Google Chrome 151.0.7922.72 · policy templates

Every Chrome policy and what it does when you leave it alone

All 733 policies from chrome.admx, Chrome 151.0.7922.72. As with Windows and Edge, two different things get called the default. The Group Policy default is Not Configured for every policy here without exception — the registry value is simply absent. The behavioural default is what Chrome actually does in that state, and it varies; where Google states it, it is quoted verbatim below. Chrome is the browser the ClickFix sample goes for first, so its settings carry real weight in the defence mapping.

733policies total
460behaviour documented
273not stated in the ADMX
673Chrome
60Chrome\Recommended
hack the planet
Google:Cat_Google / Google Chrome
AbusiveExperienceInterventionEnforce  Abusive Experience Intervention Enforce
Boolean Machine + User
If SafeBrowsingEnabled is not Disabled, then setting AbusiveExperienceInterventionEnforce to Enabled or leaving it unset prevents sites with abusive experiences from opening new windows or tabs.
Registry key
Software\Policies\Google\Chrome
Value name
AbusiveExperienceInterventionEnforce
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If SafeBrowsingEnabled is not Disabled, then setting AbusiveExperienceInterventionEnforce to Enabled or leaving it unset prevents sites with abusive experiences from opening new windows or tabs. Setting SafeBrowsingEnabled to Disabled or AbusiveExperienceInterventionEnforce to Disabled lets sites with abusive experiences open new windows or tabs.
AdsSettingForIntrusiveAdsSites  Ads setting for sites with intrusive ads
Enum Machine + User
Unless SafeBrowsingEnabled is set to False, then setting AdsSettingForIntrusiveAdsSites to 1 or leaving it unset allows ads on all sites.
Registry key
Software\Policies\Google\Chrome
Value name
AdsSettingForIntrusiveAdsSites
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow ads on all sites
2Do not allow ads on sites with intrusive ads
Unless SafeBrowsingEnabled is set to False, then setting AdsSettingForIntrusiveAdsSites to 1 or leaving it unset allows ads on all sites. Setting the policy to 2 blocks ads on sites with intrusive ads.
URLAllowlist  Allow access to a list of URLs
List (values under a subkey) Machine + User
Leaving the policy unset allows no exceptions to URLBlocklist.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\URLAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy provides access to the listed URLs, as exceptions to URLBlocklist. See that policy's description for the format of entries of this list. For example, setting URLBlocklist to * will block all requests, and you can use this policy to allow access to a limited list of URLs. Use it to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths, using the format specified at ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). The most specific filter determines if a URL is blocked or allowed. The URLAllowlist policy takes precedence over URLBlocklist. This policy is limited to 1,000 entries. This policy also allows enabling the automatic invocation by the browser of external application registered as protocol handlers for the listed protocols like "tel:" or "ssh:". Leaving the policy unset allows no exceptions to URLBlocklist. From Google Chrome version 92, this policy is also supported in the headless mode. Example value: example.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
IncognitoModeUrlAllowlist  Allow access to a list of URLs in Incognito mode.
List (values under a subkey) Machine + User
Leaving the policy unset allows no exceptions to IncognitoModeUrlBlocklist and IncognitoModeAvailability.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\IncognitoModeUrlAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy provides access to the listed URLs in Incognito mode. Use it to open exceptions to certain URL patterns defined in IncognitoModeUrlBlocklist, using the format specified at ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). If both this policy and IncognitoModeUrlBlocklist are set, the allowlist takes precedence. If a URL matches a pattern on the allowlist, it will be allowed. If it matches a pattern on the blocklist (but not the allowlist), it will be blocked. If a URL matches neither, the general URLBlocklist/URLAllowlist policies will be used as a fallback. If this policy is set and IncognitoModeUrlBlocklist is not, any URL not on the allowlist will be blocked in Incognito mode. If IncognitoModeAvailability is set to disallow (value 1), but this policy is configured, Incognito mode will be available only for the URLs matching the allowlist. Leaving the policy unset allows no exceptions to IncognitoModeUrlBlocklist and IncognitoModeAvailability. This policy only affects Incognito mode. To allow URLs for all user profiles, please use the URLAllowlist policy. This policy is limited to 1000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
ChromeForTestingAllowed  Allow Chrome for Testing
Boolean Machine + User
If this policy is set to Enabled or not set, users may install and run Chrome for Testing.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeForTestingAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls whether users may use Chrome for Testing. If this policy is set to Enabled or not set, users may install and run Chrome for Testing. If this policy is set to Disabled, users are not allowed to run Chrome for Testing. Users will still be able to install Chrome for Testing, however it will not run with the profiles where this policy is set to Disabled.
