It’s confirmed that there is no way to force an extension to run in private browsing, even with enterprise policies. This is by design.
The only way to enforcing use of extension is to disable private browsing mode entirely through enterprise policies. That would force extensions to run in normal browsing mode.
Prevention of private browsing is a real drag, from an IT support perspective. I lost count of the number of times that I was frustrated by it. AFAICT we’re currently free from the constraint, hopefully it’ll not return.
I wonder whether the Impero server, or client-side extension, will be able to enforce prevention of private browsing …