Google:Cat_Google / Google Chrome
AbusiveExperienceInterventionEnforce Abusive Experience Intervention Enforce
If SafeBrowsingEnabled is not Disabled, then setting AbusiveExperienceInterventionEnforce to Enabled or leaving it unset prevents sites with abusive experiences from opening new windows or tabs.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AbusiveExperienceInterventionEnforce
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If SafeBrowsingEnabled is not Disabled, then setting AbusiveExperienceInterventionEnforce to Enabled or leaving it unset prevents sites with abusive experiences from opening new windows or tabs. Setting SafeBrowsingEnabled to Disabled or AbusiveExperienceInterventionEnforce to Disabled lets sites with abusive experiences open new windows or tabs.
AdsSettingForIntrusiveAdsSites Ads setting for sites with intrusive ads
Unless SafeBrowsingEnabled is set to False, then setting AdsSettingForIntrusiveAdsSites to 1 or leaving it unset allows ads on all sites.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AdsSettingForIntrusiveAdsSites
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow ads on all sites2Do not allow ads on sites with intrusive adsUnless SafeBrowsingEnabled is set to False, then setting AdsSettingForIntrusiveAdsSites to 1 or leaving it unset allows ads on all sites. Setting the policy to 2 blocks ads on sites with intrusive ads.
URLAllowlist Allow access to a list of URLs
Leaving the policy unset allows no exceptions to URLBlocklist.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\URLAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy provides access to the listed URLs, as exceptions to URLBlocklist. See that policy's description for the format of entries of this list. For example, setting URLBlocklist to * will block all requests, and you can use this policy to allow access to a limited list of URLs. Use it to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths, using the format specified at ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). The most specific filter determines if a URL is blocked or allowed. The URLAllowlist policy takes precedence over URLBlocklist. This policy is limited to 1,000 entries. This policy also allows enabling the automatic invocation by the browser of external application registered as protocol handlers for the listed protocols like "tel:" or "ssh:". Leaving the policy unset allows no exceptions to URLBlocklist. From Google Chrome version 92, this policy is also supported in the headless mode. Example value: example.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
IncognitoModeUrlAllowlist Allow access to a list of URLs in Incognito mode.
Leaving the policy unset allows no exceptions to IncognitoModeUrlBlocklist and IncognitoModeAvailability.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\IncognitoModeUrlAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy provides access to the listed URLs in Incognito mode. Use it to open exceptions to certain URL patterns defined in IncognitoModeUrlBlocklist, using the format specified at ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). If both this policy and IncognitoModeUrlBlocklist are set, the allowlist takes precedence. If a URL matches a pattern on the allowlist, it will be allowed. If it matches a pattern on the blocklist (but not the allowlist), it will be blocked. If a URL matches neither, the general URLBlocklist/URLAllowlist policies will be used as a fallback. If this policy is set and IncognitoModeUrlBlocklist is not, any URL not on the allowlist will be blocked in Incognito mode. If IncognitoModeAvailability is set to disallow (value 1), but this policy is configured, Incognito mode will be available only for the URLs matching the allowlist. Leaving the policy unset allows no exceptions to IncognitoModeUrlBlocklist and IncognitoModeAvailability. This policy only affects Incognito mode. To allow URLs for all user profiles, please use the URLAllowlist policy. This policy is limited to 1000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
ChromeForTestingAllowed Allow Chrome for Testing
If this policy is set to Enabled or not set, users may install and run Chrome for Testing.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeForTestingAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls whether users may use Chrome for Testing. If this policy is set to Enabled or not set, users may install and run Chrome for Testing. If this policy is set to Disabled, users are not allowed to run Chrome for Testing. Users will still be able to install Chrome for Testing, however it will not run with the profiles where this policy is set to Disabled.
SandboxExternalProtocolBlocked Allow Chrome to block navigations toward external protocols in sandboxed iframes
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SandboxExternalProtocolBlocked
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Chrome will block navigations toward external protocols inside sandboxed iframe. See https://chromestatus.com/features/5680742077038592. When True, this lets Chrome blocks those navigations. When False, this prevents Chrome from blocking those navigations. This defaults to True: security feature enabled. This can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 117.
WebRtcEventLogCollectionAllowed Allow collection of WebRTC event logs from Google services
Leaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebRtcEventLogCollectionAllowed
- Enabled / Disabled
- 1 / 0
- Stated default
- From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means Google Chrome can collect WebRTC event logs from Google services such as Hangouts Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as the time and size of RTP packets, feedback about congestion on the network, and metadata about time and quality of audio and video frames. These logs have no audio or video content from the meeting. To make debugging easier, Google might associate these logs, by means of a session ID, with other logs collected by the Google service itself. Setting the policy to Disabled results in no collection or uploading of such logs. Leaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs. Starting at M77, Google Chrome defaults to being able to collect and upload these logs from most profiles affected by cloud-based, user-level enterprise policies. From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.
DefaultSearchProviderContextMenuAccessAllowed Allow default search provider context menu search access
If this policy is set to enabled or not set, the context menu item for your default search provider will be available.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderContextMenuAccessAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enables the use of a default search provider on the context menu. If you set this policy to disabled the search context menu item that relies on your default search provider will not be available. If this policy is set to enabled or not set, the context menu item for your default search provider will be available. The policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.
AllowDinosaurEasterEgg Allow Dinosaur Easter Egg Game
Leaving the policy unset means users can't play the game on enrolled Google ChromeOS, but can under other circumstances.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowDinosaurEasterEgg
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True allows users to play the dinosaur game. Setting the policy to False means users can't play the dinosaur easter egg game when device is offline. Leaving the policy unset means users can't play the game on enrolled Google ChromeOS, but can under other circumstances.
AdditionalDnsQueryTypesEnabled Allow DNS queries for additional DNS record types
If this policy is unset or set to Enabled, additional types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AdditionalDnsQueryTypesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether Google Chrome may query additional DNS record types when making insecure DNS requests. This policy has no effect on DNS queries made via Secure DNS, which may always query additional DNS types. If this policy is unset or set to Enabled, additional types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28). If this policy is set to Disabled, DNS will only be queried for A (DNS type 1) and/or AAAA (DNS type 28). This policy is a temporary measure and will be removed in future versions of Google Chrome. After removal of the policy, Google Chrome will always be able to query additional DNS types.
DownloadRestrictions Allow download restrictions
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DownloadRestrictions
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0No special restrictions. Default.1Block malicious downloads and dangerous file types.2Block malicious downloads, uncommon or unwanted downloads and dangerous file types.3Block all downloads.4Block malicious downloads. Recommended.Setting the policy means users can't bypass download security decisions. There are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked): * Malicious, as flagged by the Safe Browsing server * Uncommon or unwanted, as flagged by the Safe Browsing server * A dangerous file type (e.g. all SWF downloads and many EXE downloads) Setting the policy blocks different subsets of these, depending on it's value: 0: No special restrictions. Default. 1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 3: Blocks all downloads. Not recommended, except for special use cases. 4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended. Note: These restrictions apply to downloads triggered from webpage content, as well as the Download link… menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).
FileOrDirectoryPickerWithoutGestureAllowedForOrigins Allow file or directory picker APIs to be called without prior user gesture
If this policy is unset, all origins will require a prior user gesture to call these APIs.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\FileOrDirectoryPickerWithoutGestureAllowedForOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
For security reasons, the showOpenFilePicker(), showSaveFilePicker() and showDirectoryPicker() web APIs require a prior user gesture ("transient activation") to be called or will otherwise fail. With this policy set, admins can specify origins on which these APIs can be called without prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. * is not an accepted value for this policy. If this policy is unset, all origins will require a prior user gesture to call these APIs. Example value: https://www.example.com [*.]example.edu
FullscreenAllowed Allow fullscreen mode
Setting the policy to True or leaving it unset means that, with appropriate permissions, users, apps, and extensions can enter Fullscreen mode (in which only web content appears).
- Registry key
- Software\Policies\Google\Chrome
- Value name
- FullscreenAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset means that, with appropriate permissions, users, apps, and extensions can enter Fullscreen mode (in which only web content appears). Setting the policy to False means users, apps, and extensions can't enter Fullscreen mode.
HttpsOnlyMode Allow HTTPS-Only Mode to be enabled
If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HttpsOnlyMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Do not restrict users' HTTPS-Only Mode settingDisable HTTPS-Only ModeEnable HTTPS-Only Mode in Strict modeEnable HTTPS-Only Mode in Balanced ModeThis policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode upgrades all navigations to HTTPS. If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode. If this setting is set to "disallowed", HTTPS-Only Mode will be disabled. If this setting is set to "force_enabled", HTTPS-Only Mode will be enabled in Strict mode. If this setting is set to "force_balanced_enabled", HTTPS-Only Mode will be enabled in Balanced mode. "force_enabled" is supported from M112 onwards, "force_balanced_enabled" is supported from M129 onwards. "force_enabled" and "force_balanced_enabled" can be recommended to users too. HTTPS-Only Mode will be set Strict or Balanced initially but users are allowed to change it. If you set this policy to a value that is not supported by the version of Chrome that receives the policy, Chrome will default to the allowed setting. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. Example value: disallowed
AllowFileSelectionDialogs Allow invocation of file selection dialogs
Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowFileSelectionDialogs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs. Setting the policy to Disabled means that whenever users perform actions provoking a file selection dialog, such as importing bookmarks, uploading files, and saving links, a message appears instead. The user is assumed to have clicked Cancel on the file selection dialog.
AutoplayAllowed Allow media autoplay
If this policy is left unset, Google Chrome doesn't autoplay media.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AutoplayAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True lets Google Chrome autoplay media. Setting the policy to False stops Google Chrome from autoplaying media. If this policy is left unset, Google Chrome doesn't autoplay media. But, for certain URL patterns, you can use the AutoplayAllowlist policy to change this setting. If this policy changes while Google Chrome is running, it only applies to newly opened tabs.
AutoplayAllowlist Allow media autoplay on a allowlist of URL patterns
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutoplayAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets videos play automatically (without user consent) with audio content in Google Chrome. If AutoplayAllowed policy is set to True, then this policy has no effect. If AutoplayAllowed is set to False, then any URL patterns set in this policy can still play. If this policy changes while Google Chrome is running, it only applies to newly opened tabs. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. Example value: https://www.example.com [*.]example.edu
PolicyDictionaryMultipleSourceMergeList Allow merging dictionary policies from different sources
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PolicyDictionaryMultipleSourceMergeList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level. This merging is in the first level keys of the dictionary from each source. The key coming from the highest priority source takes precedence. Use the wildcard character '*' to allow merging of all supported dictionary policies. If a policy is in the list and there's conflict between sources with: * The same scopes and level: The values merge into a new policy dictionary. * Different scopes or level: The policy with the highest priority applies. If a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies. Example value: ExtensionSettings
PolicyListMultipleSourceMergeList Allow merging list policies from different sources
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PolicyListMultipleSourceMergeList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level. Use the wildcard character '*' to allow merging of all list policies. If a policy is in the list and there's conflict between sources with: * The same scopes and level: The values merge into a new policy list. * Different scopes or level: The policy with the highest priority applies. If a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies. Example value: ExtensionInstallAllowlist ExtensionInstallBlocklist
AudioCaptureAllowed Allow or deny audio capture
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AudioCaptureAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access. Setting the policy to Disabled turns off prompts, and audio capture is only available to URLs set in the AudioCaptureAllowedUrls list. Note: The policy affects all audio input (not just the built-in microphone).
VideoCaptureAllowed Allow or deny video capture
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the VideoCaptureAllowedUrls list, users get prompted for video capture access.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- VideoCaptureAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the VideoCaptureAllowedUrls list, users get prompted for video capture access. Setting the policy to Disabled turns off prompts, and video capture is only available to URLs set in the VideoCaptureAllowedUrls list. Note: The policy affects all video input (not just the built-in camera).
BuiltInAIAPIsEnabled Allow pages to use the built-in AI APIs.
If the policy is enabled or unset, the APIs are enabled to be used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BuiltInAIAPIsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls if a page can use the built-in AI APIs (such as LanguageModel API, Summarization API, Writer API, and Rewriter API). If the policy is enabled or unset, the APIs are enabled to be used. If the policy is disabled, attempting using the APIs will result in an error.
AllowBackForwardCacheForCacheControlNoStorePageEnabled Allow pages with Cache-Control: no-store header to enter back/forward cache
If the policy is enabled or unset, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowBackForwardCacheForCacheControlNoStorePageEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls if a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it is no longer accessible. If the policy is enabled or unset, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.g. when there is HTTP-only cookie change to the site). If the policy is disabled, the page with Cache-Control: no-store header will not be stored in back/forward cache.
SSLErrorOverrideAllowed Allow proceeding from the SSL warning page
Setting the policy to Enabled or leaving it unset lets users click through warning pages Google Chrome shows when users navigate to sites that have SSL errors.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SSLErrorOverrideAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset lets users click through warning pages Google Chrome shows when users navigate to sites that have SSL errors. Setting the policy to Disabled prevent users from clicking through any warning pages.
SSLErrorOverrideAllowedForOrigins Allow proceeding from the SSL warning page on specific origins
If SSLErrorOverrideAllowed is Enabled or unset, this policy does nothing. Leaving the policy unset means SSLErrorOverrideAllowed applies for all sites.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SSLErrorOverrideAllowedForOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If SSLErrorOverrideAllowed is Disabled, setting the policy lets you set a list of origin patterns that specify the sites where a user can click through warning pages Google Chrome shows when users navigate to sites that have SSL errors. Users will not be able to click through SSL warning pages on origins that are not on this list. If SSLErrorOverrideAllowed is Enabled or unset, this policy does nothing. Leaving the policy unset means SSLErrorOverrideAllowed applies for all sites. For detailed information on valid input patterns, please see https://chromeenterprise.google/policies/url-patterns/. * is not an accepted value for this policy. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
BrowserNetworkTimeQueriesEnabled Allow queries to a Google time service
Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserNetworkTimeQueriesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp. Setting the policy to Disabled stops Google Chrome from sending these queries.
QuicAllowed Allow QUIC protocol
Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- QuicAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome. Setting the policy to Disabled disallows the use of QUIC protocol.
RemoteDebuggingAllowed Allow remote debugging
If this policy is set to Enabled or not set, users may use remote debugging by specifying --remote-debugging-port and --remote-debugging-pipe command line switches.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteDebuggingAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls whether users may use remote debugging. If this policy is set to Enabled or not set, users may use remote debugging by specifying --remote-debugging-port and --remote-debugging-pipe command line switches. If this policy is set to Disabled, users are not allowed to use remote debugging.
DomainReliabilityAllowed Allow reporting of domain reliability related data
If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DomainReliabilityAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google. If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
ScreenCaptureWithoutGestureAllowedForOrigins Allow screen capture without prior user gesture
If this policy is unset, all origins will require a prior user gesture to call this API.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ScreenCaptureWithoutGestureAllowedForOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
For security reasons, the getDisplayMedia() web API requires a prior user gesture ("transient activation") to be called or will otherwise fail. With this policy set, admins can specify origins on which this API can be called without prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. * is not an accepted value for this policy. If this policy is unset, all origins will require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
ServiceWorkerToControlSrcdocIframeEnabled Allow ServiceWorker to control srcdoc iframes
Setting the policy to Enabled or leaving it unset means Google Chrome makes srcdoc iframes with "allow-same-origin" sandbox attributes to be under ServiceWorker control.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ServiceWorkerToControlSrcdocIframeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the "allow-same-origin" sandbox attribute to be under ServiceWorker control. Setting the policy to Enabled or leaving it unset means Google Chrome makes srcdoc iframes with "allow-same-origin" sandbox attributes to be under ServiceWorker control. Setting the policy to Disabled leaves the srcdoc iframe not controlled by ServiceWorker. This policy is intended to be temporary and will be removed in 2026.
ServiceWorkerAutoPreloadEnabled Allow ServiceWorker to dispatch navigation requests without waiting for its startup
Setting the policy to Enabled or leaving it unset means Google Chrome enables ServiceWorkerAutoPreload.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ServiceWorkerAutoPreloadEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
https://github.com/WICG/service-worker-auto-preload The ServiceWorkerAutoPreload feature dispatches a network request for a main resource at the same time it begins the ServiceWorker bootstrap process. Setting the policy to Enabled or leaving it unset means Google Chrome enables ServiceWorkerAutoPreload. The navigation request is automatically dispatched while starting the ServiceWorker in some scenarios, e.g. ServiceWorker is not running, If it is disabled, Google Chrome will not enable ServiceWorkerAutoPreload. The navigation request is dispatched always after starting the ServiceWorker. This policy is a temporary measure to control the feature and will be removed in M154.
SideSearchEnabled Allow showing the most recent default search engine results page in a Browser side panel
Setting the policy to Enabled or leaving the policy unset means that users can bring up their most recent default search engine results page in a side panel via toggling an icon in the toolbar.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SideSearchEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving the policy unset means that users can bring up their most recent default search engine results page in a side panel via toggling an icon in the toolbar. Setting the policy to Disabled removes the icon from the toolbar that opens the side panel with the default search engine results page.
AllowSocketPoolSizeRandomizationForProxies Allow socket pool size randomization for proxies
This is enabled by default for all pools, but this policy allows the feature to be disabled for proxy pools specifically.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowSocketPoolSizeRandomizationForProxies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Socket pool size randomization is a security mechanism that prevents attackers from exploiting deterministic capacity limits to learn cross-site information. If the capacity for a pool is normally 128 sockets, this mechanism randomly caps the pool between 128 and 256. This can allow up to 2x as many connections to the proxy, but in practice the expected value is more like 1.2x. This impacts the settings from MaxConnectionsPerProxy and MaxConnectionsPerProxyForWebSocket. Instead of them defining the upper limit, the upper limit is 2x their values (though again, the expected value in practice is more like 1.2x them). This is enabled by default for all pools, but this policy allows the feature to be disabled for proxy pools specifically.
EnableUnsafeSwiftShader Allow software WebGL fallback using SwiftShader
Setting the policy to Disabled or not set, WebGL context creation may fail if hardware GPU acceleration is not available.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableUnsafeSwiftShader
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A policy that controls if SwiftShader will be used as a WebGL fallback when hardware GPU acceleration is not available. SwiftShader has been used to support WebGL on systems without GPU acceleration such as headless systems or virtual machines but has been deprecated due to security issues. Starting in M139, WebGL context creation will fail when it would have otherwise used SwiftShader. This policy allows the browser or administrator to temporarily defer the deprecation. Setting the policy to Enabled, SwiftShader will be used as a software WebGL fallback. Setting the policy to Disabled or not set, WebGL context creation may fail if hardware GPU acceleration is not available. Web pages may misbehave if they do not gracefully handle WebGL context creation failure. This is a temporary policy which will be removed in the future.
PrefetchWithServiceWorkerEnabled Allow SpeculationRules prefetch to ServiceWorker-controlled URLs
Setting this policy to Enabled or not set allows SpeculationRules prefetch to ServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is enabled).
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrefetchWithServiceWorkerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
SpeculationRules prefetch can be issued to URLs that are controlled by ServiceWorker. However, legacy code did not allow it and canceled the prefetch requests. This policy enables to control the behavior. Setting this policy to Enabled or not set allows SpeculationRules prefetch to ServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is enabled). This is the current default behavior and is aligned with the specifications. Setting this policy to Disabled disallows SpeculationRules prefetch to ServiceWorker-controlled URLs. This is the legacy behavior. This policy is intended to be temporary and will be removed in the future.
AudioProcessHighPriorityEnabled Allow the audio process to run with priority above normal on Windows
If this policy is not set, the default configuration for the audio process will be used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AudioProcessHighPriorityEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the priority of the audio process on Windows. If this policy is enabled, the audio process will run with above normal priority. If this policy is disabled, the audio process will run with normal priority. If this policy is not set, the default configuration for the audio process will be used. This policy is intended as a temporary measure to give enterprises the ability to run audio with higher priority to address certain performance issues with audio capture. This policy will be removed in the future.
AudioSandboxEnabled Allow the audio sandbox to run
If this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AudioSandboxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the audio process sandbox. If this policy is enabled, the audio process will run sandboxed. If this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process. This leaves users open to security risks related to running the audio subsystem unsandboxed. If this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform. This policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.
ShoppingListEnabled Allow the shopping list feature to be enabled
If this policy is set to Enabled or not set, the shopping list feature will be available to users.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ShoppingListEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the availability of the shopping list feature. If enabled, users will be presented with UI to track the price of the product displayed on the current page. The tracked product will be shown in the bookmarks side panel. If this policy is set to Enabled or not set, the shopping list feature will be available to users. If this policy is set to Disabled, the shopping list feature will be unavailable.
TranslatorAPIAllowed Allow Translator API
Setting the policy to Enabled or leaving it unset allows the use of Translator API in Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TranslatorAPIAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset allows the use of Translator API in Google Chrome. Setting the policy to Disabled disallows the use of Translator API.
CloudUserPolicyOverridesCloudMachinePolicy Allow user cloud policies to override Chrome Browser Cloud Management policies.
Setting the policy to Disabled or leaving it unset causes user-level cloud policies to have default priority.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudUserPolicyOverridesCloudMachinePolicy
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled allows policies associated with a managed account to take precedence if they conflict with Chrome Enterprise Core browser policies. Setting the policy to Disabled or leaving it unset causes user-level cloud policies to have default priority. Only policies originating from secure users can take precedence. A secure user is affiliated with the organization that manages their browser using Chrome Enterprise Core. All other user-level policies will have default precedence. The policy can be combined with CloudPolicyOverridesPlatformPolicy. If both policies are enabled, user cloud policies will also take precedence over conflicting platform policies.
UserFeedbackAllowed Allow user feedback
Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UserFeedbackAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination. Setting the policy to Disabled means users can't send feedback to Google.
NTPCustomBackgroundEnabled Allow users to customize the background on the New Tab page
If the policy is set to true or unset, users can customize the background on the New Tab page.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPCustomBackgroundEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later. If the policy is set to true or unset, users can customize the background on the New Tab page.
AllowWebAuthnWithBrokenTlsCerts Allow Web Authentication requests on sites with broken TLS certificates.
If the policy is set to Disabled or left unset, the default behavior of blocking such requests will apply.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowWebAuthnWithBrokenTlsCerts
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If set to Enabled, Google Chrome will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure). If the policy is set to Disabled or left unset, the default behavior of blocking such requests will apply.
WebRtcTextLogCollectionAllowed Allow WebRTC text logs collection from Google Services
Leaving the policy unset means Google Chrome defaults to being able to collect and upload these logs.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebRtcTextLogCollectionAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to enabled means Google Chrome can collect WebRTC text logs from Google services such as Google Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as textual metadata describing incoming and outgoing WebRTC streams, WebRTC specific log entries and additional system information. These logs have no audio or video content from the meeting. Setting the policy to disabled results in no uploading of such logs to Google. Logs would still accumulate locally on the user's device. Leaving the policy unset means Google Chrome defaults to being able to collect and upload these logs.
PaymentMethodQueryEnabled Allow websites to query for available payment methods.
If the setting is enabled or not set then websites are allowed to check if the user has payment methods saved.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PaymentMethodQueryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set whether websites are allowed to check if the user has payment methods saved. If this policy is set to disabled, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available. If the setting is enabled or not set then websites are allowed to check if the user has payment methods saved.
WebAuthenticationRemoteDesktopAllowedOrigins Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebAuthenticationRemoteDesktopAllowedOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A list of origins of remote desktop client apps that may execute WebAuthn API requests that originate from a browsing session on a remote host. Any origin configured in this policy can make WebAuthn requests for Relying Party IDs (RP IDs) that it would normally not allowed to be able to claim. Only valid HTTPS origins are allowed. Wildcards are not supported. Any invalid entries are ignored. This policy only applies to affiliated users. Example value: https://remotedesktop.google.com https://vdi.corp.example https://server:8080/
OriginAgentClusterDefaultEnabled Allows origin-keyed agent clustering by default.
If this policy is enabled or not set, the browser will follow this new default from that version on.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- OriginAgentClusterDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- This policy allows origin-keyed agent clustering by default. domain accessor remains settable by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows origin-keyed agent clustering by default. The Origin-Agent-Cluster HTTP header controls whether a document is isolated in an origin-keyed agent cluster, or in a site-keyed agent cluster. This has security implications since an origin-keyed agent cluster allows isolating documents by origin. The developer-visible consequence of this is that the document.domain accessor can no longer be set. The default behaviour - when no Origin-Agent-Cluster header has been set - changes in M111 from site-keyed to origin-keyed. If this policy is enabled or not set, the browser will follow this new default from that version on. If this policy is disabled this change is reversed and documents without Origin-Agent-Cluster headers will be assigned to site-keyed agent clusters. As a consequence, the document.domain accessor remains settable by default. This matches the legacy behaviour. See https://developer.chrome.com/blog/immutable-document-domain/ for additional details.
AlwaysOpenPdfExternally Always Open PDF files externally
If not set, users can choose whether to open PDF externally or not.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AlwaysOpenPdfExternally
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application. Setting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files. If you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.
ApplicationLocaleValue Application locale
Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured).
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ApplicationLocaleValue
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the locale Google Chrome uses. Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured). 2) The system locale. 3) The fallback locale (en-US). Example value: en
PromptForDownloadLocation Ask where to save each file before downloading
Leaving the policy unset lets users change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PromptForDownloadLocation
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means users are asked where to save each file before downloading. Setting the policy to Disabled has downloads start immediately, and users aren't asked where to save the file. Leaving the policy unset lets users change this setting.
URLBlocklist Block access to a list of URLs
If left unset, no URLs are blocked in the browser.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\URLBlocklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the URLBlocklist policy stops web pages with prohibited URLs from loading. Administrators can specify the list of URL patterns to be blocked. If left unset, no URLs are blocked in the browser. Up to 1,000 exceptions can be defined in URLAllowlist. See how to format a URL pattern ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). Note: This policy does not apply to in-page JavaScript URLs with dynamically loaded data. If you blocked example.com/abc, then example.com could still load it using XMLHTTPRequest. Additionally, this policy does not prevent web pages from updating the URL shown in the omnibox to a blocked one using the JavaScript History API. From Google Chrome version 73, you can block javascript://* URLs. But, this only affects JavaScript entered in the address bar or, for example, bookmarklets. From Google Chrome version 92, this policy is also supported in the headless mode. From Google Chrome version 147, the wildcard * on its own does not apply to internal chrome:// URLs. To block these, you must explicitly use the chrome://* pattern. Note: Blocking internal chrome://* and chrome-untrusted://* URLs can lead to unexpected errors or can be circumvented in some cases. Instead of blocking certain internal URLs, see if there are more specific policies available. For example: - Instead of blocking chrome://settings/certificates, use CACertificateManagementAllowed. - Instead of blocking chrome-untrusted://crosh, use SystemFeaturesDisableList. - Instead of blocking devtools://*, use one of the DeveloperToolsAvailability, DeveloperToolsAvailabilityAllowlist or DeveloperToolsAvailabilityBlocklist policies. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
IncognitoModeUrlBlocklist Block access to a list of URLs in Incognito mode.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\IncognitoModeUrlBlocklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the IncognitoModeUrlBlocklist policy stops web pages with prohibited URLs from loading in Incognito mode. Administrators can specify the list of URL patterns to be blocked. See how to format a URL pattern ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). If both this and the IncognitoModeUrlAllowlist are set, the allowlist takes precedence. If a URL matches a pattern on the allowlist, it will be allowed. If it matches a pattern on the blocklist but not the allowlist, it will be blocked. If a URL matches neither, the general URLBlocklist/URLAllowlist policies will be used as a fallback. If the IncognitoModeUrlAllowlist policy is set and this policy is not, any URL not on the allowlist will be blocked in Incognito mode. If IncognitoModeAvailability is set to disallow (value 1), but the IncognitoModeUrlAllowlist policy is configured, Incognito mode will be available only for the URLs matching the allowlist. This policy only affects Incognito mode. To block URLs for all user profiles, please use the URLBlocklist policy. This policy is limited to 1000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
BrowserLegacyExtensionPointsBlocked Block Browser Legacy Extension Points
Setting the policy to Enabled or leaving it unset will permit Google Chrome to apply the additional extension point security mitigation to block legacy extension points in the Browser process.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserLegacyExtensionPointsBlocked
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset will permit Google Chrome to apply the additional extension point security mitigation to block legacy extension points in the Browser process. Setting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's browser process. Note: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).
BlockThirdPartyCookies Block third party cookies
Leaving it unset allows third-party cookies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BlockThirdPartyCookies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting. Leaving it unset allows third-party cookies, but users can change this setting. Note: This policy doesn't apply in Incognito mode, where third-party cookies are blocked and can only be allowed at the site level. To allow cookies at the site level, use the CookiesAllowedForUrls policy.
BrowserLabsEnabled Browser experiments icon in toolbar
Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar Setting the policy to Disabled removes the browser experimental features icon from the toolbar.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserLabsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar Setting the policy to Disabled removes the browser experimental features icon from the toolbar. chrome://flags and any other means of turning off and on browser features will still behave as expected regardless of whether this policy is Enabled or Disabled.
BrowserSignin Browser sign in settings
If this policy is not set then the user can decide if they want to enable browser sign-in in the Google Chrome settings and use it as they see fit.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSignin
- Stated default
- However, it does not mean that Google Chrome Sync will be turned on by default; the user must separately opt-in to use this feature.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Disable browser sign-in1Enable browser sign-in2Force users to sign-in to use the browserThis policy controls the sign-in behavior of the browser. It allows you to specify if the user can sign in to Google Chrome with their account and use account related services like Google Chrome Sync. If the policy is set to "Disable browser sign-in" then the user cannot sign in to the browser and use account-based services. In this case browser-level features like Google Chrome Sync cannot be used and will be unavailable. On iOS, if the user was signed in and the policy is set to "Disabled" they will be signed out immediately. On other platforms, they will be signed out the next time they run Google Chrome. On all platforms, their local profile data like bookmarks, passwords etc. will be preserved and still usable. The user will still be able to sign into and use Google web services like Gmail. If the policy is set to "Enable browser sign-in," then the user is allowed to sign in to the browser. On all platforms except iOS, the user is automatically signed in to the browser when signed in to Google web services like Gmail. Being signed in to the browser means the user's account information will be kept by the browser. However, it does not mean that Google Chrome Sync will be turned on by default; the user must separately opt-in to use this feature. Enabling this policy will prevent the user from turning off the setting that allows browser sign-in. To control the availability of Google Chrome Sync, use the SyncDisabled policy. If the policy is set to "Force browser sign-in" the user is presented with an account selection dialog and has to choose and sign in to an account to use the browser. This ensures that for managed accounts the policies associated with the account are applied and enforced. The default value of BrowserGuestModeEnabled will be set to disabled. Note that existing unsigned profiles will be locked and inaccessible after enabling this policy. For more information, see help center article: https://support.google.com/chrome/?p=force_browser_signin . This option is not supported on Google ChromeOS nor Android, where it will fall back to "Enable browser sign-in" if used. If this policy is not set then the user can decide if they want to enable browser sign-in in the Google Chrome settings and use it as they see fit.
BrowsingDataLifetime Browsing Data Lifetime Settings
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowsingDataLifetime
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. Warning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data. The available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'. 'download_history' and 'hosted_app_data' are not supported on Android. The browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour. The deletion of expired data will happen 15 seconds after the browser starts then every 30 minutes while the browser is running. The user will stay signed into their Google account when deleting cookies. Until Chrome 114, this policy required the SyncDisabled policy to be set to true. Starting Chrome 115, setting this policy will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled. See https://chromeenterprise.google/policies/?policy=BrowsingDataLifetime for more information about schema and formatting. Example value: [ { "data_types": [ "browsing_history" ], "time_to_live_in_hours": 24 }, { "data_types": [ "password_signin", "autofill" ], "time_to_live_in_hours": 12 } ]
MemorySaverModeSavings Change Memory Saver Mode Savings
If this policy is unset, the end user can control this setting in chrome://settings/performance.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MemorySaverModeSavings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Moderate memory savings.1Balanced memory savings.2Maximum memory savings.This policy changes the savings level of Memory Saver. This only takes effect when Memory Saver is enabled through settings or through the HighEfficiencyModeEnabled policy, and will affect how heuristics are used to determine when to discard tabs. For example, reducing the lifetime of an inactive tab before discarding it can save memory, but it also means that tabs will be reloaded more frequently which can lead to bad user experience and cost more network traffic. Setting the policy to 0 - Memory Saver will get moderate memory savings. Tabs become inactive after a longer period of time Setting the policy to 1 - Memory Saver will get balanced memory savings. Tabs become inactive after an optimal period of time. Setting the policy to 2 - Memory Saver will get maximum memory savings. Tabs become inactive after a shorter period of time. If this policy is unset, the end user can control this setting in chrome://settings/performance.
ClearBrowsingDataOnExitList Clear Browsing Data on Exit
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ClearBrowsingDataOnExitList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Configures a list of browsing data types that should be deleted when the user closes all browser windows. Warning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data. The available data types are browsing history (browsing_history), download history (download_history), cookies (cookies_and_other_site_data), cache(cached_images_and_files), autofill (autofill), passwords (password_signin), site settings (site_settings) and hosted apps data (hosted_app_data). This policy does not take precedence over AllowDeletingBrowserHistory. The user will stay signed into their Google account when deleting cookies. Until Chrome 114, this policy required the SyncDisabled policy to be set to true. Starting Chrome 115, setting this policy will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled. If for some reason the data deletion has started and did not complete, the browsing data will be cleared the next time the profile is loaded. If Google Chrome does not exit cleanly (for example, if the browser or the OS crashes), the browsing data will not be cleared since the browser closing was not a result of the use closing all the browser windows. Example value: browsing_history download_history cookies_and_other_site_data cached_images_and_files password_signin autofill site_settings hosted_app_data
WebAppInstallForceList Configure list of force-installed Web Apps
If disabled or unset, the web app at the given url will be installed normally.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebAppInstallForceList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off. Each list item of the policy is an object with a mandatory member: url (the URL of the web app to install) and 6 optional members: - default_launch_container (for how the web app opens—a new tab is the default) - create_desktop_shortcut (True if you want to create Linux and Microsoft® Windows® desktop shortcuts). - fallback_app_name (Starting with Google Chrome version 90, allows you to override the app name if it is not a Progressive Web App (PWA), or the app name that is temporarily installed if it is a PWA but authentication is required before the installation can be completed. If both custom_name and fallback_app_name are provided, the latter will be ignored.) - custom_name (Starting with Google ChromeOS version 99, and version 112 on all other desktop operating systems, allows you to permanently override the app name for all web apps and PWAs.) - custom_icon (Starting with Google ChromeOS version 99, and version 112 on all other desktop operating systems, allows you to override the app icon of installed apps. The icons have to be square, maximal 1 MB in size, and in one of the following formats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256 hash of the icon file. The url should be accessible without authentication to ensure the icon can be used upon app installation.) - install_as_shortcut (Starting with Google Chrome version 107). If enabled the given url will be installed as a shortcut, as if done via the "Create Shortcut..." option in the desktop browser GUI. Note that when installed as a shortcut it won't be updated if the manifest in url changes. If disabled or unset, the web app at the given url will be installed normally. See PinnedLauncherApps for pinning apps to the Google ChromeOS shelf. See https://chromeenterprise.google/policies/?policy=WebAppInstallForceList for more information about schema and formatting. Example value: [ { "create_desktop_shortcut": true, "default_launch_container": "window", "url": "https://www.google.com/maps" }, { "default_launch_container": "tab", "url": "https://docs.google.com" }, { "default_launch_container": "window", "fallback_app_name": "Editor", "url": "https://docs.google.com/editor" }, { "custom_name": "My important document", "default_launch_container": "window", "install_as_shortcut": true, "url": "https://docs.google.com/document/d/ds187akjqih89" }, { "custom_icon": { "hash": "c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38", "url": "https://mydomain.example.com/sunny_icon.png" }, "url": "https://weather.example.com" } ]
BrowserThemeColor Configure the color of the browser's theme
Leaving the policy unset lets users change their browser's theme as preferred.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserThemeColor
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows admins to configure the color of Google Chrome's theme. The input string should be a valid hex color string matching the format "#RRGGBB". Setting the policy to a valid hex color causes a theme based on that color to be automatically generated and applied to the browser. Users won't be able to change the theme set by the policy. Leaving the policy unset lets users change their browser's theme as preferred. Example value: #FFFFFF
ForcedLanguages Configure the content and order of preferred languages
Leaving the policy unset lets users manipulate the entire list of preferred languages.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ForcedLanguages
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows admins to configure the order of the preferred languages in Google Chrome's settings. The order of the list will appear in the same order under the "Order languages based on your preference" section in chrome://settings/languages. Users won't be able to remove or reorder languages set by the policy, but will be able to add languages underneath those set by the policy. Users will also have full control over the browser's UI language and translation/spell check settings, unless enforced by other policies. Leaving the policy unset lets users manipulate the entire list of preferred languages. Example value: en-US
BackgroundModeEnabled Continue running background apps when Google Chrome is closed
If unset, background mode is off at first, but users can change it.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BackgroundModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there. Setting the policy to Disabled turns background mode off. If you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.