SandboxExternalProtocolBlocked  Allow Chrome to block navigations toward external protocols in sandboxed iframes
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SandboxExternalProtocolBlocked
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Chrome will block navigations toward external protocols inside sandboxed iframe. See https://chromestatus.com/features/5680742077038592. When True, this lets Chrome blocks those navigations. When False, this prevents Chrome from blocking those navigations. This defaults to True: security feature enabled. This can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 117.
WebRtcEventLogCollectionAllowed  Allow collection of WebRTC event logs from Google services
Boolean Machine + User
Leaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs.
Registry key
Software\Policies\Google\Chrome
Value name
WebRtcEventLogCollectionAllowed
Enabled / Disabled
1 / 0
Stated default
From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means Google Chrome can collect WebRTC event logs from Google services such as Hangouts Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as the time and size of RTP packets, feedback about congestion on the network, and metadata about time and quality of audio and video frames. These logs have no audio or video content from the meeting. To make debugging easier, Google might associate these logs, by means of a session ID, with other logs collected by the Google service itself. Setting the policy to Disabled results in no collection or uploading of such logs. Leaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs. Starting at M77, Google Chrome defaults to being able to collect and upload these logs from most profiles affected by cloud-based, user-level enterprise policies. From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.
DefaultSearchProviderContextMenuAccessAllowed  Allow default search provider context menu search access
Boolean Machine + User
If this policy is set to enabled or not set, the context menu item for your default search provider will be available.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderContextMenuAccessAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enables the use of a default search provider on the context menu. If you set this policy to disabled the search context menu item that relies on your default search provider will not be available. If this policy is set to enabled or not set, the context menu item for your default search provider will be available. The policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.
AllowDinosaurEasterEgg  Allow Dinosaur Easter Egg Game
Boolean Machine + User
Leaving the policy unset means users can't play the game on enrolled Google ChromeOS, but can under other circumstances.
Registry key
Software\Policies\Google\Chrome
Value name
AllowDinosaurEasterEgg
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True allows users to play the dinosaur game. Setting the policy to False means users can't play the dinosaur easter egg game when device is offline. Leaving the policy unset means users can't play the game on enrolled Google ChromeOS, but can under other circumstances.
AdditionalDnsQueryTypesEnabled  Allow DNS queries for additional DNS record types
Boolean Machine + User
If this policy is unset or set to Enabled, additional types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).
Registry key
Software\Policies\Google\Chrome
Value name
AdditionalDnsQueryTypesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether Google Chrome may query additional DNS record types when making insecure DNS requests. This policy has no effect on DNS queries made via Secure DNS, which may always query additional DNS types. If this policy is unset or set to Enabled, additional types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28). If this policy is set to Disabled, DNS will only be queried for A (DNS type 1) and/or AAAA (DNS type 28). This policy is a temporary measure and will be removed in future versions of Google Chrome. After removal of the policy, Google Chrome will always be able to query additional DNS types.
DownloadRestrictions  Allow download restrictions
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DownloadRestrictions
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0No special restrictions. Default.
1Block malicious downloads and dangerous file types.
2Block malicious downloads, uncommon or unwanted downloads and dangerous file types.
3Block all downloads.
4Block malicious downloads. Recommended.
