This setup allows you to whitelist Cyber Guru domains on Windows devices managed with Microsoft Intune (Azure AD / Entra ID Join).
Prerequisites
- Microsoft Intune license (part of Microsoft 365 Business Premium or Enterprise)
- Windows devices enrolled in Intune
- Admin access to Microsoft Intune admin center (https://intune.microsoft.com)
- Chrome, Edge installed on client devices
- Chrome ADMX Template
- Edge ADMX Template
- Cyber Guru domains
|
WHERE TO FIND THE FULL LIST OF LANDING PAGE DOMAINS
|
Download and configure Chrome ADMX template
- Download the Chrome ADMX templates from chromeenterprise.google/browser/download/
- Go to: intune.microsoft.com
- Navigate to: Devices → Configuration → Import ADMX
- Click: "+ Import"
- Upload google.admx as the ADMX file
- Upload google.adml as the ADML file (select the language)
- Click: Import and wait for processing (2-5 minutes)
- Repeat for chrome.admx + chrome.adml
- Wait until the status shows "Available" for both
Configure Chrome on Intune
Log in to https://intune.microsoft.com with admin credentials
Navigate to: Devices → Configuration → Configuration profiles
Click + Create → New policy
Select: Platform: Windows 10 and later | Profile type: Settings Catalog
Enter the name:
Cyber Guru - Chrome Safe Browsing WhitelistClick Next
In Configuration settings, click + Add settings
Search for: "SafeBrowsingAllowlistDomains" (under Google Chrome)
- In the results below, check the box next to: "Configure the list of domains on which Safe Browsing will not trigger warnings (User)"
- Close the Settings Picker (the policy will appear on the configuration page)
- Enable the policy (toggle ON)
-
Use the + Add button to add entries or select "import" and upload a CSV file with the shared domain list:
[DOMAIN-1] [DOMAIN-2] [DOMAIN-3] ... [DOMAIN-N]Remember to select the domains after adding them.
Click Next
Assignments: Select the target device or user group (e.g., "All devices" or a specific group)
Click Next → Create
Configure Edge on Intune
From the Intune console, click + Create → New policy
Platform: Windows 10 and later | Type: Settings Catalog
Name:
Cyber Guru - Edge SmartScreen WhitelistClick Next
Click + Add settings
Search for: "SmartScreenAllowListDomains" (under Microsoft Edge)
- In the results below, check the box next to: "Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings (User)"
- Close the Settings Picker (the policy will appear on the configuration page)
- Enable the policy (toggle ON)
-
Use the + Add button to add entries or select "import" and upload a CSV file with the shared domain list:
[DOMAIN-1] [DOMAIN-2] [DOMAIN-3] ... [DOMAIN-N]Remember to select the domains after adding them.
Click Next
Assignments: Select the target device or user group (e.g., "All devices" or a specific group)
Click Next → Create
Client verification
-
On a Windows device enrolled in Intune, sync the policies:
- Open Settings → Privacy & security → Diagnostics & optional data
- Click Diagnostic data
- Wait for the sync (usually automatic, but you can force it by waiting 15 minutes)
Chrome: Open Chrome and go to
chrome://policy→ Check that SafeBrowsingAllowlistDomains shows the domainsEdge: Open Edge and go to
edge://policy→ Look for SmartScreenAllowListDomains
ℹ️ Note: Policy sync can take up to 30 minutes. If you don't see results right away, wait and then force a sync from the Windows client.
Granular assignment
You don't need to assign the policies to ALL devices. You can create specific groups:
- Assign only to the IT department
- Assign only to a specific set of testers
- Assign by project
To assign to a specific group:
- From the policy, click Assignments
- Click + Edit included groups
- Select the target Azure AD group
- Click Select → Save
Editing and updating policies
If you add or remove domains in the future:
- From the Intune console, open the policy
- Click Properties → Settings → Edit
- Edit the domains
- Click Save
- The policy will automatically update on synced clients
Troubleshooting
The policy doesn't appear in chrome://policy:
- Check that the device is enrolled in Intune (Settings → Privacy → Diagnostics)
- Force sync and wait 30 minutes
- Restart the browser
- If it persists, unenroll and re-enroll the device
Error during assignment:
- Check that the Azure AD group exists
- Check that the devices are actually in the group
- Check Intune licenses
Domains are not recognized:
- Make sure there are no extra spaces
Note: Microsoft Defender for Endpoint (MDE)
⚠️ Warning: If your organization uses Microsoft Defender for Endpoint (MDE), the Edge SmartScreenAllowListDomains policy will be ignored, even if configured via Intune. Edge whitelisting must be set up through: https://security.microsoft.com → Settings → Endpoints → Indicators → URLs/Domains → add each domain with Action: Allow.