SOLVED

Mozilla FireFox Updates

Brass Contributor

I deployed Firefox as a Win32 App using Intune. While I was able to enable automatic update for Edge Chromium and Google Chrome for MEM managed Windows workstations using Administrative Templates in the Device Configuration profiles, I am unable to update Firefox. Replacing the updated MSI file just deploys the new Firefox only on the new devices.

 

How do I setup Firefox to update on the devices?

6 Replies

Hi @somaji

 

You can’t enable auto update using Intune- Administrative Template on Firefox. You need to use Win32 supersedence, otherwise you need to explore 3rd party like PatchMyPC. 

Hope this helps!

Moe

 

https://learn.microsoft.com/en-us/mem/intune/apps/apps-win32-supersedence


https://www.pagodait.com/deploy-win32-apps-with-microsoft-intune

 

This is a great. Thanks. This works if replacing an app, e.g replacing Mozilla Firefox v103 with v107. But, for the long haul, creating a supersedence for each update, would not do. Second, when a client Joins AzureAD, the client will get multiple Deployments of Firefox from OOBE, until the latest version is deployed?

Ideally, wouldn't we want the Firefox Win32 app deployed with the Auto-Update setting enabled in Firefox?
best response confirmed by somaji (Brass Contributor)
Solution
No it will get the latest one only for new joined devices, so it’s important to use supersedence.

It might be already enabled when you install FireFox, but you have to maintain this way for out of box tools. Some organizations tend to use PatchMyPC or Scappman, these 3rd party tools eliminate the long packaging process.

I use supersedence!
Moe

https://patchmypc.com/

https://www.scappman.com/

I'm in a similar situation. I don't have a Win32App for Firefox, but I deployed a device configuration profile for Firefox to apply the following configurations for both system and user on devices that have Firefox installed:
1. Background Updater - Enabled
2. Application Autoupdate - Enabled
I've tested this on 2 separate profiles, under Admin template and by importing ADMX files, per Mozilla's instructions. Intune says it succeeded but I'm still seeing vulnerabilities on our PCs through our Vulnerability Management tool. Firefox can definitely auto-update like other browsers and I have seen it worked on Apple devices through our other MDM tool with plist configurations.
Have you had any success with configuration that works with updating Firefox while stale or not in use. I have those two settings applied to a workstation of mine and it does not seem to update Firefox.
Does supersedence only work with apps I've deployed with Intune? For example, I want to upgrade older versions of Firefox with the latest version but I didn't deploy those older versions with Intune. Will supersedence still work in this scenario?
1 best response

Accepted Solutions
best response confirmed by somaji (Brass Contributor)
Solution
No it will get the latest one only for new joined devices, so it’s important to use supersedence.

It might be already enabled when you install FireFox, but you have to maintain this way for out of box tools. Some organizations tend to use PatchMyPC or Scappman, these 3rd party tools eliminate the long packaging process.

I use supersedence!
Moe

https://patchmypc.com/

https://www.scappman.com/

View solution in original post