Setting the policy means users can't bypass download security decisions. There are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked): * Malicious, as flagged by the Safe Browsing server * Uncommon or unwanted, as flagged by the Safe Browsing server * A dangerous file type (e.g. all SWF downloads and many EXE downloads) Setting the policy blocks different subsets of these, depending on it's value: 0: No special restrictions. Default. 1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 3: Blocks all downloads. Not recommended, except for special use cases. 4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended. Note: These restrictions apply to downloads triggered from webpage content, as well as the Download link… menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).
FileOrDirectoryPickerWithoutGestureAllowedForOrigins  Allow file or directory picker APIs to be called without prior user gesture
List (values under a subkey) Machine + User
If this policy is unset, all origins will require a prior user gesture to call these APIs.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\FileOrDirectoryPickerWithoutGestureAllowedForOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
For security reasons, the showOpenFilePicker(), showSaveFilePicker() and showDirectoryPicker() web APIs require a prior user gesture ("transient activation") to be called or will otherwise fail. With this policy set, admins can specify origins on which these APIs can be called without prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. * is not an accepted value for this policy. If this policy is unset, all origins will require a prior user gesture to call these APIs. Example value: https://www.example.com [*.]example.edu
FullscreenAllowed  Allow fullscreen mode
Boolean Machine + User
Setting the policy to True or leaving it unset means that, with appropriate permissions, users, apps, and extensions can enter Fullscreen mode (in which only web content appears).
Registry key
Software\Policies\Google\Chrome
Value name
FullscreenAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset means that, with appropriate permissions, users, apps, and extensions can enter Fullscreen mode (in which only web content appears). Setting the policy to False means users, apps, and extensions can't enter Fullscreen mode.
HttpsOnlyMode  Allow HTTPS-Only Mode to be enabled
Enum Machine + User
If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode.
Registry key
Software\Policies\Google\Chrome
Value name
HttpsOnlyMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Do not restrict users' HTTPS-Only Mode setting
Disable HTTPS-Only Mode
Enable HTTPS-Only Mode in Strict mode
Enable HTTPS-Only Mode in Balanced Mode
This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode upgrades all navigations to HTTPS. If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode. If this setting is set to "disallowed", HTTPS-Only Mode will be disabled. If this setting is set to "force_enabled", HTTPS-Only Mode will be enabled in Strict mode. If this setting is set to "force_balanced_enabled", HTTPS-Only Mode will be enabled in Balanced mode. "force_enabled" is supported from M112 onwards, "force_balanced_enabled" is supported from M129 onwards. "force_enabled" and "force_balanced_enabled" can be recommended to users too. HTTPS-Only Mode will be set Strict or Balanced initially but users are allowed to change it. If you set this policy to a value that is not supported by the version of Chrome that receives the policy, Chrome will default to the allowed setting. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. Example value: disallowed
AllowFileSelectionDialogs  Allow invocation of file selection dialogs
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs.
Registry key
Software\Policies\Google\Chrome
Value name
AllowFileSelectionDialogs
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs. Setting the policy to Disabled means that whenever users perform actions provoking a file selection dialog, such as importing bookmarks, uploading files, and saving links, a message appears instead. The user is assumed to have clicked Cancel on the file selection dialog.
AutoplayAllowed  Allow media autoplay
Boolean Machine + User
If this policy is left unset, Google Chrome doesn't autoplay media.
Registry key
Software\Policies\Google\Chrome
Value name
AutoplayAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True lets Google Chrome autoplay media. Setting the policy to False stops Google Chrome from autoplaying media. If this policy is left unset, Google Chrome doesn't autoplay media. But, for certain URL patterns, you can use the AutoplayAllowlist policy to change this setting. If this policy changes while Google Chrome is running, it only applies to newly opened tabs.
AutoplayAllowlist  Allow media autoplay on a allowlist of URL patterns
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutoplayAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets videos play automatically (without user consent) with audio content in Google Chrome. If AutoplayAllowed policy is set to True, then this policy has no effect. If AutoplayAllowed is set to False, then any URL patterns set in this policy can still play. If this policy changes while Google Chrome is running, it only applies to newly opened tabs. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. Example value: https://www.example.com [*.]example.edu
PolicyDictionaryMultipleSourceMergeList  Allow merging dictionary policies from different sources
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PolicyDictionaryMultipleSourceMergeList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level. This merging is in the first level keys of the dictionary from each source. The key coming from the highest priority source takes precedence. Use the wildcard character '*' to allow merging of all supported dictionary policies. If a policy is in the list and there's conflict between sources with: * The same scopes and level: The values merge into a new policy dictionary. * Different scopes or level: The policy with the highest priority applies. If a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies. Example value: ExtensionSettings
PolicyListMultipleSourceMergeList  Allow merging list policies from different sources
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PolicyListMultipleSourceMergeList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level. Use the wildcard character '*' to allow merging of all list policies. If a policy is in the list and there's conflict between sources with: * The same scopes and level: The values merge into a new policy list. * Different scopes or level: The policy with the highest priority applies. If a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies. Example value: ExtensionInstallAllowlist ExtensionInstallBlocklist
AudioCaptureAllowed  Allow or deny audio capture
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access.
Registry key
Software\Policies\Google\Chrome
Value name
AudioCaptureAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access. Setting the policy to Disabled turns off prompts, and audio capture is only available to URLs set in the AudioCaptureAllowedUrls list. Note: The policy affects all audio input (not just the built-in microphone).
VideoCaptureAllowed  Allow or deny video capture
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the VideoCaptureAllowedUrls list, users get prompted for video capture access.
Registry key
Software\Policies\Google\Chrome
Value name
VideoCaptureAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the VideoCaptureAllowedUrls list, users get prompted for video capture access. Setting the policy to Disabled turns off prompts, and video capture is only available to URLs set in the VideoCaptureAllowedUrls list. Note: The policy affects all video input (not just the built-in camera).
BuiltInAIAPIsEnabled  Allow pages to use the built-in AI APIs.
Boolean Machine + User
If the policy is enabled or unset, the APIs are enabled to be used.
Registry key
Software\Policies\Google\Chrome
Value name
BuiltInAIAPIsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls if a page can use the built-in AI APIs (such as LanguageModel API, Summarization API, Writer API, and Rewriter API). If the policy is enabled or unset, the APIs are enabled to be used. If the policy is disabled, attempting using the APIs will result in an error.
AllowBackForwardCacheForCacheControlNoStorePageEnabled  Allow pages with Cache-Control: no-store header to enter back/forward cache
Boolean Machine + User
If the policy is enabled or unset, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.
Registry key
Software\Policies\Google\Chrome
Value name
AllowBackForwardCacheForCacheControlNoStorePageEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls if a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it is no longer accessible. If the policy is enabled or unset, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.g. when there is HTTP-only cookie change to the site). If the policy is disabled, the page with Cache-Control: no-store header will not be stored in back/forward cache.
SSLErrorOverrideAllowed  Allow proceeding from the SSL warning page
Boolean Machine + User
Setting the policy to Enabled or leaving it unset lets users click through warning pages Google Chrome shows when users navigate to sites that have SSL errors.
Registry key
Software\Policies\Google\Chrome
Value name
SSLErrorOverrideAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset lets users click through warning pages Google Chrome shows when users navigate to sites that have SSL errors. Setting the policy to Disabled prevent users from clicking through any warning pages.
SSLErrorOverrideAllowedForOrigins  Allow proceeding from the SSL warning page on specific origins
List (values under a subkey) Machine + User
If SSLErrorOverrideAllowed is Enabled or unset, this policy does nothing. Leaving the policy unset means SSLErrorOverrideAllowed applies for all sites.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SSLErrorOverrideAllowedForOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If SSLErrorOverrideAllowed is Disabled, setting the policy lets you set a list of origin patterns that specify the sites where a user can click through warning pages Google Chrome shows when users navigate to sites that have SSL errors. Users will not be able to click through SSL warning pages on origins that are not on this list. If SSLErrorOverrideAllowed is Enabled or unset, this policy does nothing. Leaving the policy unset means SSLErrorOverrideAllowed applies for all sites. For detailed information on valid input patterns, please see https://chromeenterprise.google/policies/url-patterns/. * is not an accepted value for this policy. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
BrowserNetworkTimeQueriesEnabled  Allow queries to a Google time service
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserNetworkTimeQueriesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp. Setting the policy to Disabled stops Google Chrome from sending these queries.
