AzureAD and Enterprise Chrome Policies

51 views
Skip to first unread message

Torrey Umland

unread,
Aug 12, 2020, 2:21:39 PM8/12/20
to Chromium Extensions
Hello,

We (Broadcom) have run some tests with a device joined to Microsoft Azure Active Directory domain. Azure AD is "Microsoft's cloud-based identity and access management service".

We expected Chrome's behavior to be similar to an Active Directory domain-joined device, but found this not to be the case. For example, the policy mechanism to install Chrome extensions from an "On-Premise App Store" does not seem to be enabled for an AzureAD device.

Is this behavior expected, a known issue? Are there any plans to make Chrome act similarly for AD/AzureAD?

Thank You,
Torrey

Deco

unread,
Aug 12, 2020, 7:34:30 PM8/12/20
to Torrey Umland, Chromium Extensions
CWS does not have direct integration with AzureAD containers correct - there is no mention of this being integrated anytime soon, although that doesn't mean you can't implement your own solution (to this non integration).

Thanks,
Deco

--
You received this message because you are subscribed to the Google Groups "Chromium Extensions" group.
To unsubscribe from this group and stop receiving emails from it, send an email to chromium-extens...@chromium.org.
To view this discussion on the web visit https://groups.google.com/a/chromium.org/d/msgid/chromium-extensions/cc9834c8-6769-40aa-a697-7fd90f7331e8n%40chromium.org.

Anton Bershanskiy

unread,
Aug 13, 2020, 6:16:02 AM8/13/20
to Chromium Extensions
Is this behavior expected, a known issue? Are there any plans to make Chrome act similarly for AD/AzureAD?

As far as I know, Chrome does not support this exact method, but it has equivalent methods to achieve the same result. In short, consider this.

Chrome allows remote management via its own "Admin console", Windows Registry, Windows Group Policy, and so-called master_preferences. Most of the relevant articles are linked here. You should be able to deploy these policies (registry, group policies, and preferences) via Active Directory, but the Admin console might be more convenient to use.
Reply all
Reply to author
Forward
0 new messages