Skip to main content

Windows Google Chrome Extension Deployment and Blocking Policy

Overview

The Windows Google Chrome Extension Deployment and Blocking Policy lets administrators enable the Swif Chrome extension, automatically install required Chrome extensions, and block specific extensions on enrolled Windows devices.

Use this policy to provide employees with approved browser tools and prevent unwanted extensions from running. It supports company-owned and BYOD devices.

The policy has three settings:

  • Swif Extension

  • Install Extension ID List

  • Blocked Extension ID List

Requirements

Requirement

Details

Platform

Windows 10 or later

Ownership

Company-owned or BYOD

Enrollment

Device enrolled in Swif

Browser

Google Chrome installed on the device

Connectivity

Device can check in with Swif; Chrome can reach the extension download and update services

Use extensions that are available in the Chrome Web Store and compatible with the Chrome version on your devices. This policy manages extensions; deploy Chrome separately if it is not installed.

Before assigning the policy to personal devices, review which users and browser profiles receive the resulting Chrome policies.


Policy Settings

Swif Extension

Enables the Swif Chrome extension on the managed device.

Setting

Details

Type

On/off

Default

Off (false)

Turn this setting on when your deployment requires the Swif Chrome extension. After the policy applies, verify the extension in Chrome.

The default of Off does not by itself establish whether an existing installation will be removed. Verify the result when changing this setting on a device that already has the extension.

Install Extension ID List

Specifies the extensions to install automatically without user interaction. Users cannot disable or uninstall these extensions through Chrome while the force-install requirement applies.

Setting

Details

Type

List of extension IDs

Default

No predefined IDs

Entry format

One extension ID per list entry

Add the IDs of the extensions your organization requires. Enter the ID itself, rather than the extension name or its full store URL.

Review each extension's publisher, requested permissions, and business purpose before deployment. Force-installation grants extension permissions without the usual user approval prompt. Google: Automatically install apps and extensions

Blocked Extension ID List

Specifies the extensions users cannot install. If a listed extension is already installed, it is disabled when the blocking policy takes effect, and users cannot re-enable it while it remains blocked.

Setting

Details

Type

List of extension IDs

Default

No predefined IDs

Entry format

One extension ID per list entry

Blocking disables an installed extension; it should not be described as deleting the extension or its stored data.

Keep the install and block lists consistent. Do not put the same ID in both lists. Google's ExtensionInstallForcelist takes precedence over ExtensionInstallBlocklist, so a blocklist entry alone may not stop an extension that another policy force-installs. Google: Force-install policy definition

Find an Extension ID

For an extension already installed in Chrome:

  1. Open chrome://extensions.

  2. Turn on Developer mode to display extension IDs.

  3. Copy the ID for the intended extension.

  4. Turn Developer mode off after copying the ID if it is no longer needed.

A Chrome extension ID is a 32-letter string. You can also obtain it from the extension's Chrome Web Store listing URL. Confirm the publisher and listing before copying the ID. Google: Force-install policy definition

Create and Assign the Policy

  1. In the Swif Admin Dashboard, open Device Management > Policies.

  2. Create a policy and select Windows Google Chrome Extension Deployment and Blocking Policy.

  3. Enter a descriptive policy name.

  4. Enable Swif Extension if required.

  5. Add approved extension IDs to Install Extension ID List.

  6. Add unwanted extension IDs to Blocked Extension ID List.

  7. Save the policy and assign it to a test device or device group.

  8. Allow the device to check in and review its policy status in Swif.

  9. Verify the result in Chrome before expanding the assignment.

An offline device must reconnect before it can receive the updated configuration. Policy delivery and extension download are separate steps, so verify both.


Configuration Examples

Replace the descriptions below with the actual IDs for your chosen extensions.

Goal

Swif Extension

Install Extension ID List

Blocked Extension ID List

Enable the Swif extension

On

No additional IDs

No additional IDs

Deploy required business tools

As required

IDs of your approved password manager and other required tools

No additional IDs

Prevent a specific unwanted extension

As required

IDs of any required tools

ID of the unwanted extension

Adding extensions to the install list does not create an exclusive allowlist. This policy does not expose a separate list for extensions that users may optionally install.

Verify the Policy

On a test device, open Chrome as the affected user:

  1. Open chrome://policy.

  2. Select Reload policies.

  3. Review the extension policies, including ExtensionInstallForcelist, ExtensionInstallBlocklist, and ExtensionSettings where present.

  4. Check the configured values, status, source, and scope. Investigate errors or conflicting values.

  5. Open chrome://extensions.

  6. Confirm that required extensions are installed and that users cannot disable or remove them through Chrome.

  7. Confirm that a blocked extension is disabled, or that an attempt to install it is prevented.

If necessary, close and reopen Chrome after the policy refresh. Google's policy viewer helps distinguish settings delivered by platform management from cloud-managed settings. Google: View a device's current Chrome policies


Troubleshooting

A required extension does not install

Check that:

  • The device received the policy and Chrome is installed.

  • The entry contains the correct extension ID, without a store URL or extra spaces.

  • The extension is still available and supports the installed Chrome version.

  • Chrome can reach the store and update services through the device's firewall or proxy.

  • Chrome reports no relevant policy errors.

This policy's documented input is an extension ID list. Do not assume it accepts custom update URLs or deploys locally hosted extension packages. Google also imposes additional management requirements for force-installing extensions from outside the Chrome Web Store on Windows. Google: Force-install policy definition

A blocked extension remains enabled

Confirm the ID and check for another policy that force-installs the extension. Review other Swif assignments, Windows Group Policy, Chrome cloud management, and scripts that manage Chrome settings.

Also inspect ExtensionSettings. Google documents that it can override older extension policies. Resolve conflicting configuration at its management source, then refresh Chrome policies. Google: Set Chrome app and extension policies on Windows

The policy works for one user but not another

Check chrome://policy in each affected user's Chrome session. Compare the effective scope, source, and values, including policies associated with managed Google accounts.

The Swif extension does not appear

Confirm that Swif Extension is on and the latest policy reached the device. Refresh Chrome policies and inspect the extensions page. If it still does not appear, contact Swif Support with the device identifier, policy status, Chrome version, and relevant policy errors.

Update or Remove the Policy

To change the deployment, edit the appropriate extension list, save the policy, and let the device check in. To stop assigning this configuration, remove the policy assignment and verify the resulting Chrome policies.

Plan for extension removal when changing the install list: Google documents that removing an extension from the effective ExtensionInstallForcelist causes Chrome to uninstall it. Check the resulting behavior on a test device before a broad change. Google: Force-install policy definition

Other management sources may continue to enforce installation or blocking after a Swif policy changes. Confirm the final state in both chrome://policy and chrome://extensions.

Did this answer your question?