Enterprise browser security for Microsoft Edge

Stop sensitive data at the browser — without collecting it.

Ward is a managed extension for Microsoft Edge and an admin console. It checks pastes, uploads and AI prompts and applies your policy at the moment of the action. Content stays on the device; only metadata is sent to the server.

Request accessHow it works

  • Decides at the moment of actionBlocking takes effect before the content reaches the site.
  • Deployed with IntuneForce-installed into Edge; users cannot remove it.
chatgpt.com
The block dialog as the extension renders it, with the default wording for a sensitive paste into an AI tool. The organisation name is illustrative.

Four areas of protection

What ships today and what is coming, labelled plainly. Data protection and extension visibility are available now; web and download threat protection are coming.

  1. Data protection

    Available

    Stops sensitive company data from leaving through AI prompts, pastes, uploads and form submissions — decided in the browser, at the moment of the action.

    Available today

    • AI prompt protection
    • Paste and drag-and-drop inspection
    • File upload inspection
    • Local DLP detectors and classifications
    • Corporate vs personal account context
    • App and AI discovery
    • Graduated decisions
  2. Extension protection

    Available

    Shows every browser extension in the organisation, where it comes from, what it may do and what changed — and blocks it through Microsoft Edge policy when an administrator decides to.

    Available today

    • Extension inventory
    • Publisher and store history
    • Permission-change alerts
    • Explainable risk score
    • Administrator blocking via Edge policy

    Coming

    • Malware scanning and reputation
    • Automatic blocking
  3. Web protection

    Coming

    Blocking of phishing, malware and scam sites is coming. Today, company policy can already block or warn on navigation to specific applications and categories.

    Available today

    • Policy-based site and app controls

    Coming

    • Phishing, malware and scam site blocking
  4. Download protection

    Coming

    Download reputation is coming. Today, company policy can already block, warn on or log downloads by source site and file type.

    Available today

    • Download rules by source site and file type

    Coming

    • Download reputation

All capabilities, with how each was tested

How it works

  1. Inspect locally

    At a paste, drop, upload or prompt submission, the extension classifies the content on the device with detectors that return counts, never values, and applies your signed policy on the spot. Blocking takes effect before the content reaches the site.

    On the device

    Pasted text
    Ward test WARDCANARY-W1 card 4111 1111 1111 1111
    Detector
    pci.card — 1 match (Visa prefix, Luhn check passes)
    Classification
    Payment card data · restricted
    Destination
    chatgpt.com · generative AI · not confirmed as a work account
    Policy
    Block sensitive data to personal AI → block

    Leaves the device

    pci.card × 1 · blocked

    Local inspection of the synthetic test content used in the real-world validation (a public test card number).
  2. Report the decision

    If the policy acts or sensitive data was found, the extension queues an event and uploads it in the background. Browsing never waits for the server, and allowed, non-sensitive actions produce no event.

    Metadata eventabridged
    {
      "type": "data.paste",
      "occurredAt": "2026-09-25T02:33:00Z",
      "action": "paste",
      "decision": "block",
      "outcome": "blocked",
      "severity": "high",
      "app": {
        "hostname": "chatgpt.com",
        "catalogKey": "chatgpt",
        "category": "genai"
      },
      "account": {
        "type": "unknown",
        "domain": null,
        "identifier": null
      },
      "data": {
        "classifications": ["<Payment card data>"],
        "detectors": [{ "id": "pci.card", "count": 1 }],
        "maxSensitivity": "restricted",
        "source": "clipboard"
      },
      "file": null,
      "policy": {
        "ruleId": "<Block sensitive data to personal AI>",
        "version": 2
      },
      "inspectMs": 0.2
    }
    What the server receives for a blocked paste: the detector, the count and the decision.
  3. Review in the console

    Administrators see the event, the device, the user and the policy that fired, and can route alerts to a SIEM through signed webhooks.

    Time (UTC)DeviceTypeOutcomeDetectorsInspect ms
    2026-09-25 02:33Edge · Windowsdata.pasteblockedpci.card ×10.2
    2026-09-25 03:20Edge · macOSdata.submitblockedpci.card ×13.5
    2026-09-25 03:31Edge · macOSdata.pasteblockedpci.card ×10.3
    2026-09-27 06:14Edge · Windows (Intune)data.submitblockedpci.card ×10.6
    2026-09-27 06:14Edge · Windows (Intune)data.pasteblockedpci.card ×10.2
    Blocked events recorded during the September 2026 validation on real Microsoft Edge and chatgpt.com. This metadata is everything that was stored.

Deploys to Microsoft Edge with Intune

Ward is a Manifest V3 extension that your MDM force-installs, so users cannot remove or disable it. There is no agent to install on the operating system.

You create an enrollment token in the console, download the generated configuration and assign it in Intune — the deployment steps are on the Product page.

On macOS, Ward can optionally create and update the Intune profile through Microsoft Graph — using a dedicated app registration you authorise, and only after you preview and confirm each change. Microsoft Entra ID provides directory groups for policies, single sign-on for administrators, and verification of which user is signed in to each browser.

Private by design

Ward exists to keep company data out of the wrong places, not to watch employees.

  • Content stays on the device; only metadata is sent. Pastes, prompts, files and typed text are inspected in the browser. The telemetry schema has no field that could carry content, and the server rejects unknown fields.
  • Allowed, non-sensitive actions produce no event. Ward reports when a policy acts or sensitive data is detected.
  • Only hostnames, never full URLs. Application discovery is a daily roll-up, not a browsing history — and can be limited to known applications.
  • Personal account identifiers are not collected by default. A personal account is recorded as, for example, “personal, gmail.com”.
  • Events are deleted after 180 days by default. Retention is configurable per organisation.

Read the security and privacy details.

What has been verified

Version 0.1.0 was tested in September 2026 on real Microsoft Edge, the real chatgpt.com and a real Microsoft 365 tenant with Intune — see the results, and what is not yet validated, on the Product page.