Deployment payloads
Prepare these items before assigning the deployment:- The Edge package for each target operating system and architecture.
- A managed
config.jsoncontaining the Bifrost deployment URL. - For macOS, the active Edge CA certificate as a device-scoped trusted-root profile.
The managed file takes precedence over a URL entered locally from the tray. The agent watches it for changes, so correcting the URL does not require reinstalling the package.
macOS
The macOS package supports Apple Silicon devices. For a managed rollout, apply the policy and certificate profile before or with the package.1
Disable the supported local uninstall command when required
Before installing the package, set the Boolean managed preference
DisableLocalUninstall to true in the ai.getbifrost.edge preference domain.This preference is optional. Use it when local users should not receive the package’s supported bifrost-edge-uninstall command. The preference must exist before installation or upgrade for the package to omit that command link.2
Push the managed configuration
Write
config.json to /Library/Application Support/Bifrost Edge/config.json as root and make it readable by the service.3
Push the CA as a trusted root
Download the active
.crt from Edge Control → Edge Settings and deploy it in a device-scoped certificate payload with payload type com.apple.security.root.Do not use a user-scoped profile or a generic com.apple.security.pkcs1 / com.apple.security.pem payload. Those forms do not establish the machine-wide root trust the agent checks. Confirm that the deployed certificate’s SHA-256 fingerprint matches Edge Settings.4
Install the package
Push
macos-arm64.pkg to the target devices. The package installs the system daemon and the per-user menu-bar agent.Windows with Intune or another MDM
Usewindows-amd64.intunewin for x64 Intune deployments. For another MDM, or for Windows ARM64, use the matching MSI package.
1
Install the package in the system context
Use the matching architecture and run the MSI silently:
2
Push config.json
Use a device script or remediation to write
%ProgramData%\BifrostEdge\config.json:Linux with fleet-management tooling
Deploy the.deb package to Debian/Ubuntu devices or the .rpm package to RHEL/Fedora devices, using the package that matches the device architecture. In the same policy or play, write config.json to /etc/bifrost-edge/config.json with mode 0644.
No separate CA profile is required on Linux. The agent installs the CA into the system trust store. For browser interception, ensure certutil is available through libnss3-tools on Debian/Ubuntu or nss-tools on RHEL/Fedora.
Restart computers after CA trust
After the active CA is delivered and trusted, restart each computer before testing Edge traffic. A full computer restart is required for the CA certificate change to take effect. Repeat the restart whenever the active CA is replaced. On macOS, restart after the trusted-root profile and Edge package are installed. On Windows and Linux, restart after the agent has received and installed the active CA.Rollout order
The package and managedconfig.json can arrive in either order; the agent watches for the file. On macOS, deploy the trusted-root profile before testing interception so users are not left with an authorization request they cannot approve.
Start with a small pilot group. Continue to Sign in and verify before expanding the assignment.
