# Group Policy Deployment - Chrome

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FVhvavbRIJeb5lqrvOvtr%2FGroup%20Policy%20Deployment%20-%20Chrome.jpg?alt=media&#x26;token=f6e128bd-e936-4d7c-acff-098414158d88" alt=""><figcaption></figcaption></figure>

## **Deploying Keeper Chrome Browser Extension via Group Policy Management**

This section describes how to utilize your Active Directory Group Policy Management, against Google Chrome templates, to deploy the Keeper Browser extension to all PCs in your organization. Please note this is a general guide.

### **Step 1: Adding Chrome Policy Templates**

On your domain controller, navigate to the URL, provided below, and download the correct 32 or 64 bit zip bundle.  Extract the Google Chrome bundle to your desired location. Ex: `C:\temp`

```http
https://chromeenterprise.google/browser/download
```

1. Navigate to the directory in which you extracted the Google Chrome Bundle and copy the chrome.admx file located within the\
   **64-bit**\
   `\GoogleChromeEnterpriseBundle64\Configuration\admx` directory to `C:\Windows\PolicyDefinitions` **OR**\
   **32-bit**\
   `\GoogleChromeEnterpriseBundle\Configuration\admx` directory to `C:\Windows\PolicyDefinitions`
2. Navigate to the directory in which you extracted the Google Chrome Bundle and copy the chrome.adml file located within the\
   **64-bit**\
   `\GoogleChromeEnterpriseBundle64\Configuration\admx\en-US` directory to `C:\Windows\PolicyDefinitions\en-US` **OR**\
   **32-bit**\
   `\GoogleChromeEnterpriseBundle\Configuration\admx\en-US` directory to `C:\Windows\PolicyDefinitions\en-US`

{% hint style="info" %}
NOTE: If a different language is desired instead of en-US, please navigate to the directory for the correct language of your choosing.  Ex: es-ES
{% endhint %}

### **Step 3: Create or Configure your Chrome Policy**

1. Open Group Policy Manager on your domain controller and expand out your domain -> Group Policy Objects.  If you currently do not have a Group Policy created in which you want to utilize for Chrome Policies, proceed to right clicking on Group Policy Objects and create a New Policy.

![Creating a new Policy](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWRE18Hx65nUvHHwVB%2F-MFWRpiWxBg8iL81Thya%2Fnew-pol.png?alt=media\&token=af4e449b-1db3-4084-a71c-358598cc699d)

2\. Name the policy something relevant. Ex: “**Chrome Policy**”

![Policy Name](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWS1b7mrme9FfR360g%2F-MFWk3GIoMqgQku1ywHO%2Fpolicy-name.png?alt=media\&token=6562f69e-5515-44fe-ad43-b8a161d07155)

3\. Once created, right click the new policy and select **Edit**.

![Editing a Group Policy](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWurijAFxXH3x-yTU-%2F-MFWw61Bpf05yijKPO9B%2Fedit-chrome.png?alt=media\&token=1de828a7-b676-499d-8bb1-7aab85d4fdf0)

4\. Expand out Chrome Policy -> **Computer Configuration -> Policies -> Administrative Templates -> Google Chrome -> Extensions** then Right click and Edit the “**Configure the list of force-installed apps and extensions**”

{% hint style="info" %}
If this Policy will apply to **Users** instead of Computers, the Edge Policies you will be expanding will be located under **User Configuration -> Policies -> Administrative Templates -> Google Chrome**
{% endhint %}

![Configure Forced Installed Extensions](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWS1b7mrme9FfR360g%2F-MFWoIowJWrNeTRf2gJs%2Fextensions.png?alt=media\&token=8e5fe5cb-79f4-4c49-880c-a739d4ebfacc)

5\. Tick the **Enable** button, and then click the **Show** button.

![Show Forced Extensions](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWo_05CUUSSELfNPQD%2F-MFWp8HGmNUZNUr7EFP6%2Fenable.png?alt=media\&token=1866a1fa-5aee-44d1-998c-561d2c3f8d8a)

6\. Add the following text and click **OK**.

```
bfogiafebfohielmmehodmfbbebbbpei;https://clients2.google.com/service/update2/crx
```

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2F0z2d7ApIdwhDnwq8rXn3%2Fforcedapp.jpg?alt=media&#x26;token=bc9b8844-66b1-41e4-a313-01d997f28fa4" alt=""><figcaption><p>Extension Policy</p></figcaption></figure>

7\. Click Apply, and then click **OK**

![](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWo_05CUUSSELfNPQD%2F-MFWp8HGmNUZNUr7EFP6%2Fenable.png?alt=media\&token=1866a1fa-5aee-44d1-998c-561d2c3f8d8a)

8\. Disable Chrome's Built-In Password Manager by navigating to **Google Chrome -> Password manager** and then Right click and Edit the “**Enable saving passwords to the password manager**”

![Disabling Chrome Built-In Password Manager](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MG8t62O41G3kC6n_JIf%2F-MG8vDC6uoxVpslzsHQn%2Fbuiltin-passwd.png?alt=media\&token=3c148585-6dda-4fbd-982c-b7f17168353d)

9\. Tick the "**Disabled**" button, and then click Apply, and then click **OK**.