ReduceAcceptLanguageEnabled Control Accept-Language Reduction
If this policy is set to enabled or left unset, Accept-Language Reduction will be applied through field trials.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ReduceAcceptLanguageEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
The Accept-Language HTTP request header and the JavaScript navigator.languages getter are planned for reduction for privacy reasons. To facilitate testing and ensure compatibility, this policy allows you to enable or disable the Accept-Language Reduction feature. If this policy is set to enabled or left unset, Accept-Language Reduction will be applied through field trials. If this policy is set to disabled, field trials will not be able to activate Accept-Language Reduction. For more information about this feature, please visit: https://github.com/explainers-by-googlers/reduce-accept-language. NOTE: Only newly-started renderer processes will reflect changes to this policy while the browser is running.
SafeSitesFilterBehavior Control SafeSites adult content filtering.
When this policy is set to: * Do not filter sites for adult content, or not set, sites aren't filtered * Filter sites for adult content, pornographic sites are filtered The policy applies to both the URL the user navigates to and to iframes.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeSitesFilterBehavior
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Do not filter sites for adult content1Filter sites for adult contentSetting the policy controls the SafeSites URL filter, which uses the Google Safe Search API to classify URLs as pornographic or not. When this policy is set to: * Do not filter sites for adult content, or not set, sites aren't filtered * Filter sites for adult content, pornographic sites are filtered The policy applies to both the URL the user navigates to and to iframes. The URLAllowlist policy takes precedence over this policy and can be used to override verdicts from the Google Safe Search API.
XSLTEnabled Control the availability of the XSLT feature
If this policy is left unset, XSLT availability will be determined by the browser's default settings and field trials.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- XSLTEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the availability of the XSLT feature (the XSLTProcessor Javascript API and the XSL processing instruction). If this policy is set to Enabled, XSLT will be available, regardless of the default state of the feature in the browser. If this policy is set to Disabled, XSLT will be unavailable, regardless of the default state of the feature in the browser. If this policy is left unset, XSLT availability will be determined by the browser's default settings and field trials. This policy is a temporary measure, and will be removed in M164.
IntensiveWakeUpThrottlingEnabled Control the IntensiveWakeUpThrottling feature.
If this policy is left unset then the feature will be controlled by its own internal logic, which can be manually configured by users.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- IntensiveWakeUpThrottlingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When enabled the IntensiveWakeUpThrottling feature causes JavaScript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more. This is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details. If this policy is set to enabled then the feature will be force enabled, and users will not be able to override this. If this policy is set to disabled then the feature will be force disabled, and users will not be able to override this. If this policy is left unset then the feature will be controlled by its own internal logic, which can be manually configured by users. Note that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.
NTPFooterExtensionAttributionEnabled Control the visibility of the extension attribution on the New Tab page
If this policy is left unset or set to true, the extension attribution will be visible on the NTP footer when an extension is controlling the NTP.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPFooterExtensionAttributionEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, if an extension has overridden the standard NTP, a message attributing this change to the specific extension will appear in the footer.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy determines whether an attribution to the extension modifying the New Tab Page (NTP) is displayed in the NTP's footer. By default, if an extension has overridden the standard NTP, a message attributing this change to the specific extension will appear in the footer. This attribution typically includes a link to the relevant extension in the Chrome Web Store. If this policy is left unset or set to true, the extension attribution will be visible on the NTP footer when an extension is controlling the NTP. If this policy is set to false, the attribution to the extension in the NTP footer will be suppressed.
NTPFooterManagementNoticeEnabled Control the visibility of the management notice on the New Tab Page for managed browsers
If this policy is left unset or set to true, managed browsers will display a “Managed by…” notice with an icon.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPFooterManagementNoticeEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, the NTP footer displays information when the browser is managed by an organization (indicated by a building icon and "Managed by [domain name]").
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the visibility of the management notice within the footer of the New Tab Page (NTP). By default, the NTP footer displays information when the browser is managed by an organization (indicated by a building icon and "Managed by [domain name]"). This can be customized using the EnterpriseCustomLabelForBrowser and EnterpriseLogoUrlForBrowser policies. If this policy is left unset or set to true, managed browsers will display a “Managed by…” notice with an icon. If this policy is set to false, the management notice will be hidden. Note that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
HeadlessMode Control use of the Headless Mode
Setting this policy to Enabled or leaving the policy unset allows use of the headless mode.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HeadlessMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow use of the Headless Mode2Do not allow use of the Headless ModeSetting this policy to Enabled or leaving the policy unset allows use of the headless mode. Setting this policy to Disabled denies use of the headless mode.
DeveloperToolsAvailability Control where Developer Tools can be used
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DeveloperToolsAvailability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Disallow usage of the Developer Tools on apps and extensions installed by enterprise policy or, since version 114 and if this is a managed user, extensions built into the browser. Allow usage of the Developer Tools in other contexts1Allow usage of the Developer Tools2Disallow usage of the Developer ToolsSetting the policy to 0 (the default) means you can access the developer tools and the JavaScript console, but not in the context of extensions installed by enterprise policy or, since version 114 and if this is a managed user, extensions built into the browser. Setting the policy to 1 means you can access the developer tools and the JavaScript console in all contexts, including that of extensions installed by enterprise policy. Setting the policy to 2 means you can't access developer tools, and you can't inspect website elements. This setting also turns off keyboard shortcuts and menu or context menu entries to open developer tools or the JavaScript console. As of Google Chrome version 99, this setting also controls entry points for the 'View page source' feature. If you set this policy to 'DeveloperToolsDisallowed' (value 2), users cannot access source viewing via keyboard shortcut or the context menu. To fully block source viewing, you must also add 'view-source:*' to the URLBlocklist policy. As of Google Chrome version 119, this setting also controls whether developer mode for Isolated Web Apps can be activated and used. As of Google Chrome version 128, this setting will not control developer mode on extensions page if ExtensionDeveloperModeSettings policy is set. The availability of Developer Tools is determined in the following order of precedence: 1. If a URL matches a pattern in the DeveloperToolsAvailabilityAllowlist policy, Developer Tools are allowed. 2. If the DeveloperToolsAvailabilityAllowlist is set and the DeveloperToolsAvailabilityBlocklist is not, any URL not on the allowlist is blocked. 3. If a URL matches a pattern in the DeveloperToolsAvailabilityBlocklist policy, Developer Tools are blocked. 4. If a URL is not covered by the allowlist or blocklist, this policy (DeveloperToolsAvailability) is the fallback.
StaticStorageQuotaEnabled Control whether storage quota APIs will return static values
If unset, the storage quota APIs will use the default Chrome behavior.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- StaticStorageQuotaEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When enabled, the storage quota APIs will return a static value equal to usage + min(10 GiB, disk rounded up to the nearest 1 GiB). When disabled, the storage quota APIs will generally return a dynamic value proportional to the total space available on the device, regardless of usage. If unset, the storage quota APIs will use the default Chrome behavior. Sites with unlimited storage permissions are unaffected by this setting. Enforced quota is also unaffected.
DnsOverHttpsMode Controls the mode of DNS-over-HTTPS
If this policy is unset, for managed devices DNS-over-HTTPS queries will not be sent.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DnsOverHttpsMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Disable DNS-over-HTTPSEnable DNS-over-HTTPS with insecure fallbackEnable DNS-over-HTTPS without insecure fallbackControls the mode of the DNS-over-HTTPS resolver. Please note that this policy will only set the default mode for each query. The mode may be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname. The "off" mode will disable DNS-over-HTTPS. The "automatic" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error. The "secure" mode will only send DNS-over-HTTPS queries and will fail to resolve on error. On Android Pie and above, if DNS-over-TLS is active, Google Chrome will not send insecure DNS requests. If this policy is unset, for managed devices DNS-over-HTTPS queries will not be sent. Otherwise, the browser may send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver. Example value: off
EnterpriseProfileBadgeToolbarSettings Controls visibility of enterprise profile badge in the toolbar
Leaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseProfileBadgeToolbarSettings
- Stated default
- For work and school profiles, the toolbar will show a "Work" or "School" label by default next to the toolbar avatar.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Show expanded enterprise toolbar badge1Hide expanded enterprise toolbar badgeFor work and school profiles, the toolbar will show a "Work" or "School" label by default next to the toolbar avatar. The label will only be shown if the signed in account is managed. Setting this policy to hide_expanded_enterprise_toolbar_badge (value 1) will hide the enterprise badge for a managed profile in the toolbar. Leaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge. The label is customizable via the EnterpriseCustomLabel policy.
ForcePermissionPolicyUnloadDefaultEnabled Controls whether unload event handlers can be disabled.
If this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForcePermissionPolicyUnloadDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to remain as enabled. Pages may depend on unload event handlers to save data or signal the end of a user session to the server. This is not recommended as it is unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, however the unload event has been used for a long time. Some applications may still rely on them. If this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events. If this policy is set to true then unload event handlers will continue to work by default. NOTE: This policy had an incorrectly documented default of `true` in M117. The unload event did and will not change in M117, so this policy has no effect in that version.
CORSNonWildcardRequestHeadersSupport CORS non-wildcard request headers support
If this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CORSNonWildcardRequestHeadersSupport
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Configures support of CORS non-wildcard request headers. Google Chrome version 97 introduces support for CORS non-wildcard request headers. When scripts make a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. "Explicitly" here means that the wild card symbol "*" doesn't cover the Authorization header. See https://chromestatus.com/feature/5742041264816128 for more detail. If this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above. When this policy is set to False, chrome will allow the wildcard symbol ("*") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header. This Enterprise policy is temporary; it's intended to be removed in the future.
AutoLaunchProtocolsFromOrigins Define a list of protocols that can launch an external application from listed origins without prompting the user
If this policy is not set, no protocols can launch without a prompt by default.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AutoLaunchProtocolsFromOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol, so list "skype" instead of "skype:" or "skype://". If this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false the external protocol launch prompt will not be omitted by policy. If this policy is not set, no protocols can launch without a prompt by default. Users may opt out of prompts on a per-protocol/per-site basis unless the ExternalProtocolDialogShowAlwaysOpenCheckbox policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users. The origin matching patterns use a similar format to those for the 'URLBlocklist' policy, which are documented at https://support.google.com/chrome/a?p=url_blocklist_filter_format. However, origin matching patterns for this policy cannot contain "/path" or "@query" elements. Any pattern that does contain a "/path" or "@query" element will be ignored. See https://chromeenterprise.google/policies/?policy=AutoLaunchProtocolsFromOrigins for more information about schema and formatting. Example value: [ { "allowed_origins": [ "example.com", "http://www.example.com:8080" ], "protocol": "spotify" }, { "allowed_origins": [ "https://example.com", "https://.mail.example.com" ], "protocol": "teams" }, { "allowed_origins": [ "*" ], "protocol": "outlook" } ]
AllowedDomainsForApps Define domains allowed to access Google Workspace
Leaving this setting empty or unset means users can access Google Workspace with any account.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowedDomainsForApps
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy turns on Chrome's restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains (to allow gmail or googlemail accounts, add consumer_accounts to the list of domains). This setting prevents users from signing in and adding a Secondary Account on a managed device that requires Google authentication, if that account doesn't belong to one of the explicitly allowed domains. Leaving this setting empty or unset means users can access Google Workspace with any account. Users cannot change or override this setting. Note: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://support.google.com/a/answer/1668854. Example value: managedchrome.com,example.com
ChromeVariations Determine the availability of variations
Setting the VariationsEnabled (value 0), or leaving the policy not set allows all variations to be applied to the browser.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeVariations
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Enable all variations1Enable variations concerning critical fixes only2Disable all variationsConfiguring this policy allows to specify which variations are allowed to be applied in Google Chrome. Variations provide a means for offering modifications to Google Chrome without shipping a new version of the browser by selectively enabling or disabling already existing features. See https://support.google.com/chrome/a?p=Manage_the_Chrome_variations_framework for more information. Setting the VariationsEnabled (value 0), or leaving the policy not set allows all variations to be applied to the browser. Setting the CriticalFixesOnly (value 1), allows only variations considered critical security or stability fixes to be applied to Google Chrome. Setting the VariationsDisabled (value 2), prevent all variations from being applied to the browser. Please note that this mode can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.
CertificateTransparencyEnforcementDisabledForCas Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes
Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CertificateTransparencyEnforcementDisabledForCas
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of subjectPublicKeyInfo hashes. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the hash must meet one of these conditions: * It's of the server certificate's subjectPublicKeyInfo. * It's of a subjectPublicKeyInfo that appears in a Certificate Authority (CA) certificate in the certificate chain. That CA certificate is constrained through the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName has an organizationName attribute. * It's of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate has the same number of organizationName attributes, in the same order, and with byte-for-byte identical values. Specify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored. Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates. Example value: sha256/AAAAAAAAAAAAAAAAAAAAAA== sha256//////////////////////w==
CertificateTransparencyEnforcementDisabledForUrls Disable Certificate Transparency enforcement for a list of URLs
Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CertificateTransparencyEnforcementDisabledForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy turns off Certificate Transparency disclosure requirements for the hostnames in the specified URLs. While making it harder to detect misissued certificates, hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates. A URL pattern follows this format ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). However, because the validity of certificates for a given hostname is independent of the scheme, port, or path, Google Chrome only considers the hostname portion of the URL. Wildcard hosts aren't supported. Example value: example.com .example.com
ExemptDomainFileTypePairsFromFileTypeDownloadWarnings Disable download file type extension-based warnings for specified file types on domains
If you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExemptDomainFileTypePairsFromFileTypeDownloadWarnings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the "jnlp" extension is associated with "website1.com", users would not see a warning when downloading "jnlp" files from "website1.com", but see a download warning when downloading "jnlp" files from "website2.com". Files with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Safe Browsing warnings. If you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user. If you enable this policy: * The URL pattern should be formatted according to https://chromeenterprise.google/policies/url-patterns/. * The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list "jnlp" should be used instead of ".jnlp". Example: The following example value would prevent file type extension-based download warnings on "exe" and "jnlp" extensions for *.example.com domains, and on "swf" extensions for all domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files. [ { "file_extension": "jnlp", "domains": ["example.com"] }, { "file_extension": "exe", "domains": ["example.com"] }, { "file_extension": "swf", "domains": ["*"] } ] Note that while the preceding example shows the suppression of file type extension-based download warnings for "swf" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so. If this policy is enabled alongside DownloadRestrictions, then the exemptions to file type extension-based warnings specified by this policy take precedence over a DownloadRestrictions setting that would block dangerous file types. The exemptions specified by this policy only apply to the "block dangerous file types" behavior specified by values 1 and 2 of DownloadRestrictions. For example, if this policy specifies an exemption for "exe" downloads from "website1.com", and DownloadRestrictions is set to block malicious downloads and dangerous file types (value 1), then "exe" downloads from "website1.com" will be exempt from file type extension-based blocking but will still be blocked if they are malicious. More information about DownloadRestrictions can be found at https://chromeenterprise.google/policies/?policy=DownloadRestrictions. See https://chromeenterprise.google/policies/?policy=ExemptDomainFileTypePairsFromFileTypeDownloadWarnings for more information about schema and formatting. Example value: [ { "domains": [ "https://example.com", "example2.com" ], "file_extension": "jnlp" }, { "domains": [ "*" ], "file_extension": "swf" } ]
SavingBrowserHistoryDisabled Disable saving browser history
Setting the policy to Disabled or leaving it unset saves browsing history.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SavingBrowserHistoryDisabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means browsing history is not saved, tab syncing is off and users can't change this setting. Setting the policy to Disabled or leaving it unset saves browsing history.
Disable3DAPIs Disable support for 3D graphics APIs
Setting the policy to False or leaving it unset lets webpages use the WebGL API, but the browser's default settings might still require command line arguments to use these APIs.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- Disable3DAPIs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True (or setting HardwareAccelerationModeEnabled to False) prevents webpages from accessing the WebGL API. Setting the policy to False or leaving it unset lets webpages use the WebGL API, but the browser's default settings might still require command line arguments to use these APIs.
SyncDisabled Disable synchronization of data with Google
If the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SyncDisabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns off data synchronization in Google Chrome using Google-hosted synchronization services. To fully turn off Chrome Sync services, we recommend that you turn off the service in the Google Admin console. If the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync. Note: Do not turn on this policy when RoamingProfileSupportEnabled is Enabled, because that feature shares the same client-side functionality. The Google-hosted synchronization is off completely in this case.
DisableScreenshots Disable taking screenshots
Setting the policy to Disabled or not set allows screenshots.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisableScreenshots
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled disallows screenshots taken with keyboard shortcuts or extension APIs. Setting the policy to Disabled or not set allows screenshots. Note that on Microsoft® Windows®, macOS and Linux, this does not prevent screenshots that are taken with operating system or third party applications.
DNSInterceptionChecksEnabled DNS interception checks enabled
When this policy is not set, or is enabled, the DNS interception checks are performed.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DNSInterceptionChecksEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy configures a local switch that can be used to disable DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names. This detection may not be necessary in an enterprise environment where the network configuration is known, since it causes some amount of DNS and HTTP traffic on start-up and each DNS configuration change. When this policy is not set, or is enabled, the DNS interception checks are performed. When explicitly disabled, they're not.
DynamicCodeSettings Dynamic Code Settings
If the policy is set to 0 - Default or left unset then Google Chrome will use the default settings.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DynamicCodeSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Default dynamic code settings1Prevent the browser process from creating dynamic codeThis policy controls the dynamic code settings for Google Chrome. Disabling dynamic code improves the security of Google Chrome by preventing potentially hostile dynamic code and third-party code from making changes to Google Chrome's behavior, but might cause compatibility issues with third-party software (e.g. certain printer drivers) that must run inside the browser process. If the policy is set to 0 - Default or left unset then Google Chrome will use the default settings. If the policy is set to 1 - DisabledForBrowser then the Google Chrome browser process will be prevented from creating dynamic code. Note: Read more about process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).
WebAudioOutputBufferingEnabled Enable adaptive buffering for Web Audio
Setting the policy to Disabled or not set will allow the browser feature launch process to decide if adaptive buffering is used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebAudioOutputBufferingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether the browser uses adaptive buffering for Web Audio, which may decrease audio glitches but may increase latency by a variable amount. Setting the policy to Enabled will always use adaptive buffering. Setting the policy to Disabled or not set will allow the browser feature launch process to decide if adaptive buffering is used.
BrowserAddPersonEnabled Enable add person in user manager
If this policy is set to true or not configured, Google Chrome and Lacros will allow to add a new person from the user manager.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserAddPersonEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is set to true or not configured, Google Chrome and Lacros will allow to add a new person from the user manager. If this policy is set to false, Google Chrome and Lacros will not allow adding a new person from the user manager.
AdvancedProtectionAllowed Enable additional protections for users enrolled in the Advanced Protection program
If set to True or not set, enrolled users will receive extra protections.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AdvancedProtectionAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether users enrolled in the Advanced Protection program receive extra protections. Some of these features may involve the sharing of data with Google (for example, Advanced Protection users will be able to send their downloads to Google for malware scanning). If set to True or not set, enrolled users will receive extra protections. If set to False, Advanced Protection users will receive only the standard consumer features.
AlternateErrorPagesEnabled Enable alternate error pages
If not set, the policy is on, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AlternateErrorPagesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True means Google Chrome uses alternate error pages built into (such as "page not found"). Setting the policy to False means Google Chrome never uses alternate error pages. If you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.
AmbientAuthenticationInPrivateModesEnabled Enable Ambient Authentication for profile types.
In Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AmbientAuthenticationInPrivateModesEnabled
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Enable ambient authentication in regular sessions only.1Enable ambient authentication in incognito and regular sessions.2Enable ambient authentication in guest and regular sessions.3Enable ambient authentication in regular, incognito and guest sessions.Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome. Ambient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes. Setting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate. Setting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate. Setting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate. Setting the All (value 3), allows ambient authentication for all sessions. Note that, ambient authentication is always allowed on regular profiles. In Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.
ApplicationBoundEncryptionEnabled Enable Application Bound Encryption
Setting the policy to Enabled or leaving it unset binds encryption keys used for local data storage to Google Chrome whenever that is possible.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ApplicationBoundEncryptionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset binds encryption keys used for local data storage to Google Chrome whenever that is possible. Setting the policy to Disabled has a detrimental effect on Google Chrome's security as unknown and potentially hostile apps can retrieve encryption keys used to secure data. Only turn off the policy if there are compatibility issues, such as other applications that need legitimate access to Google Chrome's data, encrypted user data is expected to be fully portable between different computers or the integrity and location of Google Chrome's executable files is not consistent.
AutofillAddressEnabled Enable AutoFill for addresses
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AutofillAddressEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI. Setting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.
AutofillCreditCardEnabled Enable AutoFill for credit cards
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AutofillCreditCardEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI. Setting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.
HttpsUpgradesEnabled Enable automatic HTTPS upgrades
If set to "true" or left unset, this feature will be enabled by default.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HttpsUpgradesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Google Chrome attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to "true" or left unset, this feature will be enabled by default. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. See also the HttpsOnlyMode policy.
BatterySaverModeAvailability Enable Battery Saver Mode
If this policy is unset, the end user can control this setting in chrome://settings/performance.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BatterySaverModeAvailability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Battery Saver Mode will be disabled.1Battery Saver Mode will be enabled when the device is on battery power and battery level is low.2This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.This policy enables or disables the Battery Saver Mode setting. On Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance. On ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off. The different levels are: Disabled (0): Battery Saver Mode will be disabled. EnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low. EnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.
BookmarkBarEnabled Enable Bookmark Bar
If not set, users decide whether to use this function.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BookmarkBarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar. If you set the policy, users can't change it. If not set, users decide whether to use this function.
ComponentUpdatesEnabled Enable component updates in Google Chrome
Enables component updates for all components in Google Chrome when not set or set to enabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ComponentUpdatesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enables component updates for all components in Google Chrome when not set or set to enabled. If set to disabled, updates to components are disabled. However, some components are exempt from this policy: updates to any component that does not contain executable code and is critical for the security of the browser will not be disabled. Examples of such components include the certificate revocation lists and subresource filters.
AllowDeletingBrowserHistory Enable deleting browser and download history
Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowDeletingBrowserHistory
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting. Setting the policy to Disabled means browser history and download history can't be deleted. Even with this policy off, the browsing and download history are not guaranteed to be retained. Users may be able to edit or delete the history database files directly, and the browser itself may expire or archive any or all history items at any time.
DesktopSharingHubEnabled Enable desktop sharing in the omnibox and 3-dot menu
Setting the policy to True or leaving it unset lets users share or save the current webpage using actions provided by the desktop sharing hub.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DesktopSharingHubEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset lets users share or save the current webpage using actions provided by the desktop sharing hub. The sharing hub is accessed through either an omnibox icon or the 3-dot menu. Setting the policy to False removes the sharing icon from the omnibox and the entry from the 3-dot menu.
TaskManagerEndProcessEnabled Enable ending processes in Task Manager
Setting the policy to Enabled or leaving it unset lets users end processes in the Task Manager.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TaskManagerEndProcessEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Disabled prevents users from ending processes in the Task Manager. Setting the policy to Enabled or leaving it unset lets users end processes in the Task Manager.
SharedWorkerExtendedLifetimeEnabled Enable extended lifetime for SharedWorkers
If this policy is set to Enabled or left unset, SharedWorkers can have an extended lifetime.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SharedWorkerExtendedLifetimeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
SharedWorkers can have an extended lifetime if the "extendedLifetime" option is set to true in the SharedWorker constructor. If this policy is set to Enabled or left unset, SharedWorkers can have an extended lifetime. If this policy is set to Disabled, SharedWorkers cannot have an extended lifetime, even if the option is set to true. This policy is intended to be temporary and will be removed in the future.
AccessibilityImageLabelsEnabled Enable Get Image Descriptions from Google.
If this policy is not set, user can choose to use this feature or not.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AccessibilityImageLabelsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
The Get Image Descriptions from Google accessibility feature enables visually-impaired screen reader users to get descriptions of unlabeled images on the web. Users who choose to enable it will have the option of using an anonymous Google service to provide automatic descriptions for unlabeled images they encounter on the web. If this feature is enabled, the content of images will be sent to Google servers in order to generate a description. No cookies or other user data is sent, and Google does not save or log any image content. If this policy is set to Enabled, the Get Image Descriptions from Google feature will be enabled, though it will only affect users who are using a screen reader or other similar assistive technology. If this policy is set to Disabled, users will not have the option of enabling the feature. If this policy is not set, user can choose to use this feature or not.
GloballyScopeHTTPAuthCacheEnabled Enable globally scoped HTTP auth cache
If this policy is unset or disabled, the browser will use the default behavior of cross-site auth, this behavior will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- GloballyScopeHTTPAuthCacheEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy configures a single global per profile cache with HTTP server authentication credentials. If this policy is unset or disabled, the browser will use the default behavior of cross-site auth, this behavior will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites. If the policy is enabled, HTTP auth credentials entered in the context of one site will automatically be used in the context of another. Enabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs. This policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures, and will be removed in the future.
DevToolsGoogleDeveloperProgramProfileAvailability Enable Google Developer Program Profiles in Chrome DevTools
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DevToolsGoogleDeveloperProgramProfileAvailability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Enable Google Developer Program integration in Chrome DevTools.1Enable Google Developer Program integration in Chrome DevTools, but without sharing tool usage (for awarding badges).2Do not enable Google Developer Program integration in Chrome DevTools.This policy controls the integration of the Google Developer Program with Chrome DevTools. The user's Google Developer Program profile is shown in Chrome DevTools, and users receive badges for performing specific actions within Chrome DevTools. Setting the policy to 0 - 'Enabled', or not setting any policy value, allows the integration of the Google Developer Program with Chrome DevTools, and allows sharing of Chrome DevTools tool usage in order to be able to award badges. Setting the policy to 1 - 'Enabled without badges', allows the integration of the Google Developer Program with Chrome DevTools, but does not allow sharing Chrome DevTools tool usage with the Google Developer Program. No badges will be awarded. Setting the policy to 2 - 'Disabled', does not allow the integration of the Google Developer Program with Chrome DevTools.
GoogleSearchSidePanelEnabled Enable Google Search Side Panel
If set to Enabled or not set, Google Search Side Panel is allowed on all web pages.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- GoogleSearchSidePanelEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If set to Enabled or not set, Google Search Side Panel is allowed on all web pages. If set to Disabled, Google Search Side Panel is not available on any webpage. GenAI capabilities that are part of this feature are not available for Educational or Enterprise accounts.
BrowserGuestModeEnabled Enable guest mode in browser
If this policy is set to Enabled or not configured, Google Chrome will enable guest logins.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserGuestModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is set to Enabled or not configured, Google Chrome will enable guest logins. Guest logins are Google Chrome profiles where all windows are in incognito mode. If this policy is set to Disabled, Google Chrome will not allow guest profiles to be started.
HighEfficiencyModeEnabled Enable High Efficiency Mode
If this policy is unset, the end user can control this setting in chrome://settings/performance.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HighEfficiencyModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy enables or disables the High Efficiency Mode setting. This setting makes it so that tabs are discarded after some period of time in the background to reclaim memory. If this policy is unset, the end user can control this setting in chrome://settings/performance.
CloudManagementEnrollmentMandatory Enable mandatory cloud management enrollment
Setting the policy to Disabled or leaving it unset renders Chrome Enterprise Core browser enrollment optional and doesn't block Google Chrome launch process if failed.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudManagementEnrollmentMandatory
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled mandates Chrome Enterprise Core browser enrollment and blocks Google Chrome launch process if failed. Setting the policy to Disabled or leaving it unset renders Chrome Enterprise Core browser enrollment optional and doesn't block Google Chrome launch process if failed. Machine scope cloud policy enrollment on desktop uses this policy. See https://support.google.com/chrome/a/answer/9301891 for details.
MediaRecommendationsEnabled Enable Media Recommendations
Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MediaRecommendationsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default the browser will show media recommendations that are personalized to the user.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.
NetworkPredictionOptions Enable network prediction
Leaving it unset turns on network prediction, but the user can change it.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NetworkPredictionOptions
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Predict network actions on any network connection1Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)2Do not predict network actions on any network connectionThis policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages. If you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.
EnableOnlineRevocationChecks Enable online OCSP/CRL checks
Setting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableOnlineRevocationChecks
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True means online OCSP/CRL checks are performed. Setting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later. Note: OCSP/CRL checks provide no effective security benefit.
DataUrlInWebWorkerOpaqueOriginEnabled Enable opaque origins for data URLs in Web Workers
If this policy is set to Enabled or left unset, the new default (more secure) behavior is used, and Web Workers created from data URLs will have a unique opaque origin.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DataUrlInWebWorkerOpaqueOriginEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls whether Web Workers created from data URLs are assigned a unique opaque origin. Web Workers can be created using a data URL containing the worker's script. Previously, these workers inherited the origin of the page that created them, allowing them to access the same local storage, cookies, and other origin-bound data. To improve security and align with the HTML specification, Chrome is changing its default behavior in milestone 149 so that workers created from data URLs will now have a unique, opaque origin. This isolates them from the creator page's data. If this policy is set to Enabled or left unset, the new default (more secure) behavior is used, and Web Workers created from data URLs will have a unique opaque origin. If this policy is set to Disabled, Chrome reverts to the legacy behavior, and Web Workers created from data URLs will inherit the origin of their creator. This allows administrators to temporarily resolve compatibility issues if internal applications break due to the security change. This policy is intended to be temporary and will be removed in milestone 157.
EditBookmarksEnabled Enable or disable bookmark editing
Setting the policy to True or leaving it unset lets users add, remove, modify, or upload bookmarks.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EditBookmarksEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset lets users add, remove, modify, or upload bookmarks. Setting the policy to False means users can't add, remove, modify or upload bookmarks. They can still use existing bookmarks.
SpellCheckServiceEnabled Enable or disable spell checking web service
Leaving the policy unset lets users choose whether to use the spellcheck service.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SpellCheckServiceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used. Leaving the policy unset lets users choose whether to use the spellcheck service. The spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.
PdfAnnotationsEnabled Enable PDF Annotations
When this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PdfAnnotationsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls if the PDF viewer in Google Chrome can annotate PDFs. When this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs. When this policy is set to false, then the PDF viewer will not be able to annotate PDFs.
ProcessIsolationEnabled Enable Process Isolation
If this policy is unset, Google Chrome will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProcessIsolationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the Process Isolation settings for Google Chrome. Enabling Process Isolation improves the security of Google Chrome by preventing authorized applications on the system from tampering with or reading the contents of Google Chrome's running processes. This helps prevent other applications on the system from gaining access to Google Chrome's encrypted data. Enabling Process Isolation may cause incompatibilities with third party applications that rely on being able to inject or tamper with Google Chrome's processes, such as antivirus, screen reader or window manager applications. Setting the policy to Enabled turns on process isolation in Google Chrome. Setting the policy to Disabled turns off process isolation in Google Chrome. If this policy is unset, Google Chrome will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users. Note: This policy is applied when Google Chrome starts. If the policy is changed while Google Chrome is running, the new setting will take effect on the next restart.
QRCodeGeneratorEnabled Enable QR Code Generator
If you enable this policy or don't configure it, the QR Code Generator feature is enabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- QRCodeGeneratorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy enables the QR Code generator feature in Google Chrome. If you enable this policy or don't configure it, the QR Code Generator feature is enabled. If you disable this policy, the QR Code Generator feature is disabled.
RendererAppContainerEnabled Enable Renderer App Container
Setting the policy to Enabled or leaving it unset means Renderer App Container configuration will be enabled on supported platforms.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RendererAppContainerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means Renderer App Container configuration will be enabled on supported platforms. Setting the policy to Disabled has a detrimental effect on the security and stability of Google Chrome as it will weaken the sandbox that renderer processes use. Only turn off the policy if there are compatibility issues with third-party software that must run inside renderer processes. Note: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).
MetricsReportingEnabled Enable reporting of usage and crash-related data
When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MetricsReportingEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default. Users will still be able to change this setting. When this policy is Disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting. When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later. (For Google ChromeOS, see DeviceMetricsReportingEnabled.) On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
SafeBrowsingForTrustedSourcesEnabled Enable Safe Browsing for trusted sources
Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingForTrustedSourcesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source. Setting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source. These restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.
ScrollToTextFragmentEnabled Enable scrolling to text specified in URL fragments
If you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ScrollToTextFragmentEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete. If you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled. If you disable this policy, web page scrolling to specific text fragments via URL will be disabled.
SearchSuggestEnabled Enable search suggestions
If not set, search suggestions are on at first, but users can turn them off any time.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SearchSuggestEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions. Suggestions based on bookmarks or history are unaffected by the policy. If you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.
CommandLineFlagSecurityWarningsEnabled Enable security warnings for command-line flags
Setting the policy to Enabled or leaving it unset means security warnings appear when potentially dangerous command-line flags are used to launch Chrome.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CommandLineFlagSecurityWarningsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means security warnings appear when potentially dangerous command-line flags are used to launch Chrome. Setting the policy to Disabled prevents security warnings from appearing when Chrome is launched with potentially dangerous command-line flags. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
PromotionsEnabled Enable showing promotional content
Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PromotionsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content. Setting the policy to False prevents Google Chrome from showing product promotional content. Setting the policy controls the presentation of promotional content, including the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.
SignedHTTPExchangeEnabled Enable Signed HTTP Exchange (SXG) support
Setting the policy to True or leaving it unset means Google Chrome will accept web contents served as Signed HTTP Exchanges.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SignedHTTPExchangeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset means Google Chrome will accept web contents served as Signed HTTP Exchanges. Setting the policy to False prevents Signed HTTP Exchanges from loading.
