โ๏ธ๐ช๐ปCP - Google Chrome - Forced Extensions
The extensions that show up whether users asked for them or not. Silently installed, always on, and not removable from the puzzle-piece menu.
What this policy is about ๐งฑโ
Some extensions are not optional. This policy force-installs a defined list on every managed device: Chrome pulls them in silently at startup, enables them, and hides the usual remove button. The user does not get a prompt and cannot turn them off.
The obvious tenant is Microsoft Defender Browser Protection (bkbeeeffjjeopflfhgeknacdieedcoml), which warns on malicious and phishing sites. If it protects the user, it should not be a checkbox the user can uncheck on a bad day.
Handy detail: a force-installed extension is automatically exempt from the extension blocklist. You do not need to add it to the allow list as well. If Chrome is installing it for you, it has already decided it is allowed.
Why this matters ๐ต๏ธโ
Security tooling that a user can disable is security tooling that gets disabled, right before the click that makes it matter. A phishing warning is only useful if it is running when the phish arrives, not sitting in a "do you want to enable this?" state nobody actioned.
Force-installing the extension makes the protection part of the device, not a suggestion. It survives new profiles, reinstalls, and the user who "just wanted the popup to go away". The security control is present because the policy says so, out loud, on every machine.
๐ ๏ธ Configurationโ
Where: Intune admin center โ Devices โ Configuration โ Create โ Windows โ Settings catalog โ Google \ Google Chrome \ Extensions.
| Setting | Value |
|---|---|
| Configure the list of force-installed apps and extensions (Device) | Enabled |
| Extension/App IDs and update URLs to be silently installed (Device) | bkbeeeffjjeopflfhgeknacdieedcoml (Microsoft Defender Browser Protection), plus any other mandatory extensions |
| Assignment, include | All devices |
| Assignment, exclude | None (standard exclusions only) |
Keep this list short and deliberate. Every forced extension is code you are choosing to run on every device with no user off-switch, so the bar is "genuinely mandatory", not "nice to have".
Caveats โ ๏ธโ
Device scope, so it applies to the machine. Unlike the user-scoped allow list, this force-installs regardless of who signs in. That is usually what you want for a security extension.
Force-install removes the escape hatch. Users cannot disable or uninstall a forced extension, which is the point. It also means a badly chosen entry annoys everyone at once, so vet before you push.
Only Web Store IDs by default. Force-installing an extension hosted outside the Chrome Web Store needs an explicit update URL and extra trust settings. For the standard Defender case the Web Store ID is enough.
License and reversibility. Included in Business Premium. Clean-revert: when the policy stops applying, Chrome removes the force-installed extensions on its next policy refresh, so unassigning genuinely rolls it back.
๐ Relatedโ
- โ๏ธ๐ช๐งโ๐ผCP - Google Chrome - Allowed Extensions: the permit list for what users may add themselves, the counterpart to what you install for them.
Resistance is futile: the protection extension installs itself, stays on, and cannot be assimilated away by a user who just wanted the popup gone. ๐งฑ