![Disabled Chrome Password Manager](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MG9Y6MXJoKV1pPIH4lN%2F-MG9_IFNo6j7F8_BY5z0%2Fdisable-passwd.png?alt=media\&token=9b383d91-d068-48bb-a1e9-1327e1143831)

10\. Following the same process as steps 8 - 9, direct within Google Chrome Administrative Templates Policy definitions, Disable Chrome's AutoFill capabilities by editing both "**Enable AutoFill for addresses**" and "**Enable AutoFill for credit cards**" and setting them to **disabled**.

![Disable Chrome"s AutoFill Capabilities](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MG9mOvdi_KJz3oECwuZ%2F-MG9npPrTd9LhNzbaJnQ%2Fdisable-cAutoFill.png?alt=media\&token=92a6a144-c9e2-43cc-a0b0-7fed481df2d9)

11\. **(Optional)**  If you would like to disable Developer Tools, to further secure against users attempting to unmask a masked password / credential, still within the Google Chrome Administrative Templates Policy definitions, disable Developer Tools by editing "**Control where developer tools can be used**" end setting it to "**Enabled**" and select the Options value of "**Don't allow using the developer tools**" and click **OK**.

![Developer Tools Policy](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MTbt8hobpsbybwLzatC%2F-MTbuSVBqMOY-oNxG_Qy%2Fdisdevtoos.PNG?alt=media\&token=49ab31be-1a61-430e-97ec-9ce3f61bf010)

![Disallow Developer Tools](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MTbt8hobpsbybwLzatC%2F-MTbvFcoZBFlVeYn6eoG%2Fdevtdis.PNG?alt=media\&token=d2661e03-4e3c-49be-b360-cdbe5bb7dca3)

12\. Exit the Group Policy Management Editor, Right Click the OU of your choice, in which contains your Computers or Users, and select **Link an Existing GPO**.

![Link Forced Installed Extension to PCs](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWo_05CUUSSELfNPQD%2F-MFWrPV0PQDtgRJg6TH6%2Fou.png?alt=media\&token=5abefb95-04a2-41ca-a672-9d25de5ff990)

13\. Select the “Chrome Policy” and click “**OK**”

![Chrome Policy Object](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MFWsNh2GPFfYiEjuDvc%2F-MFWsuBnoWjM7xpfLMhx%2Fobject.png?alt=media\&token=220e7f38-7df9-4132-b82f-7be5d0069786)

{% hint style="info" %}
If you have more than one OU (Organizational Unit) that you would like to Link this new Group Policy to, repeat steps 12 - 13.
{% endhint %}

For any PC within that OU, the “Chrome Policy” will automatically install the Keeper Security Browser Extension, if Chrome is installed on those PCs as well as disable Chrome's, less secure, built-in password manager and AutoFill capabilities.

### **Step 4: Check Your Chrome Policies**

On a target client device, open Google Chrome and navigate to **chrome://policy** to see all policies that are applied. If you applied policy settings on the local computer, policies should appear immediately.

![Chrome Polices](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MTbvxwXKR99LcvQQEyO%2F-MTbyM04pOrOgOFVTuhf%2Fchromepolices.PNG?alt=media\&token=d7e95b0c-202b-45de-8f14-a5b5a1949967)

You can also check your extension by navigating to **chrome://extensions** and ensuring your extensions are being forcefully installed.&#x20;

![](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LO5CAzpxoaEquZJBpYz%2F-MZZAYt2pwD-TU8PWqXR%2F-MZZBqSYfGV2_rAdLK2y%2Fforcedchromeapp.PNG?alt=media\&token=82e6802b-3870-4c0f-997d-e77dba704d60)

{% hint style="info" %}
You may need to run **gpupdate /force**, in an elevated command prompt, to apply this new group policy to the PCs.
{% endhint %}

```
gpupdate /force
```

You may need to close and reopen Google Chrome before the new policies appear.