QuicAllowed  Allow QUIC protocol
Boolean Machine + User
Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.
Registry key
Software\Policies\Google\Chrome
Value name
QuicAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome. Setting the policy to Disabled disallows the use of QUIC protocol.
RemoteDebuggingAllowed  Allow remote debugging
Boolean Machine + User
If this policy is set to Enabled or not set, users may use remote debugging by specifying --remote-debugging-port and --remote-debugging-pipe command line switches.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteDebuggingAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls whether users may use remote debugging. If this policy is set to Enabled or not set, users may use remote debugging by specifying --remote-debugging-port and --remote-debugging-pipe command line switches. If this policy is set to Disabled, users are not allowed to use remote debugging.
DomainReliabilityAllowed  Allow reporting of domain reliability related data
Boolean Machine + User
If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
Registry key
Software\Policies\Google\Chrome
Value name
DomainReliabilityAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google. If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
ScreenCaptureWithoutGestureAllowedForOrigins  Allow screen capture without prior user gesture
List (values under a subkey) Machine + User
If this policy is unset, all origins will require a prior user gesture to call this API.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ScreenCaptureWithoutGestureAllowedForOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
For security reasons, the getDisplayMedia() web API requires a prior user gesture ("transient activation") to be called or will otherwise fail. With this policy set, admins can specify origins on which this API can be called without prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. * is not an accepted value for this policy. If this policy is unset, all origins will require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
ServiceWorkerToControlSrcdocIframeEnabled  Allow ServiceWorker to control srcdoc iframes
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Google Chrome makes srcdoc iframes with "allow-same-origin" sandbox attributes to be under ServiceWorker control.
Registry key
Software\Policies\Google\Chrome
Value name
ServiceWorkerToControlSrcdocIframeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the "allow-same-origin" sandbox attribute to be under ServiceWorker control. Setting the policy to Enabled or leaving it unset means Google Chrome makes srcdoc iframes with "allow-same-origin" sandbox attributes to be under ServiceWorker control. Setting the policy to Disabled leaves the srcdoc iframe not controlled by ServiceWorker. This policy is intended to be temporary and will be removed in 2026.
ServiceWorkerAutoPreloadEnabled  Allow ServiceWorker to dispatch navigation requests without waiting for its startup
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Google Chrome enables ServiceWorkerAutoPreload.
Registry key
Software\Policies\Google\Chrome
Value name
ServiceWorkerAutoPreloadEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
https://github.com/WICG/service-worker-auto-preload The ServiceWorkerAutoPreload feature dispatches a network request for a main resource at the same time it begins the ServiceWorker bootstrap process. Setting the policy to Enabled or leaving it unset means Google Chrome enables ServiceWorkerAutoPreload. The navigation request is automatically dispatched while starting the ServiceWorker in some scenarios, e.g. ServiceWorker is not running, If it is disabled, Google Chrome will not enable ServiceWorkerAutoPreload. The navigation request is dispatched always after starting the ServiceWorker. This policy is a temporary measure to control the feature and will be removed in M154.
SideSearchEnabled  Allow showing the most recent default search engine results page in a Browser side panel
Boolean Machine + User
Setting the policy to Enabled or leaving the policy unset means that users can bring up their most recent default search engine results page in a side panel via toggling an icon in the toolbar.
Registry key
Software\Policies\Google\Chrome
Value name
SideSearchEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving the policy unset means that users can bring up their most recent default search engine results page in a side panel via toggling an icon in the toolbar. Setting the policy to Disabled removes the icon from the toolbar that opens the side panel with the default search engine results page.
AllowSocketPoolSizeRandomizationForProxies  Allow socket pool size randomization for proxies
Boolean Machine + User
This is enabled by default for all pools, but this policy allows the feature to be disabled for proxy pools specifically.
Registry key
Software\Policies\Google\Chrome
Value name
AllowSocketPoolSizeRandomizationForProxies
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Socket pool size randomization is a security mechanism that prevents attackers from exploiting deterministic capacity limits to learn cross-site information. If the capacity for a pool is normally 128 sockets, this mechanism randomly caps the pool between 128 and 256. This can allow up to 2x as many connections to the proxy, but in practice the expected value is more like 1.2x. This impacts the settings from MaxConnectionsPerProxy and MaxConnectionsPerProxyForWebSocket. Instead of them defining the upper limit, the upper limit is 2x their values (though again, the expected value in practice is more like 1.2x them). This is enabled by default for all pools, but this policy allows the feature to be disabled for proxy pools specifically.
EnableUnsafeSwiftShader  Allow software WebGL fallback using SwiftShader
Boolean Machine + User
Setting the policy to Disabled or not set, WebGL context creation may fail if hardware GPU acceleration is not available.
Registry key
Software\Policies\Google\Chrome
Value name
EnableUnsafeSwiftShader
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A policy that controls if SwiftShader will be used as a WebGL fallback when hardware GPU acceleration is not available. SwiftShader has been used to support WebGL on systems without GPU acceleration such as headless systems or virtual machines but has been deprecated due to security issues. Starting in M139, WebGL context creation will fail when it would have otherwise used SwiftShader. This policy allows the browser or administrator to temporarily defer the deprecation. Setting the policy to Enabled, SwiftShader will be used as a software WebGL fallback. Setting the policy to Disabled or not set, WebGL context creation may fail if hardware GPU acceleration is not available. Web pages may misbehave if they do not gracefully handle WebGL context creation failure. This is a temporary policy which will be removed in the future.
PrefetchWithServiceWorkerEnabled  Allow SpeculationRules prefetch to ServiceWorker-controlled URLs
Boolean Machine + User
Setting this policy to Enabled or not set allows SpeculationRules prefetch to ServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is enabled).
Registry key
Software\Policies\Google\Chrome
Value name
PrefetchWithServiceWorkerEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
SpeculationRules prefetch can be issued to URLs that are controlled by ServiceWorker. However, legacy code did not allow it and canceled the prefetch requests. This policy enables to control the behavior. Setting this policy to Enabled or not set allows SpeculationRules prefetch to ServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is enabled). This is the current default behavior and is aligned with the specifications. Setting this policy to Disabled disallows SpeculationRules prefetch to ServiceWorker-controlled URLs. This is the legacy behavior. This policy is intended to be temporary and will be removed in the future.
AudioProcessHighPriorityEnabled  Allow the audio process to run with priority above normal on Windows
Boolean Machine + User
If this policy is not set, the default configuration for the audio process will be used.
Registry key
Software\Policies\Google\Chrome
Value name
AudioProcessHighPriorityEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the priority of the audio process on Windows. If this policy is enabled, the audio process will run with above normal priority. If this policy is disabled, the audio process will run with normal priority. If this policy is not set, the default configuration for the audio process will be used. This policy is intended as a temporary measure to give enterprises the ability to run audio with higher priority to address certain performance issues with audio capture. This policy will be removed in the future.
AudioSandboxEnabled  Allow the audio sandbox to run
Boolean Machine + User
If this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.
Registry key
Software\Policies\Google\Chrome
Value name
AudioSandboxEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the audio process sandbox. If this policy is enabled, the audio process will run sandboxed. If this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process. This leaves users open to security risks related to running the audio subsystem unsandboxed. If this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform. This policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.
ShoppingListEnabled  Allow the shopping list feature to be enabled
Boolean Machine + User
If this policy is set to Enabled or not set, the shopping list feature will be available to users.
