Overview
The Windows Google Chrome Extension Deployment and Blocking Policy lets administrators enable the Swif Chrome extension, automatically install required Chrome extensions, and block specific extensions on enrolled Windows devices.
Use this policy to provide employees with approved browser tools and prevent unwanted extensions from running. It supports company-owned and BYOD devices.
The policy has three settings:
Swif Extension
Install Extension ID List
Blocked Extension ID List
Requirements
Requirement | Details |
Platform | Windows 10 or later |
Ownership | Company-owned or BYOD |
Enrollment | Device enrolled in Swif |
Browser | Google Chrome installed on the device |
Connectivity | Device can check in with Swif; Chrome can reach the extension download and update services |
Use extensions that are available in the Chrome Web Store and compatible with the Chrome version on your devices. This policy manages extensions; deploy Chrome separately if it is not installed.
Before assigning the policy to personal devices, review which users and browser profiles receive the resulting Chrome policies.
Policy Settings
Swif Extension
Enables the Swif Chrome extension on the managed device.
Setting | Details |
Type | On/off |
Default | Off ( |
Turn this setting on when your deployment requires the Swif Chrome extension. After the policy applies, verify the extension in Chrome.
The default of Off does not by itself establish whether an existing installation will be removed. Verify the result when changing this setting on a device that already has the extension.
Install Extension ID List
Specifies the extensions to install automatically without user interaction. Users cannot disable or uninstall these extensions through Chrome while the force-install requirement applies.
Setting | Details |
Type | List of extension IDs |
Default | No predefined IDs |
Entry format | One extension ID per list entry |
Add the IDs of the extensions your organization requires. Enter the ID itself, rather than the extension name or its full store URL.
Review each extension's publisher, requested permissions, and business purpose before deployment. Force-installation grants extension permissions without the usual user approval prompt. Google: Automatically install apps and extensions
Blocked Extension ID List
Specifies the extensions users cannot install. If a listed extension is already installed, it is disabled when the blocking policy takes effect, and users cannot re-enable it while it remains blocked.
Setting | Details |
Type | List of extension IDs |
Default | No predefined IDs |
Entry format | One extension ID per list entry |
Blocking disables an installed extension; it should not be described as deleting the extension or its stored data.
Keep the install and block lists consistent. Do not put the same ID in both lists. Google's ExtensionInstallForcelist takes precedence over ExtensionInstallBlocklist, so a blocklist entry alone may not stop an extension that another policy force-installs. Google: Force-install policy definition
Find an Extension ID
For an extension already installed in Chrome:
Open
chrome://extensions.Turn on Developer mode to display extension IDs.
Copy the ID for the intended extension.
Turn Developer mode off after copying the ID if it is no longer needed.
A Chrome extension ID is a 32-letter string. You can also obtain it from the extension's Chrome Web Store listing URL. Confirm the publisher and listing before copying the ID. Google: Force-install policy definition
Create and Assign the Policy
In the Swif Admin Dashboard, open Device Management > Policies.
Create a policy and select Windows Google Chrome Extension Deployment and Blocking Policy.
Enter a descriptive policy name.
Enable Swif Extension if required.
Add approved extension IDs to Install Extension ID List.
Add unwanted extension IDs to Blocked Extension ID List.
Save the policy and assign it to a test device or device group.
Allow the device to check in and review its policy status in Swif.
Verify the result in Chrome before expanding the assignment.
An offline device must reconnect before it can receive the updated configuration. Policy delivery and extension download are separate steps, so verify both.
Configuration Examples
Replace the descriptions below with the actual IDs for your chosen extensions.
Goal | Swif Extension | Install Extension ID List | Blocked Extension ID List |
Enable the Swif extension | On | No additional IDs | No additional IDs |
Deploy required business tools | As required | IDs of your approved password manager and other required tools | No additional IDs |
Prevent a specific unwanted extension | As required | IDs of any required tools | ID of the unwanted extension |
Adding extensions to the install list does not create an exclusive allowlist. This policy does not expose a separate list for extensions that users may optionally install.
Verify the Policy
On a test device, open Chrome as the affected user:
Open
chrome://policy.Select Reload policies.
Review the extension policies, including
ExtensionInstallForcelist,ExtensionInstallBlocklist, andExtensionSettingswhere present.Check the configured values, status, source, and scope. Investigate errors or conflicting values.
Open
chrome://extensions.Confirm that required extensions are installed and that users cannot disable or remove them through Chrome.
Confirm that a blocked extension is disabled, or that an attempt to install it is prevented.
If necessary, close and reopen Chrome after the policy refresh. Google's policy viewer helps distinguish settings delivered by platform management from cloud-managed settings. Google: View a device's current Chrome policies
Troubleshooting
A required extension does not install
Check that:
The device received the policy and Chrome is installed.
The entry contains the correct extension ID, without a store URL or extra spaces.
The extension is still available and supports the installed Chrome version.
Chrome can reach the store and update services through the device's firewall or proxy.
Chrome reports no relevant policy errors.
This policy's documented input is an extension ID list. Do not assume it accepts custom update URLs or deploys locally hosted extension packages. Google also imposes additional management requirements for force-installing extensions from outside the Chrome Web Store on Windows. Google: Force-install policy definition
A blocked extension remains enabled
Confirm the ID and check for another policy that force-installs the extension. Review other Swif assignments, Windows Group Policy, Chrome cloud management, and scripts that manage Chrome settings.
Also inspect ExtensionSettings. Google documents that it can override older extension policies. Resolve conflicting configuration at its management source, then refresh Chrome policies. Google: Set Chrome app and extension policies on Windows
The policy works for one user but not another
Check chrome://policy in each affected user's Chrome session. Compare the effective scope, source, and values, including policies associated with managed Google accounts.
The Swif extension does not appear
Confirm that Swif Extension is on and the latest policy reached the device. Refresh Chrome policies and inspect the extensions page. If it still does not appear, contact Swif Support with the device identifier, policy status, Chrome version, and relevant policy errors.
Update or Remove the Policy
To change the deployment, edit the appropriate extension list, save the policy, and let the device check in. To stop assigning this configuration, remove the policy assignment and verify the resulting Chrome policies.
Plan for extension removal when changing the install list: Google documents that removing an extension from the effective ExtensionInstallForcelist causes Chrome to uninstall it. Check the resulting behavior on a test device before a broad change. Google: Force-install policy definition
Other management sources may continue to enforce installation or blocking after a Swif policy changes. Confirm the final state in both chrome://policy and chrome://extensions.