Welcome to Microsoft Q&A!
Thank you for reaching out.
In general, creating a local Chrome profile should not bypass a properly configured device-level (machine-level) enterprise policy. To ensure required extensions are enforced across all Chrome profiles on managed Windows devices, it is recommended to deploy the policy at the computer/device scope rather than relying solely on policies associated with managed Google accounts.
You can manage this through Group Policy, Microsoft Intune, or Chrome Enterprise Core / Chrome Browser Cloud Management.
- Import the Google Chrome ADMX/ADML administrative templates into Group Policy or Intune.
- Navigate to:
Computer Configuration -> Google -> Google Chrome -> Extensions
- Enable Configure the list of force-installed apps and extensions.
- Add each required extension using the following format:
<extension-ID>;https://clients2.google.com/service/update2/crx
- To further strengthen control, configure ExtensionSettings to block extension installations by default and explicitly allow or force-install only approved extensions.
- Apply the policy to the appropriate devices or organizational units containing your managed browsers.
The extensions deployed through ExtensionInstallForcelist are installed automatically and users cannot remove or disable them through the Chrome user interface. However, please also notes that protection against modifications made directly at the operating system level is a best-effort measure. As a result, users with local administrator privileges may still be able to alter policy-related registry settings or browser files.
For that reason, if users do not require administrative privileges, removing local administrator rights is generally the most effective way to prevent policy tampering. If administrative access is required, consider ensuring devices are centrally managed, regularly reviewing policy compliance, and restricting access to developer tools where appropriate.
After deployment, you can verify that the policy is being applied by opening:
chrome://policy
Confirm that ExtensionInstallForcelist or ExtensionSettings is present and reporting a status of OK.
On Windows devices, you can also verify the policy under:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome
And for force-installed extensions:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist
If the policy does not appear as expected, run:
gpupdate /force
Then, review the Resultant Set of Policy (RSoP) to confirm that the policy is reaching the target device.
For organizations managing devices through Intune, Microsoft also provides guidance on deploying Chrome extension policies using the Settings Catalog and enabling Configure the list of force-installed apps and extensions.
Note: Before rolling out the configuration broadly, it is a good practice to validate the policy with a small pilot group. If chrome://policy does not show the expected settings, investigate policy assignment, GPO scope, ADMX ingestion, registry permissions, and any potentially conflicting management policies before troubleshooting the extension itself.
References:
- While the following are not Microsoft resources, they are official Google Chrome Enterprise documentation:
Chrome ExtensionInstallForcelist policy
Chrome ExtensionSettings policy
Automatically install Chrome apps and extensions
- From Microsoft:
Get started with the Microsoft Purview extension for Chrome | Microsoft Learn
If you find it useful, please click Accept Answer.
Thank you for choosing Microsoft Q&A.