Instiq
Chapter 5 · Managing browsers and endpoints·v1.0.0·Updated 6/15/2026·~13 min

What's changed: Created Associate Google Workspace Administrator Chapter 5 (Domain 5 "Browsers/endpoints": Chrome browser management = Chrome Browser Cloud Management/centralized policy/extension allow-block-force-install; endpoint management = basic/advanced, company-owned/BYOD, screen lock/encryption/remote wipe/account wipe, mobile app management).

5.2Endpoint (device) management

Key points

Understand the difference between basic and advanced endpoint management for mobile/PC, handling company-owned vs personal (BYOD) devices, on-device data protection (screen lock, encryption, remote wipe), app management, and lost-device response.

Since phones and PCs access Workspace data, endpoint (device) management is essential. Define how to protect on-device data and respond to loss.

5.2.1Basic and advanced management

Basic management applies minimal protection (e.g., requiring a screen lock) with no extra setup. Advanced management enables device approval, finer policies, and remote data wipe (remote wipe). Manage company-owned devices strongly, while for personal (BYOD) protect only work data (without intruding too far into private space). Map "minimal = basic management" and "approval and remote wipe = advanced management."

5.2.2Data protection and app management

Protect on-device data with screen lock (passcode/biometric), encryption, and wipe-after-failed-attempts. If a device is lost/stolen, use remote wipe to erase work data (advanced management). Also do mobile app management (push required apps, allow/block). Map "erase work data on loss = remote wipe" and "protect only work data on personal devices = account wipe/selective erase."

Exam point

Common: requirement → means. E.g., "apply only a minimal screen lock" = basic management; "device approval and remote wipe" = advanced management; "erase work data on a lost device" = remote wipe; "protect only work data on personal devices" = account wipe (selective erase); "push required apps" = mobile app management.

Warning

Watch the mix-ups: (1) Do not confuse basic (minimal) and advanced (approval/remote wipe) management. (2) For BYOD, prefer account wipe (work data only) over full wipe. (3) Advanced management may depend on edition.

Diagram of basic management (minimal screen lock) vs advanced (approval/remote wipe), company-owned/BYOD (account wipe), screen lock/encryption/remote wipe, and mobile app management.
Protect data on devices

5.2.3Section summary

  • Basic = minimal protection; advanced = approval/finer policy/remote wipe
  • Data protection = screen lock/encryption/remote wipe on loss
  • BYOD: protect only work data (account wipe); company-owned: strong management

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To erase only work data from a lost smartphone, what do you use?

Q2. To apply minimal protection like requiring a screen lock without extra setup, which is it?

Q3. To perform strong controls like device approval and remote wipe, which is it?

Q4. On a personal (BYOD) device, to protect/erase only work data without intruding on private space, which is most appropriate?

Q5. Which combination best protects work data on devices?

Q6. To distribute required mobile apps to managed devices, what do you use?

Check your understandingPractice questions for Chapter 5: Managing browsers and endpoints

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.