Credential Risk Detection, AI phishing alerts and Credential Risk Alerts are available to organizations with Credential Protection.
Estimated time to complete: 20 minutes
If you have Credential Protection and are deploying the Dashlane browser extension, you can deploy the Credential Protection features at the same time:
Admins can use the master data management (MDM) tool Microsoft Intune to set up Credential Protection features for company-managed Google Chrome and Microsoft Edge desktop browsers on Windows.
What is Microsoft Intune?
Looking to set up Risk detection on macOS using Jamf?
Looking to set up Risk detection on Windows using Group Policy (GPO)?
Although Credential Protection features are most beneficial when rolled out to your entire organization, you can start with a smaller group (or just yourself) during setup and extend it to more employees anytime. To add more employees, update the groups included in your policy deployment.
Process overview
Prerequisites
Make sure you have the appropriate access needed to set up Credential Protection features:
- Admin access to a Dashlane account with Credential Protection
- Admin access to Microsoft Intune on Windows
- Permission to deploy policies to devices using Intune
Set up Credential Protection features on Windows using Intune
Setup involves two main steps:
If you prefer, watch the Windows + Intune step-by-step video
1: Policy deployment
Don't skip this step, even if you've already deployed the Dashlane browser extension.
If the extension has already been deployed and you want to turn on Credential Protection features for existing employees, you can skip step 2 in the setup guide. You can turn on the features after deploying the Credential Protection policy.
Important: You must deploy the Dashlane security policies before you deploy the Dashlane browser extension. This order ensures the extension installs silently and the security features work as expected. If you don't deploy the policies to your targeted machines, your employees will be asked to log in to Dashlane on every login screen. If you deploy the extension before the policies, employees might create a personal account before the policies are applied.
What is a silent deployment?
A "silent deployment" of the extension means installing the extension on employees' company-managed desktop browsers without any visible prompts or interaction needed from the employee. Admins must configure the managed device policy before they deploy Credential Risk Detection to avoid inadvertently notifying employees about Dashlane.
In the Dashlane Admin Console, start the setup:
- Log in to the Dashlane browser extension and open the Admin Console
- Under Integrations, select Deployment.
-
On the Deployment page, select Start setup.
-
On the Setup page, select Start to see the steps for the policy deployment.
-
Select the Intune tab and the browsers you're deploying to. Ensure your selection is accurate before downloading the script so your file is created correctly.
- In the Windows guidelines section, select Download. Your device automatically downloads a script file so you can apply the Credential Protection policy to your deployment software. After the file downloads, open the Intune app.
In Intune, add the new policy:
- Open Intune and select the following in order:
- Devices
- Scripts and Remediations
- Platform scripts
- Add
-
Windows 10 or later
- Enter a name for the policy. For example, “Dashlane browser extension for Chrome Browser”.
- Select Next. You're prompted to select the file you downloaded.
-
Select No for the remaining three options on the screen, then select Next.
-
On the next page, select Add Groups. Then, select the boxes next to the names of the groups you want to deploy to and the policy and the configurations required for the feature to function. Ensure you include all the employees you want to protect, even if they don't have a Dashlane seat.
Even though these are being configured as Intune device configurations, the assignments need to be to Groups and not Devices.
Although Credential Protection features are most beneficial when rolled out to your entire organization, you can start with a smaller group (or just yourself) by restricting the policy. You can extend Credential Protection to more of your employees at any time.
- Select the Select button and then select Next.
-
Review and validate the configuration, then select Add. A message confirms the policy was created.
After performing these steps, the deployment might take up to eight hours, but it's usually faster.
To ensure Risk Detection's proactive threat monitoring doesn't alert or disrupt employees, you must wait for the policy to take effect in your MDM before deploying the Dashlane browser extension to enrolled devices and activating the feature.
Check the policy was applied:
Using a device that was part of the group the script was deployed to, go to Registry Editor and select the following folders in order.
Chrome:
HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\3rdparty\extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\policy
Edge:
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge\3rdparty\extensions\gehmmocbbkpblljhkekmfhjpfbkclbph\policy
In the extensions, you'll see a folder named using the Dashlane browser extension ID. Under that folder, the policy folder contains the actual values of the Credential Protection policy.
Go back to the Dashlane Admin Console, and select Continue to move to the second step.