SigninInterceptionEnabled Enable signin interception
When this policy not set or is enabled, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SigninInterceptionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This settings enables or disables signin interception. When this policy not set or is enabled, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile. When this is disabled, the signin interception dialog does not trigger. When this is disabled, a dialog will still be shown if managed account profile separation is enforced by ManagedAccountsSigninRestriction.
SilentPrintingEnabled Enable Silent Printing
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SilentPrintingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting this policy to true enables silent printing, which immediately closes print preview window when opened and prints to the default printer with default options. If the default printer is 'Save as PDF', the file will be saved to the Downloads folder. Not setting this policy or setting this policy to false disables silent printing, which doesn't automatically close print preview window and requires the user to make a selection as usual.
IsolateOrigins Enable Site Isolation for specified origins
Setting the policy to an empty string or leaving it unset means site isolation won't be required for any specific origins.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- IsolateOrigins
- Stated default
- com) are already isolated by default on Desktop platforms, as noted in the SitePerProcess policy. Note that Android isolates certain sensitive sites by default starting in Google Chrome version 77, and this policy extends that mode to isolate specific additional origins.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Specify a list of origins that run in a dedicated process. On Android, this policy only works on devices with sufficient memory (strictly more than 3.2GB RAM), as isolating too many sites on resource-constrained devices may cause performance problems. For resource-constrained Android devices, please use IsolateOriginsShortlist instead. Devices with less than 1GB memory are not recommended to configure any process isolation specifically. Each named origin's process will only be allowed to contain documents from that origin and its subdomains. For example, specifying https://a1.example.com/ allows https://a2.a1.example.com/ in the same process, but not https://example.com or https://b.example.com. Since Google Chrome 77, you can also specify a range of origins to isolate using a wildcard. For example, specifying https://[*.]corp.example.com will give every origin underneath https://corp.example.com its own dedicated process, including https://corp.example.com itself, https://a1.corp.example.com, and https://a2.a1.corp.example.com. Note that all sites (i.e., scheme plus eTLD+1, such as https://example.com) are already isolated by default on Desktop platforms, as noted in the SitePerProcess policy. This IsolateOrigins policy is useful to isolate specific origins at a finer granularity (e.g., https://a.example.com). Note that Android isolates certain sensitive sites by default starting in Google Chrome version 77, and this policy extends that mode to isolate specific additional origins. Also note that origins isolated by this policy will be unable to script other origins in the same site, which is otherwise possible if two same-site documents modify their document.domain values to match. Administrators should confirm this uncommon behavior is not used on an origin before isolating it. Setting the policy to an empty string or leaving it unset means site isolation won't be required for any specific origins. Users can still turn on process isolation manually, through the command line flag. Example value: https://a.example.com/,https://othersite.org/,https://[*.]corp.example.com
SpellcheckEnabled Enable spellcheck
Leaving the policy unset lets users turn spellcheck on or off in the language settings.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SpellcheckEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns spellcheck on, and users can't turn it off. On Microsoft® Windows®, Google ChromeOS and Linux®, spellcheck languages can be switched on or off individually, so users can still turn spellcheck off by switching off every spellcheck language. To avoid that, use the SpellcheckLanguage to force-enable specific spellcheck languages. Setting the policy to Disabled turns off spellcheck from all sources, and users can't turn it on. The SpellCheckServiceEnabled, SpellcheckLanguage and SpellcheckLanguageBlocklist policies have no effect when this policy is set to False. Leaving the policy unset lets users turn spellcheck on or off in the language settings.
StandardizedBrowserZoomEnabled Enable Standardized Browser Zoom Behavior
When this policy is Enabled or unset, the CSS "zoom" property will adhere to the specification: https://drafts.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- StandardizedBrowserZoomEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy enables conformance to the newly-adopted specification of CSS zoom. When this policy is Enabled or unset, the CSS "zoom" property will adhere to the specification: https://drafts.csswg.org/css-viewport/#zoom-property When Disabled, the CSS "zoom" property will fall back to its legacy pre-standardized behavior. This policy is a temporary reprieve to allow time to migrate web content to the new behavior. There is also an origin trial ("DisableStandardizedBrowserZoom") that corresponds to the behavior when this policy is Disabled. This policy will be removed and the "Enabled" behavior made permanent in milestone 134.
StrictMimetypeCheckForWorkerScriptsEnabled Enable strict MIME type checking for worker scripts
When enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- StrictMimetypeCheckForWorkerScriptsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy enables strict MIME type checking for worker scripts. When enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour. Worker scripts with legacy MIME types will be rejected. When disabled, then worker scripts will use lax MIME type checking, so that worker scripts with legacy MIME types, e.g. text/ascii, will continue to be loaded and executed. Browsers traditionally used lax MIME type checking, so that resources with a number of legacy MIME types were supported. E.g. for JavaScript resources, text/ascii is a legacy supported MIME type. This may cause security issues, by allowing to load resources as scripts that were never intended to be used as such. Chrome will transition to use strict MIME type checking in the near future. The enabled policy will track the default behaviour. Disabling this policy allows administrators to retain the legacy behaviour, if desired. See https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage for details about JavaScript / ECMAScript media types.
ClickToCallEnabled Enable the Click to Call Feature
If this policy is left unset, the Click to Call feature is enabled by default.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ClickToCallEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enable the Click to Call feature which allows users to send phone numbers from Chrome Desktops to an Android device when the user is Signed-in. For more information, see help center article: https://support.google.com/chrome/answer/9430554?hl=en. If this policy is set to enabled, the capability of sending phone numbers to Android devices will be enabled for the Chrome user. If this policy is set to disabled, the capability of sending phone numbers to Android devices will be disabled for the Chrome user. If you set this policy, users cannot change or override it. If this policy is left unset, the Click to Call feature is enabled by default.
NetworkServiceSandboxEnabled Enable the network service sandbox
If this policy is not set, the default configuration for the network sandbox will be used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NetworkServiceSandboxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether or not the network service process runs sandboxed. If this policy is enabled, the network service process will run sandboxed. If this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed. If this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Google Chrome release, currently running field trials, and platform. This policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.
SharedClipboardEnabled Enable the Shared Clipboard Feature
If this policy is left unset, the shared clipboard feature is enabled by default.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SharedClipboardEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enable the Shared Clipboard feature which allows users to send text between Chrome Desktops and an Android device when Sync is enabled and the user is Signed-in. If this policy is set to true, the capability of sending text, cross device, for chrome user is enabled. If this policy is set to false, the capability of sending text, cross device, for chrome user is disabled. If you set this policy, users cannot change or override it. If this policy is left unset, the shared clipboard feature is enabled by default. It is up to the admins to set policies in all platforms they care about. It's recommended to set this policy to one value in all platforms.
TLS13EarlyDataEnabled Enable TLS 1.3 Early Data
If this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TLS13EarlyDataEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
TLS 1.3 Early Data is an extension to TLS 1.3 to send an HTTP request simultaneously with the TLS handshake. If this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.3 Early Data. If it is enabled, Google Chrome will enable TLS 1.3 Early Data. If it is disabled, Google Chrome will not enable TLS 1.3 Early Data. When the feature is enabled, Google Chrome may or may not use TLS 1.3 Early Data depending on server support. TLS 1.3 Early Data is an established protocol. Existing TLS servers, middleboxes, and security software are expected to either handle or reject TLS 1.3 Early Data without dropping the connection. However, devices that do not correctly implement TLS may malfunction and disconnect when TLS 1.3 Early Data is in use. If this occurs, administrators should contact the vendor for a fix. This policy is a temporary measure to control the feature and will be removed afterwards. The policy may be enabled to allow you to test for issues and disabled while issues are being resolved.
EncryptedClientHelloEnabled Enable TLS Encrypted ClientHello
If this policy is not configured, or is set to enabled, Google Chrome will follow the default rollout process for ECH.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EncryptedClientHelloEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Encrypted ClientHello (ECH) is an extension to TLS to encrypt sensitive fields of the ClientHello and improve privacy. If this policy is not configured, or is set to enabled, Google Chrome will follow the default rollout process for ECH. If it is disabled, Google Chrome will not enable ECH. When the feature is enabled, Google Chrome may or may not use ECH depending on server support, availability of the HTTPS DNS record, or rollout status. ECH is an evolving protocol, so Google Chrome's implementation is subject to change. As such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.
TranslateEnabled Enable Translate
Leaving it unset lets them change the setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TranslateEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features. If you set the policy, users can't change this function. Leaving it unset lets them change the setting.
UrlKeyedAnonymizedDataCollectionEnabled Enable URL-keyed anonymized data collection
If this policy is left unset, the user will be able to change this setting manually. If this policy is unset for Google ChromeOS Kiosk, URL-keyed anonymized data collection is always active.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UrlKeyedAnonymizedDataCollectionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means URL-keyed anonymized data collection, which sends URLs of pages the user visits to Google to make searches and browsing better, is always active. Setting the policy to Disabled results in no URL-keyed anonymized data collection. If this policy is left unset, the user will be able to change this setting manually. In Google ChromeOS Kiosk, this policy doesn't offer the option to "Allow the user to decide". If this policy is unset for Google ChromeOS Kiosk, URL-keyed anonymized data collection is always active. When set for Google ChromeOS Kiosk, this policy enables URL-keyed metrics collection for kiosk apps.
WebAppInstallByUserEnabled Enable User Web App Install From Browser
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebAppInstallByUserEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether users can install web apps through the browser. If you enable or don’t configure this policy, users can install web apps through the browser. If you disable this policy, users can’t install web apps through the browser and the "apps" data type will be excluded from synchronization for Chrome Sync. This policy doesn't support dynamic refresh. Any changes, whether enabling, disabling or unsetting, become effective only after the browser is restarted. This policy doesn't affect the 'WebAppInstallForceList' policy.
WindowOcclusionEnabled Enable Window Occlusion
If this policy is left not set, occlusion detection will be enabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WindowOcclusionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enables window occlusion in Google Chrome. If you enable this setting, to reduce CPU and power consumption Google Chrome will detect when a window is covered by other windows, and will suspend work painting pixels. If you disable this setting Google Chrome will not detect when a window is covered by other windows. If this policy is left not set, occlusion detection will be enabled.
WPADQuickCheckEnabled Enable WPAD optimization
Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WPADQuickCheckEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome. Setting the policy to Disabled turns off WPAD optimization, causing Google Chrome to wait longer for DNS-based WPAD servers. Whether or not this policy is set, users can't change the WPAD optimization setting.
EnableExperimentalPolicies Enables experimental policies
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\EnableExperimentalPolicies
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows Google Chrome to load experimental policies. WARNING: Experimental policies are unsupported and subject to change or be removed without notice in future version of the browser! An experimental policy may not be finished or still have known or unknown defects. It may be changed or even removed without any notification. By enabling experimental policies, you could lose browser data or compromise your security or privacy. If a policy is not in the list and it's not officially released, its value will be ignored on Beta and Stable channel. If a policy is in the list and it's not officially released, its value will be applied. This policy has no effect on already released policies. Example value: ExtensionInstallAllowlist ExtensionInstallBlocklist
EnterpriseHardwarePlatformAPIEnabled Enables managed extensions to use the Enterprise Hardware Platform API
Setting the policy to False or leaving it unset prevents extensions from using this API.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseHardwarePlatformAPIEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API. Setting the policy to False or leaving it unset prevents extensions from using this API. Note: This policy also applies to component extensions, such as the Hangout Services extension.
CloudUserPolicyMerge Enables merging of user cloud policies into machine-level policies
Setting the policy to Disabled or leaving it unset prevents user-level cloud policies from being merged with policies from any other sources.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudUserPolicyMerge
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled allows policies associated with a managed account to be merged into machine-level policies. Setting the policy to Disabled or leaving it unset prevents user-level cloud policies from being merged with policies from any other sources. Only policies originating from secure users can take precedence. A secure user is affiliated with the organization that manages their browser using Chrome Enterprise Core. All other user-level policies will have default precedence. Policies that need to be merged also need to be set in either PolicyListMultipleSourceMergeList or PolicyDictionaryMultipleSourceMergeList. This policy will be ignored if neither of the two aforementioned policies is configured.
PolicyAtomicGroupsEnabled Enables the concept of policy atomic groups
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PolicyAtomicGroupsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored. Setting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority. If this policy is set from a cloud source, it can't target a specific user.
BrowserGuestModeEnforced Enforce browser guest mode
Setting the policy to Disabled, leaving it unset, or disabling browser Guest mode (through BrowserGuestModeEnabled) allows the use of new and existing profiles.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserGuestModeEnforced
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means Google Chrome enforces guest sessions and prevents profile sign-ins. Guest sign-ins are Google Chrome profiles where windows are in Incognito mode. Setting the policy to Disabled, leaving it unset, or disabling browser Guest mode (through BrowserGuestModeEnabled) allows the use of new and existing profiles.
EnterpriseLogoUrlForBrowser Enterprise Logo URL for a managed browser
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseLogoUrlForBrowser
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A URL to an image that will be used as an enterprise badge for a managed browser. The URL must point to an image. It is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px. Note that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://example.com/image.png
EnterpriseLogoUrl Enterprise Logo URL for a managed profile
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseLogoUrl
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A URL to an image that will be used as an enterprise badge for a managed profile. The URL must point to an image. This policy can only be set as a user policy. It is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px. Example value: https://example.com/image.png
EnterpriseSearchAggregatorSettings Enterprise search aggregator settings
A default icon will be used when this field is not set. If this field is not set, the address bar shortcut is not required.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseSearchAggregatorSettings
- Stated default
- By default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows administrators to set a designated enterprise search aggregator that will provide search recommendations and results within the omnibox (address bar) and the search box on the New Tab page. By default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations. Users can explicitly scope their search to just the enterprise search aggregator by typing the keyword specified in the shortcut field with or without the @ prefix (e.g. @work) followed by Space or Tab in the omnibox. Scoped enterprise searches (triggered by a keyword) are currently only supported in the omnibox and not in the search box on the New Tab page. The following fields are required: name, shortcut, search_url, suggest_url. The name field corresponds to the search engine name shown to the user in the address bar. The shortcut field corresponds to the keyword that the user enters to trigger the search. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must be unique. The search_url field specifies the URL on which to search. Enter the web address for the search engine's results page, and use '{searchTerms}' in place of the query. The suggest_url field specifies the URL that provides search suggestions. A POST request will be made and the user's query will be passed in the POST params under key 'query'. The icon_url field specifies the URL to an image that will be used on the search suggestions. A default icon will be used when this field is not set. It's recommended to use a favicon (example https://www.google.com/favicon.ico). Supported image file formats: JPEG, PNG, and ICO. The require_shortcut field specifies whether the address bar shortcut is required to see search recommendations. If required, suggestions will not be shown in the search box on the New Tab page, but will continue to be shown in the omnibox (address bar) in scoped search mode. If this field is not set, the address bar shortcut is not required. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. See https://chromeenterprise.google/policies/?policy=EnterpriseSearchAggregatorSettings for more information about schema and formatting. Example value: { "name": "My Search Aggregator", "shortcut": "work", "search_url": "https://www.aggregator.com/search?q={searchTerms}", "suggest_url": "https://www.aggregator.com/suggest", "icon_url": "https://www.google.com/favicon.ico", "require_shortcut": true }
ForceEphemeralProfiles Ephemeral profile
If the policy is set to disabled or left not set signing in leads to regular profiles.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceEphemeralProfiles
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If set to enabled this policy forces the profile to be switched to ephemeral mode. If this policy is specified as an OS policy (e.g. GPO on Windows) it will apply to every profile on the system; if the policy is set as a Cloud policy it will apply only to a profile signed in with a managed account. In this mode the profile data is persisted on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies and web databases are not preserved after the browser is closed. However this does not prevent the user from downloading any data to disk manually, save pages or print them. If the user has enabled sync all this data is preserved in their sync profile just like with regular profiles. Incognito mode is also available if not explicitly disabled by policy. If the policy is set to disabled or left not set signing in leads to regular profiles.
ExplicitlyAllowedNetworkPorts Explicitly allowed network ports
Leaving the value empty or unset means that all restricted ports will be blocked.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExplicitlyAllowedNetworkPorts
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
There is a list of restricted ports built into Google Chrome. Connections to these ports will fail. This setting permits bypassing that list. The value is a comma-separated list of zero or more ports that outgoing connections will be permitted on. Ports are restricted to prevent Google Chrome being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for errors with code "ERR_UNSAFE_PORT" while migrating a service running on a blocked port to a standard port (ie. port 80 or 443). Malicious websites can easily detect that this policy is set, and for what ports, and use that information to target attacks. Each port here is labelled with a date that it can be unblocked until. After that date the port will be restricted regardless of this setting. Leaving the value empty or unset means that all restricted ports will be blocked. If there is a mixture of valid and invalid values, the valid ones will be applied. This policy overrides the "--explicitly-allowed-ports" command-line option. Example value: 10080
FetchKeepaliveDurationSecondsOnShutdown Fetch keepalive duration on Shutdown
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- FetchKeepaliveDurationSecondsOnShutdown
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls the duration (in seconds) allowed for keepalive requests on browser shutdown. When specified, browser shutdown can be blocked up to the specified seconds, to process keepalive (https://fetch.spec.whatwg.org/#request-keepalive-flag) requests. The default value (0) means this feature is disabled.
SpellcheckLanguageBlocklist Force disable spellcheck languages
If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SpellcheckLanguageBlocklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Force-disables spellcheck languages. Unrecognized languages in that list will be ignored. If you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list. If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences. If the SpellcheckEnabled policy is set to false, this policy will have no effect. If a language is included in both this policy and the SpellcheckLanguage policy, the latter is prioritized and the spellcheck language will be enabled. The currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi. Example value: fr es
SpellcheckLanguage Force enable spellcheck languages
If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SpellcheckLanguage
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Force-enables spellcheck languages. Unrecognized languages in the list will be ignored. If you enable this policy, spellcheck will be enabled for the languages specified, in addition to the languages for which the user has enabled spellcheck. If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences. If the SpellcheckEnabled policy is set to false, this policy will have no effect. If a language is included in both this policy and the SpellcheckLanguageBlocklist policy, this policy is prioritized and the spellcheck language is enabled. The currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi. Example value: fr es
ForceForegroundPriorityForAllTabs Force foreground priority for all tabs
If this policy is set to Disabled or not set, the browser determines priority based on standard heuristics (e.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceForegroundPriorityForAllTabs
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, the browser optimizes resources by deprioritizing content in background tabs.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether background web content is forced to run at foreground priority. By default, the browser optimizes resources by deprioritizing content in background tabs. Enabling this policy overrides that behavior, causing background tabs to be scheduled the same way as the active tab. Note that forcing background content to run at foreground priority may slightly impact the responsiveness of the active tab. If this policy is set to Enabled, all web content runs at foreground priority regardless of its visibility state. If this policy is set to Disabled or not set, the browser determines priority based on standard heuristics (e.g., deprioritizing content that is not visible, not playing audio, not participating in video calls...).
ForceForegroundPriorityForUrls Force foreground priority for specific URLs
If ForceForegroundPriorityForAllTabs is disabled or unset, only content matching the patterns in this list will be forced. If this list is empty or not set, no background content is forced to foreground priority.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ForceForegroundPriorityForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows you to specify a list of URL patterns. Background web content matching these patterns will be forced to run at foreground priority. If the ForceForegroundPriorityForAllTabs policy is enabled, this list is ignored as all tabs will be forced to foreground priority. If ForceForegroundPriorityForAllTabs is disabled or unset, only content matching the patterns in this list will be forced. For detailed information on valid URL patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. If this list is empty or not set, no background content is forced to foreground priority. Example value: https://www.example.com/path?query=val example.edu https://example.com:8080 *://example.org:*/
ForceGoogleSafeSearch Force Google SafeSearch
Setting the policy to Disabled or leaving it unset means SafeSearch in Google Search is not enforced.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceGoogleSafeSearch
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means SafeSearch in Google Search is always active, and users can't change this setting. Setting the policy to Disabled or leaving it unset means SafeSearch in Google Search is not enforced.
ForceYouTubeRestrict Force minimum YouTube Restricted Mode
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceYouTubeRestrict
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Do not enforce Restricted Mode on YouTube1Enforce at least Moderate Restricted Mode on YouTube2Enforce Strict Restricted Mode for YouTubeSetting the policy enforces a minimum Restricted mode on YouTube and prevents users from picking a less restricted mode. If you set it to: * Strict, Strict Restricted mode on YouTube is always active. * Moderate, the user may only pick Moderate Restricted mode and Strict Restricted mode on YouTube, but can't turn off Restricted mode. * Off or if no value is set, Restricted mode on YouTube isn't enforced by Chrome. External policies such as YouTube policies might still enforce Restricted mode.
NativeHostsExecutablesLaunchDirectly Force Windows executable Native Messaging hosts to launch directly
Leaving the policy unset allows Google Chrome to decide which approach to use.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NativeHostsExecutablesLaunchDirectly
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether native host executables launch directly on Windows. Setting the policy to Enabled forces Google Chrome to launch native messaging hosts implemented as executables directly. Setting the policy to Disabled will result in Google Chrome launching hosts using cmd.exe as an intermediary process. Leaving the policy unset allows Google Chrome to decide which approach to use.
CloudPolicyOverridesPlatformPolicy Google Chrome cloud policy overrides Platform policy.
Setting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudPolicyOverridesPlatformPolicy
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means cloud policy takes precedence if it conflicts with platform policy. Setting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy. This mandatory policy affects machine scope cloud policies. This policy is specific to Google Chrome and does not affect Google Update because they are independent applications. Google Update has a separate policy with the same name.
HideWebStoreIcon Hide the web store from the New Tab Page and app launcher
When this policy is set to false or is not configured, the icons are visible.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HideWebStoreIcon
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Hide the Chrome Web Store app and footer link from the New Tab Page and Google ChromeOS app launcher. When this policy is set to true, the icons are hidden. When this policy is set to false or is not configured, the icons are visible.
HttpAllowlist HTTP Allowlist
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\HttpAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable HTTPS Upgrades and/or HTTPS-First Mode. Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. Blanket host wildcards (i.e., "*" or "[*]") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies. Note: This policy does not apply to HSTS upgrades. Example value: testserver.example.com [*.]example.org
ImportAutofillFormData Import autofill form data from default browser on first run
Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ImportAutofillFormData
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run. Users can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.
ImportBookmarks Import bookmarks from default browser on first run
Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ImportBookmarks
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run. Users can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.
ImportHistory Import browsing history from default browser on first run
Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ImportHistory
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run. Users can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.
ImportHomepage Import of homepage from default browser on first run
Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ImportHomepage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports the homepage from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run. Users can trigger an import dialog and the homepage checkbox will be checked or unchecked to match this policy's value.
ImportSavedPasswords Import saved passwords from default browser on first run
Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ImportSavedPasswords
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls only the first run import behavior after installation. It enables more seamless transition to Google Chrome in environments where a different browser was extensively used prior to installing the browser. This policy does not affect password manager capabilities for Google accounts. Setting the policy to Enabled imports saved passwords from the previous default browser on first run and manual importing from the settings page is also possible. Setting the policy to Disabled means no saved passwords are imported on first run and manual importing from the Settings page is blocked. Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
ImportSearchEngine Import search engines from default browser on first run
Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ImportSearchEngine
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run. Users can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.
IncognitoModeAvailability Incognito mode availability
If 'Enabled' is selected or the policy is left unset, pages may be opened in Incognito mode.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- IncognitoModeAvailability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Incognito mode available1Incognito mode disabled2Incognito mode forcedSpecifies whether the user may open pages in Incognito mode in Google Chrome. If 'Enabled' is selected or the policy is left unset, pages may be opened in Incognito mode. If 'Disabled' is selected, pages may not be opened in Incognito mode. If 'Forced' is selected, pages may be opened ONLY in Incognito mode. Note that 'Forced' does not work for Android-on-Chrome The IncognitoModeUrlAllowlist policy takes precedence over this policy and can re-enable Incognito mode for specific URLs. When Incognito mode is disabled by this policy when an allowlist is provided, Incognito mode is available only for URLs matching the allowlist, while all other pages are blocked. Note: On iOS, if the policy is changed during a session, it will only take effect on relaunch.
IntranetRedirectBehavior Intranet Redirection Behavior
If this policy is not set, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- IntranetRedirectBehavior
- Stated default
- In M88, they are enabled by default but will be disabled by default in the future release.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Use default browser behavior.1Disable DNS interception checks and did-you-mean "http://intranetsite/" infobars.2Disable DNS interception checks; allow did-you-mean "http://intranetsite/" infobars.3Allow DNS interception checks and did-you-mean "http://intranetsite/" infobars.This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names. If this policy is not set, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release. DNSInterceptionChecksEnabled is a related policy that may also disable DNS interception checks; this policy is a more flexible version which may separately control intranet redirection infobars and may be expanded in the future. If either DNSInterceptionChecksEnabled or this policy requests to disable interception checks, the checks will be disabled.
EnterpriseProfileCreationKeepBrowsingData Keep browsing data when creating enterprise profile by default
If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseProfileCreationKeepBrowsingData
- Enabled / Disabled
- 1 / 0
- Stated default
- If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default. Regardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile. This policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.
UserDataSnapshotRetentionLimit Limits the number of user data snapshots retained for use in case of emergency rollback.
If this policy is not set, the default value of 3 is used If the policy is set, old snapshots are deleted as needed to respect the limit.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UserDataSnapshotRetentionLimit
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Following each major version update, Chrome will create a snapshot of certain portions of the user's browsing data for use in case of a later emergency version rollback. If an emergency rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This allows users to retain such settings as bookmarks and autofill data. If this policy is not set, the default value of 3 is used If the policy is set, old snapshots are deleted as needed to respect the limit. If the policy is set to 0, no snapshots will be taken
AutoOpenFileTypes List of file types that should be automatically opened on download
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutoOpenFileTypes
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of file types that should be automatically opened on download. The leading separator should not be included when listing the file type, so list "txt" instead of ".txt". Files with types that should be automatically opened will still be subject to the enabled safe browsing checks and won't be opened if they fail those checks. If this policy isn't set, only file types that a user has already specified to automatically be opened will do so when downloaded. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: exe txt
HSTSPolicyBypassList List of names that will bypass the HSTS policy check
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\HSTSPolicyBypassList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies a list of hostnames that bypass preloaded HSTS upgrades from http to https. Only single-label hostnames are allowed in this policy, and this policy only applies to "static" HSTS-preloaded entries (for instance, "app", "new", "search", "play"). This policy does not prevent HSTS upgrades for servers that have "dynamically" requested HSTS upgrades using a Strict-Transport-Security response header. Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified, not to subdomains of those names. Example value: meet
SyncTypesListDisabled List of types that should be excluded from synchronization
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SyncTypesListDisabled
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is set all specified data types will be excluded from synchronization both for Chrome Sync as well as for roaming profile synchronization. This can be beneficial to reduce the size of the roaming profile or limit the type of data uploaded to the Chrome Sync Servers. The current data types for this policy are: "apps", "autofill", "bookmarks", "extensions", "preferences", "passwords", "payments", "productComparison", "readingList", "tabs", "themes", "typedUrls", "wifiConfigurations". Those names are case sensitive! Notes: Dynamic Policy Refresh is supported only in Google Chrome version 123 and later. Disabling "autofill" also disables "payments". "typedUrls" refers to all browsing history. Example value: bookmarks
DeveloperToolsAvailabilityAllowlist List of URL patterns for which Chrome DevTools are allowed to be opened
If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityBlocklist and DeveloperToolsAvailability policies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\DeveloperToolsAvailabilityAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy can be used to allow Chrome DevTools on specific URLs. URL patterns are matched against the URL of every frame on the page being inspected. The resulting behavior depends on whether the DeveloperToolsAvailabilityBlocklist policy is also set. If this policy is set and DeveloperToolsAvailabilityBlocklist is not, every frame's URL must match a pattern on this allowlist for Chrome DevTools to be allowed. If any frame's URL does not match, DevTools will be blocked for the entire page. For information on the URL format, see https://support.google.com/chrome/a?p=url_blocklist_filter_format. If both this and the DeveloperToolsAvailabilityBlocklist policies are set, this allowlist takes precedence. If a frame's URL matches a pattern on this allowlist, it will be allowed, even if it also matches a pattern in the blocklist. If a URL matches a pattern on the blocklist (but not the allowlist), it will be blocked. If a URL matches neither, the DeveloperToolsAvailability policy will be used as a fallback. If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityBlocklist and DeveloperToolsAvailability policies. This policy also applies to Chrome DevTools opened for extensions and web applications. This policy is limited to 1,000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://*
DeveloperToolsAvailabilityBlocklist List of URL patterns for which Chrome DevTools are blocked
If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityAllowlist and DeveloperToolsAvailability policies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\DeveloperToolsAvailabilityBlocklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy can be used to block Chrome DevTools on specific URLs. For information on the URL format, see https://support.google.com/chrome/a?p=url_blocklist_filter_format. URL patterns are matched against the URL of every frame on the page being inspected. The resulting behavior depends on whether the DeveloperToolsAvailabilityAllowlist policy is also set. If this policy is set and DeveloperToolsAvailabilityAllowlist is not, any frame's URL matching a pattern on this blocklist will block Chrome DevTools for the entire page. If a frame's URL doesn't match any pattern, the availability is determined by the DeveloperToolsAvailability policy. If both this and the DeveloperToolsAvailabilityAllowlist policies are set, the allowlist takes precedence. If a frame's URL matches a pattern on the allowlist, it will be allowed, even if it also matches a pattern in this blocklist. If a URL matches a pattern on this blocklist (but not the allowlist), it will be blocked. If a URL matches neither, the DeveloperToolsAvailability policy will be used as a fallback. If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityAllowlist and DeveloperToolsAvailability policies. This policy is limited to 1,000 entries. Example value: https://example.com example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com * file://*
SharedWorkerBlobURLFixEnabled Make SharedWorker blob URL behavior aligned with the specification
Setting the policy to Enabled or leaving it unset means Google Chrome inherit the controller if a blob URL is used as a SharedWorker URL.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SharedWorkerBlobURLFixEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Upon https://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers should inherit controllers for the blob URL. However, existing code allows only DedicatedWorkers to inherit the controller, and SharedWorkers do not inherit the controller. Setting the policy to Enabled or leaving it unset means Google Chrome inherit the controller if a blob URL is used as a SharedWorker URL. Setting the policy to Disabled leaves the behavior not aligned with the specification as-is. This policy is intended to be temporary and will be removed in the future.
ManagedBookmarks Managed Bookmarks
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ManagedBookmarks
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets up a list of bookmarks where each one is a dictionary with the keys "name" and "url". These keys hold the bookmark's name and target. Admins can set up a subfolder by defining a bookmark without a "url" key, but with an additional "children" key. This key also has a list of bookmarks, some of which can also be folders. Chrome amends incomplete URLs as if they were submitted through the address bar. For example, "google.com" becomes "https://google.com/". Users can't change the folders the bookmarks are placed in (though they can hide it from the bookmark bar). The default folder name for managed bookmarks is "Managed bookmarks" but it can be changed by adding a new sub-dictionary to the policy with a single key named "toplevel_name" with the desired folder name as its value. Managed bookmarks are not synced to the user account and extensions can't modify them. See https://chromeenterprise.google/policies/?policy=ManagedBookmarks for more information about schema and formatting. Example value: [ { "toplevel_name": "My managed bookmarks folder" }, { "name": "Google", "url": "google.com" }, { "name": "Youtube", "url": "youtube.com" }, { "children": [ { "name": "Chromium", "url": "chromium.org" }, { "name": "Chromium Developers", "url": "dev.chromium.org" } ], "name": "Chrome links" } ]
MaxConnectionsPerProxy Maximal number of concurrent connections per proxy server for non-WebSocket requests
Leaving the policy unset means a default of 128 is used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MaxConnectionsPerProxy
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the maximal number of simultaneous connections per proxy server for non-WebSocket requests. To modify WebSocket request limits, see MaxConnectionsPerProxyForWebSocket. Leaving the policy unset means a default of 128 is used. Some web apps are known to consume many connections with hanging GETs, so setting a value below 128 may lead to browser networking hangs if there are too many web apps with hanging connections open. Some proxy servers can't handle a high number of concurrent connections per client, which is solved by setting this policy to a lower value. The value should be equal to or higher than 6. Setting a value below that limit will cause 6 to be used. Lower below the default (128) at your own risk. The value should be equal to or lower than 256 (99 in Google Chrome 147 and earlier). Setting a value above that limit will cause 256 (99 in Google Chrome 147 and earlier) to be used. Raise above the default (128) at your own risk. Please note that the enforced limits are impacted by AllowSocketPoolSizeRandomizationForProxies.
MaxConnectionsPerProxyForWebSocket Maximal number of concurrent connections per proxy server for WebSocket requests
Leaving the policy unset means a default of 128 is used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MaxConnectionsPerProxyForWebSocket
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the maximal number of simultaneous connections per proxy server for WebSocket requests. To modify non-WebSocket request limits, see MaxConnectionsPerProxy. Leaving the policy unset means a default of 128 is used. Some web apps are known to consume many connections with hanging GETs, so setting a value below 128 may lead to browser networking hangs if there are too many web apps with hanging connections open. Some proxy servers can't handle a high number of concurrent connections per client, which is solved by setting this policy to a lower value. The value should be equal to or higher than 6. Setting a value below that limit will cause 6 to be used. Lower below the default (128) at your own risk. The value should be equal to or lower than 256. Setting a value above that limit will cause 256 to be used. Raise above the default (128) at your own risk. Please note that the enforced limits are impacted by AllowSocketPoolSizeRandomizationForProxies.
MaxInvalidationFetchDelay Maximum fetch delay after a policy invalidation
Leaving the policy unset means Google Chrome uses the default value of 10 seconds.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MaxInvalidationFetchDelay
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service. Valid values range from 1,000 (1 second) to 300,000 (5 minutes). Values outside this range will be clamped to the respective boundary. Leaving the policy unset means Google Chrome uses the default value of 10 seconds.
RelaunchNotification Notify a user that a browser relaunch or device restart is recommended or required
If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google ChromeOS indicates such via a notification in the system tray.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RelaunchNotification
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Show a recurring prompt to the user indicating that a relaunch is recommended2Show a recurring prompt to the user indicating that a relaunch is requiredNotify users that Google Chrome must be relaunched or Google ChromeOS must be restarted to apply a pending update. This policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google ChromeOS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google ChromeOS, and may be configured via the RelaunchNotificationPeriod policy setting. The user's session is restored following the relaunch/restart.
OverrideSecurityRestrictionsOnInsecureOrigin Origins or hostname patterns for which restrictions on insecure origins should not apply
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\OverrideSecurityRestrictionsOnInsecureOrigin
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies a list of origins (URLs) or hostname patterns (such as *.example.com) for which security restrictions on insecure origins won't apply. Patterns are only accepted for hostnames; URLs/origins with schemes must be exact strings. Organizations can specify origins for legacy applications that can't deploy TLS or set up a staging server for internal web development, so developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled "Not Secure" in the address bar. Setting a list of URLs in this policy amounts to setting the command-line flag --unsafely-treat-insecure-origin-as-secure to a comma-separated list of the same URLs. The policy overrides the command-line flag and UnsafelyTreatInsecureOriginAsSecure, if present. For more information on secure contexts, see Secure Contexts ( https://www.w3.org/TR/secure-contexts ). Example value: http://testserver.example.com/ *.example.org
CpuPerformanceTierOverride Override for the CPU performance tier
If the policy is not set, then the default performance tier calculation is used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CpuPerformanceTierOverride
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting this policy allows enterprises to override the value returned by the CPU Performance API (i.e., navigator.cpuPerformance, please see https://github.com/WICG/cpu-performance for details). If this policy is set, the value of navigator.cpuPerformance will be overridden to the specified value. If the policy is not set, then the default performance tier calculation is used. The possible values for this policy are 0 to 4.
ProfilePickerOnStartupAvailability Profile picker availability on startup
If 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProfilePickerOnStartupAvailability
- Stated default
- By default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true. If 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Profile picker available at startup1Profile picker disabled at startup2Profile picker forced at startupSpecifies whether the profile picker is enabled, disabled or forced at the browser startup. By default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true. If 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it. If 'Disabled' (1) is selected, the profile picker will never be shown, and users will not be able to change the setting. If 'Forced' (2) is selected, the profile picker cannot be suppressed by the user. The profile picker will be shown even if there is only one profile available.
ProfileReauthPrompt Prompt users to re-authenticate to the profile
When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProfileReauthPrompt
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Do not prompt for reauth1Prompt for reauth in a tabWhen set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser. When set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.
PromptOnMultipleMatchingCertificates Prompt when multiple certificates match
If this policy is set to Disabled or not set, the user may only be prompted when no certificate matches the auto-selection.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PromptOnMultipleMatchingCertificates
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether the user is prompted to select a client certificate when more than one certificate matches AutoSelectCertificateForUrls. If this policy is set to Enabled, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates. If this policy is set to Disabled or not set, the user may only be prompted when no certificate matches the auto-selection.
ProxySettings Proxy settings
Leaving the policy unset lets users choose their proxy settings.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProxySettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy configures the proxy settings for Chrome and ARC-apps, which ignore all proxy-related options specified from the command line. Leaving the policy unset lets users choose their proxy settings. Setting the ProxySettings policy accepts the following fields: * ProxyMode, which lets you specify the proxy server Chrome uses and prevents users from changing proxy settings * ProxyPacUrl, a URL to a proxy .pac file, or a PAC script encoded as a data URL with MIME type application/x-ns-proxy-autoconfig * ProxyPacMandatory, which prevents the network stack from falling back to direct connections with invalid or unavailable PAC script * ProxyServer, a URL of the proxy server * ProxyBypassList, a list of hosts for which the proxy will be bypassed The ProxyServerMode field is deprecated in favor of the ProxyMode field. For ProxyMode, if you choose the value: * direct, a proxy is never used and all other fields are ignored. * system, the systems's proxy is used and all other fields are ignored. * auto_detect, all other fields are ignored. * fixed_servers, the ProxyServer and ProxyBypassList fields are used. * pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used. Note: For more detailed examples, visit The Chromium Projects ( https://www.chromium.org/developers/design-documents/network-settings/#command-line-options-for-proxy-settings ). See https://chromeenterprise.google/policies/?policy=ProxySettings for more information about schema and formatting. Example value: { "ProxyBypassList": "https://www.example1.com,https://www.example2.com,https://internalsite/", "ProxyMode": "fixed_servers", "ProxyServer": "123.123.123.123:8080" }
PolicyRefreshRate Refresh rate for user policy
Leaving the policy unset uses the default value of 3 hours.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PolicyRefreshRate
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the period in milliseconds at which the device management service is queried for user policy information. Valid values range from 1,800,000 (30 minutes) to 86,400,000 (1 day). Values outside this range will be clamped to the respective boundary. Leaving the policy unset uses the default value of 3 hours. Note: Policy notifications force a refresh when the policy changes, making frequent refreshes unnecessary. So, if the platform supports these notifications, the refresh delay is 24 hours (ignoring defaults and the value of this policy).
RelaunchFastIfOutdated Relaunch fast if outdated
If not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RelaunchFastIfOutdated
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Specifies the minimum release age beyond which relaunch notifications are more aggressive. The age is calculated from the time the currently-running version was last served to clients. If a browser relaunch or device restart is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), users will be forced to relaunch or restart at the end of the period. If not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.
RequireOnlineRevocationChecksForLocalAnchors Require online OCSP/CRL checks for local trust anchors
Setting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RequireOnlineRevocationChecksForLocalAnchors
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True means Google Chrome always performs revocation checking for successfully validated server certificates signed by locally installed CA certificates. If Google Chrome can't get revocation status information, Google Chrome treats these certificates as revoked (hard-fail). Setting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings. On macOS, this policy has no effect if the ChromeRootStoreEnabled policy is set to False.
SitePerProcess Require Site Isolation for every site
Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SitePerProcess
- Enabled / Disabled
- 1 / 0
- Stated default
- Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process. A site is a scheme plus eTLD+1 (e.g., https://example.com). Setting this policy to Enabled does not change that behavior; it only prevents users from opting out (for example, using Disable site isolation in chrome://flags). Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out. IsolateOrigins might also be useful for isolating specific origins at a finer granularity than site (e.g., https://a.example.com). On Google ChromeOS version 76 and earlier, set the DeviceLoginScreenSitePerProcess device policy to the same value. (If the values don't match, a delay can occur when entering a user session.) Note: For Android, use the SitePerProcessAndroid policy instead.
RestrictBackgroundFetchFromServiceWorkerEnabled Restrict Background Fetch API when called from a Service Worker
If this policy is set to Enabled, or left unset, the restriction is active, and background fetch requests from Service Worker contexts may be blocked.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RestrictBackgroundFetchFromServiceWorkerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether background fetch requests from Service Workers are restricted. If a feature that downloads files in the background is affected, this policy may be relevant. If this policy is set to Enabled, or left unset, the restriction is active, and background fetch requests from Service Worker contexts may be blocked. If this policy is set to Disabled, the restriction is bypassed, allowing all Service Workers to make background fetch requests. This enterprise policy is temporary, and will be removed after M152.
RestrictCoreSharingOnRenderer Restrict CPU core sharing for renderer process
If this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RestrictCoreSharingOnRenderer
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy If this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running. If this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it. If this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.
RestrictPdfSaveToGoogleDriveAccountsToPattern Restrict eligible Google accounts for saving PDF files to Google Drive from the Google Chrome PDF Viewer
If this policy is left not set or blank, then the user can use any Google account to save PDF files to Google Drive.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RestrictPdfSaveToGoogleDriveAccountsToPattern
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Contains a regular expression to determine eligible Google accounts for saving PDF files to Google Drive from the Google Chrome PDF Viewer. An error is displayed if a user tries to upload a PDF file to Google Drive using an account that does not match this pattern. If this policy is left not set or blank, then the user can use any Google account to save PDF files to Google Drive. Example value: .*@example\.com
WebRtcUdpPortRange Restrict the range of local UDP ports used by WebRTC
If the policy is not set, or if it is set to the empty string or an invalid port range, WebRTC is allowed to use any available local UDP port.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebRtcUdpPortRange
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If the policy is set, the UDP port range used by WebRTC is restricted to the specified port interval (endpoints included). If the policy is not set, or if it is set to the empty string or an invalid port range, WebRTC is allowed to use any available local UDP port. Example value: 10000-11999
RestrictSigninToPattern Restrict which Google accounts are allowed to be set as browser primary accounts in Google Chrome
If this policy is left not set or blank, then the user can set any Google account as a browser primary account in Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RestrictSigninToPattern
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Contains a regular expression which is used to determine which Google accounts can be set as browser primary accounts in Google Chrome (i.e. the account that is chosen during the Sync opt-in flow). An appropriate error is displayed if a user tries to set a browser primary account with a username that does not match this pattern. If this policy is left not set or blank, then the user can set any Google account as a browser primary account in Google Chrome. Example value: .*@example\.com
EnterpriseCustomLabelForBrowser Set a custom enterprise label for a managed browser
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseCustomLabelForBrowser
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls a custom label used to indicate a managed browser. For managed browsers, this label will be shown in a management disclaimer on a footer on the New Tab page. The custom label will not be translated. Note that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: Chromium
EnterpriseCustomLabel Set a custom enterprise label for a managed profile
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseCustomLabel
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls a custom label used to identify managed profiles. For managed profiles, this label will be shown next to the avatar in the toolbar. The custom label will not be translated. When this policy is applied, any strings that surpass 16 characters will be truncated with a “...” Please refrain from using extended names. This policy can only be set as a user policy. Note that this policy has no effect if the EnterpriseProfileBadgeToolbarSettings policy is set to hide_expanded_enterprise_toolbar_badge (value 1). Example value: Chromium
DiskCacheDir Set disk cache directory
If not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DiskCacheDir
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy has Google Chrome use the directory you provide for storing cached files on the disk—whether or not users specify the --disk-cache-dir flag. If not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag. Google Chrome manages the contents of a volume's root directory. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes. See the variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: ${user_home}/Chrome_cache
DiskCacheSize Set disk cache size in bytes
) If not set, Google Chrome uses the default size.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DiskCacheSize
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to None has Google Chrome use the default cache size for storing cached files on the disk. Users can't change it. If you set the policy, Google Chrome uses the cache size you provide—whether or not users specify the --disk-cache-size flag. (Values below a few megabytes are rounded up.) If not set, Google Chrome uses the default size. Users can change that setting using the --disk-cache-size flag. Note: The value specified in this policy is used as a hint to various cache subsystems in the browser. Therefore the actual total disk consumption of all caches will be higher but within the same order of magnitude as the value specified.
DownloadDirectory Set download directory
Leaving the policy unset means Chrome uses the default download directory, and users can change it.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DownloadDirectory
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time. This policy overrides the DefaultDownloadDirectory policy. Leaving the policy unset means Chrome uses the default download directory, and users can change it. On Google ChromeOS it's possible to set it only to Google Drive directories. Note: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: /home/${user_name}/Downloads
DefaultBrowserSettingEnabled Set Google Chrome as Default Browser
Leaving the policy unset means Google Chrome lets users control whether it's the default and, if not, whether user notifications should appear.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultBrowserSettingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7
- Template
- chrome.admx
Setting the policy to True has Google Chrome always check whether it's the default browser on startup and, if possible, automatically register itself. Setting the policy to False stops Google Chrome from ever checking if it's the default and turns user controls off for this option. Leaving the policy unset means Google Chrome lets users control whether it's the default and, if not, whether user notifications should appear. Note: For Microsoft®Windows® administrators, turning this setting on only works for machines running Windows 7. For later versions, you must deploy a "default application associations" file that makes Google Chrome the handler for the https and http protocols (and, optionally, the ftp protocol and other file formats). See Chrome Help ( https://support.google.com/chrome?p=make_chrome_default_win ).
TotalMemoryLimitMb Set limit on megabytes of memory a single Chrome instance can use.
If this policy is not set, the browser will only begin attempts to save memory once it has detected that the amount of physical memory on its machine is low.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TotalMemoryLimitMb
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Configures the amount of memory that a single Google Chrome instance can use before tabs start being discarded (I.E. the memory used by the tab will be freed and the tab will have to be reloaded when switched to) to save memory. If the policy is set, browser will begin to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024. If this policy is not set, the browser will only begin attempts to save memory once it has detected that the amount of physical memory on its machine is low.
RelaunchWindow Set the time interval for relaunch
If this policy is not set, the default target time window for Google ChromeOS is between 2 AM and 4 AM.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RelaunchWindow
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Specify a target time window for the end of the relaunch notification period. Users are notified of the need for a browser relaunch or device restart based on the RelaunchNotification and RelaunchNotificationPeriod policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the RelaunchNotification policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window. If this policy is not set, the default target time window for Google ChromeOS is between 2 AM and 4 AM. The default target time window for Google Chrome is the whole day (i.e., the end of the notification period is never deferred). Note: Though the policy can accept multiple items in entries, all but the first item are ignored. Warning: Setting this policy may delay application of software updates. See https://chromeenterprise.google/policies/?policy=RelaunchWindow for more information about schema and formatting. Example value: { "entries": [ { "duration_mins": 240, "start": { "hour": 2, "minute": 15 } } ] }
RelaunchNotificationPeriod Set the time period for update notifications
If not set, the default period of 604800000 milliseconds (one week) is used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RelaunchNotificationPeriod
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set the time period, in milliseconds, over which users are notified that Google Chrome must be relaunched or that a Google ChromeOS device must be restarted to apply a pending update. Over this time period, the user will be repeatedly informed of the need for an update. For Google ChromeOS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Google Chrome browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the RelaunchNotification policy follow this same schedule. If not set, the default period of 604800000 milliseconds (one week) is used.
UserDataDir Set user data directory
If this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UserDataDir
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Configures the directory that Google Chrome will use for storing user data. If you set this policy, Google Chrome will use the provided directory regardless whether the user has specified the '--user-data-dir' flag or not. To avoid data loss or other unexpected errors this policy should not be set to a directory used for other purposes, because Google Chrome manages its contents. See https://support.google.com/chrome/a?p=Supported_directory_variables for a list of variables that can be used. If this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag. Example value: ${users}/${user_name}/Chrome
ManagedConfigurationPerOrigin Sets managed configuration values to websites to specific origins
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ManagedConfigurationPerOrigin
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy defines the return value of Managed Configuration API for given origin. Managed configuration API is a key-value configuration that can be accessed via navigator.managed.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via WebAppInstallForceList. See https://chromeenterprise.google/policies/?policy=ManagedConfigurationPerOrigin for more information about schema and formatting. Example value: [ { "managed_configuration_hash": "asd891jedasd12ue9h", "managed_configuration_url": "https://gstatic.google.com/configuration.json", "origin": "https://www.google.com" }, { "managed_configuration_hash": "djio12easd89u12aws", "managed_configuration_url": "https://gstatic.google.com/configuration2.json", "origin": "https://www.example.com" } ]
NTPShortcuts Setting shortcuts on the New Tab Page
If set to false or unset, users cannot edit the name. If set to false or unset, users cannot remove the shortcut.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPShortcuts
- Stated default
- If set, users will see these shortcuts by default, in addition to their personal shortcuts.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy pre-configures up to 10 custom shortcuts on the Google Chrome New Tab page. If set, users will see these shortcuts by default, in addition to their personal shortcuts. Users can control visibility of their organization's shortcuts on the "Customize Chrome" panel. Shortcut URLs must be unique. If allow_user_edit is set to true, users can change the name of the shortcut. If set to false or unset, users cannot edit the name. If allow_user_delete is set to true, users can remove the shortcut. If set to false or unset, users cannot remove the shortcut. See https://chromeenterprise.google/policies/?policy=NTPShortcuts for more information about schema and formatting. Example value: [ { "name": "Google", "url": "https://www.google.com" }, { "name": "YouTube", "url": "https://www.youtube.com" }, { "name": "Google Drive", "url": "https://www.drive.google.com", "allow_user_edit": true, "allow_user_delete": true } ]
HistoryClustersVisible Show a view of Chrome history with groups of pages
If the policy is left unset, a Chrome history page organized into groups will be visible at chrome://history/grouped by default. Please note, if ComponentUpdatesEnabled policy is set to Disabled, but HistoryClustersVisible is set to Enabled or unset, a Chrome history page organized into groups will still be available at chrome://history/grouped, but may be less relevant to the user.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HistoryClustersVisible
- Enabled / Disabled
- 1 / 0
- Stated default
- If the policy is left unset, a Chrome history page organized into groups will be visible at chrome://history/grouped by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the visibility of the Chrome history page organized into groups of pages. If the policy is set to Enabled, a Chrome history page organized into groups will be visible at chrome://history/grouped. If the policy is set to Disabled, a Chrome history page organized into groups will not be visible at chrome://history/grouped. If the policy is left unset, a Chrome history page organized into groups will be visible at chrome://history/grouped by default. Please note, if ComponentUpdatesEnabled policy is set to Disabled, but HistoryClustersVisible is set to Enabled or unset, a Chrome history page organized into groups will still be available at chrome://history/grouped, but may be less relevant to the user.
ExternalProtocolDialogShowAlwaysOpenCheckbox Show an "Always open" checkbox in external protocol dialog.
If this policy is set to True or not set, when an external protocol confirmation is shown, the user can select "Always allow" to skip all future confirmation prompts for the protocol on this site.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExternalProtocolDialogShowAlwaysOpenCheckbox
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether or not the "Always open" checkbox is shown on external protocol launch confirmation prompts. If this policy is set to True or not set, when an external protocol confirmation is shown, the user can select "Always allow" to skip all future confirmation prompts for the protocol on this site. If this policy is set to False, the "Always allow" checkbox is not displayed and the user will be prompted each time an external protocol is invoked.
NTPCardsVisible Show cards on the New Tab Page
If the policy is not set, the user can control the card visibility.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPCardsVisible
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the visibility of cards on the New Tab Page. Cards surface entry points to launch common user journeys based on the user's browsing behavior. If the policy is set to Enabled, the New Tab Page will show cards if content is available. If the policy is set to Disabled, the New Tab Page won't show cards. If the policy is not set, the user can control the card visibility. The default is visible.
ShowFullUrlsInAddressBar Show Full URLs
If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ShowFullUrlsInAddressBar
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This feature enables display of the full URL in the address bar. If this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains. If this policy is set to False, then the default URL display will apply. If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
NTPOutlookCardVisible Show Outlook Calendar card on the New Tab Page
If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPOutlookCardVisible
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the visibility of the Outlook Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the Outlook Calendar data in the browser. Outlook data will not be stored by the browser. The Outlook card shows the next calendar event, along with a glanceable look at the rest of the day's meetings. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their next meeting. The Microsoft Outlook card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Outlook, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards. If the NTPCardsVisible is disabled, the Outlook Card will not be shown. If NTPCardsVisible is enabled, the Outlook card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
NTPSharepointCardVisible Show SharePoint and OneDrive File Card on the New Tab Page
If NTPCardsVisible is unset, the SharePoint and OneDrive card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPSharepointCardVisible
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the visibility of the SharePoint and OneDrive File Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the SharePoint and OneDrive File data in the browser. SharePoint and OneDrive data will not be stored by the browser. The SharePoint and OneDrive Files recommendation card shows a list of recommended files. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their most important documents. The Microsoft SharePoint and OneDrive card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Sharepoint, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards. If the NTPCardsVisible is disabled, the SharePoint and OneDrive Card will not be shown. If NTPCardsVisible is enabled, the SharePoint and OneDrive card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the SharePoint and OneDrive card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
ShowAppsShortcutInBookmarkBar Show the apps shortcut in the bookmark bar
If not set, users decide to show or hide the apps shortcut from the bookmark bar context menu.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ShowAppsShortcutInBookmarkBar
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True displays the apps shortcut. Setting the policy to False means this shortcut never appears. If you set the policy, users can't change it. If not set, users decide to show or hide the apps shortcut from the bookmark bar context menu.
NTPMiddleSlotAnnouncementVisible Show the middle slot announcement on the New Tab Page
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NTPMiddleSlotAnnouncementVisible
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the visibility of the middle slot announcement on the New Tab Page. If the policy is set to Enabled, the New Tab Page will show the middle slot announcement if it is available. If the policy is set to Disabled, the New Tab Page will not show the middle slot announcement even if it is available.
SiteSearchSettings Site search settings
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SiteSearchSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy provides a list of sites that users can quickly search using shortcuts in the address bar. Users can initiate a search by typing the shortcut or @shortcut (e.g. @work), followed by Space or Tab, in the address bar. The following fields are required for each site: name, shortcut, url. The name field corresponds to the site or search engine name to be shown to the user in the address bar. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must also be unique. For each entry, the url field specifies the URL of the search engine used during a search with the corresponding keyword. The URL must include the string '{searchTerms}', replaced in the query by the user's search terms. Invalid entries and entries with duplicate shortcuts are ignored. Site search entries configured as featured are displayed in the address bar when the user types "@". Up to three entries can be selected as featured. For a site search entry where allow_user_override is true, users have the ability to edit or disable that entry. However, featured engines (beginning with "@") can only be disabled. If a user modifies an entry that was initially created by this policy, it will no longer be managed by policy and will be treated like a user-created shortcut. When allow_user_override is false or unspecified for a site search entry, users cannot edit or disable that entry. The setting to allow user override is only supported on M139 and later; earlier versions will default to disabling user override. Users cannot create new site search entries with a shortcut previously created via this policy unless allow_user_override is set to true for the site search entry. In case of a conflict with a shortcut previously created by the user, the user setting takes precedence. However, users can still trigger the option created by the policy by typing "@" in the search bar. For example, if the user already defined "work" as a shortcut to URL1 and the policy defines "work" as a shortcut to URL2, then typing "work" in the search bar will trigger a search to URL1, but typing "@work" in the search bar will trigger a search to URL2. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. See https://chromeenterprise.google/policies/?policy=SiteSearchSettings for more information about schema and formatting. Example value: [ { "featured": true, "name": "Google Wikipedia", "shortcut": "wikipedia", "url": "https://www.google.com/search?q=site%3Awikipedia.com+%s" }, { "name": "YouTube", "shortcut": "youtube", "url": "https://www.youtube.com/results?search_query=%s" }, { "name": "Google Drive", "shortcut": "drive", "url": "https://drive.google.com/?q=%s", "allow_user_override": true } ]
FeedbackSurveysEnabled Specifies whether in-product Google Chrome surveys are shown to users.
When this policy is Enabled or not set, in-product surveys may be shown to users.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- FeedbackSurveysEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Google Chrome in-product surveys collect user feedback for the browser. Survey responses are not associated with user accounts. When this policy is Enabled or not set, in-product surveys may be shown to users. When this policy is Disabled, in-product surveys are not shown to users. This policy has no effect if MetricsReportingEnabled is set to Disabled, which disables in-product surveys as well.
SharedArrayBufferUnrestrictedAccessAllowed Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context
When set to Disabled or not set, sites can only use SharedArrayBuffers when cross-origin isolated.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SharedArrayBufferUnrestrictedAccessAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. Google Chrome will require cross-origin isolation when using SharedArrayBuffers from Google Chrome 91 onward (2021-05-25) for Web Compatibility reasons. Additional details can be found on: https://developer.chrome.com/blog/enabling-shared-array-buffer/. When set to Enabled, sites can use SharedArrayBuffer with no restrictions. When set to Disabled or not set, sites can only use SharedArrayBuffers when cross-origin isolated.
DnsOverHttpsTemplates Specify URI template of desired DNS-over-HTTPS resolver
If the DnsOverHttpsMode is set to "automatic" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DnsOverHttpsTemplates
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces. If the DnsOverHttpsMode is set to "secure" then this policy must be set and not empty. On Google ChromeOS only, either this policy or the DnsOverHttpsTemplatesWithIdentifiers must be set, otherwise the DNS resolution will fail. If the DnsOverHttpsMode is set to "automatic" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider. If the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST. Incorrectly formatted templates will be ignored. Example value: https://dns.example.net/dns-query{?dns}
SuppressDifferentOriginSubframeDialogs Suppress JavaScript Dialogs triggered from different origin subframes
If the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SuppressDifferentOriginSubframeDialogs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin. This policy allows overriding that change. If the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked. If the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked. This policy will be removed from Google Chrome in the future.
LookalikeWarningAllowlistDomains Suppress lookalike domain warnings on domains
If the policy is not set, or set to an empty list, warnings may appear on any site the user visits.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LookalikeWarningAllowlistDomains
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with. If the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain. If the policy is not set, or set to an empty list, warnings may appear on any site the user visits. A hostname can be allowed with a complete host match, or any domain match. For example, a URL like "https://foo.example.com/bar" may have warnings suppressed if this list includes either "foo.example.com" or "example.com". Example value: foo.example.com example.org
SuppressUnsupportedOSWarning Suppress the unsupported OS warning
Setting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SuppressUnsupportedOSWarning
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled suppresses the warning that appears when Google Chrome is running on an unsupported computer or operating system. Setting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.
CloudManagementEnrollmentToken The enrollment token of cloud policy
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudManagementEnrollmentToken
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy means Google Chrome tries to register itself with Chrome Enterprise Core browser management. The value of this policy is an enrollment token you can retrieve from the Google Admin console. See https://support.google.com/chrome/a/answer/9301891 for details. Example value: 37185d02-e055-11e7-80c1-9a214cf093ae
CacheEncryptionEnabled This policy allows administrators to encrypt http cache on disk.
When this policy is Disabled or not set, browser cache will not be encrypted.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CacheEncryptionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows the administrators to encrypt browser http cache on disk. When this policy is Enabled, browser cache will be encrypted. When this policy is Disabled or not set, browser cache will not be encrypted. Browser cache encryption may result in a performance impact.
TabDiscardingExceptions URL pattern Exceptions to tab discarding
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\TabDiscardingExceptions
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser. This applies to memory pressure and high efficiency mode discarding. A discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload. Example value: example.com https://* *
WebRtcLocalIpsAllowedUrls URLs for which local IPs are exposed in WebRTC ICE candidates
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebRtcLocalIpsAllowedUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Patterns in this list will be matched against the security origin of the requesting URL. If a match is found or chrome://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, the local IP addresses are shown in WebRTC ICE candidates. Otherwise, local IP addresses are concealed with mDNS hostnames. Please note that this policy weakens the protection of local IPs if needed by administrators. Example value: https://www.example.com *example.com*
AudioCaptureAllowedUrls URLs that will be granted access to audio capture devices without prompt
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AudioCaptureAllowedUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to audio capture devices without prompt For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. Note, however, that the pattern "*", which matches any URL, is not supported by this policy. Example value: https://www.example.com/ https://[*.]example.edu/
VideoCaptureAllowedUrls URLs that will be granted access to video capture devices without prompt
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\VideoCaptureAllowedUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to video capture devices without prompt For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. Note, however, that the pattern "*", which matches any URL, is not supported by this policy. Example value: https://www.example.com/ https://[*.]example.edu/
AutoOpenAllowedForURLs URLs where AutoOpenFileTypes can apply
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutoOpenAllowedForURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of URLs specifying which urls AutoOpenFileTypes will apply to. This policy has no impact on automatically open values set by users. If this policy is set, files will only automatically open by policy if the url is part of this set and the file type is listed in AutoOpenFileTypes. If either condition is false the download won't automatically open by policy. If this policy isn't set, all downloads where the file type is in AutoOpenFileTypes will automatically open. A URL pattern has to be formatted according to https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
SecurityKeyPermitAttestation URLs/domains automatically permitted direct Security Key attestation
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SecurityKeyPermitAttestation
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies WebAuthn RP IDs for which no prompt appears when attestation certificates from security keys are requested. A signal is also sent to the security key indicating that enterprise attestation may be used. Without this, when sites request attestation of security keys, users are prompted in Google Chrome version 65 and later. Example value: example.com
BuiltInDnsClientEnabled Use built-in DNS client
If this policy is set to Enabled or is left unset, the built-in DNS client will be used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BuiltInDnsClientEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls which software stack is used to communicate with the DNS server: the Operating System DNS client, or Google Chrome's built-in DNS client. This policy does not affect which DNS servers are used: if, for example, the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It also does not control if DNS-over-HTTPS is used; Google Chrome will always use the built-in resolver for DNS-over-HTTPS requests. Please see the DnsOverHttpsMode policy for information on controlling DNS-over-HTTPS. If this policy is set to Enabled or is left unset, the built-in DNS client will be used. If this policy is set to Disabled, the built-in DNS client will only be used when DNS-over-HTTPS is in use.
HardwareAccelerationModeEnabled Use graphics acceleration when available
Setting the policy to Enabled or leaving it unset turns on graphics acceleration, if available.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HardwareAccelerationModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset turns on graphics acceleration, if available. Setting the policy to Disabled turns off graphics acceleration.
PdfViewerOutOfProcessIframeEnabled Use out-of-process iframe PDF Viewer
When this policy is set to Enabled or not set, Google Chrome will be able to use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PdfViewerOutOfProcessIframeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls whether the PDF viewer in Google Chrome uses an out-of-process iframe (OOPIF). This will be the new PDF viewer architecture in the future, as it is simpler and makes adding new features easier. The existing GuestView PDF viewer is an outdated, complex architecture that is being deprecated. When this policy is set to Enabled or not set, Google Chrome will be able to use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Google Chrome. When this policy is set to Disabled, Google Chrome will strictly use the existing GuestView PDF viewer. It embeds a web page with a separate frame tree into another web page. This policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.
PdfUseSkiaRendererEnabled Use Skia renderer for PDF rendering
When this policy is not set, the PDF renderer will be chosen by the browser.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PdfUseSkiaRendererEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls whether the PDF viewer in Google Chrome uses Skia renderer. When this policy is enabled, the PDF viewer uses Skia renderer. When this policy is disabled, the PDF viewer uses its current AGG renderer. When this policy is not set, the PDF renderer will be chosen by the browser.
WebAppSettings Web App management settings
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebAppSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy. The manifest_id field is the Manifest ID for the Web App. See https://developer.chrome.com/blog/pwa-manifest-id/ for instructions on how to determine the Manifest ID for an installed web app. The run_on_os_login field specifies if a web app can be run during OS login. If this field is set to blocked, the web app will not run during OS login and the user will not be able to enable this later. If this field is set to run_windowed, the web app will run during OS login and the user will not be able to disable this later. If this field is set to allowed, the user will be able to configure the web app to run at OS login. The default configuration only allows the allowed and blocked values. (Since version 117) The prevent_close_after_run_on_os_login field specifies if a web app shall be prevented from closing in any way (e.g. by the user, task manager, web APIs). This behavior can only be enabled if run_on_os_login is set to run_windowed. If the app were already running, this property will only come into effect after the app is restarted. If this field is not defined, apps will be closable by users. (Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, i.e. shortcuts, file handlers, protocol handlers etc will be removed or not. If an app is already running, this property will come into effect after the app has restarted. This should be used with caution, since this can override any OS integration that is set automatically during the startup of the web applications system. Currently only works on Windows, Mac and Linux platforms. See https://chromeenterprise.google/policies/?policy=WebAppSettings for more information about schema and formatting. Example value: [ { "manifest_id": "https://foo.example/index.html", "run_on_os_login": "allowed" }, { "manifest_id": "https://bar.example/index.html", "run_on_os_login": "allowed" }, { "manifest_id": "https://foobar.example/index.html", "run_on_os_login": "run_windowed", "prevent_close_after_run_on_os_login": true }, { "manifest_id": "*", "run_on_os_login": "blocked" }, { "manifest_id": "https://foo.example/index.html", "force_unregister_os_integration": true } ]
Google:Cat_Google / Google Chrome - Default Settings (users can override)
DefaultSearchProviderContextMenuAccessAllowed Allow default search provider context menu search access
If this policy is set to enabled or not set, the context menu item for your default search provider will be available.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderContextMenuAccessAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enables the use of a default search provider on the context menu. If you set this policy to disabled the search context menu item that relies on your default search provider will not be available. If this policy is set to enabled or not set, the context menu item for your default search provider will be available. The policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.
DownloadRestrictions Allow download restrictions
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DownloadRestrictions
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0No special restrictions. Default.1Block malicious downloads and dangerous file types.2Block malicious downloads, uncommon or unwanted downloads and dangerous file types.3Block all downloads.4Block malicious downloads. Recommended.Setting the policy means users can't bypass download security decisions. There are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked): * Malicious, as flagged by the Safe Browsing server * Uncommon or unwanted, as flagged by the Safe Browsing server * A dangerous file type (e.g. all SWF downloads and many EXE downloads) Setting the policy blocks different subsets of these, depending on it's value: 0: No special restrictions. Default. 1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 3: Blocks all downloads. Not recommended, except for special use cases. 4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended. Note: These restrictions apply to downloads triggered from webpage content, as well as the Download link… menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).
HttpsOnlyMode Allow HTTPS-Only Mode to be enabled
If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- HttpsOnlyMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Do not restrict users' HTTPS-Only Mode settingDisable HTTPS-Only ModeEnable HTTPS-Only Mode in Strict modeEnable HTTPS-Only Mode in Balanced ModeThis policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode upgrades all navigations to HTTPS. If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode. If this setting is set to "disallowed", HTTPS-Only Mode will be disabled. If this setting is set to "force_enabled", HTTPS-Only Mode will be enabled in Strict mode. If this setting is set to "force_balanced_enabled", HTTPS-Only Mode will be enabled in Balanced mode. "force_enabled" is supported from M112 onwards, "force_balanced_enabled" is supported from M129 onwards. "force_enabled" and "force_balanced_enabled" can be recommended to users too. HTTPS-Only Mode will be set Strict or Balanced initially but users are allowed to change it. If you set this policy to a value that is not supported by the version of Chrome that receives the policy, Chrome will default to the allowed setting. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. Example value: disallowed
DomainReliabilityAllowed Allow reporting of domain reliability related data
If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DomainReliabilityAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google. If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
AlwaysOpenPdfExternally Always Open PDF files externally
If not set, users can choose whether to open PDF externally or not.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- AlwaysOpenPdfExternally
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application. Setting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files. If you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.
ApplicationLocaleValue Application locale
Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured).
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ApplicationLocaleValue
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the locale Google Chrome uses. Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured). 2) The system locale. 3) The fallback locale (en-US). Example value: en
BlockThirdPartyCookies Block third party cookies
Leaving it unset allows third-party cookies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- BlockThirdPartyCookies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting. Leaving it unset allows third-party cookies, but users can change this setting. Note: This policy doesn't apply in Incognito mode, where third-party cookies are blocked and can only be allowed at the site level. To allow cookies at the site level, use the CookiesAllowedForUrls policy.
BackgroundModeEnabled Continue running background apps when Google Chrome is closed
If unset, background mode is off at first, but users can change it.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- BackgroundModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there. Setting the policy to Disabled turns background mode off. If you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.
AutofillAddressEnabled Enable AutoFill for addresses
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- AutofillAddressEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI. Setting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.
AutofillCreditCardEnabled Enable AutoFill for credit cards
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- AutofillCreditCardEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI. Setting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.
BatterySaverModeAvailability Enable Battery Saver Mode
If this policy is unset, the end user can control this setting in chrome://settings/performance.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- BatterySaverModeAvailability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Battery Saver Mode will be disabled.1Battery Saver Mode will be enabled when the device is on battery power and battery level is low.2This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.This policy enables or disables the Battery Saver Mode setting. On Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance. On ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off. The different levels are: Disabled (0): Battery Saver Mode will be disabled. EnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low. EnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.
BookmarkBarEnabled Enable Bookmark Bar
If not set, users decide whether to use this function.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- BookmarkBarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar. If you set the policy, users can't change it. If not set, users decide whether to use this function.
NetworkPredictionOptions Enable network prediction
Leaving it unset turns on network prediction, but the user can change it.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- NetworkPredictionOptions
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Predict network actions on any network connection1Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)2Do not predict network actions on any network connectionThis policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages. If you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.
SpellCheckServiceEnabled Enable or disable spell checking web service
Leaving the policy unset lets users choose whether to use the spellcheck service.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- SpellCheckServiceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used. Leaving the policy unset lets users choose whether to use the spellcheck service. The spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.
OriginKeyedProcessesEnabled Enable origin-keyed process isolation by default.
, those assigned to an origin-keyed agent cluster by default).
