Skip to main content
Use direct installation for a pilot, a test device, or a device that is not managed through MDM. The user or installer needs local administrator privileges to install the system service and establish certificate trust.

1. Download the package

Use the organization-specific Edge download location provided during onboarding. Select the package that matches the device: macOS Intel devices are not a supported Edge target.

2. Choose how the device receives the Bifrost URL

The agent needs the HTTPS URL of your Bifrost deployment. For a direct installation, use either method below.
Install the package without a managed config.json. The tray initially reports that configuration is required. Select Sign in, enter the Bifrost deployment URL when prompted, and let the agent apply the configuration. Select Sign in again after the configuration has been applied.
Use the externally reachable HTTPS origin for Bifrost, without an API path. Edge upgrades non-loopback http:// service URLs to HTTPS.

3. Install the package

Open macos-arm64.pkg and complete the Installer prompts, or install it from Terminal:
The package installs a privileged background service and a menu-bar agent for the signed-in user.

4. Sign in and establish certificate trust

Open the Edge tray or menu-bar icon and select Sign in.
  • With an IdP, Edge opens the Bifrost sign-in flow in the default browser and returns the completed session to the local agent.
  • Without an IdP, the tray can offer Use Virtual Key when virtual-key sign-in is enabled in Edge Settings.
Certificate behavior differs by platform:
After the active CA is installed and trusted, restart the computer before testing Edge. A full computer restart is required for the CA certificate change to take effect. Repeat this step whenever the active CA is replaced.
Continue to Sign in and verify.