2: Extension deployment
You can skip this step if you've previously deployed the Dashlane browser extension.
You must deploy the Credential Protection policies before you deploy the Dashlane browser extension. This order ensures the extension installs silently. If you don't deploy the policies to your targeted machines, your employees will be asked to log in to Dashlane on every login screen. If you deploy the extension before the policies, employees might create a personal account before the policies are applied.
Return to step 1 to deploy the policy
Google Chrome
To deploy the extension, you must add a new device configuration to Intune using the Configure the list of force-installed apps and extensions template using the browser value in the Dashlane Admin Console. If you can't find this template, ensure you've imported Chrome ADMX.
Import Chrome ADMX
Copy the browser value here or in the Admin Console:
fdjamakpfbbddfjaooikfcpapjohcfmg;https://clients2.google.com/service/update2/crx
In Intune, add a new device configuration:
- Select Devices, Configurations, and then Create and New policy. Use these settings to define the policy:
- Platform: Windows 10 and later
-
Profile type: Settings catalog
-
Select Create, enter a name for the Profile (for example, "Deploy Dashlane browser extension"), then select Next.
-
Locate the folders for Google:
Google; Google Chrome; Extensions - In the search bar, type "force" and select Configure list of force-installed apps and extensions.
-
In the Extension/app IDs and update URLs to be silently installed field, select Enabled, paste the value you copied from the Dashlane Admin Console, and select OK.
- Confirm the Enabled status and select Next.
-
On the next screen, set the Scope tags to Default and select Next.
-
Select Add Groups and select the boxes next to the names of the groups to which you want to deploy the extension. In this example, the group selected is called "Demodash."
Even though these are being configured as Intune device configurations, the assignments need to be to Groups and not Devices.
- Select the Select button and then Next.
-
Review the information and select Create.
The policy is now active. If a plan member hasn't enrolled with Intune, they'll be prompted to do so when they sign in on a managed device. After they enroll, Intune automatically installs the Dashlane browser extension in their browser.
Microsoft Edge
Copy the browser value here or in the Admin Console:
gehmmocbbkpblljhkekmfhjpfbkclbph;https://edge.microsoft.com/extensionwebstorebase/v1/crx
In Intune, add a new device configuration:
- Select Devices, Configurations, and then Create and New policy. Use these settings to define the policy:
- Platform: Windows 10 and later
-
Profile type: Settings catalog
-
Select Create, enter a name for the Profile (for example, "Deploy Dashlane browser extension"), then select Next.
-
In Configuration settings, search for Edge extensions and select the Microsoft Edge\Extensions folder.
- Select the Control which extensions are installed silently (User) setting.
- Paste the value you copied from the Dashlane Admin Console. Confirm the Enabled status and then select Next.
-
On the next screen, set the Scope tags to Default and select Next.
-
Select Add Groups and select the boxes next to the names of the groups to which you want to deploy the extension. In this example, the group selected is called "Demodash."
Even though these are being configured as Intune device configurations, the assignments need to be to Groups and not Devices.
- Select the Select button and then Next.
-
Review the information and select Create.
The policy is now active. If a plan member hasn't enrolled with Intune, they'll be prompted to do so when they sign in on a managed device. After they enroll, Intune automatically installs the Dashlane browser extension in their browser.
In the Dashlane Admin Console select Complete to confirm the extension was deployed.
After this deployment you can turn on Credential Risk Detection. You can also turn on AI phishing alerts and Credential Risk Alerts for logged-out plan members and employees without Dashlane accounts.
Learn more about Credential Risk Detection
Learn more about AI phishing alerts
Learn more about Credential Risk Alerts
If you turn on Credential Risk Detection or AI phishing alerts, the information collected will be logged in the Activity Log and displayed on the Risk Detection and Phishing Alerts pages.
More about Risk Detection insights
More about Phishing alerts insights
If you have any issues turning on these features, please contact our Support team.
Contact support through the Admin Console
Watch the Windows + Intune setup video
You can watch a step-by-step video of the Windows + Intune setup.
Watch the Windows + Intune setup video
What is Microsoft Intune?
Microsoft Intune is a cloud-based endpoint management solution. It manages user access to organizational resources and simplifies app and device management across devices, including mobile devices, desktop computers, and virtual endpoints.