covering installed, built-in, and developer-mode sideloaded extensions alike. Each extension surfaces with its ID, associated browser, source URL, version, and a breakdown of requested permissions. A new AI-powered risk scoring engine evaluates extensions across four weighted dimensions: permission scope (e.g., access to all URLs or cookies), known threat intelligence gathered via web scraping, publisher reputation (including GitHub contributor counts and star ratings for open-source projects), and user sentiment from reviews. Critically, the system rescans an extension whenever a new version is released, specifically to catch silent update attacks — a common technique where a previously trusted extension is later weaponized. Administrators can block extensions directly from the inventory view or through policy, though force-uninstall is not yet available; the deliberate design choice preserves forensic evidence during incident investigation.

URL Policy, History Collection, and Roadmap

URL management currently operates through direct browser policy writes rather than agent-level or DNS-based interception, which Belcher describes as a "last mile of defense" approach suited to catching threats dynamically within the browser session. Browsing history collection is an opt-in feature requiring a separate account-level flag due to data privacy considerations; when enabled, it deploys a NinjaOne browser extension via sideloading and retains domain-level history for seven days. Full URL path logging is planned for a future release pending additional privacy guardrails. The near-term roadmap for version 16 includes expanded browser settings controls — startup pages, bookmarks, safe browsing enforcement, HTTPS-only mode, third-party cookie controls, browser notification blocking, and built-in AI feature controls for Chrome, Edge, and Firefox. URL categorization with categorical blocking is also in development, which will shift enforcement into the browser extension itself. Future OS and browser support is planned for macOS, Brave, Opera, Safari, and DuckDuckGo. Pricing is not publicly disclosed; prospective customers are directed to their account managers, with early-adopter incentives implied for those who engage during the initial rollout period.

Chapters

0:00 - Introduction and Pricing Context
3:33 - Why Browser Management Matters
6:54 - Extension Inventory Live Demo
11:44 - AI Risk Scoring Explained
14:36 - URL History and Policy Editor
22:32 - URL Blocking Architecture Q&A
28:21 - Product Roadmap: v16 Features
33:06 - Feature Requests and Prioritization
38:40 - Closing Q&A and Allow List Behavior

Key Quotes

4:13 "One of the biggest attack vectors right now that we see is extensions. I know even talking with Red Teamers, it's become like one of their chief exploit paths now for credential and identity theft stuff."
5:03 "The goal here is to give control to the browser spaces. It's a fragmented space that we have to deal with. It should be easy. But it is not."
13:43 "One of the biggest issues that you see in terms of attacks today with extensions is silent updates, where you already have a stated trusted extension, and then things flip. This gets called out as we grade these."
24:28 "I almost think of it more of last mile of defense for URL management."
35:19 "There's way more of you than there are of us. And we absolutely want to build stuff you guys need, but it can be hard sometimes for us to determine which, reading the tea leaves."
40:26 "Coming in v16 that we don't have currently in 15 is that we will have toggleable enforced states. So if I'm building an allow list and I need to protect these extensions, it will not go into an enforced state until I flip that toggle."

FAQ

Can NinjaOne Browser Management force-uninstall a risky extension remotely?

Not in the current v15.0 release. The product blocks extensions via policy rather than force-uninstalling them. This is intentional: removing an extension immediately could destroy forensic evidence needed during incident investigation or cleanup. Force-uninstall is on the roadmap but has not been given a specific release target.

Does URL blocking work at the network or DNS level?

No. URL policy management in v15.0 operates through direct browser policy writes — it is not agent-side interception and is not DNS filtering. A future release will introduce URL categorization that shifts enforcement into the NinjaOne browser extension itself, enabling dynamic categorical blocking outside the network perimeter.

What happens to existing extensions if an administrator switches to an allow list?

Any extension not included in the allow list will be immediately disabled with no grace period. In v16, NinjaOne plans to add a toggleable enforced state so administrators can build and review an allow list before enforcement goes live, reducing the risk of accidentally disabling critical tools like password managers.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Endpoint Management
  • Security Operations
  • Data Protection
  • Demo
  • Best Practices
  • Technical Deep Dive
  • Browser Extension Security
  • Extension Inventory Management
  • AI-Powered Risk Scoring
  • URL Policy Enforcement
  • Browser History Collection
  • MSP Security Services
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: NinjaOne Browser Management: Extension Risk & Control

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Ensuring Compliance Through Audit Evidence: From CJIS to FERPA

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Ensuring Compliance Through Audit Evidence: From CJIS to FERPA
                      https://www.truthinit.com/index.php/channel/2159/ensuring-compliance-through-audit-evidence-from-cjis-to-ferpa/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version