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- OriginKeyedProcessesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enables origin-keyed process isolation for most pages (i.e., those assigned to an origin-keyed agent cluster by default). This improves security but also increases the number of processes created. Users are allowed to override the set policy value via the command-line flags or chrome://flags (both to turn this feature on or off). Setting the policy to Enabled results in most origins being isolated, even from other origins in the same site. See also the IsolateOrigins and SitePerProcess policies. Setting the policy to Disabled results in no origins being isolated from the rest of their site unless an origin explicitly asks to. Not setting the policy results in the browser determining which origins to isolate and when to isolate them.
MetricsReportingEnabled Enable reporting of usage and crash-related data
When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- MetricsReportingEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default. Users will still be able to change this setting. When this policy is Disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting. When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later. (For Google ChromeOS, see DeviceMetricsReportingEnabled.) On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
SearchSuggestEnabled Enable search suggestions
If not set, search suggestions are on at first, but users can turn them off any time.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- SearchSuggestEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions. Suggestions based on bookmarks or history are unaffected by the policy. If you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.
TranslateEnabled Enable Translate
Leaving it unset lets them change the setting.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- TranslateEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features. If you set the policy, users can't change this function. Leaving it unset lets them change the setting.
ImportAutofillFormData Import autofill form data from default browser on first run
Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ImportAutofillFormData
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run. Users can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.
ImportBookmarks Import bookmarks from default browser on first run
Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ImportBookmarks
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run. Users can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.
ImportHistory Import browsing history from default browser on first run
Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ImportHistory
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run. Users can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.
ImportSavedPasswords Import saved passwords from default browser on first run
Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ImportSavedPasswords
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls only the first run import behavior after installation. It enables more seamless transition to Google Chrome in environments where a different browser was extensively used prior to installing the browser. This policy does not affect password manager capabilities for Google accounts. Setting the policy to Enabled imports saved passwords from the previous default browser on first run and manual importing from the settings page is also possible. Setting the policy to Disabled means no saved passwords are imported on first run and manual importing from the Settings page is blocked. Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
ImportSearchEngine Import search engines from default browser on first run
Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ImportSearchEngine
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run. Users can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.
EnterpriseProfileCreationKeepBrowsingData Keep browsing data when creating enterprise profile by default
If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- EnterpriseProfileCreationKeepBrowsingData
- Enabled / Disabled
- 1 / 0
- Stated default
- If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default. Regardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile. This policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.
DefaultDownloadDirectory Set default download directory
Leaving the policy unset means Chrome uses its platform-specific default directory.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultDownloadDirectory
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory. Leaving the policy unset means Chrome uses its platform-specific default directory. This policy has no effect if the policy DownloadDirectory is set. Note: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: /home/${user_name}/Downloads
DownloadDirectory Set download directory
Leaving the policy unset means Chrome uses the default download directory, and users can change it.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DownloadDirectory
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time. This policy overrides the DefaultDownloadDirectory policy. Leaving the policy unset means Chrome uses the default download directory, and users can change it. On Google ChromeOS it's possible to set it only to Google Drive directories. Note: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: /home/${user_name}/Downloads
ShowFullUrlsInAddressBar Show Full URLs
If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ShowFullUrlsInAddressBar
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This feature enables display of the full URL in the address bar. If this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains. If this policy is set to False, then the default URL display will apply. If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Accessibility settings
LiveCaptionEnabled Enable Live Caption
If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- LiveCaptionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enable the Live Caption feature. If this policy is set to Enabled, Live Caption will always be turned on. If this policy is set to Disabled, Live Caption will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
LiveTranslateEnabled Enable Live Translate
If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- LiveTranslateEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enable translation of live captions. Captions will be sent to Google for translation. If this policy is set to Enabled, Live Translate will always be turned on. If this policy is set to Disabled, Live Translate will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime. In LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Content settings
RegisteredProtocolHandlers Register protocol handlers
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- RegisteredProtocolHandlers
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy (as recommended only) lets you register a list of protocol handlers, which merge with the ones that the user registers, putting both sets in use. Set the property "protocol" to the scheme, such as "mailto", and set the property "URL" to the URL pattern of the application that handles the scheme specified in the "protocol" field. The pattern can include a "%s" placeholder, which the handled URL replaces. Users can't remove a protocol handler registered by policy. However, by installing a new default handler, they can change the protocol handlers installed by policy. See https://chromeenterprise.google/policies/?policy=RegisteredProtocolHandlers for more information about schema and formatting. Example value: [ { "default": true, "protocol": "mailto", "url": "https://mail.google.com/mail/?extsrc=mailto&url=%s" } ]
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Default search provider
DefaultSearchProviderEncodings_recommended Default search provider encodings
Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- List subkey
- Software\Policies\Google\Chrome\Recommended\DefaultSearchProviderEncodings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided. Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use. Example value: UTF-8 UTF-16 GB2312 ISO-8859-1
DefaultSearchProviderKeyword Default search provider keyword
Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderKeyword
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider. Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider. Example value: mis
DefaultSearchProviderName Default search provider name
Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderName
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name. Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used. Example value: My Intranet Search
DefaultSearchProviderNewTabURL Default search provider new tab page URL
Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderNewTabURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page. Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided. Example value: https://search.my.company/newtab
DefaultSearchProviderSearchURL Default search provider search URL
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderSearchURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'. Example value: https://search.my.company/search?q={searchTerms}
DefaultSearchProviderSuggestURL Default search provider suggest URL
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderSuggestURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'. Example value: https://search.my.company/suggest?q={searchTerms}
DefaultSearchProviderEnabled Enable the default search provider
If not set, the default search provider is on, and users can set the search provider list.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar. The Disabled value is not supported by the Google Admin console. If you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
DefaultSearchProviderAlternateURLs_recommended List of alternate URLs for the default search provider
Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- List subkey
- Software\Policies\Google\Chrome\Recommended\DefaultSearchProviderAlternateURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'. Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms. Example value: https://search.my.company/suggest#q={searchTerms} https://search.my.company/suggest/search#q={searchTerms}
DefaultSearchProviderImageURL Parameter providing search-by-image feature for the default search provider
) Leaving DefaultSearchProviderImageURL unset means no image search is used.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderImageURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.) Leaving DefaultSearchProviderImageURL unset means no image search is used. If image search uses the GET method, then the URL must specify image parameters using a valid combination of the following placeholders: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: https://search.my.company/searchbyimage/upload
DefaultSearchProviderImageURLPostParams Parameters for image URL which uses POST
Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderImageURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it. Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method. The URL must specify the image parameter using a valid combination of the following placeholders depending on what the search provider supports: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: content={google:imageThumbnail},url={google:imageURL},sbisrc={google:imageSearchSource}
DefaultSearchProviderSearchURLPostParams Parameters for search URL which uses POST
Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderSearchURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
DefaultSearchProviderSuggestURLPostParams Parameters for suggest URL which uses POST
Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderSuggestURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Deprecated policies
AutoFillEnabled Enable AutoFill
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- AutoFillEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingEnabled Enable Safe Browsing
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- SafeBrowsingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Password manager
PasswordManagerEnabled Enable saving passwords to the password manager
If not set, the user can turn off password saving.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- PasswordManagerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the browser's ability to automatically remember passwords on websites and save them in the built-in password manager. It does not limit access or change the contents of passwords saved in the password manager and possibly synchronized to the Google account profile and Android. Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site. Setting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work. If the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Printing
PrintHeaderFooter Print Headers and Footers
If unset, users decides whether headers and footers appear.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- PrintHeaderFooter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview. If you set the policy, users can't change it. If unset, users decides whether headers and footers appear.
PrintPreviewUseSystemDefaultPrinter Use System Default Printer as Default
Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- PrintPreviewUseSystemDefaultPrinter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview. Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Removed policies
ClearSiteDataOnExit Clear site data on browser shutdown (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ClearSiteDataOnExit
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderIconURL Default search provider icon
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderIconURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURL Default search provider instant URL
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderInstantURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InstantEnabled Enable Instant
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- InstantEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DnsPrefetchingEnabled Enable network prediction
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DnsPrefetchingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderSearchTermsReplacementKey Parameter controlling search term placement for the default search provider
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderSearchTermsReplacementKey
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURLPostParams Parameters for instant URL which uses POST
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- DefaultSearchProviderInstantURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Safe Browsing settings
SafeBrowsingProtectionLevel Safe Browsing Protection Level
If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- SafeBrowsingProtectionLevel
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Safe Browsing is never active.1Safe Browsing is active in the standard mode.2Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in. If this policy is set to 'NoProtection' (value 0), Safe Browsing is never active. If this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode. If this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google. If you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome. If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting. See https://support.google.com/chrome?p=safe_browsing_preferences for more info on Safe Browsing.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Startup, Home page and New Tab page
RestoreOnStartup Action on startup
Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If not set, users can change it.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- RestoreOnStartup
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
5Open New Tab Page1Restore the last session4Open a list of URLs6Open a list of URLs and restore the last sessionSetting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If you set the policy, users can't change it in Google Chrome. If not set, users can change it. Setting this policy to RestoreOnStartupIsLastSession or RestoreOnStartupIsLastSessionAndURLs turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies. If this policy is set to RestoreOnStartupIsLastSessionAndURLs, browser will restore previous session and open a separate window to show URLs that are set from RestoreOnStartupURLs. Note that users can choose to keep those URLs open and they will also be restored in the future session. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
HomepageLocation Configure the home page URL
Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- HomepageLocation
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup. If the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect. The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome. Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://www.chromium.org
ShowHomeButton Show Home button on toolbar
If not set, users chooses whether to show the Home button.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- ShowHomeButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing. If you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.
RestoreOnStartupURLs_recommended URLs to open on startup
If not set, the New Tab page opens on start up.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- List subkey
- Software\Policies\Google\Chrome\Recommended\RestoreOnStartupURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open. If not set, the New Tab page opens on start up. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://example.com https://www.chromium.org
HomepageIsNewTabPage Use New Tab Page as homepage
If not set, the user decides whether or not the New Tab page is their homepage.
- Registry key
- Software\Policies\Google\Chrome\Recommended
- Value name
- HomepageIsNewTabPage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab. If you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
Google:Cat_Google / Google Chrome / Accessibility settings
LiveCaptionEnabled Enable Live Caption
If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LiveCaptionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enable the Live Caption feature. If this policy is set to Enabled, Live Caption will always be turned on. If this policy is set to Disabled, Live Caption will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
LiveTranslateEnabled Enable Live Translate
If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LiveTranslateEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enable translation of live captions. Captions will be sent to Google for translation. If this policy is set to Enabled, Live Translate will always be turned on. If this policy is set to Disabled, Live Translate will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime. In LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.
Google:Cat_Google / Google Chrome / Allow or deny screen capture
ScreenCaptureAllowedByOrigins Allow Desktop, Window, and Tab capture by these origins
Leaving the policy unset means that sites will not be considered for an override at this level of Capture.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ScreenCaptureAllowedByOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture. Leaving the policy unset means that sites will not be considered for an override at this level of Capture. This policy is not considered if a site matches a URL pattern in any of the following policies: WindowCaptureAllowedByOrigins, TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins. If a site matches a URL pattern in this policy, the ScreenCaptureAllowed will not be considered. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
ScreenCaptureAllowed Allow or deny screen capture
If enabled or not configured (default), a Web page can use screen-share APIs (e.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ScreenCaptureAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If enabled or not configured (default), a Web page can use screen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API) to prompt the user to select a tab, window or desktop to capture. When this policy is disabled, any calls to screen-share APIs will fail with an error; however this policy is not considered (and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies: ScreenCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins.
SameOriginTabCaptureAllowedByOrigins Allow Same Origin Tab capture by these origins
Leaving the policy unset means that sites will not be considered for an override at this level of capture.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SameOriginTabCaptureAllowedByOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin. Leaving the policy unset means that sites will not be considered for an override at this level of capture. Note that windowed Chrome Apps with the same origin as this site will still be allowed to be captured. If a site matches a URL pattern in this policy, the following policies will not be considered: TabCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
TabCaptureAllowedByOrigins Allow Tab capture by these origins
Leaving the policy unset means that sites will not be considered for an override at this level of capture.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\TabCaptureAllowedByOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that can use Tab Capture. Leaving the policy unset means that sites will not be considered for an override at this level of capture. Note that windowed Chrome Apps will still be allowed to be captured. This policy is not considered if a site matches a URL pattern in the SameOriginTabCaptureAllowedByOrigins policy. If a site matches a URL pattern in this policy, the following policies will not be considered: WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
WindowCaptureAllowedByOrigins Allow Window and Tab capture by these origins
Leaving the policy unset means that sites will not be considered for an override at this level of Capture.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WindowCaptureAllowedByOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture. Leaving the policy unset means that sites will not be considered for an override at this level of Capture. This policy is not considered if a site matches a URL pattern in any of the following policies: TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins. If a site matches a URL pattern in this policy, the following policies will not be considered: ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
Google:Cat_Google / Google Chrome / Certificate management settings
CACertificateManagementAllowed Allow users to manage installed CA certificates.
Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CACertificateManagementAllowed
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow users to manage all certificates1Allow users to manage user certificates2Disallow users from managing certificatesSetting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.
CAHintCertificates TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CAHintCertificates
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A list of certificates that are not trusted or distrusted in Google Chrome but can be used as hints for path-building. Certificates should be base64-encoded. Example value: MIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd
CADistrustedCertificates TLS certificates that should be distrusted by Google Chrome for server authentication
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CADistrustedCertificates
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A list of certificate public keys that should be distrusted by Google Chrome for TLS server authentication. The policy value is a list of base64-encoded X.509 certificates. Any certificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted. Example value: MIIB/TCCAaOgAwIBAgIUQthnWVsd1jWpUCNBf/uILjXC+t4wCgYIKoZIzj0EAwIwVDELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFZpcmdpbmlhMQ8wDQYDVQQHDAZSZXN0b24xITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMzEyMDcxNjE5NTVaFw0yMzEyMjExNjE5NTVaMFQxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhWaXJnaW5pYTEPMA0GA1UEBwwGUmVzdG9uMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ9Akav/KB0aVA9FM1QK4J1CEHn5rFOyY/nxcr5HG3+Fom0Kwu5zTR/kz9eOYgtG/1NmCzbiEKaULDfzA8V9aJ7o1MwUTAdBgNVHQ4EFgQUq37bLKiuw8Y/G+rurMf46hw7EekwHwYDVR0jBBgwFoAUq37bLKiuw8Y/G+rurMf46hw7EekwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAgNIADBFAiEA/JhtLSgtVOcXkgFJ9V5Vb6lhGdiKQFfzO9wTxPeCxCECIFePYPucys2n/r9MOBMHiX/8068ssv+uceqokzUg0mAb
CACertificates TLS certificates that should be trusted by Google Chrome for server authentication
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CACertificates
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A list of TLS certificates that should be trusted by Google Chrome for server authentication. Certificates should be base64-encoded. Example value: MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X
CACertificatesWithConstraints TLS certificates that should be trusted by Google Chrome for server authentication with constraints
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CACertificatesWithConstraints
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A list of TLS certificates that should be trusted by Google Chrome for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed. Certificates should be base64-encoded. At least one constraint must be specified for each certificate. See https://chromeenterprise.google/policies/?policy=CACertificatesWithConstraints for more information about schema and formatting. Example value: [ { "certificate": "MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X", "constraints": { "permitted_dns_names": [ "example.org" ], "permitted_cidrs": [ "10.1.1.0/24" ] } } ]
CAPlatformIntegrationEnabled Use user-added TLS certificates from platform trust stores for server authentication
If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CAPlatformIntegrationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication. If disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.
Google:Cat_Google / Google Chrome / Content settings
SensorsAllowedForUrls Allow access to sensors on these sites
Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SensorsAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can access sensors like motion and light sensors. Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies. If the same URL pattern exists in both this policy and the SensorsBlockedForUrls policy, the latter is prioritized and access to motion or light sensors will be blocked. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
AutomaticDownloadsAllowedForUrls Allow automatic downloads on these sites
If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutomaticDownloadsAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of URL patterns that specify sites which are allowed to download multiple files automatically. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns. If a URL matches both AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls, AutomaticDownloadsBlockedForUrls takes precedence. If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set. If not, the user's personal setting applies. Example value: https://www.example.com [*.]example.edu
AutomaticFullscreenAllowedForUrls Allow automatic fullscreen on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutomaticFullscreenAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
For security reasons, the requestFullscreen() web API requires a prior user gesture ("transient activation") to be called or will otherwise fail. Users' personal settings may allow certain origins to call this API without a prior user gesture, as described in https://chromestatus.com/feature/6218822004768768. This policy supersedes users' personal settings and allows matching origins to call the API without a prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Origins matching both blocked and allowed policy patterns will be blocked. Origins not specified by policy nor user settings will require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
ClipboardAllowedForUrls Allow clipboard on these sites
Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ClipboardAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that can use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission. Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
CookiesAllowedForUrls Allow cookies on these sites
If this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting or BlockThirdPartyCookies policies if they are set, or the user's personal configuration otherwise.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CookiesAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of url patterns that specify sites which are allowed to set cookies. URL patterns may be a single URL indicating that the site may use cookies on all top-level sites. Patterns may also be two URLs delimited by a comma. The first specifies the site that should be allowed to use cookies. The second specifies the top-level site that the first value should be applied on. If you use a pair of URLs, the first value in the pair supports * but the second value does not. Using * for the first value indicates that all sites may use cookies when the second URL is the top-level site. If this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting or BlockThirdPartyCookies policies if they are set, or the user's personal configuration otherwise. See also policies CookiesBlockedForUrls and CookiesSessionOnlyForUrls. Note that there must be no conflicting URL patterns between these three policies - it is unspecified which policy takes precedence. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu https://www.example.com/,https://www.toplevel.com/ *,https://www.toplevel.com/
IdleDetectionAllowedForUrls Allow idle detection on these sites
If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\IdleDetectionAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of URL patterns that specify the sites that are allowed to use the Idle Detection API witout asking the user. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise. Example value: https://www.example.com [*.]example.edu
ImagesAllowedForUrls Allow images on these sites
Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ImagesAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that may display images. Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Note that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android. Example value: https://www.example.com [*.]example.edu
InsecureContentAllowedForUrls Allow insecure content on these sites
If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\InsecureContentAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled. If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
JavaScriptAllowedForUrls Allow JavaScript on these sites
Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\JavaScriptAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can run JavaScript. Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
JavaScriptOptimizerAllowedForSites Allow JavaScript optimization on these sites
If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise Javascript optimization is enabled for the site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\JavaScriptOptimizerAllowedForSites
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations enabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise Javascript optimization is enabled for the site. Example value: [*.]example.edu
JavaScriptJitAllowedForSites Allow JavaScript to use JIT on these sites
If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\JavaScriptJitAllowedForSites
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled. If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site. Example value: [*.]example.edu
PdfLocalFileAccessAllowedForDomains Allow local file access to file:// URLs on these sites in the PDF Viewer
Leaving the policy unset disallows all domains from accessing file:// URLs in the PDF Viewer.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PdfLocalFileAccessAllowedForDomains
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting this policy allows the domains listed to access file:// URLs in the PDF Viewer. Adding to the policy allows the domain to access file:// URLs in the PDF Viewer. Removing from the policy disallows the domain from accessing file:// URLs in the PDF Viewer. Leaving the policy unset disallows all domains from accessing file:// URLs in the PDF Viewer. Example value: example.com google.com
LocalFontsAllowedForUrls Allow Local Fonts permission on these sites
If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LocalFontsAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Sets a list of site url patterns that specify sites which will automatically grant the local fonts permission. This will extend the ability of sites to see information about local fonts. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. Example value: https://www.example.com [*.]example.edu
NotificationsAllowedForUrls Allow notifications on these sites
Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\NotificationsAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can display notifications. Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
PopupsAllowedForUrls Allow pop-ups on these sites
Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PopupsAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can open pop-ups. Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
PreciseGeolocationAllowedForUrls Allow precise geolocation on these sites
Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PreciseGeolocationAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that are allowed to access the user's high accuracy geolocation without first having to request the user's permission to do so. Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
FileSystemReadAskForUrls Allow read access via the File System API on these sites
Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\FileSystemReadAskForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API. Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns must not conflict with FileSystemReadBlockedForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
SerialAskForUrls Allow the Serial API on these sites
Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SerialAskForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a serial port. Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. For URL patterns which do not match the policy SerialBlockedForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order. If URL patterns conflict with SerialBlockedForUrls they will be ignored. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WebHidAskForUrls Allow the WebHID API on these sites
Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebHidAskForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device. Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. For URL patterns which do not match the policy, the following take precedence, in this order: * WebHidBlockedForUrls (if there is a match), * DefaultWebHidGuardSetting (if set), or * Users' personal settings. URL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://google.com https://chromium.org
WebUsbAskForUrls Allow WebUSB on these sites
Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebUsbAskForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a USB device. Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns must not conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WindowManagementAllowedForUrls Allow Window Management permission on these sites
If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WindowManagementAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of site url patterns that specify sites which will automatically grant the window management permission. This will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. This replaces the deprecated WindowPlacementAllowedForUrls policy. Example value: https://www.example.com [*.]example.edu
FileSystemWriteAskForUrls Allow write access to files and directories on these sites
Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\FileSystemWriteAskForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system. Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns must not conflict with FileSystemWriteBlockedForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
SerialAllowAllPortsForUrls Automatically grant permission to sites to connect all serial ports.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SerialAllowAllPortsForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports. The URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered. On Google ChromeOS, this policy only applies to affiliated users. This policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences. Example value: https://www.example.com
WebHidAllowAllDevicesForUrls Automatically grant permission to sites to connect to any HID device.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebHidAllowAllDevicesForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy allows you to list sites which are automatically granted permission to access all available devices. The URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered. On ChromeOS, this policy only applies to affiliated users. This policy overrides DefaultWebHidGuardSetting, WebHidAskForUrls, WebHidBlockedForUrls and the user's preferences. Example value: https://google.com https://chromium.org
SerialAllowUsbDevicesForUrls Automatically grant permission to sites to connect to USB serial devices.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SerialAllowUsbDevicesForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy allows you to list sites which are automatically granted permission to access USB serial devices with vendor and product IDs matching the vendor_id and product_id fields. Omitting the product_id field allows the given sites permission to access devices with a vendor ID matching the vendor_id field and any product ID. The URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered. On ChromeOS, this policy only applies to affiliated users. This policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences. This policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the WebUsbAllowDevicesForUrls policy. See https://chromeenterprise.google/policies/?policy=SerialAllowUsbDevicesForUrls for more information about schema and formatting. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://specific-device.example.com" ] }, { "devices": [ { "vendor_id": 1234 } ], "urls": [ "https://all-vendor-devices.example.com" ] } ]
WebHidAllowDevicesWithHidUsagesForUrls Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage.
Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebHidAllowDevicesWithHidUsagesForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage. Each item in the list requires both usages and urls fields for the policy to be valid. Each item in the usages field must have a usage_page and may have a usage field. Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page. An item which has a usage field without a usage_page field is invalid and is ignored. Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies. URLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls. See https://chromeenterprise.google/policies/?policy=WebHidAllowDevicesWithHidUsagesForUrls for more information about schema and formatting. Example value: [ { "urls": [ "https://google.com", "https://chromium.org" ], "usages": [ { "usage": 5678, "usage_page": 1234 } ] } ]
WebHidAllowDevicesForUrls Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs.
Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebHidAllowDevicesForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored. Each item in the devices field must have a vendor_id and may have a product_id field. Omitting the product_id field will create a policy matching any device with the specified vendor ID. An item which has a product_id field without a vendor_id field is invalid and is ignored. Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies. URLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls. See https://chromeenterprise.google/policies/?policy=WebHidAllowDevicesForUrls for more information about schema and formatting. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://google.com", "https://chromium.org" ] } ]
WebUsbAllowDevicesForUrls Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebUsbAllowDevicesForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites are automatically granted permission to access a USB device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the policy to be valid. Each item in the devices field can have a vendor_id and product_id field. Omitting the vendor_id field will create a policy matching any device. Omitting the product_id field will create a policy matching any device with the given vendor ID. A policy which has a product_id field without a vendor_id field is invalid. The USB permission model will grant the specified URL permission to access the USB device as a top-level origin. If embedded frames need to access USB devices, the 'usb' feature-policy header should be used to grant access. The URL must be valid, otherwise the policy is ignored. Deprecated: The USB permission model used to support specifying both the requesting and embedding URLs. This is deprecated and only supported for backwards compatibility in this manner: if both a requesting and embedding URL is specified, then the embedding URL will be granted the permission as top-level origin and the requesting URL will be ignored entirely. This policy overrides DefaultWebUsbGuardSetting, WebUsbAskForUrls, WebUsbBlockedForUrls and the user's preferences. This policy only affects access to USB devices through the WebUSB API. To grant access to USB devices through the Web Serial API see the SerialAllowUsbDevicesForUrls policy. See https://chromeenterprise.google/policies/?policy=WebUsbAllowDevicesForUrls for more information about schema and formatting. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://google.com" ] } ]
AutoSelectCertificateForUrls Automatically select client certificates for these sites
Leaving the policy unset means there's no autoselection for any site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutoSelectCertificateForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you make a list of URL patterns that specify sites for which Chrome can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { "pattern": "$URL_PATTERN", "filter" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected. On Android and iOS, Chrome can only select client certificates that it has provisioned itself; it cannot access certificates installed at the operating system level. Examples for the usage of the $FILTER section: * When $FILTER is set to { "ISSUER": { "CN": "$ISSUER_CN" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected. * When $FILTER contains both the "ISSUER" and the "SUBJECT" sections, only client certificates that satisfy both conditions are selected. * When $FILTER contains a "SUBJECT" section with the "O" value, a certificate needs at least one organization matching the specified value to be selected. * When $FILTER contains a "SUBJECT" section with a "OU" value, a certificate needs at least one organizational unit matching the specified value to be selected. * When $FILTER is set to {}, the selection of client certificates is not additionally restricted. Note that filters provided by the web server still apply. Leaving the policy unset means there's no autoselection for any site. See https://chromeenterprise.google/policies/?policy=AutoSelectCertificateForUrls for more information about schema and formatting. Example value: {"pattern":"https://www.example.com","filter":{"ISSUER":{"CN":"certificate issuer name", "L": "certificate issuer location", "O": "certificate issuer org", "OU": "certificate issuer org unit"}, "SUBJECT":{"CN":"certificate subject name", "L": "certificate subject location", "O": "certificate subject org", "OU": "certificate subject org unit"}}}
SensorsBlockedForUrls Block access to sensors on these sites
Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SensorsBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't access sensors like motion and light sensors. Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies. If the same URL pattern exists in both this policy and the SensorsAllowedForUrls policy, this policy is prioritized and access to motion or light sensors will be blocked. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
AutomaticDownloadsBlockedForUrls Block automatic downloads on these sites
If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutomaticDownloadsBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of URL patterns that specify sites which are not allowed to download multiple files automatically. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns. If a URL matches both AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls, AutomaticDownloadsBlockedForUrls takes precedence. If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set. If not, the user's personal setting applies. Example value: https://www.example.com [*.]example.edu
AutomaticFullscreenBlockedForUrls Block automatic fullscreen on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutomaticFullscreenBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
For security reasons, the requestFullscreen() web API requires a prior user gesture ("transient activation") to be called or will otherwise fail. Users' personal settings may allow certain origins to call this API without a prior user gesture, as described in https://chromestatus.com/feature/6218822004768768. This policy supersedes users' personal settings and blocks matching origins from calling the API without a prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Origins matching both blocked and allowed policy patterns will be blocked. Origins not specified by policy nor user settings will require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
ClipboardBlockedForUrls Block clipboard on these sites
Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ClipboardBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that can't use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission. Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
CookiesBlockedForUrls Block cookies on these sites
Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CookiesBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you make a list of URL patterns that specify sites that can't set cookies. Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. While no specific policy takes precedence, see CookiesAllowedForUrls and CookiesSessionOnlyForUrls. URL patterns among these 3 policies must not conflict. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
GeolocationBlockedForUrls Block geolocation on these sites
Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\GeolocationBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that are not allowed to access the user's geolocation, and are also prevented from requesting user permission to do so. Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
IdleDetectionBlockedForUrls Block idle detection on these sites
If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\IdleDetectionBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of URL patterns that specify the sites that are not allowed to use the Idle Detection API. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise. Example value: https://www.example.com [*.]example.edu
ImagesBlockedForUrls Block images on these sites
Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ImagesBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that can't display images. Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Note that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android. Example value: https://www.example.com [*.]example.edu
InsecureContentBlockedForUrls Block insecure content on these sites
If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\InsecureContentBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded. If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
JavaScriptJitBlockedForSites Block JavaScript from using JIT on these sites
If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\JavaScriptJitBlockedForSites
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled. Disabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT disabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled. If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site. Example value: [*.]example.edu
JavaScriptBlockedForUrls Block JavaScript on these sites
Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\JavaScriptBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't run JavaScript. Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Note that this policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that is also displayed in the address bar) matches any of the patterns. Therefore this policy is not appropriate for mitigating web supply-chain attacks. For example, supplying the pattern "https://[*.]foo.com/" will not prevent a page hosted on, say, https://example.com from running a script loaded from https://www.foo.com/example.js. Furthermore, supplying the pattern "https://example.com/" will not prevent a document from https://example.com from running scripts if it is not the top-level document, but embedded as a sub-frame into a page hosted on another origin, say, https://www.bar.com. Example value: https://www.example.com [*.]example.edu
JavaScriptOptimizerBlockedForSites Block JavaScript optimizations on these sites
If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise JavaScript optimization is enabled for the site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\JavaScriptOptimizerBlockedForSites
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled. Disabling JavaScript optimizations will mean that Google Chrome may render web content more slowly. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations disabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise JavaScript optimization is enabled for the site. Example value: [*.]example.edu
LocalFontsBlockedForUrls Block Local Fonts permission on these sites
If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LocalFontsBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Sets a list of site url patterns that specify sites which will automatically deny the local fonts permission. This will limit the ability of sites to see information about local fonts. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. Example value: https://www.example.com [*.]example.edu
NotificationsBlockedForUrls Block notifications on these sites
Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\NotificationsBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't display notifications. Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
PopupsBlockedForUrls Block pop-ups on these sites
Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PopupsBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't open pop-ups. Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
FileSystemReadBlockedForUrls Block read access via the File System API on these sites
Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\FileSystemReadBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API. Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns can't conflict with FileSystemReadAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
SerialBlockedForUrls Block the Serial API on these sites
Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SerialBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a serial port. Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies. For URL patterns which do not match the policy SerialAskForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order. If URL patterns conflict with SerialAskForUrls this policy will take precedence. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WebHidBlockedForUrls Block the WebHID API on these sites
Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebHidBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device. Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. For URL patterns which do not match the policy, the following take precedence, in this order: * WebHidAskForUrls (if there is a match), * DefaultWebHidGuardSetting (if set), or * Users' personal settings. URL patterns can't conflict with WebHidAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://google.com https://chromium.org
WebUsbBlockedForUrls Block WebUSB on these sites
Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebUsbBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a USB device. Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies. URL patterns can't conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WindowManagementBlockedForUrls Block Window Management permission on these sites
If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WindowManagementBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to set a list of site url patterns that specify sites which will automatically deny the window management permission. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. This replaces the deprecated WindowPlacementBlockedForUrls policy. Example value: https://www.example.com [*.]example.edu
FileSystemWriteBlockedForUrls Block write access to files and directories on these sites
Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\FileSystemWriteBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system. Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns can't conflict with FileSystemWriteAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
PartitionedBlobUrlUsage Choose whether Blob URLs are partitioned during fetching and navigations
If this policy is set to Enabled or not set, Blob URLs will be partitioned.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PartitionedBlobUrlUsage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether Blob URLs are partitioned during fetching and navigation. If this policy is set to Enabled or not set, Blob URLs will be partitioned. If this policy is set to Disabled, Blob URLs won't be partitioned. If you must use the policy, please file a bug at Google Chrome explaining your use case. The policy is scheduled to be offered through Google Chrome version 146, after which the old implementation will be removed. NOTE: Only newly-started renderer processes will reflect changes to this policy while the browser is running. For detailed information on third-party storage partitioning, please see https://developers.google.com/privacy-sandbox/cookies/storage-partitioning.
DefaultInsecureContentSetting Control use of insecure content exceptions
If this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultInsecureContentSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to load mixed content3Allow users to add exceptions to allow mixed contentAllows you to set whether users can add exceptions to allow mixed content for specific sites. This policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' and 'InsecureContentBlockedForUrls' policies. If this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.
DefaultJavaScriptJitSetting Control use of JavaScript JIT
If this policy is left not set, JavaScript JIT is enabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultJavaScriptJitSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow any site to run JavaScript JIT2Do not allow any site to run JavaScript JITAllows you to set whether Google Chrome will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not. Disabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration. This policy can be overridden for specific URL patterns using the JavaScriptJitAllowedForSites and JavaScriptJitBlockedForSites policies. If this policy is left not set, JavaScript JIT is enabled.
DefaultJavaScriptOptimizerSetting Control use of JavaScript optimizers
If this policy is left not set, JavaScript optimizations are enabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultJavaScriptOptimizerSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Enable advanced JavaScript optimizations on all sites2Disable advanced JavaScript optimizations on all sitesAllows you to set whether Google Chrome will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled. Disabling JavaScript optimizations (by setting this policy's value to 2) will mean that Google Chrome may render web content more slowly. This policy can be overridden for specific URL patterns using the JavaScriptOptimizerAllowedForSites and JavaScriptOptimizerBlockedForSites policies. If this policy is left not set, JavaScript optimizations are enabled.
DefaultFileSystemReadGuardSetting Control use of the File System API for reading
Leaving it unset lets websites ask for access, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultFileSystemReadGuardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to request read access to files and directories via the File System API3Allow sites to ask the user to grant read access to files and directories via the File System APISetting the policy to 3 lets websites ask for read access to files and directories in the host operating system's file system via the File System API. Setting the policy to 2 denies access. Leaving it unset lets websites ask for access, but users can change this setting.
DefaultFileSystemWriteGuardSetting Control use of the File System API for writing
Leaving it unset lets websites ask for access, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultFileSystemWriteGuardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to request write access to files and directories3Allow sites to ask the user to grant write access to files and directoriesSetting the policy to 3 lets websites ask for write access to files and directories in the host operating system's file system. Setting the policy to 2 denies access. Leaving it unset lets websites ask for access, but users can change this setting.
DefaultSerialGuardSetting Control use of the Serial API
Leaving it unset lets websites ask for access, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSerialGuardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to request access to serial ports via the Serial API3Allow sites to ask the user to grant access to a serial portSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports. Leaving it unset lets websites ask for access, but users can change this setting.
DefaultWebBluetoothGuardSetting Control use of the Web Bluetooth API
Leaving the policy unset lets sites ask for access, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultWebBluetoothGuardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API3Allow sites to ask the user to grant access to a nearby Bluetooth deviceSetting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices. Leaving the policy unset lets sites ask for access, but users can change this setting.
DefaultWebHidGuardSetting Control use of the WebHID API
Leaving it unset lets websites ask for access, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultWebHidGuardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to request access to HID devices via the WebHID API3Allow sites to ask the user to grant access to a HID deviceSetting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices. Leaving it unset lets websites ask for access, but users can change this setting. This policy can be overridden for specific url patterns using the WebHidAskForUrls and WebHidBlockedForUrls policies.
