In this text we’ll get acquainted with the Chrome Group Policy administrative templates (admx), supplied by Google, that permit you to centrally handle browser settings in an Active Directory area. Chrome`s ADMX GPO templates drastically simplifies the deployment and configuring of this browser in a company community. Also, we are going to present a number of typical duties of managing Google Chrome settings utilizing GPO and putting in browser extensions.
Installing GPO ADMX Templates for Google Chrome
In order to handle Chrome settings by Group Policies, it’s essential to obtain and set up a particular set of administrative GPO templates
- Download and extract an archive with ADM/ADMX templates of Group Policies for Google Chrome ( http://dl.google.com/dl/edgedl/chrome/coverage/policy_templates.zip — the file dimension is about 13 MB);
- There are three directories within the policy_templates:
- chromeos (administrative templates for Chromium);
- widespread (comprises html information with a full description of all Chrome coverage settings – see chrome_policy_list.html file);
- home windows – comprises Chrome coverage templates in two codecs: ADM and ADMX (admx is a more moderen administrative coverage format, supported ranging from Windows Vista / Windows Server 2008 and newer);
- Copy the Chrome administrative template information to the
C:WindowsPolicyDefinitionslisting (native administrative GPO templates are saved on this listing). In order for the Chrome Group Policy settings to be localized, you want to copy the corresponding ADML template information (folders en-US, de-De, and many others…).
Note. If you need to use Chrome insurance policies within the Active Directory area, you want to copy the ADMX and ADML information to a particular GPO listing (not the most suitable choice) or to PolicyDefinitions folder in SYSVOL on the area controller.
- Suppose, we’re going to use the ADMX format of the GPO template and area Central Policy Store. Copy the chrome.admx file and localization directories to the woshub.locSYSVOLwoshub.locPoliciesPolicyDefinitionsPolicyDefinitions;
- Open the area Group Policy Management Console (gpmc.msc) and edit any present GPO(or create a brand new one). Make certain new Google folder containing two subsections (Google Chrome and Google Chrome – Default Settings (customers can override)) appeared each in User and Computer sections of Policies -> Administrative Templates;
These administrative templates include about 300+ completely different Google Chrome settings which you could handle. You can discover them your self and configure the browser settings which can be wanted in your atmosphere.
After you might have put in the executive group coverage templates for the Google Chrome browser, you possibly can proceed to configure Chrome settings on customers’ computer systems.
Configuring Typical Google Chrome Settings by way of GPO
Please notice that Google Chrome settings are saved in two sections of Group Policy (each in Computer and User Configuration):
- Google Chrome – customers (and even the native administrator) can not change the Chrome settings on their pc specified on this GPO part ;
- Google Chrome – Default Settings (customers can override) – advisable browser settings that customers can change.
Let’s think about the essential Chrome settings which can be typically centrally configured in an enterprise atmosphere:
- Set Goggle Chrome as Default Browser: Enabled;
- Set disk cache listing – path to the Chrome disk cache (as a rule it’s “$GoogleChromeUser Data”);
- Set disk cache dimension – disk cache dimension (in bytes);
- Set Google Chrome Frame person knowledge listing – Chrome listing with person settings “$GoogleChromeUser Data”;
- Managed Bookmarks;
- Disable Chrome auto-update: Allow Installation: Disable, Update Policy Override: Enable and within the Policy area specify Updates Disable;
- Add sure websites to trusted websites listing – Policies HTTP Authentication -> Authentication server whitelist;
- Allow for a particular websites. Add a listing of server and website addresses to the coverage settings HTTP Authentication -> Kerberos Delegation Server Whitelist and Authentication Server Whitelist;
- Send nameless utilization statistics and crash data: False;
- Use a short lived Chrome profile (knowledge is deleted after the person session ends). Ephemeral profile -> Enabled;
- Block entry to a listing of URLs: add a listing of internet sites to be blocked;
- Change the situation of the obtain folder: Set obtain listing: c:tempdownloads.
Note that the $ listing corresponds to the folder %usernamepercentAppDataNative, and $ – to %usernamepercentAppDataRoaming.
Configuring Proxy Server and Home Page with Chrome GPO
Let’s configure a proxy server in Chrome. We have an interest within the following coverage part: Google Chrome -> Proxy Server.
- proxy server tackle: ProxyServer – 192.168.123.123:3128
- an exception listing for proxy: ProxyBypassList – http://www.woshub.native,192.168.*, *.corp.woshub.native
Set a house web page: Google Chrome -> Startup, Home web page and New Tab page-> Configure the house web page URL: http://woshub.com/
It stays to hyperlink the coverage to the specified container (OU) of Active Directory. Apply the group coverage on a consumer by working the command:
Launch Chrome on the consumer and be sure that the settings specified within the GPO are utilized (within the instance on the screenshot, the person can not change the values assigned by the administrator – “This settings is enforced by your administrator”).
You can troubleshoot group coverage project on a desktop pc utilizing .[/ alert]
And on the settings web page, “Your browser is managed by your group” is displayed.
To show all Google Chrome settings which can be set by the GPO, go to the Chrome://coverage tackle (right here the parameters specified by the registry or admx GPO template information are displayed).
Deploying Google Chrome Extensions Using Group Policy
You can use ADMX templates to set up sure Google Chrome extensions for all area customers. For instance, you need to mechanically set up the AdvertBlock extension on all computer systems. Open the chrome://extensions settings web page and set up the extension you want in your pc.
Now you want to get the extension ID and the URL from which the extension is up to date. The Google Chrome Extension ID might be discovered within the extension properties (Developer mode have to be enabled).
By ID, you want to discover the extension folder within the person profile C:Users%Username%AppDataNative GoogleChromeUser DataDefaultExtensions.
In the extension folder discover and open the manifest.json file and duplicate the worth of the update_url. Most doubtless, you will note the next URL:
Now, within the GPO editor console, go to the Computer Configuration -> Policies -> Administrative Templates -> Google -> Google Chrome -> Extensions. Enable the coverage Configure the listing of force-installed extensions.
Click the Show button and add a line for every extension that you really want to set up. Use the next format:
After making use of to the person’s computer systems, all specified Chrome extensions shall be put in in silent mode with out interplay with the person.