Skip to content

Chrome Enterprise configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Chrome Enterprise, Black Cat runs 10 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Chrome Enterprise connector needs.

Checks (10)

severity: medium Sideloaded Extension Detected fix difficulty: medium #

Remove sideloaded extensions and enforce extension installation policy in Chrome Enterprise

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
  2. Review the flagged extension that was installed outside the Chrome Web Store
  3. If the extension is unauthorized, add it to the Blocked apps and extensions list
  4. Navigate to User & Browser Settings and enable Block all apps and extensions except the ones I allow
  5. Instruct affected users to remove the sideloaded extension from their browser

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.2 DORA (SaaS Security) DORA-8.3

severity: medium Outdated Browser Version fix difficulty: medium #

Update Chrome browser to the latest stable version on affected devices

  1. Navigate to Google Admin Console > Devices > Chrome > Settings > Device Settings
  2. Under Updates, set the Auto-update policy to Always allow updates
  3. Set the minimum Chrome version to the latest stable release
  4. For devices that cannot auto-update, identify them via Admin Console > Devices > Chrome > Managed Browsers
  5. Push a manual update or re-enroll the device if automatic updates are not available

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.2 DORA (SaaS Security) DORA-8.3

severity: high Extension With Risky Permissions fix difficulty: medium #

Block or remove Chrome extensions with risky permissions from managed devices

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
  2. Identify the flagged extension with risky permissions (e.g., read all browsing data, nativeMessaging)
  3. Evaluate whether the extension is business-critical and the permissions are justified
  4. If not justified, add the extension to the Blocked apps and extensions list
  5. If required for business use, document the approval and monitor the extension regularly
  6. Notify affected users of the policy change

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.2 DORA (SaaS Security) DORA-8.3

severity: high Safe Browsing Disabled fix difficulty: easy #

Enable Safe Browsing in Chrome Enterprise to protect users from malicious sites and downloads

  1. Navigate to Google Admin Console > Devices > Chrome > Settings > User & Browser Settings
  2. Search for Safe Browsing in the policy search bar
  3. Set the policy to Always enable Safe Browsing
  4. Optionally enable Enhanced Safe Browsing for stronger protection
  5. Apply the policy to all organizational units and save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.2

severity: medium Non-Stable Browser Channel In Use fix difficulty: easy #

Restrict Chrome browser channel to stable in Chrome Enterprise settings

  1. Navigate to Google Admin Console > Devices > Chrome > Settings > Device Settings
  2. Under Updates, locate the Target Channel Override policy
  3. Set the policy to Stable channel for all production organizational units
  4. Save changes and allow policy to propagate to managed devices
  5. Verify affected browser versions have moved to the stable channel

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Browser Running Windows 10 fix difficulty: hard #

Upgrade browsers running on Windows 10 to Windows 11 as Windows 10 reached end of support

  1. Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
  2. Filter by OS to identify browsers running Windows 10
  3. Coordinate with the device owner or IT team to schedule an OS upgrade to Windows 11
  4. If the device cannot be upgraded, isolate it from sensitive systems and plan decommission
  5. After upgrade, verify the device appears with Windows 11 in the browser inventory

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Widespread Outdated Browser Version fix difficulty: medium #

Prioritize updating outdated Chrome versions that are deployed on more than 100 devices

  1. Navigate to Google Admin Console > Devices > Chrome > Browser Versions
  2. Identify the outdated version affecting a large number of devices
  3. Review Chrome update policies to ensure auto-update is enabled for affected org units
  4. If auto-update is blocked by policy, remove the version pin and allow updates
  5. Monitor the version distribution report to confirm devices are updating
  6. Escalate to IT if specific devices remain on the outdated version after policy changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Telemetry Device Missing OS Version fix difficulty: easy #

Investigate telemetry devices not reporting OS version to restore patch compliance visibility

  1. Navigate to Google Admin Console > Devices > Chrome > Telemetry
  2. Locate the device with missing OS version information
  3. Check if the device is powered on and connected to the network
  4. Verify that telemetry reporting is enabled in the device management policy
  5. If the device is offline, contact the device owner to bring it online
  6. Confirm OS version appears in the telemetry report after remediation

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Browser Not Reporting Version fix difficulty: easy #

Investigate enrolled browsers not reporting their version to restore update compliance visibility

  1. Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
  2. Locate the browser with missing version information
  3. Check if the browser enrollment token is still valid
  4. Verify that the browser reporting policy is enabled for the device's org unit
  5. Re-enroll the browser if the token has expired or the enrollment is stale
  6. Confirm the browser version appears in the inventory after remediation

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Extension Not Hosted on Chrome Web Store fix difficulty: medium #

Review Chrome extensions sourced outside the Chrome Web Store and restrict installation to approved sources

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
  2. Review the flagged extension and verify its publisher and source against your approved-software list
  3. If the extension is unauthorized, add it to the Blocked apps and extensions list
  4. Under Additional Settings, restrict Allow installation of apps and extensions to the Chrome Web Store sources you trust
  5. Instruct affected users to remove the extension and reinstall an approved version from the Chrome Web Store

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.2 DORA (SaaS Security) DORA-8.3

More Chrome Enterprise checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial