Back to blog
DeploymentPublished on August 21, 20268 min read

Deploy and Update Chrome and Firefox via Intune

Install Chrome and Firefox across your whole fleet and keep them updated automatically with Microsoft Intune, without winget on endpoints or manual packaging.

The browser is the most used app on the fleet, and one of the most targeted. Chrome and Firefox flaws are exploited regularly, sometimes before the fix is even widely deployed, through booby-trapped web pages or malicious extensions. Installing these browsers on every machine and ensuring they stay current is therefore a top-tier security priority, not a mere convenience. An outdated browser is a direct entry point to the machine and, from there, to the company's data.

Many organizations let each user install and update their own browser. The result: a heterogeneous fleet where recent versions live alongside others vulnerable for months, with no one able to say precisely which machine runs what. Centralized control through Intune solves this by making the browser a managed application like any other, deployed and updated on your terms rather than the user's.

Deploying Chrome and Firefox cleanly

A clean deployment always starts from the vendors' official installers and targets the right devices, rather than letting everyone download their own version from an uncertain source. A few principles keep the rollout consistent across the whole fleet.

  • Push the vendor's official installer to every managed device through Intune.
  • Assign the deployment to the right user or device groups.
  • Check installation and success rate, then retry on failures.
  • Avoid depending on winget on endpoints, which is often absent or restricted.
A fleet where every browser shares the same up-to-date version shrinks the attack surface.

Why start from official installers

Relying on the signed binaries from Google and Mozilla guarantees the integrity of what is installed: you know exactly where the software comes from and that it has not been tampered with. Depending on winget on endpoints is fragile, because the tool is frequently absent, disabled by group policy or restricted in managed environments. Pushing the official installer directly through Intune avoids this dependency and offers a single, consistent deployment channel.

Keeping browsers up to date over time

Installing a version once is not enough: an unmaintained browser becomes vulnerable again within a few weeks, given the steady release pace of Google and Mozilla, who ship new versions every few weeks. Updating must therefore be continuous, automated and, above all, verified.

  1. 1Track the new versions released by Google (Chrome) and Mozilla (Firefox).
  2. 2Deploy the update to the fleet as soon as it is available, in waves if needed.
  3. 3Confirm each device actually moved to the target version.
  4. 4Prioritize fixing machines still on a vulnerable version.

You can also manage certain security settings — forced updates, browser policies, disabling risky features — through Intune, so a user cannot deliberately keep their own browser stuck on an old version. These policies strengthen the security posture beyond simply updating the binary.

Given the release pace, an unmonitored browser becomes vulnerable again within weeks.

Simplifying the whole cycle

The initial deployment and long-term maintenance follow the same logic: start from official installers, target the right devices, measure the result. Automating this chain avoids manual packaging and the tedious tracking of version numbers, two time-consuming tasks with no added value for the IT team. It also removes the human error that creeps in whenever someone has to repackage an installer and reassign it by hand every few weeks.

Handling multiple browsers and edge cases

Many organizations run several browsers in parallel: Edge for the intranet, Chrome or Firefox for certain line-of-business apps. Each must be maintained with the same rigor, because a single forgotten browser is enough to reopen a way in. A few principles help keep control over the whole set.

  • Standardize on a small set of officially supported browsers.
  • Uninstall or block outdated or unauthorized browsers.
  • Apply the same update policies to every browser on the fleet.
  • Document which browser is required for which line-of-business app.

Don't overlook extensions

The browser itself is only part of the attack surface: extensions installed by users can also introduce flaws or exfiltrate data. Browser policies driven through Intune let you restrict which extensions are allowed, or permit only a whitelist. Keeping the binary up to date while letting dubious extensions proliferate would be like securing the door and leaving the window wide open.

Common mistakes to avoid

A few classic pitfalls leave vulnerable browsers in circulation despite good intentions.

  • Counting on the browser's auto-update when it is sometimes blocked by limited rights.
  • Deploying once without ever verifying the whole fleet actually moved to the target version.
  • Forgetting remote-work machines, rarely present at deployment time.
  • Leaving old versions installed alongside new ones, without uninstalling them.

A concrete browser-deployment example

Take an organization of a hundred machines where, until now, each user installed their own browser. The inventory reveals a fragmented fleet: four different Chrome versions coexist, two of them vulnerable, and a handful of machines have no managed browser at all. The team decides to standardize. It pushes Google's official installer through Intune to a pilot group, confirms the line-of-business apps work, then extends to the rest of the fleet. In parallel, a browser policy forces updates and restricts extensions to an approved list.

  1. 1Map the browser versions actually installed across the fleet.
  2. 2Push the vendor's official installer through Intune to a pilot group.
  3. 3Validate the line-of-business apps before extending to the rest.
  4. 4Force updates and frame extensions through policy.
  5. 5Verify that each machine actually moved to the target version.

By the end of the operation, all hundred machines share the same up-to-date version, unapproved extensions are blocked, and the team has a report showing precisely which device runs which version. Vulnerable browsers have vanished from the fleet, and future updates will follow the same automated channel. This example shows that a browser, despite its central role and high attack surface, is managed exactly like any other application deployed through Intune, provided you start from a reliable inventory.

How AuPoint helps

AuPoint lets SMBs and MSSPs deploy Chrome and Firefox in a few clicks and keep them updated automatically: the platform tracks the versions published by the vendors, pushes official installers through Intune, and flags devices still on a vulnerable version, with automatic retry on failures. You keep a consistent, up-to-date browser fleet, with no manual packaging and no reliance on winget.

Frequently asked questions

Should I disable the browser's auto-update?

Not necessarily, but you should not rely on it alone. Auto-update can be blocked by limited user rights, paused when a machine stays off for a while, or disabled by mistake. A managed deployment through Intune guarantees that every machine moves to the target version and provides the proof that it did.

Can Edge be managed the same way?

Yes, the same centralized management logic applies. What matters is treating every browser present on the fleet with the same rigor, because a single unmaintained browser is enough to reopen a flaw. Document which one is required for each line-of-business app.

Why not use winget to install Chrome?

Because winget is often absent, disabled or restricted on managed endpoints, and its behavior varies from one machine to another. Pushing the vendor's official installer through Intune is more reliable and guarantees the integrity of the installed binary.

How are users' bookmarks and settings handled?

A deployment driven through Intune installs or updates the browser binary without wiping the user's profile: bookmarks, saved passwords and history are preserved. Browser policies, on the other hand, let you enforce certain security settings, such as the home page or the blocking of risky features, without touching each person's legitimate personal preferences.

Stop letting your browsers, attackers' first target, drift toward vulnerable versions. With AuPoint, deploy Chrome and Firefox across your whole fleet through Intune and keep them updated automatically. Request a demo to standardize your browser fleet.

Secure your tenant in 15 minutes

Free trial