how to deploy chrome extensions to managed devices via intune
Deploys Chrome extensions to managed devices via Intune: the ExtensionInstallForcelist policy and targeting. Use when standardizing extensions across the fleet. Not for unmanaged Chrome installs.
TL;DR
Pushing Chrome extensions through Intune means setting the ExtensionInstallForcelist policy in a Chrome configuration profile, targeted at the right device groups. Users get the extensions automatically with no manual installs, and you can block everything else.
The query
how to deploy chrome extensions to managed devices via intuneUse this when
- forcing a security extension onto all managed browsers
- standardizing developer tooling extensions
- blocking unapproved extensions fleet-wide
Not for
- unmanaged personal Chrome installs
- extensions outside the Chrome Web Store without a custom policy
- Firefox or Edge extension management (different policies)
Steps
- Collect the extension IDs from the Chrome Web Store URLs of each extension. Expected output: a list of extension IDs
- In Intune, create a Settings Catalog or Administrative Templates profile for Chrome. Expected output: a Chrome policy profile created
- Set ExtensionInstallForcelist with each ID plus the update URL. Expected output: the policy lists every required extension
- Optionally set ExtensionInstallBlocklist to star to block everything not explicitly allowed. Expected output: unapproved extensions blocked
- Assign the profile to a pilot group and confirm the extensions appear in Chrome. Expected output: extensions auto-installed on pilots
- Roll out broadly and verify in Intune reporting. Expected output: fleet-wide compliance shown
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_5dajUxbbJWVOM048qyGjGw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.