Browser policy reference
Everything the extension takes from browser policy. All its other settings are made in the admin console.
| Setting | Values | Default | What it does |
|---|---|---|---|
enrolmentKey | Your organisation's key | None | Enrols the browser in your admin console. See Enrol in the admin console. |
userEmail | An email address | The browser's signed-in account | Names the user for the admin console's user and group policies, when the browser isn't signed in with their work account. Set per user. See Name users. |
defaultPolicies.dangerousFileTypes | true or false | true | Before enrolment, false switches that default policy off. See The default policies. |
defaultPolicies.nestedZips | true or false | true | |
defaultPolicies.maliciousCommands | true or false | true | |
consoleServer | An https:// address | Built in | For testing only. Leave it unset. |
Where browser policy goes
| Platform | Chrome | Edge |
|---|---|---|
| Windows registry | HKLM\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policy | HKLM\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policy |
| macOS profile payload | com.google.Chrome.extensions.bjhkclliijjffonmofmimpebcbigigem | com.microsoft.Edge.extensions.bjhkclliijjffonmofmimpebcbigigem |
| Linux policy file | "3rdparty": { "extensions": { "bjhkclliijjffonmofmimpebcbigigem": { ... } } } in the managed policy folder | |
| Google Admin | The extension's Policy for extensions box, as JSON | |
On Windows, text values are REG_SZ, true or false is a REG_DWORD (1 or 0), and defaultPolicies is a subkey holding its values. For why it goes under HKLM, see Why machine-wide.
Which value wins
Browser policy comes first; an enrolment key typed on the extension's settings page is used only when policy doesn't set one. A value that isn't valid is ignored and its default applies; the settings page says what was wrong.
Settings from earlier versions (configuration, contentChecks, limits, zipFeatures, excludedWebsites, allowUserOverride, overrideMinutes) are no longer read. Set them in the admin console, and remove them from your device management.