Manage Chrome browser with Windows device management
发布时间:2026-08-19 | 浏览:2
For administrators who manage Chrome browser on Windows for a business or school.
As an administrator, you can use custom settings to configure Chrome browser settings on your organization’s Microsoft Windows 10 devices. You first set a custom setting to allow Chrome on the managed devices to accept policy settings, then you set a custom setting for each Chrome policy.
Step 1: Ingest the Chrome ADMX file into your Google Admin console
Get the Chrome ADMX file contents:
On a Windows device, download the Chrome ADMX templates .
In a text editor, open C:\Users\username\Downloads\template\windows\admx\chrome.admx and copy the contents.
Set up a custom setting for ingesting the Chrome ADMX policy:
Sign in with an administrator account to the Google Admin console. If you aren’t using an administrator account, you can’t access the Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
Go to Menu Devices > Mobile and endpoints > Settings > Windows . Requires having the Services and devices administrator privilege.
Requires having the Services and devices administrator privilege.
Click Custom settings .
Click Add a custom setting .
Enter text into the fields: Name Chrome ADMX Ingestion OMA-URI ./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Chrome/Policy/ChromeAdmx Data type String (select from drop-down list) Value Enter the text from chrome.admx Description (optional) Enter a description
Name Chrome ADMX Ingestion
OMA-URI ./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Chrome/Policy/ChromeAdmx
Data type String (select from drop-down list)
Value Enter the text from chrome.admx
Description (optional) Enter a description
Choose the organizational unit to apply the policy to.
Step 2: Add a custom setting for each Chrome policy
Sign in with an administrator account to the Google Admin console. If you aren’t using an administrator account, you can’t access the Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
Go to Menu Devices > Mobile and endpoints > Settings > Windows . Requires having the Services and devices administrator privilege.
Requires having the Services and devices administrator privilege.
Click Custom settings .
Click Add a custom setting .
Enter text into the fields, following the examples below for the type of policy you’re implementing. For a complete list of available policies, go to the Chrome Enterprise policy list . Note: The OMA-URI field does not automatically populate Chrome browser policies because they are ADMX based.
Choose the organizational unit to apply the policy to.
Example A: Enable home button
Name Chrome – ADMX – ShowHomeButton
Description Enable the home button
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome*~Startup*/ShowHomeButton
Data type String
Value <enabled/>
Example B: Configure URL for homepage button
Name Chrome – ADMX – HomepageLocation
Description Configure the URL the homepage button opens
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome*~Startup*/HomepageLocation
Data type String
Value <enabled/>
Example C: Enable site isolation
Name Chrome – ADMX – SitePerProcess
Description Enable Site Isolation
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome/SitePerProcess
Data type String
Value <enabled/>
Example D: Set application locale value
Name Chrome – ADMX – ApplicationLocaleValue
Description Application locale
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome/ApplicationLocaleValue
Data type String
Value <enabled/> <data id="ApplicationLocaleValue" value="de"/>
Example E: Set URL blocklist
Name Chrome – ADMX – URLBlacklist
Description List of URLs to deny
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome/URLBlacklist
Data type String
Value <enabled/> <data id="URLBlacklistDesc" value="1http://www.xyz.com2http://www.abc.com"/> Important: Use  as the separator between key-value pairs.
Example F: Allow specific extensions
Name Chrome – ADMX – ExtensionInstallWhitelist
Description Allow specific extensions
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome*~Startup*/ExtensionInstallWhitelist
Data type String
Value <enabled/>
Example G: Block all extensions
Name Chrome – ADMX – ExtensionInstallBlacklist
Description Extension blocklist
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome~Extensions/ExtensionInstallBlacklist
Data type String
Value <enabled/> <data id="ExtensionInstallBlacklistDesc" value="1*"/> Important: Use  as the separator between key-value pairs.
Example H: Manage Bookmarks
Name Chrome – ADMX – ManagedBookmarks
Description Managed Bookmarks
OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome/ManagedBookmarks
Data type String
Value <enabled/> <data id='ManagedBookmarks' value='[ {"toplevel_name":"Company Bookmarks"}, {"url":"solarmora.com","name":"Solarmora Company"}, {"url":"blogs.altostrat.com","name":"Favorite blogs"}, {"name":"Email services","children":[ {"url":"your-company.com","name":"An email service"}, {"url":"other-company.com","name":"Another email service"}]}]'/> Important: Use double quotes on the inner values and single quotes on the outer values.
Step 3: Confirm that the policy is set
After you apply any Chrome policies, users need to restart Chrome browser for the settings to take effect. You can check users’ devices to make sure the policy was applied correctly.
On a managed device, open Chrome browser.
In the address bar, enter chrome://policy .
Click Reload policies .
Verify that the policy you set is enabled.
Step 4: (Optional) Configure other templates
In addition to managing the Chrome browser following the steps above, you can ingest and configure other templates, such as Google Updater , and Chrome Beta Policy Templates .
To use these templates, first you need to download them. Then, similar to Step 2 above, add new custom settings.
Troubleshooting
If the custom policy you set isn’t in your list of Chrome policies, make sure that you allowed adequate time for the policy to propagate on the managed device. It can take up to 3 hours for policies to apply to devices with internet connection. To force a policy sync, on the device open Settings and find Managed by Google . Manually sync the device twice then check the policies again.
To verify that the policy is in the registry, in the Run box enter regedit to open the Registry Editor in Windows 10. Verify that the correctly defined policy is visible at HKLM\Software\Policies\Google\Chrome . If it’s not visible, it means the policy is not pushed correctly.
Make sure you've typed the OMA-URI correctly and ensure that the value is correct XML. If you get any of these wrong, an error message won't appear, but the policy won't be enforced on your users machines.
Add, edit, or delete custom settings for Windows 10 devices
Chrome Enterprise policy list
Set up Chrome browser on Windows
Download the Chrome Enterprise Bundle (includes ADMX files)
Allow or block websites—URL filter format
Google and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.
Was this helpful?
Need more help?
Try these next steps: