Prism DLP browser extension: Jamf Pro rollout (macOS)
Four files, uploaded as two configuration profiles. The Prism DLP extension’s Chrome Web Store ID is oblejifclpmcamglacjnhmfmdccpbnmk (Edge installs the same one); it’s already filled in. You need one value from Prism:
- Sensor key (
SENSOR_KEYbelow): startspk_…, from the Prism console under Set up. It can only send events to your organisation; revoke and replace it there if it leaks.
The Set up page also generates these four files with your key already filled in (Jamf Pro section), so you can skip step 1.
1. Fill in the files
In the two ….extensions.….plist files, replace SENSOR_KEY. Leave $EMAIL and $FULLNAME as they are: Jamf fills them from the user assigned to each Mac.
| File | Preference domain | What it does |
|---|---|---|
com.google.Chrome.plist |
com.google.Chrome |
Force-installs Prism, pins it, turns off Incognito and guest profiles |
com.google.Chrome.extensions.oblejifclpmcamglacjnhmfmdccpbnmk.plist |
com.google.Chrome.extensions.oblejifclpmcamglacjnhmfmdccpbnmk |
Prism’s settings in Chrome |
com.microsoft.Edge.plist |
com.microsoft.Edge |
The same for Edge (InPrivate off) |
com.microsoft.Edge.extensions.oblejifclpmcamglacjnhmfmdccpbnmk.plist |
com.microsoft.Edge.extensions.oblejifclpmcamglacjnhmfmdccpbnmk |
Prism’s settings in Edge |
Drop the Incognito/InPrivate and guest keys if you don’t want them. Extensions don’t run in private windows, so leaving them on is a gap.
2. Create the profiles in Jamf Pro
- Computers → Configuration Profiles → New. Name it “Prism DLP for Chrome”, level Computer Level.
- Application & Custom Settings → Upload → Add. Preference domain
com.google.Chrome, uploadcom.google.Chrome.plist. - Add again in the same payload. Preference domain
com.google.Chrome.extensions.oblejifclpmcamglacjnhmfmdccpbnmk, upload that file. - Scope to the test Mac first, then save.
- Repeat for Edge with the two Edge files, if Edge is in use.
If you already manage Chrome with a com.google.Chrome profile, add the ExtensionSettings entry to it instead: two profiles setting the same domain don’t merge reliably.
3. Check it on the test Mac
chrome://policy→ Reload policies.ExtensionSettingsshows OK, and under the Prism DLP extensionapiUrl,apiKey,emailandnameare listed. In Edge,edge://policy.chrome://extensions: Prism DLP is there, “Installed by your administrator”, and can’t be turned off.- Prism’s settings page (extension menu → Options) shows the fields as set by your organisation. The email should be the user’s own address, not
$EMAIL. If it’s blank, the Mac has no assigned user in Jamf, and Prism uses the browser profile’s email if someone is signed in. - Paste a harmless test secret such as
AKIAIOSFODNN7EXAMPLEinto ChatGPT. It shows in the Prism console within seconds (recorded, not blocked, in observe mode).
Then widen the scope.
Notes
- Payload variables need the Mac assigned to a user (Inventory → User and Location). Prism ignores a variable that arrives unfilled rather than recording
$EMAILas someone’s address. - Edge reads the extension’s settings from
com.microsoft.Edge.extensions.<id>; Microsoft doesn’t document this yet, so checkedge://policyon a test Mac. - The extension covers Chrome and Edge. Desktop AI apps (ChatGPT, Claude, Cursor) need the Prism macOS agent.
Updated 9 October 2026