Skip to main content

โš™๏ธ๐ŸชŸ๐Ÿ’ปCP - Google Chrome - Forced Extensions

The extensions that show up whether users asked for them or not. Silently installed, always on, and not removable from the puzzle-piece menu.

โš™๏ธType Configuration profile๐ŸชŸPlatform Windows๐Ÿ’ปTarget Devices
reference-build ยท google-chrome-forced-extensionsGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog
Scope
Windows, all devices
Reversibility
clean-revert

What this policy is about ๐Ÿงฑโ€‹

Some extensions are not optional. This policy force-installs a defined list on every managed device: Chrome pulls them in silently at startup, enables them, and hides the usual remove button. The user does not get a prompt and cannot turn them off.

The obvious tenant is Microsoft Defender Browser Protection (bkbeeeffjjeopflfhgeknacdieedcoml), which warns on malicious and phishing sites. If it protects the user, it should not be a checkbox the user can uncheck on a bad day.

๐Ÿค” Force-install allow-lists itself

Handy detail: a force-installed extension is automatically exempt from the extension blocklist. You do not need to add it to the allow list as well. If Chrome is installing it for you, it has already decided it is allowed.

Why this matters ๐Ÿ•ต๏ธโ€‹

Security tooling that a user can disable is security tooling that gets disabled, right before the click that makes it matter. A phishing warning is only useful if it is running when the phish arrives, not sitting in a "do you want to enable this?" state nobody actioned.

Force-installing the extension makes the protection part of the device, not a suggestion. It survives new profiles, reinstalls, and the user who "just wanted the popup to go away". The security control is present because the policy says so, out loud, on every machine.

๐Ÿ› ๏ธ Configurationโ€‹

Where: Intune admin center โ†’ Devices โ†’ Configuration โ†’ Create โ†’ Windows โ†’ Settings catalog โ†’ Google \ Google Chrome \ Extensions.

SettingValue
Configure the list of force-installed apps and extensions (Device)Enabled
Extension/App IDs and update URLs to be silently installed (Device)bkbeeeffjjeopflfhgeknacdieedcoml (Microsoft Defender Browser Protection), plus any other mandatory extensions
Assignment, includeAll devices
Assignment, excludeNone (standard exclusions only)

Keep this list short and deliberate. Every forced extension is code you are choosing to run on every device with no user off-switch, so the bar is "genuinely mandatory", not "nice to have".

Caveats โš ๏ธโ€‹

Device scope, so it applies to the machine. Unlike the user-scoped allow list, this force-installs regardless of who signs in. That is usually what you want for a security extension.

Force-install removes the escape hatch. Users cannot disable or uninstall a forced extension, which is the point. It also means a badly chosen entry annoys everyone at once, so vet before you push.

Only Web Store IDs by default. Force-installing an extension hosted outside the Chrome Web Store needs an explicit update URL and extra trust settings. For the standard Defender case the Web Store ID is enough.

License and reversibility. Included in Business Premium. Clean-revert: when the policy stops applying, Chrome removes the force-installed extensions on its next policy refresh, so unassigning genuinely rolls it back.


Resistance is futile: the protection extension installs itself, stays on, and cannot be assimilated away by a user who just wanted the popup gone. ๐Ÿงฑ