Skip to content

Chrome Enterprise identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Chrome Enterprise, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Chrome Enterprise connector needs.

Checks (5)

severity: high Widely Deployed Extension With Risky Permissions fix difficulty: medium #

Review and restrict Chrome extensions with risky permissions deployed to more than 50 devices

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
  2. Identify the flagged extension and review its declared permissions
  3. Determine whether the extension is business-critical and the permissions are necessary
  4. If not justified, add the extension to the Blocked apps and extensions list
  5. If approved, document the risk acceptance and schedule a periodic review
  6. Consider replacing the extension with a less-privileged alternative

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: high Browser Running on Unsupported OS fix difficulty: hard #

Upgrade or decommission Chrome-managed devices still running end-of-life Windows versions

  1. Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
  2. Filter or search for browsers to identify the affected device
  3. Coordinate with the device owner or IT asset team to schedule an OS upgrade
  4. If the device cannot be upgraded, isolate it from sensitive network segments and plan decommission
  5. After upgrade, verify the device re-enrolls with the correct Chrome policies
  6. Update your asset inventory to reflect the OS change

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: high Admin-Forced Extension With Risky Permissions fix difficulty: medium #

Review admin-pushed Chrome extensions that carry high-risk permissions and cannot be removed by users

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
  2. Locate the extension marked as Force Installed and review its declared permissions
  3. Assess whether the risky permission (e.g., nativeMessaging, debugger, cookies) is required for its function
  4. If not required, replace the extension with a less-privileged version or switch to a different tool
  5. If the permission is required, document the risk acceptance and set up monitoring for abnormal behaviour
  6. Notify your security team of all admin-forced extensions with elevated privileges

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: medium Shadow IT Extension Widely Deployed fix difficulty: medium #

Evaluate and either formally approve or block non-managed extensions installed on more than 100 devices

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
  2. Identify the flagged extension and review its install count and publisher
  3. Determine whether the extension serves a legitimate business purpose
  4. If approved, add it to the managed catalog with appropriate install policy
  5. If not approved, add it to the Blocked apps and extensions list to prevent further spread
  6. Communicate the policy decision to affected users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

severity: high Device Running Outdated OS (Telemetry) fix difficulty: hard #

Upgrade devices reported via Chrome telemetry that are running end-of-support operating systems

  1. Navigate to Google Admin Console > Devices > Chrome > Devices
  2. Locate the flagged device using its machine name or serial number
  3. Confirm the OS version shown in the device detail view
  4. Coordinate with the device owner to schedule an OS upgrade (macOS 13+ or a supported Windows version)
  5. If the device cannot be upgraded, isolate it from sensitive systems and plan decommission
  6. After upgrade, verify the device appears with a supported OS version in the telemetry report

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13

More Chrome Enterprise checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial