Instiq
Chapter 5 · Managing browsers and endpoints·v1.0.0·Updated 6/15/2026·~13 min

What's changed: Created Associate Google Workspace Administrator Chapter 5 (Domain 5 "Browsers/endpoints": Chrome browser management = Chrome Browser Cloud Management/centralized policy/extension allow-block-force-install; endpoint management = basic/advanced, company-owned/BYOD, screen lock/encryption/remote wipe/account wipe, mobile app management).

5.2Endpoint (device) management

Key points

Understand the difference between basic and advanced endpoint management for mobile/PC, handling company-owned vs personal (BYOD) devices, on-device data protection (screen lock, encryption, remote wipe), app management, and lost-device response.

Since phones and PCs access Workspace data, endpoint (device) management is essential. Define how to protect on-device data and respond to loss.

5.2.1Basic and advanced management

Basic management applies minimal protection (e.g., requiring a screen lock) with no extra setup. Advanced management enables device approval, finer policies, and remote data wipe (remote wipe). Manage company-owned devices strongly, while for personal (BYOD) protect only work data (without intruding too far into private space). Map "minimal = basic management" and "approval and remote wipe = advanced management."

5.2.2Data protection and app management

Protect on-device data with screen lock (passcode/biometric), encryption, and wipe-after-failed-attempts. If a device is lost/stolen, use remote wipe to erase work data (advanced management). Also do mobile app management (push required apps, allow/block). Map "erase work data on loss = remote wipe" and "protect only work data on personal devices = account wipe/selective erase."

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.