Browser Security Extension
Overview
The Bastion Browser Extension provides real-time protection within the browser. Detect phishing, prevent credential theft, and enforce safe browsing policies.
Features
Real-Time Protection
| Feature | Protection |
|---|---|
| Phishing Detection | Blocks fake login pages |
| Malware Sites | Prevents malicious downloads |
| Typosquatting | Warns about suspicious domains |
| SSL Verification | Checks certificate validity |
Password Protection
- Detects password reuse
- Warns on corporate password entry to external sites
- Prevents credential phishing
Policy Enforcement
- Block/warn on policy violations
- Enforce safe search
- Control file downloads
Installation
Supported Browsers
| Browser | Version | Platforms |
|---|---|---|
| Chrome | 90+ | Windows, macOS, Linux |
| Edge | 90+ | Windows, macOS |
| Firefox | 90+ | Windows, macOS, Linux |
| Safari | 14+ | macOS |
User Installation
- Send installation link to employees
- User clicks link to browser store
- User installs extension
- Extension configures automatically
Managed Deployment
Deploy via enterprise management:
Chrome (GPO/MDM):
{
"ExtensionInstallForcelist": [
"extension-id;https://clients2.google.com/service/update2/crx"
]
}
Firefox (GPO):
{
"Extensions": {
"Install": ["extension-url"]
}
}
Enrollment
After installation:
- Extension prompts for enrollment
- User signs in with SSO
- Extension links to Bastion account
- Policies applied automatically
Configuration
Extension Settings
Configure via Bastion dashboard:
- Navigate to Web Browsing → Browser Extension
- Click Settings
- Configure:
- Protection levels
- User notifications
- Reporting options
- Save
Protection Levels
| Level | Behavior |
|---|---|
| Block | Prevent access, show block page |
| Warn | Show warning, allow proceed |
| Monitor | Log activity, no user impact |
| Off | Disable protection |
Policy Settings
| Setting | Options |
|---|---|
| Phishing Protection | Block, Warn, Monitor |
| Malware Protection | Block, Warn, Monitor |
| Password Protection | Enable, Disable |
| Safe Search | Enforce, Off |
| Download Scanning | Enable, Disable |
Password Protection
How It Works
- User enters password on a site
- Extension checks if password matches corporate password
- If match on non-approved site, action taken:
- Alert user
- Block submission
- Notify security team
Configuration
- Go to Settings → Password Protection
- Configure:
- Approved login domains
- Action on violation (block/warn)
- Admin notifications
- Save
Approved Domains
Define where corporate passwords can be used:
login.company.comlogin.microsoftonline.com*.yourcompany.com
User Experience
Notifications
Users see notifications for:
- Blocked pages (with reason)
- Warnings (with proceed option)
- Security tips
- Policy updates
Customization
Customize user messaging:
- Block page content
- Warning messages
- IT contact information
- Request exception process
Reporting
Extension Analytics
View extension usage:
- Installed users
- Active users
- Threats blocked
- Warnings shown
Threat Reports
See detected threats:
- Phishing attempts
- Malware sites
- Password warnings
- Policy violations
User Activity
View per-user data (if enabled):
- Sites visited
- Threats encountered
- Actions taken
Troubleshooting
Common Issues
Extension Not Connecting
- Check network connectivity
- Verify SSO is working
- Clear browser cache
- Reinstall extension
False Positives
- Add site to allowlist
- Report false positive
- Adjust sensitivity settings
Performance Issues
- Check for conflicting extensions
- Update browser
- Reduce monitoring scope
Privacy
Data Collection
Extension collects:
- URLs visited (for threat checking)
- Blocked/warned sites
- Extension status
Extension does not collect:
- Page content
- Form data (except for password warnings)
- Personal files
User Controls
Users can:
- View extension activity
- Report false positives
- Request exceptions
Best Practices
Deploy with Training
Accompany extension deployment with user training on why it's needed.
Start with Warnings
Begin with warn mode. Move to block after users understand the system.
Monitor False Positives
Watch for false positives and adjust allowlists accordingly.
Keep Updated
Enable auto-updates for latest protection.