DefaultWebUsbGuardSetting Control use of the WebUSB API
Leaving it unset lets websites ask for access, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultWebUsbGuardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to request access to USB devices via the WebUSB API3Allow sites to ask the user to grant access to a connected USB deviceSetting the policy to 3 lets websites ask for access to connected USB devices. Setting the policy to 2 denies access to connected USB devices. Leaving it unset lets websites ask for access, but users can change this setting.
DataUrlInSvgUseEnabled Data URL support for SVGUseElement.
If this policy is set to Disabled or not set, Data URLs won't work in SVGUseElement.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DataUrlInSvgUseEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- This policy enables Data URL support for SVGUseElement, which will be disabled by default starting in M119.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy enables Data URL support for SVGUseElement, which will be disabled by default starting in M119. If this policy is set to Enabled, Data URLs will continue to work in SVGUseElement. If this policy is set to Disabled or not set, Data URLs won't work in SVGUseElement.
DefaultAutomaticDownloadsSetting Default automatic downloads setting
Leaving the policy unset means the AskAutomaticDownloads policy applies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultAutomaticDownloadsSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow sites to download multiple files automatically2Do not allow any site to download multiple files automatically3Ask whenever a site wants to download multiple files automaticallySetting the policy to 1 lets websites download multiple files automatically. Setting the policy to 2 denies this permission. You can set the policy to ask whenever a website wants to download multiple files automatically. Leaving the policy unset means the AskAutomaticDownloads policy applies, but users can change this setting.
DefaultClipboardSetting Default clipboard setting
Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use one.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultClipboardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to use the clipboard site permission3Allow sites to ask the user to grant the clipboard site permissionSetting the policy to 2 blocks sites from using the clipboard site permission. Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use one. This policy can be overridden for specific URL patterns using the ClipboardAllowedForUrls and ClipboardBlockedForUrls policies. This policy only affects clipboard operations controlled by the clipboard site permission, and does not affect sanitized clipboard writes or trusted copy and paste operations.
DefaultCookiesSetting Default cookies setting
Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultCookiesSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow all sites to set local data2Do not allow any site to set local data4Keep cookies for the duration of the sessionUnless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session. Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults. While no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.
DefaultGeolocationSetting Default geolocation setting
Leaving the policy unset means the AskGeolocation policy applies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultGeolocationSetting
- Stated default
- Setting the policy to 2 denies this tracking by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow sites to track the users' physical location2Do not allow any site to track the users' physical location3Ask whenever a site wants to track the users' physical locationSetting the policy to 1 lets sites track the users' physical location as the default state. Setting the policy to 2 denies this tracking by default. You can set the policy to ask whenever a site wants to track the users' physical location. Leaving the policy unset means the AskGeolocation policy applies, but users can change this setting.
DefaultIdleDetectionSetting Default idle detection setting
When this policy is set to 3 - AskIdleDetection or not set, websites can't use the API without the user's permission.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultIdleDetectionSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow sites to detect idle state without asking the user2Do not allow any site to detect the user's idle state3Ask every time a site wants to detect the user's idle stateAllows you to set whether websites are allowed to use the Idle Detection API. When this policy is set to 1 - AllowIdleDetection, websites can use the API without asking the user for permission. When this policy is set to 2 - BlockIdleDetection, websites can't use the API, regardless of the user's permission. When this policy is set to 3 - AskIdleDetection or not set, websites can't use the API without the user's permission.
DefaultImagesSetting Default images setting
Leaving it unset allows images, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultImagesSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow all sites to show all images2Do not allow any site to show imagesSetting the policy to 1 lets all websites display images. Setting the policy to 2 denies image display. Leaving it unset allows images, but users can change this setting.
DefaultJavaScriptSetting Default JavaScript setting
Leaving it unset allows JavaScript, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultJavaScriptSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow all sites to run JavaScript2Do not allow any site to run JavaScriptSetting the policy to 1 lets websites run JavaScript. Setting the policy to 2 denies JavaScript. Leaving it unset allows JavaScript, but users can change this setting.
DefaultLocalFontsSetting Default Local Fonts permission setting
Setting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. Setting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultLocalFontsSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Denies the Local Fonts permission on all sites by default3Ask every time a site wants obtain the Local Fonts permissionSetting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. This will limit the ability of sites to see information about local fonts. Setting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about local fonts. Leaving the policy unset means the default behavior applies which is to prompt the user, but users can change this setting
DefaultNotificationsSetting Default notification setting
Leaving it unset means AskNotifications applies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultNotificationsSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow sites to show desktop notifications2Do not allow any site to show desktop notifications3Ask every time a site wants to show desktop notificationsSetting the policy to 1 lets websites display desktop notifications. Setting the policy to 2 denies desktop notifications. Leaving it unset means AskNotifications applies, but users can change this setting.
DefaultPopupsSetting Default pop-ups setting
Leaving it unset means BlockPopups applies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultPopupsSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow all sites to show pop-ups2Do not allow any site to show pop-upsSetting the policy to 1 lets websites display pop-ups. Setting the policy to 2 denies pop-ups. Leaving it unset means BlockPopups applies, but users can change this setting.
DefaultSensorsSetting Default sensors setting
Leaving it unset means AllowSensors applies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSensorsSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow sites to access sensors2Do not allow any site to access sensors3Ask whenever a site wants to access sensorsSetting the policy to 1 lets websites access and use sensors such as motion and light. Setting the policy to 2 denies access to sensors. When the policy is set to 3 it will ask the user when a site requests access to sensors if the tri-state feature flag is enabled, otherwise it will default to allowing access to sensors. Leaving it unset means AllowSensors applies, but users can change this setting.
DefaultWindowManagementSetting Default Window Management permission setting
Leaving the policy unset means the AskWindowManagement policy applies, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultWindowManagementSetting
- Stated default
- Setting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. Setting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Denies the Window Management permission on all sites by default3Ask every time a site wants obtain the Window Management permissionSetting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. Setting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. Leaving the policy unset means the AskWindowManagement policy applies, but users can change this setting. This replaces the deprecated DefaultWindowPlacementSetting policy.
CookiesSessionOnlyForUrls Limit cookies from matching URLs to the current session
Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CookiesSessionOnlyForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session. Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults. While no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
RestrictYouTubeCookiesDeletion Restrict YouTube cookies deletion
Setting the policy to Disabled or not set allows YouTube cookies to be deleted normally.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RestrictYouTubeCookiesDeletion
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Prevents the manual deletion of YouTube cookies. This policy is intended to prevent users from accessing unauthorized YouTube after manually clearing their YouTube cookies from the site settings page. Setting the policy to Enabled prevents YouTube cookies from being manually deleted. Setting the policy to Disabled or not set allows YouTube cookies to be deleted normally. Note: This policy only prevents manual deletion from the site settings UI. It does not prevent automated deletion by the ClearBrowsingDataOnExitList or BrowsingDataLifetime policies. Furthermore, if the AllowDeletingBrowserHistory policy is enabled, users can still clear all their cookies via the Clear Browsing Data dialog.
Google:Cat_Google / Google Chrome / Cryptography compliance policies
PreferSlowCiphers Prefer specific encryption cipher algorithms for TLS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PreferSlowCiphers
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0Use Google Chrome's default cipher orderThis policy configures Google Chrome to order its preferred encryption ciphers in TLS 1.3 to reflect a preference for algorithms that have been approved by a specific compliance regime. Setting this policy does not guarantee that any specific algorithms will be negotiated. This policy exists to allow server operators who wish to support clients with and without compliance requirements to differentiate between those clients, and only use certain non-default algorithms with increased cryptographic strength for those explicitly configured to prefer them. Setting the policy to 'cnsa' configures Google Chrome to prefer ciphers required for compliance with the Commercial National Security Algorithm Suite versions 1.0 and 2.0 (CNSA 1.0 and 2.0). Not setting the policy, or setting it to 'default', configures Google Chrome to use its default ciphers. Setting this policy is not required for security. The default cryptography used by Google Chrome is strong enough to withstand a brute force attack using the entire power of the Sun. Setting this policy will cause Google Chrome to be slower when accessing websites. This policy only affects TLS 1.3 and QUIC; it does not affect earlier versions of TLS. Example value: cnsa
PreferSlowKexAlgorithms Prefer specific key exchange algorithms for TLS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PreferSlowKexAlgorithms
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Prefer key exchange methods satisfying the requirements of CNSA 2.0Use Google Chrome's default supported groupsThis policy configures Google Chrome to order its preferred key agreement algorithms (supported groups) in TLS 1.3 to reflect a preference for algorithms that have been approved by a specific compliance regime. Setting this policy does not guarantee that any specific algorithms will be negotiated. This policy exists to allow server operators who wish to support clients with and without compliance requirements to differentiate between those clients, and only use certain non-default algorithms with increased cryptographic strength for those explicitly configured to prefer them. Setting the policy to 'cnsa2' configures Google Chrome to prefer key exchange methods required for compliance with the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0). Not setting the policy, or setting it to 'default', configures Google Chrome to use its default key exchange methods. Setting this policy is not required for security. The default cryptography used by Google Chrome is strong enough to withstand a brute force attack using the entire power of the Sun. Setting this policy will cause Google Chrome to be slower when accessing websites. This policy only affects TLS 1.3 and QUIC; it does not affect earlier versions of TLS. Example value: cnsa2
Google:Cat_Google / Google Chrome / Default search provider
DefaultSearchProviderEncodings Default search provider encodings
Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\DefaultSearchProviderEncodings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided. Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use. Example value: UTF-8 UTF-16 GB2312 ISO-8859-1
DefaultSearchProviderKeyword Default search provider keyword
Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderKeyword
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider. Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider. Example value: mis
DefaultSearchProviderName Default search provider name
Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderName
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name. Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used. Example value: My Intranet Search
DefaultSearchProviderNewTabURL Default search provider new tab page URL
Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderNewTabURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page. Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided. Example value: https://search.my.company/newtab
DefaultSearchProviderSearchURL Default search provider search URL
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderSearchURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'. Example value: https://search.my.company/search?q={searchTerms}
DefaultSearchProviderSuggestURL Default search provider suggest URL
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderSuggestURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'. Example value: https://search.my.company/suggest?q={searchTerms}
DefaultSearchProviderEnabled Enable the default search provider
If not set, the default search provider is on, and users can set the search provider list.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar. The Disabled value is not supported by the Google Admin console. If you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
DefaultSearchProviderAlternateURLs List of alternate URLs for the default search provider
Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\DefaultSearchProviderAlternateURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'. Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms. Example value: https://search.my.company/suggest#q={searchTerms} https://search.my.company/suggest/search#q={searchTerms}
DefaultSearchProviderImageURL Parameter providing search-by-image feature for the default search provider
) Leaving DefaultSearchProviderImageURL unset means no image search is used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderImageURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.) Leaving DefaultSearchProviderImageURL unset means no image search is used. If image search uses the GET method, then the URL must specify image parameters using a valid combination of the following placeholders: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: https://search.my.company/searchbyimage/upload
DefaultSearchProviderImageURLPostParams Parameters for image URL which uses POST
Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderImageURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it. Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method. The URL must specify the image parameter using a valid combination of the following placeholders depending on what the search provider supports: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: content={google:imageThumbnail},url={google:imageURL},sbisrc={google:imageSearchSource}
DefaultSearchProviderSearchURLPostParams Parameters for search URL which uses POST
Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderSearchURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
DefaultSearchProviderSuggestURLPostParams Parameters for suggest URL which uses POST
Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderSuggestURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
Google:Cat_Google / Google Chrome / Deprecated policies
ManagedAccountsSigninRestriction Add restrictions on managed accounts
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ManagedAccountsSigninRestriction
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
A Managed account must be a primary account and importing existing browsing data is allowed at the time of profile creationA Managed account must be a primary account and have no secondary accounts and importing existing browsing data is allowed at the time of profile creationNo restrictions on managed accountsA Managed account must be a primary account and the user can import existing data at the time of its creationA Managed account must be a primary account and have no secondary accounts and the user can import existing data at the time of its creationThis policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: primary_account
ProxyServer Address or URL of proxy server
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProxyServer
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: 123.123.123.123:8080
LensDesktopNTPSearchEnabled Allow Google Lens button to be shown in the search box on the New Tab page if supported.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LensDesktopNTPSearchEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
LensRegionSearchEnabled Allow Google Lens region search menu item to be shown in context menu if supported.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LensRegionSearchEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
SigninAllowed Allow sign in to Google Chrome
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SigninAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
WindowPlacementAllowedForUrls Allow Window Placement permission on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WindowPlacementAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://www.example.com [*.]example.edu
WindowPlacementBlockedForUrls Block Window Placement permission on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WindowPlacementBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://www.example.com [*.]example.edu
ProxyMode Choose how to specify proxy server settings
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProxyMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Never use a proxyAuto detect proxy settingsUse a .pac proxy scriptUse fixed proxy serversUse system proxy settingsThis policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: direct
ProxyServerMode Choose how to specify proxy server settings
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProxyServerMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Never use a proxy1Auto detect proxy settings2Manually specify proxy settings3Use system proxy settingsThis policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxAdMeasurementEnabled Choose whether the Privacy Sandbox ad measurement setting can be disabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrivacySandboxAdMeasurementEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxAdTopicsEnabled Choose whether the Privacy Sandbox Ad topics setting can be disabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrivacySandboxAdTopicsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxPromptEnabled Choose whether the Privacy Sandbox prompt can be shown to your users
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrivacySandboxPromptEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxSiteEnabledAdsEnabled Choose whether the Privacy Sandbox Site-suggested ads setting can be disabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrivacySandboxSiteEnabledAdsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostClientDomain Configure the required domain name for remote access clients
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostClientDomain
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: my-awesome-domain.com
RemoteAccessHostDomain Configure the required domain name for remote access hosts
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostDomain
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: my-awesome-domain.com
DefaultMediaStreamSetting Default mediastream setting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultMediaStreamSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any site to access the camera and microphone3Ask every time a site wants to access the camera and/or microphoneThis policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultWindowPlacementSetting Default Window Placement permission setting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultWindowPlacementSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Denies the Window Placement permission on all sites by default3Ask every time a site wants obtain the Window Placement permissionThis policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
DeveloperToolsDisabled Disable Developer Tools
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DeveloperToolsDisabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
DisabledSchemes Disable URL protocol schemes
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\DisabledSchemes
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: file https
AutoFillEnabled Enable AutoFill
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AutoFillEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
FirstPartySetsEnabled Enable First-Party Sets.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- FirstPartySetsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ForceBrowserSignin Enable force sign in for Google Chrome
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceBrowserSignin
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
IncognitoEnabled Enable Incognito mode
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- IncognitoEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
JavascriptEnabled Enable JavaScript
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- JavascriptEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
RelatedWebsiteSetsEnabled Enable Related Website Sets
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RelatedWebsiteSetsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingEnabled Enable Safe Browsing
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PromotionalTabsEnabled Enable showing full-tab promotional content
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PromotionalTabsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
RoamingProfileSupportEnabled Enable the creation of roaming copies for Google Chrome profile data
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RoamingProfileSupportEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
InsecureFormsWarningsEnabled Enable warnings for insecure forms
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- InsecureFormsWarningsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ForceSafeSearch Force SafeSearch
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceSafeSearch
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ForceYouTubeSafetyMode Force YouTube Safety Mode
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceYouTubeSafetyMode
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
UnsafelyTreatInsecureOriginAsSecure Origins or hostname patterns for which restrictions on insecure origins should not apply
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\UnsafelyTreatInsecureOriginAsSecure
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: http://testserver.example.com/ *.example.org
FirstPartySetsOverrides Override First-Party Sets.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- FirstPartySetsOverrides
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 See https://chromeenterprise.google/policies/?policy=FirstPartySetsOverrides for more information about schema and formatting. Example value: { "additions": [ { "associatedSites": [ "https://associate2.test" ], "ccTLDs": { "https://associate2.test": [ "https://associate2.com" ] }, "primary": "https://primary2.test", "serviceSites": [ "https://associate2-content.test" ] } ], "replacements": [ { "associatedSites": [ "https://associate1.test" ], "ccTLDs": { "https://associate1.test": [ "https://associate1.co.uk" ] }, "primary": "https://primary1.test", "serviceSites": [ "https://associate1-content.test" ] } ] }
RelatedWebsiteSetsOverrides Override Related Website Sets.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RelatedWebsiteSetsOverrides
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 See https://chromeenterprise.google/policies/?policy=RelatedWebsiteSetsOverrides for more information about schema and formatting. Example value: { "additions": [ { "associatedSites": [ "https://associate2.test" ], "ccTLDs": { "https://associate2.test": [ "https://associate2.com" ] }, "primary": "https://primary2.test", "serviceSites": [ "https://associate2-content.test" ] } ], "replacements": [ { "associatedSites": [ "https://associate1.test" ], "ccTLDs": { "https://associate1.test": [ "https://associate1.co.uk" ] }, "primary": "https://primary1.test", "serviceSites": [ "https://associate1-content.test" ] } ] }
ProxyBypassList Proxy bypass rules
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProxyBypassList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://www.example1.com,https://www.example2.com,https://internalsite/
RoamingProfileLocation Set the roaming profile directory
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RoamingProfileLocation
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: ${roaming_app_data}\chrome-profile
LensOverlaySettings Settings for the Lens Overlay feature
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LensOverlaySettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow1Do not allowThis policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ProxyPacUrl URL to a proxy .pac file
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProxyPacUrl
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://internal.site/example.pac
Google:Cat_Google / Google Chrome / Extensions
ExtensionInstallTypeBlocklist Blocklist for install types of extensions
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionInstallTypeBlocklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
The blocklist controls which extensions install types are disallowed. Setting "command_line" will block extension from being loaded from command line. Example value: command_line
BlockExternalExtensions Blocks external extensions from being installed
Setting this policy to Disabled or leaving it unset allows external extensions to be installed.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BlockExternalExtensions
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls external extensions installation. Setting this policy to Enabled blocks external extensions from being installed. Setting this policy to Disabled or leaving it unset allows external extensions to be installed. External extensions and their installation are documented at https://developer.chrome.com/docs/extensions/how-to/distribute/install-extensions. Note: This policy only applies to platforms that support extensions.
ExtensionExtendedBackgroundLifetimeForPortConnectionsToUrls Configure a list of origins that grant extended background lifetime to the connecting extensions.
If unset, the policy's default values will be used.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionExtendedBackgroundLifetimeForPortConnectionsToUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Extensions that connect to one of these origins will be be kept running as long as the port is connected. If unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state: - Smart Card Connector - Citrix Receiver (stable, beta, back-up) - VMware Horizon (stable, beta) If set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected. Example value: chrome-extension://abcdefghijklmnopabcdefghijklmnop/ chrome-extension://bcdefghijklmnopabcdefghijklmnopa/
ExtensionAllowedTypes Configure allowed app/extension types
Leaving the policy unset results in no restrictions on the acceptable extension and app types.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionAllowedTypes
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy controls which apps and extensions may be installed in Google Chrome, which hosts they can interact with, and limits runtime access. Leaving the policy unset results in no restrictions on the acceptable extension and app types. Extensions and apps which have a type that's not on the list won't be installed. Each value should be one of these strings: * "extension" * "theme" * "user_script" * "hosted_app" * "legacy_packaged_app" * "platform_app" See the Google Chrome extensions documentation for more information on these types. Versions earlier than 75 that use multiple comma separated extension IDs aren't supported and are skipped. The rest of the policy applies. Note: This policy also affects extensions and apps to be force-installed using ExtensionInstallForcelist. Note: This policy only applies to platforms that support extensions. Example value: hosted_app
ExtensionInstallAllowlist Configure extension installation allow list
By default, all extensions are allowed.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionInstallAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies which extensions are not subject to the blocklist. A blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list. By default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy. Note: This policy only applies to platforms that support extensions. Example value: extension_id1 extension_id2
ExtensionInstallBlocklist Configure extension installation blocklist
If this policy is left not set the user can install any extension in Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionInstallBlocklist
- Stated default
- A blocklist value of '*' means all extensions are blocked by default.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. Once an extension disabled due to the blocklist is removed from it, it will automatically get re-enabled. A blocklist value of '*' means all extensions are blocked by default. Extensions that are explicitly listed in the allowlist are allowed if they are signed (packed). All unpacked extensions are blocked. If this policy is left not set the user can install any extension in Google Chrome. Note: This policy only applies to platforms that support extensions. Example value: extension_id1 extension_id2
ExtensionInstallSources Configure extension, app, and user script install sources
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionInstallSources
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow. Each item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns. ExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list. Note: This policy only applies to platforms that support extensions. Example value: https://corp.mycompany.com/*
ExtensionInstallForcelist Configure the list of force-installed apps and extensions
Leaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionInstallForcelist
- Stated default
- By default, the Chrome Web Store's update URL is used.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies a list of apps and extensions that install silently, without user interaction, and which users can't uninstall or turn off through the Google Chrome interface. Permissions are granted implicitly, including for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These 2 APIs aren't available to apps and extensions that aren't force-installed.) Although Google Chrome aims to prevent users from uninstalling these extensions, some operating systems make it impossible for Google Chrome to defend robustly against extensions being modified externally, so this prevention is best efforts. Leaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome. This policy supersedes ExtensionInstallBlocklist policy. If a previously force-installed app or extension is removed from this list, Google Chrome automatically uninstalls it. The source code of any extension may be altered by users through developer tools, potentially rendering the extension dysfunctional. If this is a concern, set the DeveloperToolsDisabled policy. Each list item of the policy is a string that contains an extension ID and, optionally, an update URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on chrome://extensions when in Developer mode. If specified, the update URL should point to an Update Manifest XML document ( https://developer.chrome.com/extensions/autoupdate ). The update URL should use one of the following schemes: http, https or file. By default, the Chrome Web Store's update URL is used. The update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest. The update url for subsequent updates can be overridden using the ExtensionSettings policy, see http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy. On Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Note: This policy doesn't apply to Incognito mode. Read about hosting extensions ( https://developer.chrome.com/extensions/hosting ). Note: This policy only applies to platforms that support extensions. Example value: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa;https://clients2.google.com/service/update2/crx abcdefghijklmnopabcdefghijklmnop
ExtensionUnpublishedAvailability Control availability of extensions unpublished on the Chrome Web Store.
If the policy is set to AllowUnpublished (0) or not set, extensions that are unpublished on the Chrome Web Store are allowed.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExtensionUnpublishedAvailability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow unpublished extensions1Disable unpublished extensionsIf this policy is enabled, extensions that are unpublished on the Chrome Web Store will be disabled in Google Chrome. This policy only applies to extensions that are installed and updated from the Chrome Web Store. Off-store extensions such as unpacked extensions installed using developer mode and extensions installed using the command-line switch are ignored. Force-installed extensions that are self-hosted are ignored. All version-pinned extensions are also ignored. If the policy is set to AllowUnpublished (0) or not set, extensions that are unpublished on the Chrome Web Store are allowed. If the policy is set to DisableUnpublished (1), extensions that are unpublished on the Chrome Web Store are disabled.
ExtensionDeveloperModeSettings Control the availability of developer mode on extensions page
If the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExtensionDeveloperModeSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow the usage of developer mode on extensions page1Do not allow the usage of developer mode on extensions pageControl if users can turn on Developer Mode on chrome://extensions. If the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2). If the policy is set to Allow (0), users can turn on developer mode on extensions page. If the policy is set to Disallow (1), users can not turn on developer mode on extensions page. If this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode. Note: This policy only applies to platforms that support extensions.
ExtensionSettings Extension management settings
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExtensionSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy controls extension management settings for Google Chrome, including any controlled by existing extension-related policies. This policy maps an extension ID or an update URL to its specific setting only. A default configuration can be set for the special ID "*", which applies to all extensions without a custom configuration in this policy. This policy can override per-extension config from legacy policies. Note that any per-ID extension setting from either ExtensionInstallForcelist, ExtensionInstallAllowlist, ExtensionInstallBlocklist, or ExtensionSettings will only inherit 'installation_mode' and 'update_url' from the "*" defaults. It will not inherit any other properties. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest ( http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy ). If the 'override_update_url' flag is set to true, the extension is installed and updated using the "update" URL specified in the ExtensionInstallForcelist policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is a Chrome Web Store url. On Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Note: This policy only applies to platforms that support extensions. See https://chromeenterprise.google/policies/?policy=ExtensionSettings for more information about schema and formatting. Example value: { "*": { "allowed_types": [ "hosted_app" ], "blocked_install_message": "Custom error message.", "blocked_permissions": [ "downloads", "bookmarks" ], "install_sources": [ "https://company-intranet/chromeapps" ], "installation_mode": "blocked", "runtime_allowed_hosts": [ "*://good.example.com" ], "runtime_blocked_hosts": [ "*://*.example.com" ] }, "abcdefghijklmnopabcdefghijklmnop": { "blocked_permissions": [ "history" ], "installation_mode": "allowed", "minimum_version_required": "1.0.1", "toolbar_pin": "force_pinned", "file_url_navigation_allowed": true }, "bcdefghijklmnopabcdefghijklmnopa": { "allowed_permissions": [ "downloads" ], "installation_mode": "force_installed", "runtime_allowed_hosts": [ "*://good.example.com" ], "runtime_blocked_hosts": [ "*://*.example.com" ], "update_url": "https://example.com/update_url" }, "cdefghijklmnopabcdefghijklmnopab": { "blocked_install_message": "Custom error message.", "installation_mode": "blocked" }, "defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd": { "blocked_install_message": "Custom error message.", "installation_mode": "blocked" }, "fghijklmnopabcdefghijklmnopabcde": { "blocked_install_message": "Custom removal message.", "installation_mode": "removed" }, "ghijklmnopabcdefghijklmnopabcdef": { "installation_mode": "force_installed", "override_update_url": true, "update_url": "https://example.com/update_url" }, "update_url:https://www.example.com/update.xml": { "allowed_permissions": [ "downloads" ], "blocked_permissions": [ "wallpaper" ], "installation_mode": "allowed" } }
Google:Cat_Google / Google Chrome / Generative AI
GeminiActOnWebAllowedForURLs Allow Gemini app integrations to directly act on specified sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\GeminiActOnWebAllowedForURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows to set a list of URL patterns that specify on which sites Gemini app integrations can directly act on web pages. URLs matching neither the allowlist or the blocklist use GeminiActOnWebSettings. URLs matching both the allowlist and the blocklist are allowed. For detailed information on valid url patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
GeminiActOnWebSettings Allows Gemini app integrations to directly act on web pages
0/unset = Gemini app is allowed to take action on the web pages.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- GeminiActOnWebSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow the Gemini app to take action on the web pages.1Disallow the Gemini app to take action on the web pages.Controls if the Gemini app is allowed to take action on the web pages on behalf of the user. 0/unset = Gemini app is allowed to take action on the web pages. 1 = Gemini app is not allowed to take action on the web pages. This policy has no effect when the Gemini app is disabled. For example, the Gemini app can be disabled by GeminiSettings policy. For more information on Gemini in Chrome, please see https://support.google.com/chrome/a/answer/16291696. Gemini's actuation is not available in all countries or all languages. Setting this policy does not guarantee the feature will be enabled; it remains subject to availability. For more info on the roll-out, check the Enterprise Release Notes: https://support.google.com/chrome/a/answer/7679408?hl=en
GeminiSparkSettings Allows Gemini Spark to connect to and use Google Chrome auto browse
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- GeminiSparkSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Gemini Spark is allowed to connect to and use Google Chrome auto browse.1Gemini Spark is not allowed to connect to or use Google Chrome auto browse.Controls if the Gemini Spark agent is allowed to connect to Google Chrome and use auto browse. 0 = Gemini Spark is allowed to connect to and use Google Chrome auto browse 1 = Gemini Spark is not allowed to connect to or use Google Chrome auto browse Warning: Enabling Gemini Spark to connect to Google Chrome and use auto browse permits the Gemini Spark agent to perform autonomous, multi-step actions on Google Chrome clients using the active browser session. This entails significant security risks, including credential risks, Local Network Ingress and loss of context aware signals. Existing management and security controls might not be respected. Administrators are advised to carefully evaluate their organization's network threat model, compliance and privacy guidelines before enabling this feature. This policy has no effect when the Google Gemini app or Google Chrome auto browse policies are disabled. For example, the Google Gemini app can be disabled by GeminiSettings policy. For more information on Google Gemini in Google Chrome, please see https://support.google.com/chrome/a?p=gemini_in_chrome. Google Chrome auto browse and Gemini Spark are not available in all countries or all languages. Setting this policy to 0 - Enabled does not guarantee the feature will be enabled; it remains subject to availability. For more info on the roll-out, check the Enterprise Release Notes: https://chromeenterprise.google/resources/release-notes/.
GeminiActOnWebBlockedForURLs Block Gemini app integrations to directly act on specified sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\GeminiActOnWebBlockedForURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allows to set a list of URL patterns that specify on which sites Gemini app integrations cannot directly act on web pages. URLs matching neither the allowlist or the blocklist use GeminiActOnWebSettings. URLs matching both the allowlist and the blocklist are allowed. For detailed information on valid url patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com
SearchContentSharingSettings Enable content sharing with Google AI Mode and Lens integrations
If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SearchContentSharingSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow content sharing with Google AI Mode integrations.1Do not allow content sharing with Google AI Mode integrations.This policy controls sharing of page and file content with Google AI Mode and Lens through Google Chrome side panel or tabs. Note that this policy doesn't affect Google AI Mode on the web. It only controls how users can share information with it when using Google Chrome. 0 = users can share page or file content with Google AI Mode. 1 = users cannot share page or file content with Google AI Mode. The entry points for sharing context and the side panel will be disabled or hidden. This policy will be ignored when Google Search is not users' default search engine as the feature is disabled. This policy is independent of the AIModeSettings policy. The AIModeSettings policy only controls entry points on omnibox or NTP search box, while this policy controls context sharing through side panel or tabs. This policy also doesn't control Google Gemini integration which can be disabled by GeminiSettings. If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
ThirdPartyAiChatSettings Settings for 3rd party AI Mode integrations in the address bar and New Tab page search box.
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ThirdPartyAiChatSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow 3rd party AI Mode integrations.1Do not allow 3rd party AI Mode integrations.This policy controls 3rd party AI Mode integrations in the address bar and the New Tab page search box. To access this feature, a 3rd party search engine that supports AI Mode must be set as the user's default search engine. 0 = The feature will be available to users. 1 = The feature will not be available to users. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
HistorySearchSettings Settings for AI-powered History Search
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HistorySearchSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow AI History Search and improve AI models.1Allow AI History Search without improving AI models.2Do not allow AI History Search.AI History Search is a feature that allows users to search their browsing history and receive generated answers based on page contents and not just the page title and URL. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
DevToolsGenAiSettings Settings for Chrome DevTools Generative AI Features
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DevToolsGenAiSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow Chrome DevTools Generative AI Features and improve AI models.1Allow Chrome DevTools Generative AI Features without improving AI models.2Do not allow Chrome DevTools Generative AI Features.These features in Chrome DevTools employ generative AI models to provide additional debugging information. To use these features, Google Chrome has to collect data such as error messages, stack traces, code snippets, and network requests and send them to a server owned by Google, which runs a generative AI model. Response body or authentication and cookie headers in network requests are not included in the data sent to the server. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. Chrome DevTools Generative AI features include: - Console Insights: explains console messages and offers suggestions on how to fix console errors. - AI assistance: get help with understanding CSS styles (since version 131), network requests, performance, and files (all since version 132). For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
ChromeSuggestionsSettings Settings for ChromeSuggestions
0/unset = Chrome suggestions will be enabled for users.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeSuggestionsSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This setting allows Chrome to suggest AI capabilities at relevant moments. 0/unset = Chrome suggestions will be enabled for users. 1 = Chrome suggestions are disabled for users. For more information, please check the help center article: https://support.google.com/chrome/a?p=chrome_suggestions
CreateThemesSettings Settings for Create Themes with AI
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CreateThemesSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow Create Themes and improve AI models.1Allow Create Themes without improving AI models.2Do not allow Create Themes.Create Themes with AI lets users create custom themes/wallpapers by preselecting from a list of options. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
AutofillPredictionSettings Settings for enhanced autofill
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AutofillPredictionSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow enhanced autofill and improve AI models.1Allow enhanced autofill without improving AI models.2Do not allow enhanced autofill.Specifies whether users can let Google Chrome use Generative AI to better understand forms and help them fill more fields. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
GeminiSettings Settings for Gemini integration
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- GeminiSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow Gemini integrations.1Do not allow Gemini integrations.This setting allows Gemini app integrations. 0 = Gemini integration will be available for users. 1 = Gemini integration will not be available for users. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information, please check the Help Center article https://support.google.com/chrome/a?p=gemini_in_chrome.
GenAILocalFoundationalModelSettings Settings for GenAI local foundational model
When the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- GenAILocalFoundationalModelSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Downloads model automatically1Do not download modelConfigure how Google Chrome downloads the foundational GenAI model and uses for inference locally. When the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference. When the policy is set to Disabled (1), the model will not be downloaded, and the existing model (if already downloaded) will be deleted. On desktop platforms, model downloading can also be disabled by setting ComponentUpdatesEnabled to false.
AIModeSettings Settings for Google's AI Mode integrations in the address bar and New Tab page search box.
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AIModeSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow AI Mode integrations.1Do not allow AI Mode integrations.This policy controls Google's AI Mode integrations in the address bar and the New Tab page search box. To access this feature, Google must be set as the user's default search engine. 0 = The feature will be available to users. 1 = The feature will not be available to users. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
HelpMeWriteSettings Settings for Help Me Write
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HelpMeWriteSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow Help Me Write and improve AI models.1Allow Help Me Write without improving AI models.2Do not allow Help Me Write.Help Me Write is an AI-based writing assistant for short-form content on the web. Suggested content is based on prompts entered by the user and the content of the web page. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
VoiceTypingSettings Settings for Voice Typing
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- VoiceTypingSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow Voice Typing.1Allow Voice Typing without data collection.2Do not allow Voice Typing.Voice Typing is an AI-based feature that allows users to input and edit text using their voice, powered by generative AI models to provide high-quality transcription and formatting. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
SmartTabSharingSettings Smart tab sharing settings
If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SmartTabSharingSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow smart tab sharing with Google AI Mode integrations.1Do not allow smart tab sharing with Google AI Mode integrations.This policy controls the smart tab sharing feature of Google AI Mode through Google Chrome side panel or tabs. Note that this policy doesn't affect Google AI Mode on the web. It only controls how users can share information with it when using Google Chrome. 0 = users can share page or file content with Google AI Mode. 1 = users cannot share page or file content with Google AI Mode. The entry points for sharing context and the side panel will be disabled or hidden. This policy will be ignored when Google Search is not users' default search engine as the feature is disabled. This policy is independent of the AIModeSettings policy. The AIModeSettings policy only controls entry points on omnibox or NTP search box, while this policy controls context sharing through side panel or tabs. This policy also doesn't control Google Gemini integration which can be disabled by GeminiSettings. Note that if SearchContentSharingSettings is disabled, this policy will be ignored. If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
TabCompareSettings Tab Compare settings
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TabCompareSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow Tab Compare and improve AI models.1Allow Tab Compare without improving AI models.2Do not allow Tab Compare.Tab Compare is an AI-powered tool for comparing information across a user's tabs. As an example, the feature can be offered to the user when multiple tabs with products in a similar category are open. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
Google:Cat_Google / Google Chrome / Google Cast
MediaRouterCastAllowAllIPs Allow Google Cast to connect to Cast devices on all IP addresses.
