Skip to the article
Browser Rules Help
Help centre
Browser Rules help

Set up Browser Rules in Chrome and Edge, managed from the admin console.

Using the admin console / Getting started

Name devices on the Browsers page

Optional: give each browser its computer's name with the deviceName policy, so the Browsers page matches your device list.

You don't need it. Without it, the Browsers page shows each browser, its system and its user, as before. With it, you can find a browser by the name your device management already uses.

  • Where it shows: the Device column on the Browsers page, which you can search and sort, each user's browsers on the Users page, and the audit log, beside the browser.
  • Only a label: Browser Rules never uses it to recognise a device. Names can repeat and change.
  • Up to 100 characters. Change it, and the console shows the new name at the browser's next check-in. Remove it, and the name goes too.
  • Needs version 0.4.0 of the extension.

Each computer has its own name, so set it with something that knows the name on each one.

Group Policy (Windows)

Group Policy Preferences fill in %ComputerName% on each computer. Add two registry items under Computer Configuration, Preferences, Windows Settings, Registry, with the action Update:

FieldChromeEdge
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Policies\Google\Chrome\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policySOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policy
Value namedeviceName
Value typeREG_SZ
Value data%ComputerName%

Intune and scripts (Windows)

The Intune settings catalog sets the same value on every computer, so use a script. Add these lines to the enrolment script, or run them on their own the same way (as SYSTEM, in 64-bit PowerShell). Intune runs a platform script once, so a computer renamed later keeps its old name until it runs again. A remediation script on a schedule keeps names current.

browser-rules-device-name.ps1
# Browser Rules: name this device on the console's Browsers page (optional).
$id = "bjhkclliijjffonmofmimpebcbigigem"

foreach ($browser in @("Google\Chrome", "Microsoft\Edge")) {
  $policy = "HKLM:\SOFTWARE\Policies\$browser\3rdparty\extensions\$id\policy"
  New-Item -Path $policy -Force | Out-Null
  New-ItemProperty -Path $policy -Name "deviceName" -Value $env:COMPUTERNAME -PropertyType String -Force | Out-Null
}

macOS

Add deviceName beside enrolmentKey in the configuration profile, both for Chrome and for Edge, using your device management's variable for the computer's name. In Jamf Pro that's $COMPUTERNAME:

Add to each extension payload
<key>deviceName</key>
<string>$COMPUTERNAME</string>

Other tools have their own profile variables; their documentation lists them.

Linux

Write the policy file on each computer with its host name, for example from your provisioning script:

browser-rules-policy.sh
#!/bin/sh
# Browser Rules: install the extension, enrol it and name this device. Run as root.
name=$(hostname)
for dir in /etc/opt/chrome/policies/managed /etc/opt/microsoft/msedge/policies/managed; do
  mkdir -p "$dir"
  cat > "$dir/browser-rules.json" <<EOF
{
  "ExtensionInstallForcelist": [
    "bjhkclliijjffonmofmimpebcbigigem;https://clients2.google.com/service/update2/crx"
  ],
  "3rdparty": {
    "extensions": {
      "bjhkclliijjffonmofmimpebcbigigem": {
        "enrolmentKey": "BR-ABCDE-FGHJK-LMNPQ-RSTUV",
        "deviceName": "$name"
      }
    }
  }
}
EOF
done

Google Admin

Google Admin sets one value for every browser in an organisational unit, so it can't name devices one by one. Its own list of managed browsers already shows each computer's name.

Still stuck? We're happy to help.[email protected]