Registry key
Software\Policies\Google\Chrome
Value name
ShoppingListEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the availability of the shopping list feature. If enabled, users will be presented with UI to track the price of the product displayed on the current page. The tracked product will be shown in the bookmarks side panel. If this policy is set to Enabled or not set, the shopping list feature will be available to users. If this policy is set to Disabled, the shopping list feature will be unavailable.
TranslatorAPIAllowed  Allow Translator API
Boolean Machine + User
Setting the policy to Enabled or leaving it unset allows the use of Translator API in Google Chrome.
Registry key
Software\Policies\Google\Chrome
Value name
TranslatorAPIAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset allows the use of Translator API in Google Chrome. Setting the policy to Disabled disallows the use of Translator API.
CloudUserPolicyOverridesCloudMachinePolicy  Allow user cloud policies to override Chrome Browser Cloud Management policies.
Boolean Machine + User
Setting the policy to Disabled or leaving it unset causes user-level cloud policies to have default priority.
Registry key
Software\Policies\Google\Chrome
Value name
CloudUserPolicyOverridesCloudMachinePolicy
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled allows policies associated with a managed account to take precedence if they conflict with Chrome Enterprise Core browser policies. Setting the policy to Disabled or leaving it unset causes user-level cloud policies to have default priority. Only policies originating from secure users can take precedence. A secure user is affiliated with the organization that manages their browser using Chrome Enterprise Core. All other user-level policies will have default precedence. The policy can be combined with CloudPolicyOverridesPlatformPolicy. If both policies are enabled, user cloud policies will also take precedence over conflicting platform policies.
UserFeedbackAllowed  Allow user feedback
Boolean Machine + User
Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination.
Registry key
Software\Policies\Google\Chrome
Value name
UserFeedbackAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination. Setting the policy to Disabled means users can't send feedback to Google.
NTPCustomBackgroundEnabled  Allow users to customize the background on the New Tab page
Boolean Machine + User
If the policy is set to true or unset, users can customize the background on the New Tab page.
Registry key
Software\Policies\Google\Chrome
Value name
NTPCustomBackgroundEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later. If the policy is set to true or unset, users can customize the background on the New Tab page.
AllowWebAuthnWithBrokenTlsCerts  Allow Web Authentication requests on sites with broken TLS certificates.
Boolean Machine + User
If the policy is set to Disabled or left unset, the default behavior of blocking such requests will apply.
Registry key
Software\Policies\Google\Chrome
Value name
AllowWebAuthnWithBrokenTlsCerts
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If set to Enabled, Google Chrome will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure). If the policy is set to Disabled or left unset, the default behavior of blocking such requests will apply.
WebRtcTextLogCollectionAllowed  Allow WebRTC text logs collection from Google Services
Boolean Machine + User
Leaving the policy unset means Google Chrome defaults to being able to collect and upload these logs.
Registry key
Software\Policies\Google\Chrome
Value name
WebRtcTextLogCollectionAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to enabled means Google Chrome can collect WebRTC text logs from Google services such as Google Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as textual metadata describing incoming and outgoing WebRTC streams, WebRTC specific log entries and additional system information. These logs have no audio or video content from the meeting. Setting the policy to disabled results in no uploading of such logs to Google. Logs would still accumulate locally on the user's device. Leaving the policy unset means Google Chrome defaults to being able to collect and upload these logs.
PaymentMethodQueryEnabled  Allow websites to query for available payment methods.
Boolean Machine + User
If the setting is enabled or not set then websites are allowed to check if the user has payment methods saved.
Registry key
Software\Policies\Google\Chrome
Value name
PaymentMethodQueryEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set whether websites are allowed to check if the user has payment methods saved. If this policy is set to disabled, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available. If the setting is enabled or not set then websites are allowed to check if the user has payment methods saved.
