Hi Ezreal,
By design, Application Guard isolates the browsing session, so extensions are blocked unless explicitly trusted and deployed through policy.
The supported way to configure this is via Intune Administrative Templates for Microsoft Edge. In Intune, you’ll find the policy setting called “Allow specific extensions to be installed”. Here you can list the extension IDs of the trusted add-ons your finance team depends on. Once applied, those extensions will be permitted to run inside the Application Guard environment while everything else remains blocked.
Best practice is to scope this policy only to the device groups that require the extensions, so you maintain strict isolation elsewhere. Also, make sure the extensions come from the Microsoft Edge Add-ons store, since Application Guard will only allow trusted sources.
I hope the response provided some helpful insight. If you find this answer useful, please hit “accept answer” so I know it addressed your concern.
Jason.