Skip to the article
Browser Rules Help
Help centre
Browser Rules help

Set up Browser Rules in Chrome and Edge, managed from the admin console.

The extension / Browser policy

Why machine-wide (HKLM)

Put Browser Rules' browser policy where only administrators can change it: machine-wide, under HKEY_LOCAL_MACHINE on Windows.

Machine and user policy

Chrome and Edge read extension policy from two places on Windows:

WhereApplies toWho can change it
HKLM\SOFTWARE\Policies\...Everyone who uses the computerAdministrators
HKCU\SOFTWARE\Policies\...One person, in their own profileAdministrators, and Group Policy for that user. People can read their own Policies key but not change it.

So both are out of a standard user's reach. The difference is coverage and precedence:

  • HKLM covers everyone. A new person signing in to the computer is protected straight away, with no per-user policy to arrive first.
  • The machine value wins. When both set the same setting, HKLM is used, so nothing in a user's profile can loosen it.
  • One place to manage and check. Settings that protect everyone are set once per computer, not once per person.

What goes where

  • HKLM: installing the extension (ExtensionInstallForcelist), its enrolmentKey, and defaultPolicies if you use it.
  • HKCU: only userEmail, which names each person for the admin console and so differs per user.

Browser policy also beats anything set in the browser itself: an enrolment key set by policy can't be changed or removed from the extension's settings page, so people can't disconnect it.

Check it applied machine-wide

On chrome://policy or edge://policy, Browser Rules' values should show Machine as their scope and Platform as their source.

Anyone with administrator rights on a computer can change machine policy, or anything else. Browser Rules works best where people use standard accounts.

macOS profiles installed as System scope, and Linux files under /etc/opt, are machine-wide in the same way.

Still stuck? We're happy to help.[email protected]