Documentation

Kandji

Deploy the SURF browser extension to managed Macs using Kandji, with configuration profiles built in the iMazing Profile Editor. Google Chrome and Arc are both covered.

Before you start

RequirementDetail
iMazing Profile EditorInstalled on your Mac. Download it from the official site if needed.
Kandji accessAccess to the Kandji admin portal with rights to add Library items
Extension IDThe SURF extension ID from the Chrome Web Store

Step 1: Create the configuration profile for Chrome

  1. Launch the iMazing Profile Editor.
  2. Click File → New Profile and set the platform to macOS.
  3. Navigate to the Google Chrome managed settings section.
  4. Locate the setting ExtensionInstallForcelist and click + to add an entry.
  5. Enter the details:
FieldValue
Extension IDdpjmcncaehmgiefclapmfaenmibeca, or the SURF extension ID for your tenant
Update URLLeave blank unless supplied by the extension developer
  1. Click File → Save and save the profile as a .mobileconfig file.

Step 2: Upload the profile to Kandji

  1. Log in to the Kandji admin portal.
  2. Go to Library → Add New → Configuration Profile.
  3. Upload the .mobileconfig file saved in Step 1.
  4. Scope the profile to the appropriate devices or groups.
  5. Save and apply the changes.

Step 3: Deploy for the Arc browser

Arc uses the same Chrome policy structure under a different payload type, so the profile is duplicated and one value changed.

  1. In iMazing Profile Editor, open the Chrome profile from Step 1 and save a duplicate under a new name.
  2. Open the duplicated .mobileconfig in a text editor.
  3. Find the PayloadType key and change its value:
FromTo
com.google.Chromecompany.thebrowser.Browser
  1. Save the modified file.
  2. Upload and scope it in Kandji following Step 2.

Verification

  1. Open Google Chrome or Arc on a managed device.
  2. Confirm the SURF extension installed automatically, without user interaction.
  3. Confirm users cannot remove or disable it.

Troubleshooting

SymptomCheck
Extension does not appearThe extension ID is wrong, the profile is not scoped to the device, or the browser does not support managed extensions
Chrome works but Arc does notPayloadType was not changed to company.thebrowser.Browser in the duplicated profile

For anything not covered here, contact the SURF support team.