The default policies
Three policies are built in. They protect people as soon as the extension is installed, and come after your own policies.
| Policy | Blocks | Browser policy name |
|---|---|---|
| Default: dangerous file types | Programs, scripts, packages and archives that can't be checked, downloaded directly or inside ZIPs. | dangerousFileTypes |
| Default: ZIPs inside ZIPs | Blocks a ZIP that contains another ZIP, even one renamed to hide it. Other archives inside a ZIP, such as .7z, are checked by download policies that inspect ZIPs, such as Default: dangerous file types. | nestedZips |
| Default: malicious commands | Websites putting command-like text on the clipboard for people to paste into Run or a terminal. | maliciousCommands |
Once enrolled
The admin console decides. Its policy lists end with the default policies, each with an on/off switch, and an Allow policy above one makes an exception to it (for a website or file type you trust). See How policies work.
Switching one off before enrolment
Until a browser is enrolled, the defaultPolicies browser policy can switch default policies off: set one to false. Leave out the ones you want on. Once the browser is enrolled, the admin console's switches apply instead.
A registry key holding a REG_DWORD for each one to switch off (0 is off). This example switches off ZIPs inside ZIPs, in both browsers:
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policy\defaultPolicies] "nestedZips"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policy\defaultPolicies] "nestedZips"=dword:00000000
In the configuration profile, a payload of type com.google.Chrome.extensions.bjhkclliijjffonmofmimpebcbigigem for Chrome and com.microsoft.Edge.extensions.bjhkclliijjffonmofmimpebcbigigem for Edge, each with:
<key>defaultPolicies</key> <dict> <key>nestedZips</key> <false/> </dict>
As root, in /etc/opt/chrome/policies/managed/ for Chrome and /etc/opt/microsoft/msedge/policies/managed/ for Edge:
{
"3rdparty": {
"extensions": {
"bjhkclliijjffonmofmimpebcbigigem": {
"defaultPolicies": {
"nestedZips": false
}
}
}
}
}In the Google Admin console, select the extension, then paste this into Policy for extensions:
{
"defaultPolicies": {
"Value": {
"nestedZips": false
}
}
}With both default download policies switched off, the extension leaves downloads to the browser: nothing is checked. Switch one off only for a reason, such as a tool your organisation downloads that it blocks.