Leaving the policy unset connects Google Cast to Cast devices only on RFC1918/RFC4193, unless the CastAllowAllIPs feature is turned on.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MediaRouterCastAllowAllIPs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Unless EnableMediaRouter is set to Disabled, setting MediaRouterCastAllowAllIPs to Enabled connects Google Cast to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses. Setting the policy to Disabled connects Google Cast to Cast devices only on RFC1918/RFC4193. Leaving the policy unset connects Google Cast to Cast devices only on RFC1918/RFC4193, unless the CastAllowAllIPs feature is turned on.
AccessCodeCastEnabled Allow users to select cast devices with an access code or QR code from within the Google Cast menu.
When this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AccessCodeCastEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired.
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether a user will be presented with an option, within the Google Cast menu which allows them to cast to cast devices that do not appear in the Google Cast menu, using either the access code or QR code displayed on the cast devices's screen. By default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired. When this policy is set to Enabled, users will be presented with the option to select cast devices by using an access code or by scanning a QR code. When this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.
EnableMediaRouter Enable Google Cast
Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableMediaRouter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon. Setting the policy to Disabled turns off Google Cast.
ShowCastSessionsStartedByOtherDevices Show media controls for Google Cast sessions started by other devices on the local network
When this policy is unset for enterprise users or is disabled, media playback controls UI is unavailable for Google Cast sessions started by other devices on the local network.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ShowCastSessionsStartedByOtherDevices
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When this policy is enabled, media playback controls UI is available for Google Cast sessions started by other devices on the local network. When this policy is unset for enterprise users or is disabled, media playback controls UI is unavailable for Google Cast sessions started by other devices on the local network. If the policy EnableMediaRouter is disabled, then this policy's value has no effect, as the entire Google Cast functionality is disabled.
ShowCastIconInToolbar Show the Google Cast toolbar icon
Setting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ShowCastIconInToolbar
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled displays the Cast toolbar icon on the toolbar or the overflow menu, and users can't remove it. Setting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu. If the policy EnableMediaRouter is set to Disabled, then this policy's value has no effect, and the toolbar icon doesn't appear.
AccessCodeCastDeviceDuration Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.
By default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AccessCodeCastDeviceDuration
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy specifies how long (in seconds) a cast device that was previously selected via an access code or QR code can be seen within the Google Cast menu of cast devices. The lifetime of an entry starts at the time the access code was first entered or the QR code was first scanned. During this period the cast device will appear in the Google Cast menu's list of cast devices. After this period, in order to use the cast device again the access code must be reentered or the QR code must be rescanned. By default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session. Note that this policy only affects how long a cast devices appears in the Google Cast menu, and has no effect on any ongoing cast session which will continue even if the period expires. This policy has no effect unless the AccessCodeCastEnabled policy is Enabled.
Google:Cat_Google / Google Chrome / HTTP authentication
BasicAuthOverHttpEnabled Allow Basic authentication for HTTP
Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BasicAuthOverHttpEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP. Setting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed. This policy setting is ignored (and Basic is always forbidden) if the AuthSchemes policy is set and does not include Basic.
AuthServerAllowlist Authentication server allowlist
Leaving the policy unset means Google Chrome tries to detect if a server is on the intranet.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AuthServerAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies which servers should be allowed for integrated authentication. Integrated authentication is only on when Google Chrome gets an authentication challenge from a proxy or from a server in this permitted list. Leaving the policy unset means Google Chrome tries to detect if a server is on the intranet. Only then will it respond to IWA requests. If a server is detected as internet, then Google Chrome ignores IWA requests from it. Note: Separate multiple server names with commas. Wildcards, *, are allowed. Example value: *.example.com,example.com
AllowCrossOriginAuthPrompt Cross-origin HTTP Authentication prompts
Setting the policy to Disabled or leaving it unset renders third-party images unable to show an authentication prompt.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowCrossOriginAuthPrompt
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled allows third-party images on a page to show an authentication prompt. Setting the policy to Disabled or leaving it unset renders third-party images unable to show an authentication prompt. Typically, this policy is Disabled as a phishing defense.
DisableAuthNegotiateCnameLookup Disable CNAME lookup when negotiating Kerberos authentication
Setting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisableAuthNegotiateCnameLookup
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN. Setting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.
EnableAuthNegotiatePort Include non-standard port in Kerberos SPN
Setting the policy to Disabled or leaving it unset means the generated Kerberos SPN won't include a port.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableAuthNegotiatePort
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled and entering a nonstandard port (in other words, a port other than 80 or 443) includes it in the generated Kerberos SPN. Setting the policy to Disabled or leaving it unset means the generated Kerberos SPN won't include a port.
AuthNegotiateDelegateAllowlist Kerberos delegation server allowlist
Leaving the policy unset means Google Chrome won't delegate user credentials, even if a server is detected as intranet.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AuthNegotiateDelegateAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy assigns servers that Google Chrome may delegate to. Separate multiple server names with commas. Wildcards, *, are allowed. Leaving the policy unset means Google Chrome won't delegate user credentials, even if a server is detected as intranet. Example value: *.example.com,foobar.example.com
AllHttpAuthSchemesAllowedForOrigins List of origins allowing all HTTP authentication
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AllHttpAuthSchemesAllowedForOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies for which origins to allow all the HTTP authentication schemes Google Chrome supports regardless of the AuthSchemes policy. Format the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in AllHttpAuthSchemesAllowedForOrigins. Wildcards are allowed for the host component (e.g., '*:8000' matches all hosts on port 8000). To match all schemes or all ports, omit the component entirely (e.g., 'example.com' matches any scheme and any port). A hostname (e.g., 'example.com') also matches its subdomains. To match a host exactly and exclude its subdomains, prepend it with a dot (e.g., '.example.com'). To match all origins, use a single asterisk ('*'). Example value: https://example.com example.com *:8000 *
AuthSchemes Supported authentication schemes
Leaving the policy unset employs all 4 schemes.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AuthSchemes
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies which HTTP authentication schemes Google Chrome supports. Leaving the policy unset employs all 4 schemes. Valid values: * basic * digest * ntlm * negotiate Note: Separate multiple values with commas. Example value: basic,digest,ntlm,negotiate
Google:Cat_Google / Google Chrome / Idle Browser Actions
IdleTimeoutActions Actions to run when the computer is idle
If the IdleTimeout policy is unset, this policy has no effect. If this policy is empty or left unset, the IdleTimeout policy has no effect.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\IdleTimeoutActions
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of actions to run when the timeout from the IdleTimeout policy is reached. Warning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data. If the IdleTimeout policy is unset, this policy has no effect. When the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy. If this policy is empty or left unset, the IdleTimeout policy has no effect. Supported actions are: 'close_browsers': close all browser windows and PWAs for this profile. Not supported on Android and iOS. 'close_tabs': close all open tabs in open windows. Only supported on iOS. 'show_profile_picker': show the Profile Picker window. Not supported on Android and iOS. 'sign_out': Signs out the current signed in user. Only supported on iOS. 'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings', 'clear_hosted_app_data': clear the corresponding browsing data. See the ClearBrowsingDataOnExitList policy for more details. The types supported on iOS are 'clear_browsing_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', and 'clear_autofill' 'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first. Not supported on iOS. The user will stay signed into their Google account when deleting cookies using 'clear_cookies_and_other_site_data'. Setting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled. Example value: close_browsers show_profile_picker
IdleTimeout Delay before running idle actions
If this policy is not set, no action will be ran.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- IdleTimeout
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Triggers an action when the computer is idle. If this policy is set, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy. If this policy is not set, no action will be ran. The minimum threshold is 1 minute. "User input" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.
Google:Cat_Google / Google Chrome / Legacy Browser Support
AlternativeBrowserPath Alternative browser to launch for configured websites.
Leaving the policy unset puts a platform-specific default in use: Internet Explorer® for Microsoft® Windows®, or Safari® for macOS.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AlternativeBrowserPath
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy controls which command to use to open URLs in an alternative browser. The policy can be set to one of ${ie}, ${firefox}, ${safari}, ${opera}, ${edge} or a file path. When this policy is set to a file path, that file is used as an executable file. ${ie} is only available on Microsoft® Windows®. ${safari} and ${edge} are only available on Microsoft® Windows® and macOS. Leaving the policy unset puts a platform-specific default in use: Internet Explorer® for Microsoft® Windows®, or Safari® for macOS. On Linux®, launching an alternative browser will fail. Example value: ${ie}
BrowserSwitcherChromeParameters Command-line parameters for switching from the alternative browser.
Leaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\BrowserSwitcherChromeParameters
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If a parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line. Environment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable. Leaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter. Note: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect. Example value: --force-dark-mode
AlternativeBrowserParameters Command-line parameters for the alternative browser.
Leaving the policy unset means only the URL is passed as a command-line parameter.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AlternativeBrowserParameters
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to a list of strings means each string is passed to the alternative browser as separate command-line parameters. On Microsoft® Windows®, the parameters are joined with spaces. On macOS and Linux®, a parameter can have spaces and still be treated as a single parameter. If a parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line. Environment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable. On macOS and Linux®, ${ABC} is replaced with the value of the ABC environment variable. Leaving the policy unset means only the URL is passed as a command-line parameter. Example value: -foreground -new-window ${url} -profile %HOME%\browser_profile
BrowserSwitcherDelay Delay before launching alternative browser (milliseconds)
Leaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherDelay
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to a number has Google Chrome show a message for that number of milliseconds, then it opens an alternative browser. Leaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.
BrowserSwitcherEnabled Enable the Legacy Browser Support feature.
Setting the policy to Disabled or leaving it unset means Google Chrome won't try to launch designated URLs in an alternate browser.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means Google Chrome will try to launch some URLs in an alternate browser, such as Internet Explorer®. This feature is set using the policies in the Legacy Browser support group. Setting the policy to Disabled or leaving it unset means Google Chrome won't try to launch designated URLs in an alternate browser.
BrowserSwitcherKeepLastChromeTab Keep last tab open in Chrome.
Setting the policy to Enabled or leaving it unset has Google Chrome keep at least one tab open, after switching to an alternate browser.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherKeepLastChromeTab
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset has Google Chrome keep at least one tab open, after switching to an alternate browser. Setting the policy to Disabled has Google Chrome close the tab after switching to an alternate browser, even if it was the last tab. This causes Google Chrome to exit completely.
BrowserSwitcherChromePath Path to Chrome for switching from the alternative browser.
Leaving the policy unset means Internet Explorer® autodetects Google Chrome's own executable path when launching Google Chrome from Internet Explorer.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherChromePath
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the command to use to open URLs in Google Chrome when switching from Internet Explorer®. This policy can be set to an executable file path or ${chrome} to autodetect the location of Google Chrome. Leaving the policy unset means Internet Explorer® autodetects Google Chrome's own executable path when launching Google Chrome from Internet Explorer. Note: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect. Example value: ${chrome}
BrowserSwitcherParsingMode Sitelist parsing mode
If 'Default' (0) or unset, URL matching is less strict.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherParsingMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Default behavior for LBS.1More compatible with Microsoft IE/Edge enterprise mode sitelists.This policy controls how Google Chrome interprets sitelist/greylist policies for the Legacy Browser Support feature. It affects the following policies: BrowserSwitcherUrlList, BrowserSwitcherUrlGreylist, BrowserSwitcherUseIeSitelist, BrowserSwitcherExternalSitelistUrl, and BrowserSwitcherExternalGreylistUrl. If 'Default' (0) or unset, URL matching is less strict. Rules that do not contain "/" look for a substring anywhere in the URL's hostname. Matching the path component of a URL is case-sensitive. If 'IESiteListMode' (1), URL matching is more strict. Rules that do not contain "/" only match at the end of the hostname. They must also be at a domain name boundary. Matching the path component of a URL is case-insensitive. This is more compatible with Microsoft® Internet Explorer® and Microsoft® Edge®. For example, with the rules "example.com" and "acme.com/abc": "http://example.com/", "http://subdomain.example.com/" and "http://acme.com/abc" match regardless of parsing mode. "http://notexample.com/", "http://example.com.invalid.com/", "http://example.comabc/" only match in 'Default' mode. "http://acme.com/ABC" only matches in 'IESiteListMode'.
BrowserSwitcherExternalGreylistUrl URL of an XML file that contains URLs that should never trigger a browser switch.
Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for not switching browsers.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherExternalGreylistUrl
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlGreylist policy. These policies prevent Google Chrome and the alternative browser from opening one another. Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for not switching browsers. Note: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode ) Example value: http://example.com/greylist.xml
BrowserSwitcherExternalSitelistUrl URL of an XML file that contains URLs to load in an alternative browser.
Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherExternalSitelistUrl
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlList policy. Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers. Note: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode) Example value: http://example.com/sitelist.xml
BrowserSwitcherUseIeSitelist Use Internet Explorer's SiteList policy for Legacy Browser Support.
When this policy is false or unset, Google Chrome does not use Internet Explorer®'s SiteList policy as a source of rules for switching browsers.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BrowserSwitcherUseIeSitelist
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether to load rules from Internet Explorer®'s SiteList policy. When this policy is set to true, Google Chrome reads Internet Explorer®'s SiteList to obtain the site list's URL. Google Chrome then downloads the site list from that URL, and applies the rules as if they had been configured with the BrowserSwitcherUrlList policy. When this policy is false or unset, Google Chrome does not use Internet Explorer®'s SiteList policy as a source of rules for switching browsers. For more information on Internet Explorer's SiteList policy: https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode
BrowserSwitcherUrlGreylist Websites that should never trigger a browser switch.
Leaving the policy unset adds no websites to the list.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\BrowserSwitcherUrlGreylist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy controls the list of websites that will never cause a browser switch. Each item is treated as a rule. Those rules that match won't open an alternative browser. Unlike the BrowserSwitcherUrlList policy, rules apply to both directions. When the Internet Explorer® add-in is on, it also controls whether Internet Explorer® should open these URLs in Google Chrome. Leaving the policy unset adds no websites to the list. Note: Elements can also be added to this list through the BrowserSwitcherExternalGreylistUrl policy. Example value: ie.com !open-in-chrome.ie.com foobar.com/ie-only/
BrowserSwitcherUrlList Websites to open in alternative browser
Leaving the policy unset adds no websites to the list.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\BrowserSwitcherUrlList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy controls the list of websites to open in an alternative browser. Each item is treated as a rule for something to open in an alternative browser. Google Chrome uses those rules when choosing if a URL should open in an alternative browser. When the Internet Explorer® add-in is on, Internet Explorer® switches back to Google Chrome when the rules don't match. If rules contradict each other, Google Chrome uses the most specific rule. Leaving the policy unset adds no websites to the list. Note: Elements can also be added to this list through the BrowserSwitcherUseIeSitelist and BrowserSwitcherExternalSitelistUrl policies. Example value: ie.com !open-in-chrome.ie.com foobar.com/ie-only/
Google:Cat_Google / Google Chrome / Local Network Access settings
LocalNetworkAccessPermissionsPolicyDefaultEnabled Allow Local Network Access (LNA) requests in subframes without explicit delegation
If this policy is set to disabled or not set, then subframes must be explicitly delegated the permissions policy feature in order make local network requests and trigger the permission prompt.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LocalNetworkAccessPermissionsPolicyDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, the permissions for Local Network Access (LNA) are only allowed to be requested in cross-origin subframes if they are explicitly delegated. If this policy is set to enabled, then subframes are by default delegated all LNA permissions policy features and can make local network requests (triggering the permission prompt).
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
By default, the permissions for Local Network Access (LNA) are only allowed to be requested in cross-origin subframes if they are explicitly delegated. This policy can be used to override this default behavior so that LNA permissions are default inherited into subframes, unless explicitly denied in permissions policy. If this policy is set to enabled, then subframes are by default delegated all LNA permissions policy features and can make local network requests (triggering the permission prompt). If this policy is set to disabled or not set, then subframes must be explicitly delegated the permissions policy feature in order make local network requests and trigger the permission prompt. This policy applies to the permissions policy features "local-network-access", "loopback-network", and "local-network". For more information on Local Network Access, see https://wicg.github.io/local-network-access/ and https://developer.chrome.com/blog/local-network-access. For more information on permissions policy, see https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Permissions_Policy.
LocalNetworkAccessAllowedForUrls Allow sites to make network requests to local devices and local network endpoints.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LocalNetworkAccessAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins are not subject to Local Network Access checks. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local device and local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkAccessBlockedForUrls - LoopbackNetworkAccessAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAllowedForUrls Allow sites to make network requests to local network endpoints.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LocalNetworkAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to local network endpoints are not subject to Local Network Access checks. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LoopbackNetworkAllowedForUrls Allow sites to make network requests to the local device.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LoopbackNetworkAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to the local device are not subject to Local Network Access checks. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to the local device. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAccessBlockedForUrls Block sites from making network requests to local devices and local network endpoints.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LocalNetworkAccessBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local device and local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkAccessBlockedForUrls - LoopbackNetworkAccessAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkBlockedForUrls Block sites from making network requests to local network endpoints.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LocalNetworkBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to local network endpoints are blocked from issuing Local Network Access requests. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LoopbackNetworkBlockedForUrls Block sites from making network requests to the local device.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LoopbackNetworkBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to the local device are blocked from issuing Local Network Access requests. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to the local device. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAccessIpAddressSpaceOverrides Override IP address space mappings
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LocalNetworkAccessIpAddressSpaceOverrides
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This can be used to treat certain internal address ranges as "public" and thus not subject to Local Network Access checks. Conversely, this can be used to treat certain public address ranges that might be used internally as "local" so that they are protected by Local Network Access checks. IP address space overrides have two forms: [cidr]=[public|local|loopback] where [cidr] is a IP address range in CIDR notation (see section 3.1 of https://tools.ietf.org/html/rfc4632 for IPv4 and section 2.3 of https://tools.ietf.org/html/rfc4291 for IPv6). IPv6 addresses must be specified in URL-safe (bracketed) format. CIDR overrides apply to all ports. or [ip-address]:[port]=[public|local|loopback] For more information on Local Network Access, see https://wicg.github.io/local-network-access/ and https://developer.chrome.com/blog/local-network-access. This policy does not support dynamic refresh. Overrides from the command-line switch --ip-address-space-overrides take precedence over overrides set by this policy. Example value: 100.64.0.0/10=public [2001:db8::]/32=local 192.168.0.1:8000=public [2001:DB8::8:800:200C:417A]:8080=local
LocalNetworkAccessRestrictionsTemporaryOptOut Specifies whether to (temporarily) opt out of Local Network Access restrictions
When this policy is set to Disabled or unset, Local Network Access requests will use the default handling of these requests.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LocalNetworkAccessRestrictionsTemporaryOptOut
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When this policy is set to Enabled, Local Network Access requests will only display warnings in Chrome DevTools due to Local Network Access checks failing. When this policy is set to Disabled or unset, Local Network Access requests will use the default handling of these requests. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. This enterprise policy is temporary, and will be removed after M152. Long term, the policy LocalNetworkAccessAllowedForUrls can be used to allowlist URL patterns that should be automatically granted the Local Network Access permission.
Google:Cat_Google / Google Chrome / Microsoft® Active Directory® management settings
CloudAPAuthEnabled Allow automatic sign-in to Microsoft® cloud identity providers
By setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudAPAuthEnabled
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Disable Microsoft® cloud authentication1Enable Microsoft® cloud authenticationConfigures automatic user sign-in for accounts backed by a Microsoft® cloud identity provider. By setting this policy to 1 (Enabled), users who sign into their computer with an account backed by a Microsoft® cloud identity provider (i.e., Microsoft® Azure® Active Directory® or the consumer Microsoft® account identity provider) or who have added a work or school account to Microsoft® Windows® can be signed into web properties using that identity automatically. Information pertaining to the user's device and account is transmitted to the user's cloud identity provider for each authentication event. By setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled. This feature is available starting in Microsoft® Windows® 10. Note: This policy doesn't apply to Incognito or Guest modes.
Google:Cat_Google / Google Chrome / Native Messaging
NativeMessagingUserLevelHosts Allow user-level Native Messaging hosts (installed without admin permissions)
Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NativeMessagingUserLevelHosts
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level. Setting the policy to Disabled means Google Chrome can only use these hosts if installed at the system level.
NativeMessagingAllowlist Configure native messaging allowlist
All native messaging hosts are allowed by default.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\NativeMessagingAllowlist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies which native messaging hosts aren't subject to the deny list. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed. All native messaging hosts are allowed by default. But, if all native messaging hosts are denied by policy, the admin can use the allow list to change that policy. Example value: com.native.messaging.host.name1 com.native.messaging.host.name2
NativeMessagingBlocklist Configure native messaging blocklist
Leaving the policy unset means Google Chrome loads all installed native messaging hosts.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\NativeMessagingBlocklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies which native messaging hosts shouldn't be loaded. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed. Leaving the policy unset means Google Chrome loads all installed native messaging hosts. Example value: com.native.messaging.host.name1 com.native.messaging.host.name2
Google:Cat_Google / Google Chrome / Network settings
DataURLWhitespacePreservationEnabled DataURL Whitespace Preservation for all media types
If this policy is left unset or is set to True, the new behavior is enabled.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DataURLWhitespacePreservationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy provides a temporary opt-out for changes to how Chrome handles whitepsace in data URLS. Previously, whitespace would be kept only if the top level media type was text or contained the media type string xml. Now, whitespace will be preserved in all data URLs, regardless of media type. If this policy is left unset or is set to True, the new behavior is enabled. When this policy is set to False, the old behavior is enabled.
CompressionDictionaryTransportEnabled Enable compression dictionary transport support
Setting the policy to Enabled or leaving it unset means Google Chrome will accept web contents using the compression dictionary transport feature.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CompressionDictionaryTransportEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header ("sbr" and "zst-d") when dictionaries are available for use. Setting the policy to Enabled or leaving it unset means Google Chrome will accept web contents using the compression dictionary transport feature. Setting the policy to Disabled turns off the compression dictionary transport feature.
IPv6ReachabilityOverrideEnabled Enable IPv6 reachability check override
Setting the policy to false or leaving it unset does not overrides the IPv6 reachability check.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- IPv6ReachabilityOverrideEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to true overrides the IPv6 reachability check. This means that the system will always query AAAA records when resolving host names. It applies to all users and interfaces on the device. Setting the policy to false or leaving it unset does not overrides the IPv6 reachability check. The system only queries AAAA records when it is reachable to a global IPv6 host.
AccessControlAllowMethodsInCORSPreflightSpecConformant Make Access-Control-Allow-Methods matching in CORS preflight spec conformant
If the policy is Enabled or not set, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AccessControlAllowMethodsInCORSPreflightSpecConformant
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight. If the policy is Disabled, request methods are uppercased. This is the behavior on or before Google Chrome 108. If the policy is Enabled or not set, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT. This would reject fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: FOO" response header, and would accept fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: Foo" response header. Note: request methods "post" and "put" are not affected, while "patch" is affected. This policy is intended to be temporary and will be removed in the future.
HappyEyeballsV3Enabled Use the Happy Eyeballs V3 algorithm
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HappyEyeballsV3Enabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This feature enables the Happy Eyeballs V3 algorithm to make connection attempts. See https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3 for details. Setting the policy to Enabled means Google Chrome will use the Happy Eyeballs V3 algorithm for connection attempts. Setting the policy to Disabled turns off the Happy Eyeballs V3 algorithm. Not setting the policy, Google Chrome will turn on or off the Happy Eyeballs V3 algorithm based on chrome://flags/#happy-eyeballs-v3. This policy supports dynamic refresh. This policy is a temporary measure and will be removed in future versions of Google Chrome.
Google:Cat_Google / Google Chrome / Password manager
PasswordManagerBlocklist Configure the list of domains for which the Password Manager (Save and Fill) will be disabled
If the policy is unset, the Password Manager will be available for all domains.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PasswordManagerBlocklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Configure the list of domains where Google Chrome should disable the Password Manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms. If a domain is present in the list, the Password Manager will be disabled for it. If a domain is not present in the list, the Password Manager will be available for it. If the policy is unset, the Password Manager will be available for all domains. For detailed information on valid URL patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com login.example.com
AutomatedPasswordChangeSettings Enable automated password change
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AutomatedPasswordChangeSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow feature use and improving AI models1Allow feature use without improving AI models2Do not allow featureThis policy controls the availability of Google Chrome's automated password change feature. If enabled, a user can trigger a process where the browser attempts to change their password on a website automatically. This process is managed by Generative AI. The new password is saved in the browser's password manager. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
DeletingUndecryptablePasswordsEnabled Enable deleting undecryptable passwords
Setting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DeletingUndecryptablePasswordsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions. Setting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched. Setting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality. If the policy is set, users can't change it in Google Chrome.
PasswordDismissCompromisedAlertEnabled Enable dismissing compromised password alerts for entered credentials
Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordDismissCompromisedAlertEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts. If you disable this setting, users will not be able to dismiss alerts about compromised passwords. If enabled, users will be able to dismiss alerts about compromised passwords.
PasswordLeakDetectionEnabled Enable leak detection for entered credentials
If not set, credential leak checking is allowed, but the user can turn it off.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordLeakDetectionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak. Setting the policy to Disabled does not let users have this functionality. If the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.
PasswordManagerPasskeysEnabled Enable saving passkeys to the password manager
Setting the policy to Enabled or leaving unset means that users can save passkeys in the built-in password manager if signed into Google Chrome.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordManagerPasskeysEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the browser's ability to save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager. If the PasswordManagerEnabled policy is set to Disabled then saving in the built-in password manager is disabled in general, including passkeys and passwords, and thus this policy is not applicable. Setting the policy to Enabled or leaving unset means that users can save passkeys in the built-in password manager if signed into Google Chrome. Setting the policy to Disabled means users can't save passkeys to the built-in password manager, but previously saved passkeys will still work.
PasswordManagerEnabled Enable saving passwords to the password manager
If not set, the user can turn off password saving.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordManagerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy controls the browser's ability to automatically remember passwords on websites and save them in the built-in password manager. It does not limit access or change the contents of passwords saved in the password manager and possibly synchronized to the Google account profile and Android. Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site. Setting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work. If the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.
PasswordSharingEnabled Enable sharing user credentials with other users
When the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordSharingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled lets users send to and receive from family members (according to Family Service) their passwords. When the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password. The received passwords are stored into user's account and are available in the Password Manager. Setting the policy to Disabled means users can't send passwords from Password Manager to other users, and can't receive passwords from other users. The feature is not available if synchronization of Passwords is turned off (either via user settings or SyncDisabled policy is Enabled). Managed accounts aren't eligible to join or create a family group and therefore cannot share passwords.
Google:Cat_Google / Google Chrome / Printing
PrintingBackgroundGraphicsDefault Default background graphics printing mode
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintingBackgroundGraphicsDefault
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Enable background graphics printing mode by defaultDisable background graphics printing mode by defaultOverrides default background graphics printing mode. Example value: enabled
DefaultPrinterSelection Default printer selection rules
Leaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultPrinterSelection
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets the rules for selecting the default printer in Google Chrome, overriding the default rules. Printer selection occurs the first time users try to print, when Google Chrome seeks a printer matching the specified attributes. In case of a less than perfect match, Google Chrome can be set to select any matching printer, depending on the order printers are discovered. Leaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default. If there's no PDF printer, Google Chrome defaults to none. Currently, all printers are classified as "local". Printers connected to Google Cloud Print are considered "cloud", but Google Cloud Print is no longer supported. Note: Omitting a field means all values match for that particular field. For example, not specifying idPattern means Print Preview accepts all printer IDs. Regular expression patterns must follow the JavaScript RegExp syntax, and matches are case sensistive. See https://chromeenterprise.google/policies/?policy=DefaultPrinterSelection for more information about schema and formatting. Example value: { "kind": "local", "idPattern": ".*public", "namePattern": ".*Color" }
PrintingPaperSizeDefault Default printing page size
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintingPaperSizeDefault
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Overrides default printing page size. name should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored. If the page size is unavailable on the printer chosen by the user this policy is ignored. See https://chromeenterprise.google/policies/?policy=PrintingPaperSizeDefault for more information about schema and formatting. Example value: { "custom_size": { "height": 297000, "width": 210000 }, "name": "custom" }
DisablePrintPreview Disable Print Preview
Setting the policy to Disabled or leaving it unset has print commands trigger the print preview screen.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisablePrintPreview
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled has Google Chrome open the system print dialog instead of the built-in print preview when users request a printout. Setting the policy to Disabled or leaving it unset has print commands trigger the print preview screen.
PrinterTypeDenyList Disable printer types on the deny list
If the policy is not set, or is set to an empty list, all printer types will be available for discovery.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PrinterTypeDenyList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
The printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched. Placing all printer types on the deny list effectively disables printing, as there would be no available destinations to send a document for printing. In versions before 102, including cloud on the deny list has the same effect as setting the CloudPrintSubmitEnabled policy to false. In order to keep Google Cloud Print destinations discoverable, the CloudPrintSubmitEnabled policy must be set to true and cloud must not be on the deny list. Beginning in version 102, Google Cloud Print destinations are not supported and will not appear regardless of policy values. If the policy is not set, or is set to an empty list, all printer types will be available for discovery. Extension printers are also known as print provider destinations, and include any destination that belongs to a Google Chrome extension. Local printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers. Example value: local pdf
PrintingEnabled Enable printing
Setting the policy to Enabled or leaving it unset lets users print in Google Chrome, and users can't change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset lets users print in Google Chrome, and users can't change this setting. Setting the policy to Disabled means users can't print from Google Chrome. Printing is off in the three dots menu, extensions, and JavaScript applications.
PrintingLPACSandboxEnabled Enable Printing LPAC Sandbox
Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintingLPACSandboxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it. Setting the policy to Disabled has a detrimental effect on Google Chrome's security as services used for printing might run in a weaker sandbox configuration. Only turn off the policy if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.
OopPrintDriversAllowed Out-of-process print drivers allowed
When this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- OopPrintDriversAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview. When this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks. When this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks. This policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.
PrintHeaderFooter Print Headers and Footers
If unset, users decides whether headers and footers appear.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintHeaderFooter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview. If you set the policy, users can't change it. If unset, users decides whether headers and footers appear.
PrintPdfAsImageAvailability Print PDF as Image Available
When this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintPdfAsImageAvailability
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls how Google Chrome makes the Print as image option available on Microsoft® Windows® and macOS when printing PDFs. When printing a PDF on Microsoft® Windows® or macOS, sometimes print jobs need to be rasterized to an image for certain printers to get correct looking output. When this policy is set to Enabled, Google Chrome will make the Print as image option available in the Print Preview when printing a PDF. When this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.
PrintPdfAsImageDefault Print PDF as Image Default
When this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintPdfAsImageDefault
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls if Google Chrome makes the Print as image option default to set when printing PDFs. When this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF. When this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available. For Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.
PrintPostScriptMode Print PostScript Mode
When this policy is not set, Google Chrome will be in Default mode.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintPostScriptMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Default1Type42Controls how Google Chrome prints on Microsoft® Windows®. When printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance. When this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts. When this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers. When this policy is not set, Google Chrome will be in Default mode.
PrintRasterizationMode Print Rasterization Mode
When this policy is not set, Google Chrome will be in Full mode.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintRasterizationMode
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Full1FastControls how Google Chrome prints on Microsoft® Windows®. When printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly. When this policy is set to Full, Google Chrome will do full page rasterization if necessary. When this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed. When this policy is not set, Google Chrome will be in Full mode.
PrintRasterizePdfDpi Print Rasterize PDF DPI
If this policy is set to zero or not set at all then the system default resolution will be used during rasterization of page images.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintRasterizePdfDpi
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls print image resolution when Google Chrome prints PDFs with rasterization. When printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality. This policy allows a particular resolution to be specified for use when rasterizing PDFs for printing. If this policy is set to zero or not set at all then the system default resolution will be used during rasterization of page images.
PrintingAllowedBackgroundGraphicsModes Restrict background graphics printing mode
Unset policy is treated as no restriction.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintingAllowedBackgroundGraphicsModes
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Allow printing both with and without background graphicsAllow printing only with background graphicsAllow printing only without background graphicsRestricts background graphics printing mode. Unset policy is treated as no restriction. Example value: enabled
PrintPreviewUseSystemDefaultPrinter Use System Default Printer as Default
Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrintPreviewUseSystemDefaultPrinter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview. Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
Google:Cat_Google / Google Chrome / Protected Content
ProtectedContentIdentifiersAllowed Allows web pages to use identifiers for the purpose of protected content playback
If the policy is set to true or unset, the use of protected content identifiers is allowed, which can help enable higher quality of protected content playback.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ProtectedContentIdentifiersAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If the policy is set to true or unset, the use of protected content identifiers is allowed, which can help enable higher quality of protected content playback. If the policy is set to false, protected content identifiers are not allowed to be used.
Google:Cat_Google / Google Chrome / Proxy server
EnableProxyOverrideRulesForAllUsers Controls which managed users can set the ProxyOverrideRules policy.
When this policy is set to 0 or left unset, the ProxyOverrideRules policy will only be applied at the user scope for affiliated users.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableProxyOverrideRulesForAllUsers
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When this policy is set to 0 or left unset, the ProxyOverrideRules policy will only be applied at the user scope for affiliated users. When this policy is set to 1, the ProxyOverrideRules policy will be applied at the user scope, even that user is unaffiliated.
Google:Cat_Google / Google Chrome / Remote access
RemoteAccessHostAllowPinAuthentication Allow PIN and pairing authentication methods for remote access hosts
Leaving it unset lets the host decide whether PIN and/or pairing authentications can be used.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowPinAuthentication
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled allows the remote access host to use PIN and pairing authentications when accepting client connections. Setting the policy to Disabled disallows PIN or pairing authentications. Leaving it unset lets the host decide whether PIN and/or pairing authentications can be used. Note: If the setting results in no mutually supported authentication methods by both the host and the client, then the connection will be rejected.
RemoteAccessHostAllowRemoteAccessConnections Allow remote access connections to this machine
This policy has no effect if it is set to Enabled, left empty, or is not set.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowRemoteAccessConnections
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is Disabled, the remote access host service cannot be started or configured to accept incoming connections. This policy does not affect remote support scenarios. This policy has no effect if it is set to Enabled, left empty, or is not set.
RemoteAccessHostAllowUrlForwarding Allow remote access users to open host-side URLs in their local client browser
Setting the policy to Enabled or leaving it unset may allow users connected to a remote access host to open host-side URLs in their local client browser.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowUrlForwarding
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset may allow users connected to a remote access host to open host-side URLs in their local client browser. Setting the policy to Disabled will prevent the remote access host from sending URLs to the client. This setting doesn't apply to remote assistance connections as the feature is not supported for that connection mode. Note: This feature is not yet generally available so enabling it does not mean that the feature will be visible in the client UI.
RemoteAccessHostAllowFileTransfer Allow remote access users to transfer files to/from the host
Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowFileTransfer
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer. Setting the policy to Disabled disallows file transfer.
RemoteAccessHostAllowRemoteSupportConnections Allow remote support connections to this machine
This policy has no effect if enabled, left empty, or is not set.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowRemoteSupportConnections
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is disabled, the remote support host cannot be started or configured to accept incoming connections. This policy does not affect remote access scenarios. This policy does not prevent enterprise admins from connecting to managed Google ChromeOS devices. This policy has no effect if enabled, left empty, or is not set.
