Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

Bringing Uncontrolled Browser Extensions Under Management at No Extra Cost

Table of contents · 6 items

An employee installs a PDF conversion extension to generate expense reimbursement receipts. A sales rep adds a translation extension to browse foreign sites. Someone adds an "AI webpage summarizer" extension and recommends it to coworkers. None of this is malicious; in fact, it stems from trying to work faster.

The problem is that many of these extensions request permission to "Read and change all your data on all websites." Internal enterprise portals and quotes opened in Google Drive are visible to the extension. Furthermore, not even the user who installed it knows what capabilities next week's update might introduce.

Chrome extensions can change ownership. Time and again, extensions that amassed significant user bases were acquired, with subsequent updates injecting data collection code. To end users, behavior does not suddenly alter overnight; updates arrive silently without badges or notifications.

Why Telling Users "Don't Install" Fails

Trying to prohibit extensions through company memos rarely works. The reason is simple: certain extensions are genuinely necessary for business operations. With more workflows confined entirely to browsers, an outright ban halts productivity.

Moreover, memo-based governance has a fatal flaw: administrators have no way of knowing what is installed on which PC. Announcing "please do not install them" leaves already-installed extensions running undisturbed.

Chrome Enterprise Core fills this visibility gap. It can be enrolled directly from Google Workspace Admin Console at no additional fee. It enables managing Chrome instances across Windows, Mac, Linux, iOS, and Android from a single admin console. For organizations already using Google Workspace, the key advantage is starting without expanding vendor contracts.

Account Management and Browser Management Are Different

Where confusion often arises is the relationship with existing administration. If you manage accounts in Google Workspace Admin Console, browsers might appear to be under control as well. In reality, they operate on separate layers.

Management targetWhat is controlledExamples
Accounts (Google Workspace)Who can access which servicesEnforcing 2-step verification, external sharing permissions
Browsers (Chrome Enterprise Core)Browser behavior and extensionsAllowing/blocking extensions, sync controls
Devices (Endpoint management)Hardware state itselfRequiring screen locks, remote wipes

Browsers not signed into corporate accounts or Chrome installed on personal PCs cannot be influenced by account policies alone. Browser management bridges this divide. Comprehensive endpoint architecture including device-level controls is covered in Google Workspace Endpoint Management and BYOD, while conditional access strategies are explored in Conditional Access with Context-Aware Access.

Diagram illustrating the three layers of account management, browser management, and device management, showing where Chrome extension governance resides

Establish Visibility Before Tightening Controls

In sequence, inventory comes before restriction. Creating an allowlist without seeing what is currently installed will inadvertently break business-critical extensions.

Phase 1: Enrollment and visibility. Issue browser enrollment tokens in the Admin Console and enroll Chrome on company PCs. Once enrolled, installed extensions across all devices appear in the Admin Console inventory. Enforce no restrictions here. Gathering data over a few weeks reveals actual usage.

Phase 2: Block obvious hazards. Reviewing the inventory typically exposes abandoned extensions, extensions from unknown developers, or redundant tools. Build a blocklist for these first. Because the scope is narrow, business operations remain uninterrupted.

Phase 3: Filter by permissions. Extensions can be governed by requested permissions and accessible sites. Restricting only extensions that can "read data on all websites" narrows the target, serving as a practical intermediate milestone before enforcing a comprehensive allowlist.

Stage 4: Switch to an allowlist. Put things in a state where no extensions can be installed except those approved by the company. Once you reach this point, operations shift to having administrators automatically distribute necessary extensions to everyone. Rather than letting frontline staff install things themselves, you need a workflow where requesting an extension gets it installed; otherwise, shadow IT will simply migrate elsewhere (to personal devices or personal accounts).

Many companies try to rush all the way to Stage 4 and stall, but even stopping at Stage 2 represents substantial progress compared to leaving things unattended. The key to maintaining momentum is not turning this into an all-or-nothing choice.

Three easily overlooked gaps

The first is Chrome on personal devices. Enrolling a browser requires action on the device itself, so it cannot be applied to personally owned PCs. If you permit BYOD, you must address this not through browser management, but through access-side controls (restricting which services can be opened with corporate accounts).

The second is browsers other than Chrome. If employees are using Edge or Safari for work, those fall outside the scope of Chrome Enterprise Core management. "Locking down Chrome only to have them migrate to Edge" defeats the purpose, so this must be paired with a policy that consolidates work-related browser usage onto Chrome.

The third is confusing extensions with connected apps on the Google Workspace side. External apps that access Google Drive or Gmail are managed separately from extensions under "Security → Access and data control → API controls." Even if you lock down the browser side, apps authorized via OAuth remain unaffected. Unless you look at both, your efforts will be half-baked.

What to do next

To start, enable Chrome Enterprise Core in the admin console and try going as far as issuing an enrollment token. Up to this point, it is free of charge and imposes no restrictions, meaning there is zero impact on your organization.

Next, enroll just a few devices—such as those belonging to the IT team or administrative departments—and verify how the extension inventory appears. Being able to show this screen to executive leadership makes it far easier to secure buy-in for a company-wide rollout. That is because presenting an actual list of what is installed is much faster than explaining in words that "extensions are dangerous."

If you would like to discuss how to proceed with a rollout tailored to your company's device setup, or how to combine it with Google Workspace configurations, we handle inquiries through GleamHub's Free IT & Google Workspace Consultation. The optimal sequence varies depending on device counts and whether BYOD is present, so please consult with us individually. Reach out via Contact Us.

Sources

Share this articleXFacebook
Kakeru Suzuki

Fascinated by the possibilities of technology, has had a deep interest in programming and digital art since student days

Turn this article's theme into your company's next step

The right way forward with Workspace for your company.

We organize data to migrate, sharing rules, and governance structures to map out the journey from implementation to daily operations.

  • Migration and initial setup
  • Sharing and permission organization
  • Governance structure
Consult on Workspace implementation and operations

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles by email