Skip to the article
Browser Rules Help
Help centre
Browser Rules help

Set up Browser Rules in Chrome and Edge, managed from the admin console.

The extension / Browser policy

Browser policy reference

Everything the extension takes from browser policy. All its other settings are made in the admin console.

SettingValuesDefaultWhat it does
enrolmentKeyYour organisation's keyNoneEnrols the browser in your admin console. See Enrol in the admin console.
userEmailAn email addressThe browser's signed-in accountNames the user for the admin console's user and group policies, when the browser isn't signed in with their work account. Set per user. See Name users.
defaultPolicies.dangerousFileTypestrue or falsetrueBefore enrolment, false switches that default policy off. See The default policies.
defaultPolicies.nestedZipstrue or falsetrue
defaultPolicies.maliciousCommandstrue or falsetrue
consoleServerAn https:// addressBuilt inFor testing only. Leave it unset.

Where browser policy goes

PlatformChromeEdge
Windows registryHKLM\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policyHKLM\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\bjhkclliijjffonmofmimpebcbigigem\policy
macOS profile payloadcom.google.Chrome.extensions.bjhkclliijjffonmofmimpebcbigigemcom.microsoft.Edge.extensions.bjhkclliijjffonmofmimpebcbigigem
Linux policy file"3rdparty": { "extensions": { "bjhkclliijjffonmofmimpebcbigigem": { ... } } } in the managed policy folder
Google AdminThe extension's Policy for extensions box, as JSON

On Windows, text values are REG_SZ, true or false is a REG_DWORD (1 or 0), and defaultPolicies is a subkey holding its values. For why it goes under HKLM, see Why machine-wide.

Which value wins

Browser policy comes first; an enrolment key typed on the extension's settings page is used only when policy doesn't set one. A value that isn't valid is ignored and its default applies; the settings page says what was wrong.

Settings from earlier versions (configuration, contentChecks, limits, zipFeatures, excludedWebsites, allowUserOverride, overrideMinutes) are no longer read. Set them in the admin console, and remove them from your device management.

Still stuck? We're happy to help.[email protected]