Prerequisites
Force Install and Magic Login require a Tango Enterprise plan with SSO set up. See How do I set up SSO and SCIM?
To be successful during setup, you should know the answers to the following questions:
What operating system do you want to deploy to? i.e. MacOS or Windows
What browser do you want to deploy to? i.e. Google Chrome or Microsoft Edge
What Mobile Device Management (MDM) software do you use? i.e. Intune, Jamf, Rippling, etc.
What Identity Provider (IdP) do you use? i.e. Okta, Azure, Google, etc.
What is Force Install and Magic Login?
Force Install and Magic Login automatically downloads the extension and signs the user in to Tango automatically using your existing Identity Provider (IdP). These features work seamlessly together to ensure a smooth Tango rollout.
How does it work?
Force Install is a built-in Chrome and Edge Extension Setting that lets you automatically install a specific browser extension to a user’s device. Magic Login is a custom Extension Setting that leverages an existing Chrome feature (Force Install) to sign your users in automatically through their IdP.
How do I set it up?
You can set up Force Install and Magic Login for Tango in three easy steps. For your convenience, we have created PowerShell scripts for Windows and provided the PList code for MacOS. Here is a quick overview of the process:
Windows
Download the appropriate scripts below
Find your
IdPConnectUrland replaceYOUR_IDP_CONNECT_URLin the script with itDeploy the script using your MDM
MacOS
Download the provided PList below or edit your existing PList with the code provided
Find your
IdPConnectUrland replaceYOUR_IDP_CONNECT_URLin the PList with itDeploy the PList using your MDM
How do I find my IdpConnectUrl?
IdpConnectUrl is a URL used to sign in through SSO for your IdP users. This allows us to sign the user into Tango through your IdP in a background tab.
You can typically find this URL within the Tango tile in your IdP’s “My Application” page.
3-Step Windows Instructions
1️⃣ Download the applicable PowerShell scripts for your browser of choice
2️⃣ Replace YOUR_IDP_CONNECT_URL in the script with the IdpConnectUrl from above and save the script
3️⃣ Deploy the script using your MDM
Most teams are successful with the merged setup script. However, if you’d like to set up Force Install and Magic Login separately, here are the individual scripts.
3-Step MacOS Instructions
1️⃣ Copy the following code to your com.google.Chrome.plist file.
<key>lggdbpblkekjjbobadliahffoaobaknh</key>
<dict>
<key>installation_mode</key>
<string>force_installed</string>
<key>update_url</key>
<string>https://clients2.google.com/service/update2/crx</string>
<key>toolbar_pin</key>
<string>force_pinned</string>
<key>IdpConnectUrl</key>
<string>YOUR_IDP_CONNECT_URL</string>
</dict>
If you do not have an existing com.google.Chrome.plist, please use this .plist file:
2️⃣ Replace YOUR_IDP_CONNECT_URL with the IdpConnectUrl from above and save the changes
3️⃣ Deploy the newly updated com.google.Chrome.plist file using your MDM
How do you verify that it works?
Check that the Tango extension shows up in the user’s browser.
If the user is logged in to the IdP, check that they are also logged in to Tango.
That’s it! 🎉
Resources
FAQ
What do the PowerShell scripts do?
These scripts will set the correct registries for each user in the respective browser so Force Install and Magic Login can work properly.
We use the Extension Setting “installation_mode”: “force_installed” to force install the extension. For the best end-user experience, we force pin the Tango extension in the provided script, using the following lines:
Chrome:
“toolbar_pin”: “force_pinned”Edge:
“toolbar_state”: “force_shown”
We also use a custom extension policy setting to store your IdpConnectUrl value, which will be used to sign in your users to Tango.
What happens after I deploy the script?
Force Install will distribute the extension to all of your end users. When the extension is first installed, Magic Login will attempt to sign users in. If the first attempt fails, it will retry 1 hour later, then 2 hours later, then 4 hours later, etc. exponentially backing off in delay. It will try up to 10 times, with a maximum delay of 512 hours. If a user was not originally logged into their IdP, these retries can help ensure they’re eventually signed in to Tango.
I don’t want to use the script. What registries need to be set for Windows devices to use Force Install and Magic Login?
Please choose the browser (Edge or Chrome) and ensure that the following registries are set for both Magic Login and Force Install to work properly. This is important to decide at the start as the directories for the specific browsers are different. You can enable Force Install and Magic Login for both browsers if needed.
For faster updates and bug fixes, we recommend using the Tango extension from the Chrome store, which works in Edge and Chrome. Alternatively, if you would like to install the Tango extension from the Edge store, use this “update_url”: "https://edge.microsoft.com/extensionwebstorebase/v1/crx"
Google Chrome
Force Install
HKLM:\SOFTWARE\Policies\Google\Chrome\Extensions\lggdbpblkekjjbobadliahffoaobaknh
“update_url”: “https://clients2.google.com/service/update2/crx”
“installation_mode”: “force_installed”
“toolbar_pin”: “force_pinned”
Magic Login
HKLM:\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\lggdbpblkekjjbobadliahffoaobaknh\policy
“IdpConnectUrl": YOUR_IDP_CONNECT_URL
Microsoft Edge
Force Install
HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionSettings\lggdbpblkekjjbobadliahffoaobaknh
“update_url”: “https://clients2.google.com/service/update2/crx”
“installation_mode”: “force_installed”
“toolbar_state”: “force_shown”
Magic Login
HKLM:\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\lggdbpblkekjjbobadliahffoaobaknh\policy
“IdpConnectUrl": YOUR_IDP_CONNECT_URL
