Deploy the ConcealBrowse extension to Chrome on Windows 10+ using Intune Deploy the ConcealBrowse extension to Chrome on Windows 10+ using Intune

Deploy the ConcealBrowse extension to Chrome on Windows 10+ using Intune

Description

Deploy the ConcealBrowse extension to Google Chrome on Windows 10+ endpoints seamlessly with Microsoft Intune.

Applies to

  • Microsoft Intune
    • You must have an administrator account for Intune to use this guide
  • Any edition of Windows 10 and 11 but not Windows Home
  • Google Chrome version 101 or later

Pre-requisite: Windows, Google Chrome, and ConcealBrowseChrome administrative templates

Check if the ADMX templates have been imported

  1. In your web browser, log in to the Microsoft Endpoint Manager admin center
  2. On the left, click Devices. Then under the Policy section click Configuration Profiles
  3. While in Configuration Profiles, click the tab labeled Import ADMX
  4. Verify that Windows.admx, google.admx, chrome.admx, and ConcealBrowseChrome.admx appear and have a status of Available
    1. If they are all available, you may skip to either Procedure for Normal Installation (users can disable) or Procedure for Enforced Installation (users cannot disable)
    2. If they are not available, continue to the next step below.

Download ConcealBrowse ADMX files

  1. Download the ConcealBrowse.admx and .adml files attached to this article
  2. Note the download location of the files for the import step

Download Windows ADMX files

  1. Navigate to the official Microsoft ADMX templates for Windows 10+ here
  2. Download and run the MSI file which extracts the ADMX files
  3. Note the location of the extracted files for the import step

Download Chrome ADMX files

  1. Navigate to the official Google’s ADMX templates and Google’s Updater ADM template here.
  2. In the Manage Policies section for Policy templates, click the button labeled Download under the Chrome ADM/ADMX templates
    ADM_Download.png

  3. Locate policy_templates.zip and unzip/extract it
  4. Note the location of the extracted files for the import step

Import the ADMX templates

  1. In your web browser navigate to the Microsoft Endpoint Manager admin center.
  2. On the left click Devices. Then under the Policy section click Configuration Profiles
    Config_Profiles_2.png
  3. While in Configuration Profiles, click the tab labeled Import ADMX
  4. NOTE: You must upload the windows.admx and windows.adml files before chrome.admx. If not, the error message "ADMX file referenced not found NamespaceMissing:Microsoft.Policies.Windows. Please upload it first." is displayed.
  5. NOTE: You must upload the google.admx and google.adml files before chrome.admx. If not, the error message "ADMX file referenced not found NamespaceMissing:Google.Policies. Please upload it first." is displayed.
  6. To import the Windows.admx and Windows.adml files:
    1. Click Import
    2. Select the ADMX file found at .../Windows.admx

    3. Select the ADML file found at .../en-US/Windows.adml

    4. Click Next

    5. Click Create

  7. To import the google.admx and google.adml files:
    1. Click Import
    2. Select the ADMX file found at .../policy_templates/windows/admx/google.admx
    3. Select the ADML file found at .../policy_templates/windows/admx/en-US/google.adml
    4. Click Next
    5. Click Create
  8. To import the chrome.admx and chrome.adml files:

    1. Click Import

    2. Select the ADMX file found at .../policy_templates/windows/admx/chrome.admx

    3. Select the ADML file found at .../policy_templates/windows/admx/en-US/chrome.adml

    4. Click Next

    5. Click Create

  9. To import the ConcealBrowse.admx and ConcealBrowse.adml files:
    1. Click Import
    2. Select the ADMX file found at .../ConcealBrowse.admx
    3. Select the ADML file found at .../ConcealBrowse.adml
    4. Click Next
    5. Click Create
  10. Verify the ADMX templates have successfully loaded by refreshing the Import ADMX list and verifying the Status is Available for all templates.

Procedure for Normal Installation (users can disable)

  1. In the Microsoft Endpoint Manager admin center, click Devices > Windows > Configuration profiles

  2. Click Create Profile
  3. In Platforms, select Windows 10 and later
  4. In Profile type, select Templates
  5. Click Imported Administrative templates (Preview)
  6. Click Create
  7. Enter a configuration name, such as Google Chrome - ConcealBrowse
  8. Click Next
  9. Configure the policy based on the Chrome Settings Guide below
  10. Select any applicable Scope Tags
  11. Click Next
  12. Select any applicable Included groups and Excluded groups, and respective Filters. We recommend starting with a small test group to verify the settings work as intended

  13. Click Next
  14. Click Create

Procedure for Enforced Installation (users cannot disable)

Use the Procedure for Normal Installation and within the "Extension management settings", edit the installation_mode from normal_installed to force_installed

Chrome Settings Guide

Required Settings

"Extension management settings"

  • Path: Computer Configuration\Google\Google Chrome\Extensions\Extension management settings
  • Toggle: Enabled
  • Value:
  • { "jmdpihfpelphmllgmamebdbelmobjfpg": { "installation_mode": "normal_installed", "toolbar_pin": "force_pinned", "update_url": "https://clients2.google.com/service/update2/crx" }}

"Google Chrome, ConcealBrowse Company ID"

"Google Chrome, ConcealBrowse Site ID"

Recommended Settings

"Incognito mode availability"

  • Conceal Recommends because extensions cannot be enforced for Incognito mode (STIG Medium)
  • Path: Computer Configuration\Google\Google Chrome\Incognito mode availability
  • Toggle: Enabled
  • Value: Incognito mode disabled

"Enable guest mode in browser"

  • Conceal Recommends because extensions cannot be enforced for Guest mode (STIG Medium)
  • Path: Computer Configuration\Google\Google Chrome\Enable guest mode in browser
  • Toggle: Disabled

References

Was this article helpful?

0 out of 0 found this helpful