## TL;DR
Pushing Chrome extensions through Intune means setting the ExtensionInstallForcelist policy in a Chrome configuration profile, targeted at the right device groups. Users get the extensions automatically with no manual installs, and you can block everything else.

## The query
```text
how to deploy chrome extensions to managed devices via intune
```

## Use this when
- forcing a security extension onto all managed browsers
- standardizing developer tooling extensions
- blocking unapproved extensions fleet-wide

## Not for
- unmanaged personal Chrome installs
- extensions outside the Chrome Web Store without a custom policy
- Firefox or Edge extension management (different policies)

## Steps
1. Collect the extension IDs from the Chrome Web Store URLs of each extension. Expected output: a list of extension IDs
2. In Intune, create a Settings Catalog or Administrative Templates profile for Chrome. Expected output: a Chrome policy profile created
3. Set ExtensionInstallForcelist with each ID plus the update URL. Expected output: the policy lists every required extension
4. Optionally set ExtensionInstallBlocklist to star to block everything not explicitly allowed. Expected output: unapproved extensions blocked
5. Assign the profile to a pilot group and confirm the extensions appear in Chrome. Expected output: extensions auto-installed on pilots
6. Roll out broadly and verify in Intune reporting. Expected output: fleet-wide compliance shown

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_5dajUxbbJWVOM048qyGjGw
