This article explains how Swif’s browser extension behaves on its own and how its capabilities expand when paired with the Swif MDM agent—including the dual-auth model, silent login & sign-up detection (Shadow IT), PII monitoring, upload restrictions, and shared accounts (password vault).
Overview
Swif’s browser extension and MDM agent work together to provide comprehensive endpoint and web security:
Browser Extension – Controls in-browser actions (web app access, site/sign-up blocking, data loss prevention/PII monitoring, and credential autofill).
MDM Agent – Delivers device-level identity and context (verifying managed device status, assigned employee identity, and enforcing device-scoped policies).
Many advanced security and discovery features rely on device context provided by MDM. Without the MDM agent, the extension continues to function for basic controls, but advanced device-scoped features remain inactive.
Learn more about Browser Extension Security and Privacy in Swif.
Dual Auth Model: How Features Are Enabled
Swif operates on a dual authentication model:
1. Employee / Device Path (MDM-Enrolled Devices)
On an enrolled and managed device:
The extension automatically pairs browser activity with the managed device identity and its assigned employee via device tokens.
Employees do not need to log in to the extension for core protections and discovery to work.
The following run automatically in the background:
Blocklist (site and web app blocking)
Sign-in & Sign-up Detection (Shadow IT Discovery) – Automatically detects email/password and SSO logins (e.g., “Continue with Google”) and links app accounts to the employee.
Sign-up Blocking (per-app intervention when enabled by admin)
Device-Scoped Policies, eg. Chrome policy
You can find all available browser extension available features at Configuring Shadow IT Browser Extension Features.
2. Admin / Supporter Path (Extension Login)
Admins, IT staff, and supporters log in directly to the extension when they need diagnostic tools, support controls, or administrative features.
On non-MDM devices, employees must explicitly log in to the extension to enable basic protections (blocklists, manual sign-in/sign-up tracking). Advanced device-bound policies remain inactive.
What You Get With and Without MDM
Feature | MDM-Enrolled Device (No Extension Login Required) | Non‑MDM Device (Requires Extension Login) | Needs MDM? | What Users & Admins Will Notice |
Blocklist (site/app blocking) | Yes | Yes, if logged in | No | Blocked pages display a standard organization access restriction screen. |
Login & Sign-up Detection (Shadow IT) | Yes (Automatic for Email/Password & SSO) | Yes, if logged in | No | Silent background detection. Newly accessed SaaS accounts automatically register under Shadow IT in the Swif Admin Console. |
PII Monitoring & DLP | Yes | No (Inactive) | Yes | Sensitive data interactions are silently monitored in the background and reported to admin Insights dashboards without popups. |
Upload Restrictions | Yes | No (Inactive) | Yes | Unauthorized file uploads are blocked immediately with a full-screen notification directing the user to IT. |
Sign-Up Blocking | Yes | No (Inactive) | Yes | When enabled by admin for specific apps, sign-up attempts trigger an intervention UI blocking account creation. |
Sensitive App Tracking | Yes | No (Inactive) | Yes | Deep activity and interaction tracking on designated sensitive SaaS apps. |
Password Vault | Yes (Policy & employee assigned) | Limited / policy-dependent | Often | Extension presents authorized shared credentials to eligible employees without revealing the raw password. |
Key Feature Deep Dives
1. App Login & Sign-up Detection (Shadow IT Discovery)
How it works:
On MDM-enrolled devices, the extension monitors auth submissions and SSO action buttons (such as “Continue with Google”, “Sign in with Apple”, or standard email/password forms).
When an employee signs in or creates an account on a third-party app with their work email, the extension securely resolves the employee's identity via the MDM agent and registers the app under Shadow IT in the Swif Admin Console.
No employee login to the extension is required.
2. PII Monitoring & Data Loss Prevention (DLP)
How it works:
When configured, the extension monitors sensitive data inputs (e.g., API keys, customer PII, confidential terms) across web apps.
Detected events are logged silently and surfaced in the admin Insights dashboard.
Users do not receive intrusive inline prompts during standard monitoring.
3. Upload Restrictions
How it works:
When upload restriction policies are active, the extension blocks unauthorized file uploads to unapproved domains or external web apps.
When a restricted upload attempt occurs, the user sees a full-screen overlay:
“File upload blocked by your organization. Contact your IT team if you need to upload files to this domain.”
4. Shared Accounts & Central Password Vault
How it works:
Allows teams to access shared accounts (e.g., shared social channels, vendor portals) securely.
Access is centrally granted by admins based on team, employee, or device compliance.
Best Practices & Summary
For Employees on Managed Devices: Just browse normally. Core security policies, Shadow IT discovery for logins/sign-ups, upload blocks, and DLP protections run silently in the background without needing to sign into the extension.
For Employees on Unmanaged (Non-MDM) Devices: Sign in to the Swif extension to activate basic protection rules and web tracking.
For IT & Security Admins: View discovered SaaS applications, employee logins, DLP events, and policy violations in real-time within the Swif Admin Console.
Frequently Asked Questions (FAQ)
Does login and sign-up tracking work if the user clicks "Continue with Google" SSO?
Yes. The extension detects both direct credential entry and third-party SSO buttons, mapping the device and employee identity to the newly accessed app in Shadow IT.
Why don't employees see prompts when PII or logins are tracked?
Tracking operates silently in the background to ensure zero friction for legitimate day-to-day work while providing complete visibility to security administrators.
What happens if a user is on an unmanaged device?
Basic blocking and tracking only function if the user manually logs into the extension. Device-scoped features (such as PII monitoring and upload restrictions) remain inactive.