# Privacy Policy The `linux-entra-sso` browser extension does not collect any data of any kind. - `linux-entra-sso` has no home server - `linux-entra-sso` doesn't embed any analytic or telemetry hooks in its code To fulfill its purpose, the extension interfaces with the following services: - Microsoft Graph API (web service) - Microsoft Entra ID (web service) - `com.microsoft.identity.broker1` (`broker`, DBus service) ## Microsoft Graph API To show data about the currently logged in user (e.g. the profile picture in the app icon) and the device (display name and compliance state), we request an access token for the `graph.microsoft.com` API. The token is acquired from the locally running broker. Both queries can be disabled independently via the `loadProfilePicture` and `checkDeviceCompliance` managed settings, see [Global Install](docs/global_install.md). If `loadProfilePicture` is disabled, the avatar is neither fetched nor displayed next to the user name or as the extension icon. If `checkDeviceCompliance` is disabled, the device name and its compliance state are no longer displayed. If both settings are disabled, no access token is requested from the broker and the Graph API is not contacted at all. ## Microsoft Identity Broker DBus service (broker) To implement the SSO functionality, a `PRT SSO Cookie` is requested from the locally running `com.microsoft.identity.broker1` DBus service. In the Firefox version, whenever an URL starting with `https://login.microsoftonline.com/` (Entra ID login URL) is accessed, a token is requested with the full request URL. On Chrome and Chromium, the `PRT SSO Cookie` is requested periodically with a generic URL. The returned token is injected into all http requests hitting the Entra ID login URL. ### Note on required and optional permissions We use the `WebRequest` (Firefox) or `declarativeNetRequest` (Chrome) API to inject the `PRT SSO Cookie` into requests targeting the login provider. To support this, we need the permission to access your data on `https://login.microsoftonline.com/`. This permission is (usually) requested at extension install time (required permission). For single-page applications (SPAs, like the Teams PWA) that perform automated token refreshes in the background, we further need the permission to access your data on the corresponding domains. To minimize the number of permissions we request, we provide users with the ability to grant these permissions on a case-by-case basis via the extension's UI or policy settings. Granted permissions can also be revoked through the same interface. On Firefox, SSO can be enabled per tab container, so that different containers can use different accounts or no account at all. Telling containers apart requires two further required permissions: `cookies` exposes the cookie store ID of a tab and of an outgoing request, and `contextualIdentities` resolves that ID to the container name and color shown in the extension's UI. We neither read nor modify any cookies, and we do not enumerate or change your containers. ## Privacy statement for Microsoft services The privacy statement for all Microsoft provided services is found on .