Enterprise Chrome Extension Management for IT Teams
Patrick Bushe
January 3, 2025 · 5 min read
Extensions can read the pages your staff use, including email, CRMs and admin tools, so unmanaged extensions are a real security risk. Chrome gives IT teams detailed control through policies, managed from Google's Admin console or your existing device management tools.
Where to manage it
- Google Admin console: Chrome Enterprise Core (formerly Chrome Browser Cloud Management) manages Chrome on Windows, Mac and Linux, and ChromeOS devices, from the cloud. It also shows which extensions are installed across the fleet.
- Group Policy and Intune: on Windows, use Chrome's policy templates. On Mac, use configuration profiles from your device management tool.
The key policies
- Block by default, allow by exception: block all extensions with
ExtensionInstallBlocklistset to*, then list approved ones inExtensionInstallAllowlist. - Force-install:
ExtensionInstallForcelistinstalls required extensions, such as your password manager, and stops users removing them. - Fine-grained control:
ExtensionSettingssets rules per extension or for all: blocked permissions, install mode, andruntime_blocked_hoststo keep extensions off sensitive sites like your HR or finance systems. - Extension requests: users can request a blocked extension, and admins approve or deny it in the Admin console.
Roll it out without chaos
- Inventory first. Use the Admin console's extension report to see what's installed and how widely.
- Approve the common, safe ones before you turn on blocking, so day one isn't a flood of tickets.
- Block risky permissions rather than only specific extensions, for example access to all sites, where it isn't needed.
- Announce the change and explain how to request an extension.
- Review regularly. Extensions change owners and get compromised. See how to check if an extension was compromised.
What to check before approving
- Who publishes it, and whether it's actively maintained.
- The permissions it asks for, compared with what it actually needs to do.
- Its privacy policy and whether it sends page data to its own servers.
- Whether a built-in Chrome feature already does the job.
Extensions that work entirely in the browser, with no outside servers, are easier to approve. See what each permission means.
Custom internal extensions
Many companies build small private extensions for internal tools, published privately to their own domain or force-installed by policy. See Chrome extension development.