Deploying Using Microsoft SCCM for Chrome on Windows
- Open the SCCM console on your administrative workstation.
- Go to Assets and Compliance > Compliance Settings > Configuration Items.
- Select Create Configuration Item.
- In the Name field, enter a name to identify the configuration item.
- Select Next.
- Select the desired platforms for which this configuration will apply.
- Select Next.
- Select New to create a new setting.
-
In the New Settings window, complete the following:
- In the Name field, enter ExtensionInstallForcelist.
- In the Description field, enter SAAM Browser Extension.
- In the Key Name field, enter
Software\Policies\Google\Chrome\ExtensionInstallForcelist. - In the Value Name field, enter 1.
Note
This number must be unique. If you have added other extensions, this number should be incremented accordingly.
-
Select OK.
- Select the Compliance Rules tab, and select New.
- In the Create window, complete the following:
- In the Name field, enter SAAM Security Extension Compliance Rule.
- In the Description field, enter SAAM Browser Extension.
- In the the following values: field, enter the value
ckdibgmbbhmafmjpjmknleccgcddanan;https://extension.savvy.security/update.xml. - Select Remediate noncompliant rules when supported.
- Select Report noncompliance if this setting instance is not found.
- Select OK to close the window.
- Select OK to create the new compliance rule.
- Select Assets and Compliance > Compliance Settings > Configuration Baselines.
- Select Create Configuration Baseline.
- In the Name field, enter a name to identify the configuration baseline.
- Select Add > Configuration Item.
- Select the SAAM Browser Extension Configuration Item, and select OK.
- Select OK to complete the new configuration baseline.
-
Deploy the configuration baseline containing the SAAM Browser Extension Configuration Item and complete the following:
- Select Remediate noncompliant rules when supported.
- In the Schedule section, set the schedule to the desired value.
Note
Group policies update, by default, every 90 minutes. If this is replacing a GPO, consider lowering the policies update interval.
-
Select OK.
- Once SCCM has updated its policies, verify that Chrome is now managed on endpoints:
- Open a Chrome and browse to
chrome://policy. - Verify under Chrome Policies you can see the ExtensionInstallForcelistDesc policy name with the following value:
ckdibgmbbhmafmjpjmknleccgcddanan;https://extension.savvy.security/update.xml.
- Open a Chrome and browse to