Hello Huang,
Thank you for posting question on Microsoft Windows Forum!
Well! The plausible explanation to this symptom is that local admin users can bypass enterprise Chrome extension restrictions because administrative privileges grant full control over the local Windows registry (HKEY_LOCAL_MACHINE), allowing them to modify or delete policy keys. Standard users cannot do this because they lack write permissions to HKLM, which is why policies apply normally to them.
As a result, you can consider to demote users to standard user accounts by removing local administrator rights from the affected user accounts via Local Users and Groups (lusrmgr.msc) or your domain controller, ensuring they belong only to the Standard Users group. This blocks users from altering system registry keys or tampering with enterprise policies.
In case users must retain local admin privileges for business reasons, it is recommended to enroll the devices or browsers into Microsoft Intune or Chrome Browser Cloud Management (CBCM) which will use a background service that continuously monitors and automatically re-applies enterprise policies, immediately overriding any manual registry tampering by a local admin.
Another point worth mentioning here is that if your enterprise uses Chrome Browser Cloud Management, move your extension‑restriction policies into Windows Group Policy. Policies set through Group Policy are written to the registry under HKLM and are treated as platform policies. Since they occupy the highest precedence tier, a local admin’s manual registry edits will still conflict with the Group Policy‑enforced values, and Group Policy will win. You can import the Chrome ADMX/ADML templates and configure the required extension settings (such as ExtensionInstallBlocklist, ExtensionInstallAllowlist, ExtensionSettings) under Computer Configuration → Administrative Templates → Google → Google Chrome → Extensions. If you instead leave the Group Policy setting as Not Configured, the policy will not appear in the registry, and a local admin’s registry value will take effect. So you must explicitly enable the policy in Group Policy to block the override.
Please note: Try to perform the above policy in a testing environment first and you can confirm the effective policies by opening chrome://policy in the browser.
Hope the above information is helpful!