RemoteAccessHostAllowUiAccessForRemoteAssistance Allow remote users to interact with elevated windows in remote assistance sessions
Setting the policy to Disabled or leaving it unset means the remote assistance host runs in the user's context, and remote users can't interact with elevated windows on the desktop.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowUiAccessForRemoteAssistance
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means the remote assistance host runs in a process with uiAccess permissions. This lets remote users interact with elevated windows on the local user's desktop. Setting the policy to Disabled or leaving it unset means the remote assistance host runs in the user's context, and remote users can't interact with elevated windows on the desktop.
RemoteAccessHostClientDomainList Configure the required domain names for remote access clients
Setting the policy to an empty list or leaving it unset applies the default policy for the connection type.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\RemoteAccessHostClientDomainList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the client domain names that are imposed on remote access clients, and users can't change them. Only clients from one of the specified domains can connect to the host. Setting the policy to an empty list or leaving it unset applies the default policy for the connection type. For remote assistance, this allows clients from any domain to connect to the host. For anytime remote access, only the host owner can connect. See also RemoteAccessHostDomainList. Note: This setting overrides RemoteAccessHostClientDomain, if present. Example value: my-awesome-domain.com my-auxiliary-domain.com
RemoteAccessHostDomainList Configure the required domain names for remote access hosts
Setting the policy to an empty list or leaving it unset means hosts can be shared using any account.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\RemoteAccessHostDomainList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy specifies the host domain names that are imposed on remote access hosts, and users can't change them. Hosts can be shared only using accounts registered on one of the specified domain names. Setting the policy to an empty list or leaving it unset means hosts can be shared using any account. See also RemoteAccessHostClientDomainList. Note: This setting will override RemoteAccessHostDomain, if present. Example value: my-awesome-domain.com my-auxiliary-domain.com
RemoteAccessHostRequireCurtain Enable curtaining of remote access hosts
Setting the policy to Disabled or leaving it unset lets both local and remote users interact with the host while it's shared.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostRequireCurtain
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns off remote access hosts' physical input and output devices during a remote connection. Setting the policy to Disabled or leaving it unset lets both local and remote users interact with the host while it's shared.
RemoteAccessHostFirewallTraversal Enable firewall traversal from remote access host
Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostFirewallTraversal
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall. Setting the policy to Disabled when outgoing UDP connections are filtered by the firewall means the machine only allows connections from client machines within the local network.
RemoteAccessHostAllowClientPairing Enable or disable PIN-less authentication for remote access hosts
Setting the policy to Enabled or leaving it unset lets users pair clients and hosts at connection time, eliminating the need to enter a PIN every time.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowClientPairing
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled or leaving it unset lets users pair clients and hosts at connection time, eliminating the need to enter a PIN every time. Setting the policy to Disabled makes this feature unavailable.
RemoteAccessHostAllowRelayedConnection Enable the use of relay servers by the remote access host
If RemoteAccessHostFirewallTraversal is set to Enabled, setting RemoteAccessHostAllowRelayedConnection to Enabled or leaving it unset allows the use of remote clients to use relay servers to connect to this machine when a direct connection is not available, for example, because of firewall restrictions.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostAllowRelayedConnection
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If RemoteAccessHostFirewallTraversal is set to Enabled, setting RemoteAccessHostAllowRelayedConnection to Enabled or leaving it unset allows the use of remote clients to use relay servers to connect to this machine when a direct connection is not available, for example, because of firewall restrictions. Setting the policy to Disabled doesn't turn remote access off, but only allows connections from the same network (not NAT traversal or relay).
RemoteAccessHostMaximumSessionDurationMinutes Maximum session duration allowed for remote access connections
This policy has no effect if it is not set.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostMaximumSessionDurationMinutes
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is set, remote access connections will automatically disconnect after the number of minutes defined in the policy have elapsed. This does not prevent the client from reconnecting after the maximum session duration has been reached. Setting the policy to a value that is not within the min/max range may prevent the host from starting. This policy does not affect remote support scenarios. This policy has no effect if it is not set. In this case, remote access connections will have no maximum duration on this machine.
RemoteAccessHostUdpPortRange Restrict the UDP port range used by the remote access host
Leaving the policy unset or set to an empty string means the remote access host can use any available port.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostUdpPortRange
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy restricts the UDP port range used by the remote access host in this machine. Leaving the policy unset or set to an empty string means the remote access host can use any available port. Note: If RemoteAccessHostFirewallTraversal is Disabled, the remote access host will use UDP ports in the 12400-12409 range. Example value: 12400-12409
RemoteAccessHostClipboardSizeBytes The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization
This policy has no effect if it is not set.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostClipboardSizeBytes
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is set, clipboard data sent to and from the host will be truncated to the limit set by this policy. If a value of 0 is set, then clipboard sync is disabled. This policy affects both remote access and remote support scenarios. This policy has no effect if it is not set. Setting the policy to a value that is not within the min/max range may prevent the host from starting. Please note that the actual upper bound for the clipboard size is based on the maximum WebRTC data channel message size which this policy does not control.
Google:Cat_Google / Google Chrome / Removed policies
URLWhitelist Allow access to a list of URLs
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\URLWhitelist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TabFreezingEnabled Allow background tabs freeze
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TabFreezingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableCommonNameFallbackForLocalAnchors Allow certificates issued by local trust anchors without subjectAlternativeName extension
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableCommonNameFallbackForLocalAnchors
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionAllowInsecureUpdates Allow insecure algorithms in integrity checks on extension updates and installs
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExtensionAllowInsecureUpdates
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
KeygenAllowedForUrls Allow key generation on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\KeygenAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebRtcAllowLegacyTLSProtocols Allow legacy TLS/DTLS downgrade in WebRTC
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebRtcAllowLegacyTLSProtocols
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AutoplayWhitelist Allow media autoplay on a allowlist of URL patterns
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\AutoplayWhitelist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PPAPISharedImagesSwapChainAllowed Allow modern buffer allocation for Graphics3D APIs PPAPI plugin.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PPAPISharedImagesSwapChainAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UseMojoVideoDecoderForPepperAllowed Allow Pepper to use a new decoder for hardware accelerated video decoding.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UseMojoVideoDecoderForPepperAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AllowOutdatedPlugins Allow running plugins that are outdated
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowOutdatedPlugins
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableSha1ForLocalAnchors Allow SHA-1 signed certificates issued by local trust anchors
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableSha1ForLocalAnchors
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TabUnderAllowed Allow sites to simultaneously navigate and open pop-ups
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TabUnderAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
FileHandlingAllowedForUrls Allow the File Handling API on these web apps
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\FileHandlingAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PluginsAllowedForUrls Allow the Flash plugin on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PluginsAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InsecurePrivateNetworkRequestsAllowedForUrls Allow the listed sites to make requests to more-private network endpoints in an insecure manner.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\InsecurePrivateNetworkRequestsAllowedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingExtendedReportingOptInAllowed Allow users to opt in to Safe Browsing extended reporting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingExtendedReportingOptInAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PasswordManagerAllowShowPasswords Allow users to show passwords in Password Manager (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordManagerAllowShowPasswords
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AssistantWebEnabled Allow using Google Assistant on the web, e.g. to enable changing passwords automatically
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AssistantWebEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
U2fSecurityKeyApiEnabled Allow using the deprecated U2F Security Key API
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- U2fSecurityKeyApiEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebDriverOverridesIncompatiblePolicies Allow WebDriver to Override Incompatible Policies
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebDriverOverridesIncompatiblePolicies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AllowSyncXHRInPageDismissal Allows a page to perform synchronous XHR requests during page dismissal.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowSyncXHRInPageDismissal
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AllowPopupsDuringPageUnload Allows a page to show pop-ups during its unloading
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AllowPopupsDuringPageUnload
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NewBaseUrlInheritanceBehaviorAllowed Allows enabling the feature NewBaseUrlInheritanceBehavior
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NewBaseUrlInheritanceBehaviorAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ThrottleNonVisibleCrossOriginIframesAllowed Allows enabling throttling of non-visible, cross-origin iframes
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ThrottleNonVisibleCrossOriginIframesAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AppCacheForceEnabled Allows the AppCache feature to be re-enabled even if it is off by default.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AppCacheForceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AlwaysAuthorizePlugins Always runs plugins that require authorization (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AlwaysAuthorizePlugins
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AuthServerWhitelist Authentication server allowlist
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AuthServerWhitelist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
URLBlacklist Block access to a list of URLs
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\URLBlacklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
KeygenBlockedForUrls Block key generation on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\KeygenBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
FileHandlingBlockedForUrls Block the File Handling API on these web apps
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\FileHandlingBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PluginsBlockedForUrls Block the Flash plugin on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PluginsBlockedForUrls
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
BlockTruncatedCookies Block truncated cookies
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BlockTruncatedCookies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CECPQ2Enabled CECPQ2 post-quantum key-agreement enabled for TLS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CECPQ2Enabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RSAKeyUsageForLocalAnchorsEnabled Check RSA key usage for server certificates issued by local trust anchors
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RSAKeyUsageForLocalAnchorsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxFingerprintingProtectionEnabled Choose whether the Privacy Sandbox Fingerprinting Protection feature is to be enabled in Incognito mode.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrivacySandboxFingerprintingProtectionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxIpProtectionEnabled Choose whether the Privacy Sandbox IP Protection feature should be enabled.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrivacySandboxIpProtectionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ClearSiteDataOnExit Clear site data on browser shutdown (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ClearSiteDataOnExit
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionInstallWhitelist Configure extension installation allowlist
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionInstallWhitelist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionInstallBlacklist Configure extension installation blocklist
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ExtensionInstallBlacklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeMessagingWhitelist Configure native messaging allowlist
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\NativeMessagingWhitelist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeMessagingBlacklist Configure native messaging blocklist
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\NativeMessagingBlacklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingWhitelistDomains Configure the list of domains on which Safe Browsing will not trigger warnings.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SafeBrowsingWhitelistDomains
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostTalkGadgetPrefix Configure the TalkGadget prefix for remote access hosts
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostTalkGadgetPrefix
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeCleanupReportingEnabled Control how Chrome Cleanup reports data to Google
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeCleanupReportingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SetTimeoutWithout1MsClampEnabled Control Javascript setTimeout() function minimum timeout.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SetTimeoutWithout1MsClampEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionManifestV2Availability Control Manifest v2 extension availability
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExtensionManifestV2Availability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Default browser behavior1Manifest v2 is disabled2Manifest v2 is enabled3Manifest v2 is enabled for forced extensions onlyThis policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
BeforeunloadEventCancelByPreventDefaultEnabled Control new behavior for the cancel dialog produced by the beforeunload event
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BeforeunloadEventCancelByPreventDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UnthrottledNestedTimeoutEnabled Control the nesting threshold before which Javascript setTimeout() function start being clamped
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UnthrottledNestedTimeoutEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SendMouseEventsDisabledFormControlsEnabled Control the new behavior for event dispatching on disabled form controls
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SendMouseEventsDisabledFormControlsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
OffsetParentNewSpecBehaviorEnabled Control the new behavior of HTMLElement.offsetParent
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- OffsetParentNewSpecBehaviorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UrlParamFilterEnabled Control the URL parameter filter feature
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UrlParamFilterEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UserAgentClientHintsEnabled Control the User-Agent Client Hints feature.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UserAgentClientHintsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UserAgentClientHintsGREASEUpdateEnabled Control the User-Agent Client Hints GREASE Update feature.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UserAgentClientHintsGREASEUpdateEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultFileHandlingGuardSetting Control use of the File Handling API
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultFileHandlingGuardSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
2Do not allow any web app to access file types via the File Handling API3Allow web apps to ask the user to grant access to file types via the File Handling APIThis policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CSSCustomStateDeprecatedSyntaxEnabled Controls whether the deprecated :--foo syntax for CSS custom state is enabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CSSCustomStateDeprecatedSyntaxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SelectParserRelaxationEnabled Controls whether the new HTML parser behavior for the <select> element is enabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SelectParserRelaxationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultPluginsSetting Default Flash setting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultPluginsSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow all sites to automatically run the Flash plugin2Block the Flash plugin3Click to playThis policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultKeygenSetting Default key generation setting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultKeygenSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow all sites to use key generation2Do not allow any site to use key generationThis policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LegacySameSiteCookieBehaviorEnabled Default legacy SameSite cookie behavior setting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LegacySameSiteCookieBehaviorEnabled
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Revert to legacy SameSite behavior for cookies on all sites2Use SameSite-by-default behavior for cookies on all sitesThis policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderIconURL Default search provider icon
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderIconURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURL Default search provider instant URL
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderInstantURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultThirdPartyStoragePartitioningSetting Default third-party storage partitioning setting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultThirdPartyStoragePartitioningSetting
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
1Allow third-party storage partitioning by default.2Disable third-party storage partitioning.This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnforceLocalAnchorConstraintsEnabled Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnforceLocalAnchorConstraintsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeRootStoreEnabled Determines whether the Chrome Root Store and built-in certificate verifier will be used to verify server certificates
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeRootStoreEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CertificateTransparencyEnforcementDisabledForLegacyCas Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CertificateTransparencyEnforcementDisabledForLegacyCas
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisableSpdy Disable SPDY protocol
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisableSpdy
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ThirdPartyStoragePartitioningBlockedForOrigins Disable third-party storage partitioning for specific top-level origins
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ThirdPartyStoragePartitioningBlockedForOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisableSSLRecordSplitting Disable TLS False Start
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisableSSLRecordSplitting
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TargetBlankImpliesNoOpener Do not set window.opener for links targeting _blank
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TargetBlankImpliesNoOpener
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TripleDESEnabled Enable 3DES cipher suites in TLS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TripleDESEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TLS13HardeningForLocalAnchorsEnabled Enable a TLS 1.3 security feature for local trust anchors.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TLS13HardeningForLocalAnchorsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeCleanupEnabled Enable Chrome Cleanup on Windows
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeCleanupEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LocalDiscoveryEnabled Enable chrome://devices
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LocalDiscoveryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CorsMitigationList Enable CORS check mitigations in the new CORS implementation
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\CorsMitigationList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SupervisedUserCreationEnabled Enable creation of supervised users
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SupervisedUserCreationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableDeprecatedPrivetPrinting Enable deprecated privet printing
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableDeprecatedPrivetPrinting
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableDeprecatedWebPlatformFeatures Enable deprecated web platform features for a limited time
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\EnableDeprecatedWebPlatformFeatures
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DHEEnabled Enable DHE cipher suites in TLS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DHEEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DownloadBubbleEnabled Enable download bubble UI
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DownloadBubbleEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessClientFirewallTraversal Enable firewall traversal from remote access client
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessClientFirewallTraversal
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionForceInstallWithNonMalwareViolationsEnabled Enable Force-installed Extensions With Non-Malware Violations
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ExtensionForceInstallWithNonMalwareViolationsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CloudPrintProxyEnabled Enable Google Cloud Print proxy
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudPrintProxyEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
Http09OnNonDefaultPortsEnabled Enable HTTP/0.9 support on non-default ports
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- Http09OnNonDefaultPortsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InstantEnabled Enable Instant
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- InstantEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
KeyboardFocusableScrollersEnabled Enable keyboard focusable scrollers
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- KeyboardFocusableScrollersEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LockIconInAddressBarEnabled Enable lock icon in the omnibox for secure connections
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LockIconInAddressBarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeWindowOcclusionEnabled Enable Native Window Occlusion
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NativeWindowOcclusionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DnsPrefetchingEnabled Enable network prediction
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DnsPrefetchingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
OptimizationGuideFetchingEnabled Enable Optimization Guide Fetching
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- OptimizationGuideFetchingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UserAgentReduction Enable or disable the User-Agent Reduction.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UserAgentReduction
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Reduced User Agent.1Full (legacy) User Agent.2Reduced User Agent.This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PacHttpsUrlStrippingEnabled Enable PAC URL stripping (for https://)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PacHttpsUrlStrippingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PostQuantumKeyAgreementEnabled Enable post-quantum key agreement for TLS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PostQuantumKeyAgreementEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RC4Enabled Enable RC4 cipher suites in TLS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RC4Enabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RendererCodeIntegrityEnabled Enable Renderer Code Integrity
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RendererCodeIntegrityEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AdvancedProtectionDeepScanningEnabled Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AdvancedProtectionDeepScanningEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WelcomePageOnOSUpgradeEnabled Enable showing the welcome page on the first browser launch following OS upgrade
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WelcomePageOnOSUpgradeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
StricterMixedContentTreatmentEnabled Enable stricter treatment for mixed content
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- StricterMixedContentTreatmentEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CloudPrintSubmitEnabled Enable submission of documents to Google Cloud Print
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudPrintSubmitEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceEnablePepperVideoDecoderDevAPI Enable support for the PPB_VideoDecoder(Dev) API.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceEnablePepperVideoDecoderDevAPI
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UiAutomationProviderEnabled Enable the browser's UI Automation accessibility framework provider on Windows
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UiAutomationProviderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableDeprecatedWebBasedSignin Enable the old web-based signin flow
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableDeprecatedWebBasedSignin
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ThirdPartyBlockingEnabled Enable third party software injection blocking
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ThirdPartyBlockingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableSymantecLegacyInfrastructure Enable trust in Symantec Corporation's Legacy PKI Infrastructure
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnableSymantecLegacyInfrastructure
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostRequireTwoFactor Enable two-factor authentication for remote access hosts
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostRequireTwoFactor
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ZstdContentEncodingEnabled Enable zstd content-encoding support
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ZstdContentEncodingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnterpriseWebStoreName Enterprise web store name (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseWebStoreName
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnterpriseWebStoreURL Enterprise web store URL (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EnterpriseWebStoreURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RunAllFlashInAllowMode Extend Flash content setting to all content (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RunAllFlashInAllowMode
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeAppsEnabled Extend support for Chrome Apps on Microsoft® Windows®, macOS, and Linux.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeAppsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SpellcheckLanguageBlacklist Force disable spellcheck languages
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SpellcheckLanguageBlacklist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceNetworkInProcess Force networking code to run in the browser process
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceNetworkInProcess
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PersistentQuotaEnabled Force persistent quota to be enabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PersistentQuotaEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebSQLNonSecureContextEnabled Force WebSQL in non-secure contexts to be enabled.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebSQLNonSecureContextEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebSQLInThirdPartyContextEnabled Force WebSQL in third-party contexts to be re-enabled.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebSQLInThirdPartyContextEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebSQLAccess Force WebSQL to be enabled.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebSQLAccess
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeClientForceAllowed Forces Native Client (NaCl) to be allowed to run.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NativeClientForceAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceMajorVersionToMinorPositionInUserAgent Freeze User-Agent string major version at 99
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceMajorVersionToMinorPositionInUserAgent
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Default to browser settings for User-Agent string version.1The User-Agent string will not freeze the major version.2The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InsecureHashesInTLSHandshakesEnabled Insecure Hashes in TLS Handshakes Enabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- InsecureHashesInTLSHandshakesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AuthNegotiateDelegateWhitelist Kerberos delegation server allowlist
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- AuthNegotiateDelegateWhitelist
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LoadCryptoTokenExtension Load the CryptoToken component extension at startup
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LoadCryptoTokenExtension
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrefixedVideoFullscreenApiAvailability Manage the deprecated prefixed video fullscreen API's availability
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrefixedVideoFullscreenApiAvailability
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Follows regular deprecation timelines for the PrefixedVideoFullscreen APIDisables prefixed video fullscreen APIsEnables prefixed video fullscreen APIsThis policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ToolbarAvatarLabelSettings Managed toolbar avatar label setting
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ToolbarAvatarLabelSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Always display management label1Display management labels for 30sThis policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SSLVersionMax Maximum SSL version enabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SSLVersionMax
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
TLS 1.2TLS 1.3This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SSLVersionMin Minimum SSL version enabled
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SSLVersionMin
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
TLS 1.0TLS 1.1TLS 1.2This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SSLVersionFallbackMin Minimum TLS version to fallback to
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SSLVersionFallbackMin
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
TLS 1.1TLS 1.2This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderSearchTermsReplacementKey Parameter controlling search term placement for the default search provider
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderSearchTermsReplacementKey
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURLPostParams Parameters for instant URL which uses POST
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DefaultSearchProviderInstantURLPostParams
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostDebugOverridePolicies Policy overrides for Debug builds of the remote access host
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RemoteAccessHostDebugOverridePolicies
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
HideWebStorePromo Prevent app promotions from appearing on the new tab page
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HideWebStorePromo
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
MutationEventsEnabled Re-enable deprecated/removed Mutation Events
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MutationEventsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
FileSystemSyncAccessHandleAsyncInterfaceEnabled Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- FileSystemSyncAccessHandleAsyncInterfaceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrefixedStorageInfoEnabled Re-enable the deprecated window.webkitStorageInfo API
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrefixedStorageInfoEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EventPathEnabled Re-enable the Event.path API until M115.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- EventPathEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebComponentsV0Enabled Re-enable Web Components v0 API until M84.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebComponentsV0Enabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeAppsWebViewPermissiveBehaviorAllowed Restore permissive Chrome Apps <webview> behavior
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ChromeAppsWebViewPermissiveBehaviorAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LegacySameSiteCookieBehaviorEnabledForDomainList Revert to legacy SameSite behavior for cookies on these sites
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\LegacySameSiteCookieBehaviorEnabledForDomainList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
MediaCacheSize Set media disk cache size in bytes
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MediaCacheSize
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TabOrganizerSettings Settings for Tab Organizer
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- TabOrganizerSettings
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Allow Tab Organizer and improve AI models.1Allow Tab Organizer without improving AI models.2Do not allow Tab Organizer.This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisplayCapturePermissionsPolicyEnabled Specifies whether the display-capture permissions-policy is checked or skipped.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisplayCapturePermissionsPolicyEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InsecurePrivateNetworkRequestsAllowed Specifies whether to allow websites to make requests to more-private network endpoints in an insecure manner
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- InsecurePrivateNetworkRequestsAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LocalNetworkAccessRestrictionsEnabled Specifies whether to apply restrictions to requests to local network endpoints
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- LocalNetworkAccessRestrictionsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrivateNetworkAccessRestrictionsEnabled Specifies whether to apply restrictions to requests to more-private network endpoints
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PrivateNetworkAccessRestrictionsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CrossOriginWebAssemblyModuleSharingEnabled Specifies whether WebAssembly modules can be sent cross-origin
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CrossOriginWebAssemblyModuleSharingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisabledPlugins Specify a list of disabled plugins
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\DisabledPlugins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnabledPlugins Specify a list of enabled plugins
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\EnabledPlugins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisabledPluginsExceptions Specify a list of plugins that the user can enable or disable
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\DisabledPluginsExceptions
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisablePluginFinder Specify whether the plugin finder should be disabled (deprecated)
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisablePluginFinder
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CloudPrintWarningsSuppressed Suppress Google Cloud Print deprecation messages
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CloudPrintWarningsSuppressed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
MachineLevelUserCloudPolicyEnrollmentToken The enrollment token of cloud policy on desktop
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- MachineLevelUserCloudPolicyEnrollmentToken
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceLegacyDefaultReferrerPolicy Use a default referrer policy of no-referrer-when-downgrade.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ForceLegacyDefaultReferrerPolicy
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UseLegacyFormControls Use Legacy Form Controls until M84.
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- UseLegacyFormControls
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CorsLegacyModeEnabled Use the legacy CORS implementation rather than new CORS
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- CorsLegacyModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
Google:Cat_Google / Google Chrome / Safe Browsing settings
SafeBrowsingDeepScanningEnabled Allow download deep scanning for Safe Browsing-enabled users
When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingDeepScanningEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives. When this policy is disabled, this scanning will not be performed. This policy does not impact download content analysis configured by Chrome Enterprise Connectors.
SafeBrowsingProxiedRealTimeChecksAllowed Allow Safe Browsing Proxied Real Time Checks
Setting the policy to Enabled or leaving it unset allows the higher-protection proxied lookups.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingProxiedRealTimeChecksAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This controls whether Safe Browsing's standard protection mode is allowed to send partial hashes of URLs to Google through a proxy via Oblivious HTTP in order to determine whether they are safe to visit. The proxy allows browsers to upload partial hashes of URLs to Google without them being linked to the user's IP address. The policy also allows browsers to upload the partial hashes of URLs with higher frequency for better Safe Browsing protection quality. This policy will be ignored if Safe Browsing is disabled or set to enhanced protection mode. Setting the policy to Enabled or leaving it unset allows the higher-protection proxied lookups. Setting the policy to Disabled disallows the higher-protection proxied lookups. Partial hashes of URLs will be uploaded to Google directly with much lower frequency, which will degrade protection.
SafeBrowsingSurveysEnabled Allow Safe Browsing Surveys
When this policy is enabled or left unset, the user may receive surveys related to Safe Browsing.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingSurveysEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
When this policy is enabled or left unset, the user may receive surveys related to Safe Browsing. When this policy is disabled, the user will not receive surveys related to Safe Browsing.
PasswordProtectionChangePasswordURL Configure the change password URL.
Turning the policy off or leaving it unset means the service sends users to https://myaccount.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordProtectionChangePasswordURL
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets the URL for users to change their password after seeing a warning in the browser. The password protection service sends users to the URL (HTTP and HTTPS protocols only) you designate through this policy. For Google Chrome to correctly capture the salted hash of the new password on this change password page, make sure your change password page follows these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ). Turning the policy off or leaving it unset means the service sends users to https://myaccount.google.com to change their password. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://mydomain.com/change_password.html
SafeBrowsingAllowlistDomains Configure the list of domains on which Safe Browsing will not trigger warnings.
Leaving the policy unset means default Safe Browsing protection applies to all resources.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\SafeBrowsingAllowlistDomains
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled means Safe Browsing will trust the domains you designate. It won't check them for dangerous resources such as phishing, malware, or unwanted software. Safe Browsing's download protection service won't check downloads hosted on these domains. Its password protection service won't check for password reuse. Leaving the policy unset means default Safe Browsing protection applies to all resources. This policy does not support regular expressions; however, subdomains of a given domain are allowlisted. Fully qualified domain names (FQDNs) are not required. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: mydomain.com myuniversity.edu
PasswordProtectionLoginURLs Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords.
Turning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\PasswordProtectionLoginURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets the list of enterprise login URLs (HTTP and HTTPS protocols only). Password protection service will capture salted hashes of passwords on these URLs and use them for password reuse detection. For Google Chrome to correctly capture password salted hashes, ensure your sign-in pages follow these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ). Turning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.google.com. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://mydomain.com/login.html https://login.mydomain.com
DisableSafeBrowsingProceedAnyway Disable proceeding from the Safe Browsing warning page
Setting the policy to Disabled or leaving it unset means users can choose to proceed to the flagged site after the warning appears.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- DisableSafeBrowsingProceedAnyway
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled prevents users from proceeding past the warning page the Safe Browsing service shows to the malicious site. This policy only prevents users from proceeding on Safe Browsing warnings such as malware and phishing, not for SSL certificate-related issues such as invalid or expired certificates. Setting the policy to Disabled or leaving it unset means users can choose to proceed to the flagged site after the warning appears. See more about Safe Browsing ( https://developers.google.com/safe-browsing ).
SafeBrowsingExtendedReportingEnabled Enable Safe Browsing Extended Reporting
If not set, users can decide whether to send reports or not.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingExtendedReportingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled turns on Google Chrome's Safe Browsing Extended Reporting, which sends some system information and page content to Google servers to help detect dangerous apps and sites. Setting the policy to Disabled means reports are never sent. If you set this policy, users can't change it. If not set, users can decide whether to send reports or not. See more about Safe Browsing ( https://developers.google.com/safe-browsing ).
PasswordProtectionWarningTrigger Password protection warning trigger
Leaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- PasswordProtectionWarningTrigger
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Password protection warning is off1Password protection warning is triggered by password reuse2Password protection warning is triggered by password reuse on phishing pageSetting the policy lets you control the triggering of password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites. Use PasswordProtectionLoginURLs and PasswordProtectionChangePasswordURL to set which password to protect. If this policy is set to: * PasswordProtectionWarningOff, no password protection warning will be shown. * PasswordProtectionWarningOnPasswordReuse, password protection warning will be shown when the user reuses their protected password on a non-allowed site. * PasswordProtectionWarningOnPhishingReuse, password protection warning will be shown when the user reuses their protected password on a phishing site. Leaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.
SafeBrowsingProtectionLevel Safe Browsing Protection Level
If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- SafeBrowsingProtectionLevel
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
0Safe Browsing is never active.1Safe Browsing is active in the standard mode.2Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in. If this policy is set to 'NoProtection' (value 0), Safe Browsing is never active. If this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode. If this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google. If you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome. If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting. See https://support.google.com/chrome?p=safe_browsing_preferences for more info on Safe Browsing.
Google:Cat_Google / Google Chrome / Sign-in settings
BoundSessionCredentialsEnabled Bind Google credentials to a device
If this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- BoundSessionCredentialsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Controls the state of the Device Bound Session Credentials feature. Device Bound Session Credentials protects Google authentication cookies against cookie theft by regularly providing a cryptographic proof of device possession to Google servers. If this policy is set to false, Device Bound Session Credentials feature will be disabled. If this policy is set to true, Device Bound Session Credentials feature will be enabled. If this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.
ProfileSeparationDomainExceptionList Enterprise profile separation secondary domain allowlist
If this policy is unset, account logins will not be required to create a new separate profile.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\ProfileSeparationDomainExceptionList
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If this policy is unset, account logins will not be required to create a new separate profile. If this policy is set, account logins from the listed domains will not be required to create a new separate profile. This policy can be set to an empty string so that all account logins are required to create a new separate profile. Example value: domain.com otherdomain.com
Google:Cat_Google / Google Chrome / Startup, Home page and New Tab page
RestoreOnStartup Action on startup
Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If not set, users can change it.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- RestoreOnStartup
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
5Open New Tab Page1Restore the last session4Open a list of URLs6Open a list of URLs and restore the last sessionSetting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If you set the policy, users can't change it in Google Chrome. If not set, users can change it. Setting this policy to RestoreOnStartupIsLastSession or RestoreOnStartupIsLastSessionAndURLs turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies. If this policy is set to RestoreOnStartupIsLastSessionAndURLs, browser will restore previous session and open a separate window to show URLs that are set from RestoreOnStartupURLs. Note that users can choose to keep those URLs open and they will also be restored in the future session. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
HomepageLocation Configure the home page URL
Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HomepageLocation
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup. If the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect. The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome. Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://www.chromium.org
NewTabPageLocation Configure the New Tab page URL
Leaving the policy unset or empty puts the default New Tab page in use.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- NewTabPageLocation
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy configures the default New Tab page URL and prevents users from changing it. The New Tab page opens with new tabs and windows. This policy doesn't decide which pages open on start up. Those are controlled by the RestoreOnStartup policies. This policy does affect the homepage, if that's set to open the New Tab page, as well as the startup page if it's set to open the New Tab page. It is a best practice to provide fully canonicalized URL, if the URL is not fully canonicalized Google Chrome will default to https://. Leaving the policy unset or empty puts the default New Tab page in use. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://www.chromium.org
ShowHomeButton Show Home button on toolbar
If not set, users chooses whether to show the Home button.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- ShowHomeButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing. If you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.
RestoreOnStartupURLs URLs to open on startup
If not set, the New Tab page opens on start up.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\RestoreOnStartupURLs
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open. If not set, the New Tab page opens on start up. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://example.com https://www.chromium.org
HomepageIsNewTabPage Use New Tab Page as homepage
If not set, the user decides whether or not the New Tab page is their homepage.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- HomepageIsNewTabPage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab. If you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
Google:Cat_Google / Google Chrome / WebRtc settings
WebRtcPostQuantumKeyAgreement Enable post-quantum key agreement for WebRTC
If this policy is not set, the value would be set by the default rollout process for post-quantum key agreement offered for WebRTC.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebRtcPostQuantumKeyAgreement
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows controlling post-quantum key agreement for WebRTC. If this policy is set to Enabled, post-quantum key agreement would be offered for WebRTC. If this policy is set to Disabled, post-quantum key agreement would not be offered for WebRTC. If this policy is not set, the value would be set by the default rollout process for post-quantum key agreement offered for WebRTC. Offering a post-quantum key agreement is backwards-compatible. Existing DTLS peers and networking middleware are expected to ignore the new option and continue selecting previous options. However, devices that do not correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or the resulting larger messages. Such devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If encountered, administrators should contact the vendor for a fix. This policy is a temporary measure and will be removed after some milestones.
WebRtcDiagnosticLogCollectionAllowedForOrigins Enable WebRTC diagnostic log collection for specific origins
If the policy is not set, diagnostic log collection will be disabled by default.
- Registry key
- Software\Policies\Google\Chrome
- List subkey
- Software\Policies\Google\Chrome\WebRtcDiagnosticLogCollectionAllowedForOrigins
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows enabling diagnostic log collection for WebRTC for specific origins. For detailed information on valid input patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. This policy only matches based on origin, so any path in the URL pattern is ignored. Scheme and subdomains are supported. If the policy is set, diagnostic log collection will be enabled for the origins matched by the patterns in the list. If the policy is not set, diagnostic log collection will be disabled by default. Example value: https://www.example.com example.com [*.]example.com *://example.edu:*/ https://example.com:8080
WebRtcIPHandling WebRTC IP handling
When unset, defaults to using all available network interfaces.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebRtcIPHandling
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
WebRTC will use all available interfaces when searching for the best path.WebRTC will only use the interface connecting to the public Internet, but may connect using private IP addresses.WebRTC will only use the interface connecting to the public Internet, and will not connect using private IP addresses.WebRTC will use TCP on the public-facing interface, and will only use UDP if supported by a configured proxy.This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. Valid values: * default - WebRTC uses all available network interfaces. * default_public_and_private_interfaces - WebRTC uses all public and private interfaces. * default_public_interface_only - WebRTC uses all public interfaces, but not private ones. * disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying. When unset, defaults to using all available network interfaces. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values. Example value: default
WebRtcIPHandlingUrl WebRTC per URL IP Handling
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
- Registry key
- Software\Policies\Google\Chrome
- Value name
- WebRtcIPHandlingUrl
- Supported on
- Microsoft Windows 7 or later
- Template
- chrome.admx
This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection for each specific URL pattern. It accepts a list of URL patterns and handling type pairs. The URL patterns are checked in order and the first match will configure which handling is used by WebRTC for the domain. When the URL of the current document is not matched against any entry, it uses the configuration set by the policy WebRtcIPHandling. For detailed information on valid input patterns, please see https://chromeenterprise.google/policies/url-patterns/. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. Valid handling values: * default - WebRTC uses all network interfaces. * default_public_and_private_interfaces - WebRTC uses all public and private interfaces. * default_public_interface_only - WebRTC uses all public interfaces, but not private ones. * disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values. See https://chromeenterprise.google/policies/?policy=WebRtcIPHandlingUrl for more information about schema and formatting. Example value: [ { "url": "https://www.example.com", "handling": "default_public_and_private_interfaces" }, { "url": "https://[*.]example.edu", "handling": "default_public_interface_only" }, { "url": "*", "handling": "disable_non_proxied_udp" } ]
No policies match those filters.