What's changed: Created Associate Google Workspace Administrator Chapter 5 (Domain 5 "Browsers/endpoints": Chrome browser management = Chrome Browser Cloud Management/centralized policy/extension allow-block-force-install; endpoint management = basic/advanced, company-owned/BYOD, screen lock/encryption/remote wipe/account wipe, mobile app management).
5.1Chrome browser management
Understand centralized policy with Chrome Browser Cloud Management, allowing/blocking and force-installing extensions, browser security settings, and differentiating policy per OU.
Much work happens in the browser, making Chrome an important management target. With Chrome Browser Cloud Management, apply organizational policy centrally to many browsers.
5.1.1Centralized policy
Chrome Browser Cloud Management distributes Chrome policies centrally from the Admin console (startup pages, sync, Safe Browsing, enabling/disabling features). Many policies are differentiated per OU. By enrolling browsers into the org, you gain visibility into version/state and can govern them. Map "centrally distribute Chrome policy = Chrome Browser Cloud Management."
5.1.2Managing extensions
Because extensions can be risky, govern adoption via allow/block (allowlist/blocklist) and distribute required ones with force-install. Restricting high-permission extensions reduces data-exfiltration and malware risk. Map "push required extensions to everyone = force-install" and "prevent dangerous extensions = blocklist/allowlist."
Common: requirement → means. E.g., "apply the same policy to many Chrome browsers" = Chrome Browser Cloud Management; "distribute a work extension to everyone" = force-install; "ban dangerous extensions" = blocklist; "vary browser settings per department" = per-OU policy.
Watch the mix-ups: (1) Chrome browser management (the PC browser) differs from ChromeOS device management (the device itself). (2) Govern extensions by combining allow/block + force-install. (3) Many settings differentiate per OU.
5.1.3Section summary
- Chrome Browser Cloud Management centrally distributes policy (differentiated per OU)
- Govern extensions via allow/block; force-install required ones
- Enroll browsers to gain visibility into version/state and govern them
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To centrally apply the same security policy to Chrome on many PCs, what do you use?
Q2. To reliably distribute a required work extension to all users, which best fits?
Q3. To prevent the use of dangerous, high-permission extensions, what do you use?
Q4. To apply different Chrome policies per department, which best fits?
Q5. Which correctly contrasts Chrome browser management and ChromeOS device management?
Q6. Which best describes a key benefit of enrolling browsers into the org?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

