Why machine-wide (HKLM)
Put Browser Rules' browser policy where only administrators can change it: machine-wide, under HKEY_LOCAL_MACHINE on Windows.
Machine and user policy
Chrome and Edge read extension policy from two places on Windows:
| Where | Applies to | Who can change it |
|---|---|---|
HKLM\SOFTWARE\Policies\... | Everyone who uses the computer | Administrators |
HKCU\SOFTWARE\Policies\... | One person, in their own profile | Administrators, and Group Policy for that user. People can read their own Policies key but not change it. |
So both are out of a standard user's reach. The difference is coverage and precedence:
- HKLM covers everyone. A new person signing in to the computer is protected straight away, with no per-user policy to arrive first.
- The machine value wins. When both set the same setting, HKLM is used, so nothing in a user's profile can loosen it.
- One place to manage and check. Settings that protect everyone are set once per computer, not once per person.
What goes where
- HKLM: installing the extension (
ExtensionInstallForcelist), itsenrolmentKey, anddefaultPoliciesif you use it. - HKCU: only
userEmail, which names each person for the admin console and so differs per user.
Browser policy also beats anything set in the browser itself: an enrolment key set by policy can't be changed or removed from the extension's settings page, so people can't disconnect it.
Check it applied machine-wide
On chrome://policy or edge://policy, Browser Rules' values should show Machine as their scope and Platform as their source.
Anyone with administrator rights on a computer can change machine policy, or anything else. Browser Rules works best where people use standard accounts.
macOS profiles installed as System scope, and Linux files under /etc/opt, are machine-wide in the same way.