How a deployment works
How Avanoo reaches browsers through Group Policy or Intune, and why installation targets computers while identity targets users.
Avanoo is a browser extension, deployed through the browser policies your organization already manages. There is no installer to run on each device and nothing for users to do. This page explains the model. The exact values, generated files, and step-by-step procedures for your organization become available once you have platform access.
Two channels, two scopes
Every deployment delivers two things, through two separate channels:
| Installation | Identity | |
|---|---|---|
| What it does | Makes the extension present in every managed browser | Tells the extension which person it is running for |
| Target | The computer | The user |
| Where it is written on Windows | Machine policy (HKLM) | The signed-in user's policy hive (HKEY_CURRENT_USER) |
| What it carries | The force-install policy and update URL | A managed userEmail value: the real e-mail address, or an alias in Pseudonymous mode |
Installation is machine-wide: every user who opens a managed browser on that computer gets the extension. Identity is per user: two people sharing a computer must each receive their own value. That is why identity never goes in the machine policy. If it did, every user on the device would be reported as the same person.
Installing the extension alone does not identify anyone. Until identity arrives, activity is reported with no person attached. Keeping the two channels apart also makes a rollout easy to diagnose: a missing extension points to the installation policy, an anonymous extension points to the identity source.
The value sent as identity depends on the identity mode your organization chooses. See the identity mode comparison.
With Group Policy (GPO)
On domain-joined Windows, a deployment uses two Group Policy Objects:
- Installation: a Computer Configuration GPO, linked to an OU of devices. It uses the Avanoo ADMX template to force-install the extension in Chrome, Edge, and Brave, and Firefox if you use it.
- Identity: a separate User Configuration GPO, linked to an OU of users. It uses
Group Policy Preferences (GPP) to write each user's value from Active Directory: the
mailattribute in Identified mode, or an alias stored on the user object in Pseudonymous mode.
Because the two GPOs target different OUs, installation follows where the computer sits in Active Directory and identity follows where the user sits.
With Microsoft Intune
On Intune-managed Windows, the same split maps onto Intune assignments:
- Installation: a Settings catalog profile assigned to a device group. It force-installs the extension in Chrome and Edge. Brave uses a platform script.
- Identity: a remediation script assigned to a user group. In Identified mode it
writes each signed-in user's UPN, or Active Directory
mailon hybrid-joined devices when it differs. The script runs as SYSTEM, whose ownHKCUis not the user's hive, so it writes directly into the hive of each signed-in user.
In Pseudonymous mode, the alias comes from Active Directory, so identity is delivered by Group Policy Preferences on hybrid-joined devices while Intune handles installation.
Google Workspace and Firefox-only policy deployments are also supported. They follow the same principle of separate installation and identity channels.
A typical rollout
- Choose a pilot: a small group of devices for installation and the matching group of users for identity.
- Deploy both channels to the pilot.
- Verify each channel separately: the extension is installed and cannot be removed, then activity appears under the expected identity.
- Widen the device scope and the user scope together until the whole organization is covered.
Removing Avanoo follows the reverse order: withdraw the installation policy first, since a force-installed extension cannot be removed while the policy is still in place.
What you receive once onboarded
After platform access is provisioned, the documentation shows the procedure that matches the console you use (GPO, Intune, or Google Workspace) and the identity mode you chose. It includes:
- generated policy files for your organization (ADMX template, GPP file, or Intune scripts) with your extension identifiers and update URLs already filled in;
- installation, identity, verification, expansion, and removal steps in order; and
- troubleshooting for common deployment issues.
To prepare, read the identity mode comparison and usage modes and privacy.