Install for your organisation
Install the extension on every computer with your device management, so it can't be removed.
Two things are the same everywhere:
| Extension ID | bjhkclliijjffonmofmimpebcbigigem |
| Update URL | https://clients2.google.com/service/update2/crx |
Edge uses the Chrome Web Store ID and update URL too. On Windows computers that aren't joined to a domain or managed by device management, Chrome only force-installs extensions from the Chrome Web Store, which is where Browser Rules comes from, so this works on them too.
Choose how you manage your computers:
- In a Group Policy Object, go to Computer Configuration, Preferences, Windows Settings, Registry.
- Add the values below (or import them as a
.regfile). Leave out the Edge keys if you only use Chrome, or the other way round. - Link the object to the computers to protect. Browsers install the extension at the next policy refresh.
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist] "1"="bjhkclliijjffonmofmimpebcbigigem;https://clients2.google.com/service/update2/crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist] "1"="bjhkclliijjffonmofmimpebcbigigem;https://clients2.google.com/service/update2/crx"
If you already force-install other extensions, use the next free number instead of "1", or you'll replace one of them.
- In Intune, go to Devices, Scripts and remediations, Platform scripts and add the script below.
- Set it to run as the system account, not the signed-in user.
- Assign it to your device groups. Browsers install the extension at their next restart.
$id = "bjhkclliijjffonmofmimpebcbigigem"
foreach ($browser in @("Google\Chrome", "Microsoft\Edge")) {
# Add it to the force-installed list, in the next free entry.
$list = "HKLM:\SOFTWARE\Policies\$browser\ExtensionInstallForcelist"
New-Item -Path $list -Force | Out-Null
$entries = (Get-Item $list).Property
if (-not ($entries | Where-Object { (Get-ItemPropertyValue $list $_) -like "$id*" })) {
$next = 1; while ($entries -contains "$next") { $next++ }
Set-ItemProperty -Path $list -Name "$next" -Value "$id;https://clients2.google.com/service/update2/crx"
}
}Deploy a configuration profile with your device management (Jamf, Kandji, Intune for Mac). It needs a payload for each browser:
| Browser | Payload type |
|---|---|
| Chrome | com.google.Chrome |
| Edge | com.microsoft.Edge |
<key>ExtensionInstallForcelist</key> <array> <string>bjhkclliijjffonmofmimpebcbigigem;https://clients2.google.com/service/update2/crx</string> </array>
As root, save this file in /etc/opt/chrome/policies/managed/ for Chrome and /etc/opt/microsoft/msedge/policies/managed/ for Edge, then restart the browser.
{
"ExtensionInstallForcelist": [
"bjhkclliijjffonmofmimpebcbigigem;https://clients2.google.com/service/update2/crx"
]
}- In the Google Admin console, open Devices, Chrome, Apps and extensions, Users and browsers.
- Choose the organisational unit, then add the extension from the Chrome Web Store by ID.
- Set its installation policy to Force install (or Force install + pin to browser toolbar).
This covers Chrome where people are signed in to managed accounts, or browsers enrolled in Chrome Enterprise Core.
Pin it to the toolbar (optional)
The toolbar button explains the latest download, and is where people answer a warning for a download started from the address bar. To pin it for everyone, use the browsers' ExtensionSettings policy: "toolbar_pin": "force_pinned" for Chrome, "toolbar_state": "force_shown" for Edge.
Next
The default policies already apply. To set your own, enrol the browsers in the admin console: its enrolment guide makes a file for your device management that installs the extension and enrols it in one go. For why it all goes under HKLM, see Why machine-wide.