Skip to content
Articles
Extensions

How to allow only approved extensions in Chrome and Edge with Intune

A browser extension can read and change every page a user opens. How to block all but the extensions you approve in Chrome and Edge, using Intune, without breaking work.

Browser extensions are some of the most powerful software on a work computer. One with broad permissions can read and change every page a user opens, including email, documents and admin portals, and can send what it sees anywhere.

Most are harmless, but the risk is real. In December 2024, attackers phished a Cyberhaven employee, took over the company’s Chrome Web Store account, and published a malicious update of its extension. The update stole cookies and session tokens. The same campaign hit more than 30 other extensions with over 2.6 million users (RH-ISAC).

If users can install any extension they like, you can’t know which ones have that kind of access. The fix is to block extensions by default, allow the ones you’ve approved, and install the essential ones for everyone.

Before you start

  • Find out what’s installed. Blocking everything disables extensions people already use, so start with a list. Chrome Enterprise Core, which is free, can report the extensions installed in managed Chrome browsers. Microsoft Defender Vulnerability Management can list browser extensions across your devices.
  • Decide what to approve. Agree the list with the people who rely on each extension. For each one, check who publishes it, what permissions it asks for, and how recently it was updated. Fewer is better.
  • Get the extension IDs. Every extension has a 32-letter ID, shown at the end of its address in the Chrome Web Store or Edge Add-ons, and on the browser’s extensions page with developer mode on.

The policies to set

Chrome and Edge use the same policies, with different names in Intune.

What it doesChrome settingEdge settingValue
Blocks every extension not allowedConfigure extension installation blocklistControl which extensions cannot be installed*
Allows your approved extensionsConfigure extension installation allow listAllow specific extensions to be installedThe approved IDs
Installs the essential ones for everyoneConfigure the list of force-installed apps and extensionsControl which extensions are installed silentlyID;update address
Stops users loading their own extensionsControl the availability of developer mode on extensions pageControl the availability of developer mode on extensions pageDo not allow
Blocks extensions installed by other softwareBlocks external extensions from being installedBlocks external extensions from being installedEnabled

A few things to know:

  • A blocklist of * disables extensions already installed, not just new ones. Users can’t turn them back on. If an extension is added to the allow list later, it comes back on by itself.
  • Force-installed extensions can’t be removed or turned off by users. Each entry is the extension’s ID, a semicolon, then where it updates from: https://clients2.google.com/service/update2/crx for the Chrome Web Store, or https://edge.microsoft.com/extensionwebstorebase/v1/crx for Edge Add-ons. Edge can force-install from the Chrome Web Store too.
  • Developer mode is how users load unpacked extensions from their own files. Turning it off closes that route. This setting needs Chrome or Edge 128 or later.

Setting it up in Intune

  1. In the Intune admin center, create a configuration profile for Windows 10 and later, with the profile type Settings catalog.
  2. Add the settings from the table, searching for each by name. The Chrome and Edge settings are listed separately, so add both if your organisation uses both browsers.
  3. Fill in the values, then assign the profile to a pilot group of devices first.
  4. On a pilot device, open chrome://policy or edge://policy to check the settings have arrived. Then open the extensions page: blocked extensions are turned off and can’t be turned back on.

On a Mac, Intune applies the same policy names through a configuration profile.

Finer control with the extension management setting

Chrome’s “Extension management settings” and Edge’s “Configure extension management settings” take all of this as one block of JSON, with a few extra controls:

  • blocked_install_message adds your own text when someone tries to install a blocked extension, such as how to request one.
  • runtime_blocked_hosts keeps extensions away from chosen websites, such as your admin portals, even if they’re allowed.
  • blocked_permissions blocks any extension that asks for a permission you don’t allow.
  • minimum_version_required turns off versions of an extension older than the one you name, which helps when a bad version is released.

For example, block everything with a message, allow one extension and force-install another:

{"*":{"installation_mode":"blocked","blocked_install_message":"Extensions need IT approval. Ask at [email protected]."},"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa":{"installation_mode":"allowed"},"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb":{"installation_mode":"force_installed","update_url":"https://clients2.google.com/service/update2/crx"}}

This setting overrides the separate blocklist, allow list and force-install settings, so use one approach or the other, not both.

Rolling it out without disruption

  • Tell people first. Blocking disables extensions overnight, so say what’s changing, why, and how to ask for one.
  • Give people a way to ask. A short form or an email address works. Chrome Enterprise Core also lets users request an extension from inside Chrome, for you to approve.
  • Review the list. Remove extensions nobody uses, and recheck the permissions of the ones you keep.

What these policies don’t cover

  • Approved extensions can still go bad. The Cyberhaven extension was legitimate until its update. Keep the list short, and use runtime_blocked_hosts to keep extensions away from your most sensitive websites.
  • Other browsers. If staff can install Firefox, Brave or another browser, they can install extensions there. Manage those browsers too, or block them with application control.
  • Unmanaged devices. These policies only apply to devices enrolled in Intune.

Where Browser Rules fits

Browser Rules is itself an extension, deployed the same way: force-installed by Intune, with its enrolment key set by policy (see Install for your organisation). It doesn’t manage other extensions; the policies above do that. What it adds is protection inside the browser that extension policies can’t give, against dangerous downloads, malicious websites and clipboard attacks.