IT admin guide

Roll out Sidekick to a managed fleet

A practical path for a 5–30 device pilot today, plus the force-install policy to use once the browser-store listings are live.

Current release status: Vericode Sidekick is not yet published in the Chrome Web Store or Edge Add-ons. VER-231 tracks publication and remains in progress. Today, your Vericode contact supplies the approved package.
Available today

Pilot the approved package

Use your normal software-deployment tool to place the approved ZIP on pilot devices. There is no MSI, agent, ADMX package, or server component to deploy. Each pilot user still completes the browser’s manual Load unpacked action.

  1. 1

    Choose a pilot

    Start with two or three staff across the browser and device combinations you support.

  2. 2

    Pre-stage the package

    Distribute Vericode’s approved package with your existing Intune Win32, Group Policy software distribution, or login-script process.

  3. 3

    Complete today’s install

    Ask pilot users to unzip the package and follow the quickstart guide’s Load unpacked step. Browser policy cannot silently install this unpublished package.

  4. 4

    Sign in and test

    Staff sign in through WorkOS, then follow the quickstart guide’s Send a test to yourself step.

  5. 5

    Move to force-install later

    After VER-231 is complete and the listing is live, replace the pilot process with the target-state browser policy below.

Open the individual install and test steps
Once the listings are live

Switch to browser force-install

These are standard browser-vendor policies, documented here as the target state. Do not activate them until the relevant listing resolves to the genuine Vericode Sidekick extension.

Google Chrome

Target state — not available today

  1. In Google Admin, open Devices → Chrome → Apps & extensions → Users & browsers.
  2. Add Sidekick from the Chrome Web Store and set its installation policy to Force install.
  3. For Windows policy, configure ExtensionInstallForcelist under HKLM\Software\Policies\Google\Chrome (or the equivalent HKCU path). Each numbered value is extension_id;update_url.
  4. For macOS, configure the ExtensionInstallForcelist array in the com.google.Chrome preference domain.
Chrome Enterprise policy reference Google Admin app management steps

Microsoft Edge

Target state — not available today

  1. Configure Control which extensions are installed silently in the Edge administrative template.
  2. On Windows, the policy maps to HKLM\Software\Policies\Microsoft\Edge\ExtensionInstallForcelist (or HKCU). Use a numbered value containing extension_id;update_url.
  3. On macOS, configure the ExtensionInstallForcelist array in the com.microsoft.Edge preference domain.
Microsoft Edge policy reference

Store references to validate before rollout

Microsoft Intune

Target-state Intune setup

Target state — not available today

  1. In Devices → Configuration, create a Windows configuration policy using Settings catalog.
  2. For Edge, add Microsoft Edge → Extensions → Control which extensions are installed silently, enable it, and add the published extension ID and update URL.
  3. For Chrome, import Google’s current Chrome ADMX/ADML files, then configure Google Chrome → Extensions → Configure the list of force-installed apps and extensions.
  4. Assign the policy to the pilot group, confirm installation in the browser policy page, then expand the assignment.
Microsoft’s current Intune Edge walkthrough
Security review

What IT should know

Right-click menus

Adds “Verify with Vericode” when a user deliberately selects a phone number.

Current tab and scripting

Reads only the text selected after the user activates Sidekick. It does not scrape pages in the background.

Access on all sites

Lets the same deliberate selection work in any browser-based business system. Page contents and browsing history are not collected.

Storage

Keeps the workspace connection and recent local verification history on this browser.

Identity

Opens the secure WorkOS sign-in flow for the user’s Vericode workspace.

Allowlist these verified hosts

  • app.vericode.com.au
  • api.vericode.com.au
  • api.workos.com
  • app.vericode.com.au/callback

The production callback returns to the Vericode app. WorkOS authorization and key discovery use api.workos.com. Restrict rules by HTTPS and validate them against your own proxy logs during the pilot.

Managed configuration

No managed settings schema yet

Sidekick does not currently declare a storage.managed schema. There are no supported organisation-hint, environment, or preconfigured workspace keys for IT to push. Do not invent registry or plist values: users connect their workspace after installation. This gap has been flagged on VER-673 for product follow-up.

Individual quickstart Security postureTrust FAQManifest and vendor policies checked 19 July 2026