Description
Deploy the ConcealBrowse extension to Google Chrome on Windows 10+ endpoints seamlessly with Group Policy Objects (GPO).
Applies to
- Active Directory and Group Policy Objects (GPO)
- You need an administrator account capable of administering your active directory domain(s) and Group Policy.
-
Any edition of Windows 10 and 11 but not Windows Home
-
Google Chrome 101+
- ConcealBrowse Extension v0.7+
Pre-requisite: Google Chrome and ConcealBrowse administrative templates
Download ConcealBrowse ADMX files
- Download the ConcealBrowse.admx and .adml files attached to this article
- Note the download location of the files for the import step
Download Chrome ADMX files
- Navigate to the official Google’s ADMX templates and Google’s Updater ADM template here.
-
In the Manage Policies section for Policy templates, click the button labeled Download under the Chrome ADM/ADMX templates
- Locate policy_templates.zip and unzip/extract it
- Note the location of the extracted files for the import step
Import or Update the ADMX files
- Navigate to %LogonServer%\sysvol\<DomainName>\Policies\PolicyDefinitions where <DomainName> is your domain. Create the PolicyDefinitions folder if not present
- Ex: %LogonServer%\sysvol\conceal.io\Policies\PolicyDefinitions -
Copy google.admx, chrome.admx, and ConcealBrowse.admx:
- From: ..\policy_templates\windows\admx and Downloads
- To: %LogonServer%\sysvol\<DomainName>\Policies\PolicyDefinitions
-
Copy google.adml, chrome.adml, and ConcealBrowse.adml:
- From: ..\policy_templates\windows\admx\en-US and Downloads
- To: %LogonServer%\sysvol\<DomainName>\Policies\PolicyDefinitions\en-US
Procedure for Normal Installation (users can disable)
You may either edit an existing group policy which configures Google Chrome or create a new policy. These instructions assume the creation of a new policy.
- Open the Group Policy Management Console
- Expand the navigation tree until you see your domain
- Expand your domain
- Right click Group Policy Objects and click New
- Name the new policy, example “Computer - Google Chrome” and click OK
- Right Click the new policy and choose Edit
- Within the policy, navigate to Computer Configuration > Policies > Administrative Templates
- Using the Chrome Settings Guide below:
- Navigate to Google > Google Chrome > Extensions and set the "Extension management settings" and Recommended settings as desired
- Navigate to Conceal > ConcealBrowse Extension and set the Google Chrome, ConcealBrowse Company ID and Google Chrome, ConcealBrowse Site ID
- Apply the policy to a limited group of test devices, this is usually done with an Organizational Unit (OU) containing a few computers
- Right click the target OU and choose Link an Existing GPO
- Select the policy created above - Once testing is successful, apply the policy more generally across your organization.
Recommended Steps
Assuming your policy contains no User settings, it’s recommended to disable User settings to improve enterprise group policy performance:
- Right click the google chrome policy, choose properties, then the General tab
- Select Disable User Configuration Settings
Procedure for Enforced Installation (users cannot disable)
Use the Procedure for Normal Installation and within the "Extension management settings", edit the installation_mode from normal_installed to force_installed
Chrome Settings Guide
Required Setting
"Extension management settings"
- Path: Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Extensions\Extension management settings
- Toggle: Enabled
- Value:
-
{"jmdpihfpelphmllgmamebdbelmobjfpg": {"installation_mode": "normal_installed","toolbar_pin": "force_pinned","update_url": "https://clients2.google.com/service/update2/crx"}}
"Google Chrome, ConcealBrowse Company ID"
- Path: Computer Configuration\Policies\Administrative Templates\Conceal\ConcealBrowse Extension
- Toggle: Enabled
- Value: Your Company ID, Find your Company ID & Site ID: Register New Device > Step 4
-
Example: abcdefgh-ijklm-nopq-rstuvwxyz123
"Google Chrome, ConcealBrowse Site ID"
- Path: Computer Configuration\Policies\Administrative Templates\Conceal\ConcealBrowse Extension
- Toggle: Enabled
- Value: Your Site ID, Find your Company ID & Site ID: Register New Device > Step 4
-
Example: abcdefgh-ijklm-nopq-rstuvwxyz123
Recommended Settings
"Incognito mode availability"
- Conceal Recommends because extensions cannot be enforced for Incognito mode (STIG Medium)
- Path: Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Incognito mode availability
- Toggle: Enabled
- Value: Incognito mode disabled
"Enable guest mode in browser"
- Conceal Recommends because extensions cannot be enforced for Guest mode (STIG Medium)
- Path: Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable guest mode in browser
- Toggle: Disabled
References
Was this article helpful?
Articles in this section
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using Kaseya VSA and PowerShell
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using ConnectWise Command and PowerShell
- Deploy the ConcealBrowse extension to Chrome on most operating systems using Chrome Browser Cloud Management and Jumpcloud
- Deploy the ConcealBrowse extension to Chrome on most operating systems using Chrome Browser Cloud Management
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using NinjaOne/NinjaRMM and PowerShell
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using LogMeIn Central and PowerShell
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using JumpCloud and PowerShell
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using Syncro and PowerShell
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using PDQ Deploy and PowerShell
- Deploy the ConcealBrowse extension to Chrome, Edge, and Brave on Windows 10+ using Automox and the PowerShell Script