WebAuthenticationRemoteDesktopAllowedOrigins  Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebAuthenticationRemoteDesktopAllowedOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A list of origins of remote desktop client apps that may execute WebAuthn API requests that originate from a browsing session on a remote host. Any origin configured in this policy can make WebAuthn requests for Relying Party IDs (RP IDs) that it would normally not allowed to be able to claim. Only valid HTTPS origins are allowed. Wildcards are not supported. Any invalid entries are ignored. This policy only applies to affiliated users. Example value: https://remotedesktop.google.com https://vdi.corp.example https://server:8080/
OriginAgentClusterDefaultEnabled  Allows origin-keyed agent clustering by default.
Boolean Machine + User
If this policy is enabled or not set, the browser will follow this new default from that version on.
Registry key
Software\Policies\Google\Chrome
Value name
OriginAgentClusterDefaultEnabled
Enabled / Disabled
1 / 0
Stated default
This policy allows origin-keyed agent clustering by default. domain accessor remains settable by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows origin-keyed agent clustering by default. The Origin-Agent-Cluster HTTP header controls whether a document is isolated in an origin-keyed agent cluster, or in a site-keyed agent cluster. This has security implications since an origin-keyed agent cluster allows isolating documents by origin. The developer-visible consequence of this is that the document.domain accessor can no longer be set. The default behaviour - when no Origin-Agent-Cluster header has been set - changes in M111 from site-keyed to origin-keyed. If this policy is enabled or not set, the browser will follow this new default from that version on. If this policy is disabled this change is reversed and documents without Origin-Agent-Cluster headers will be assigned to site-keyed agent clusters. As a consequence, the document.domain accessor remains settable by default. This matches the legacy behaviour. See https://developer.chrome.com/blog/immutable-document-domain/ for additional details.
AlwaysOpenPdfExternally  Always Open PDF files externally
Boolean Machine + User
If not set, users can choose whether to open PDF externally or not.
Registry key
Software\Policies\Google\Chrome
Value name
AlwaysOpenPdfExternally
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application. Setting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files. If you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.
ApplicationLocaleValue  Application locale
String Machine + User
Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured).
Registry key
Software\Policies\Google\Chrome
Value name
ApplicationLocaleValue
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the locale Google Chrome uses. Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured). 2) The system locale. 3) The fallback locale (en-US). Example value: en
PromptForDownloadLocation  Ask where to save each file before downloading
Boolean Machine + User
Leaving the policy unset lets users change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
PromptForDownloadLocation
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means users are asked where to save each file before downloading. Setting the policy to Disabled has downloads start immediately, and users aren't asked where to save the file. Leaving the policy unset lets users change this setting.
URLBlocklist  Block access to a list of URLs
List (values under a subkey) Machine + User
If left unset, no URLs are blocked in the browser.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\URLBlocklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the URLBlocklist policy stops web pages with prohibited URLs from loading. Administrators can specify the list of URL patterns to be blocked. If left unset, no URLs are blocked in the browser. Up to 1,000 exceptions can be defined in URLAllowlist. See how to format a URL pattern ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). Note: This policy does not apply to in-page JavaScript URLs with dynamically loaded data. If you blocked example.com/abc, then example.com could still load it using XMLHTTPRequest. Additionally, this policy does not prevent web pages from updating the URL shown in the omnibox to a blocked one using the JavaScript History API. From Google Chrome version 73, you can block javascript://* URLs. But, this only affects JavaScript entered in the address bar or, for example, bookmarklets. From Google Chrome version 92, this policy is also supported in the headless mode. From Google Chrome version 147, the wildcard * on its own does not apply to internal chrome:// URLs. To block these, you must explicitly use the chrome://* pattern. Note: Blocking internal chrome://* and chrome-untrusted://* URLs can lead to unexpected errors or can be circumvented in some cases. Instead of blocking certain internal URLs, see if there are more specific policies available. For example: - Instead of blocking chrome://settings/certificates, use CACertificateManagementAllowed. - Instead of blocking chrome-untrusted://crosh, use SystemFeaturesDisableList. - Instead of blocking devtools://*, use one of the DeveloperToolsAvailability, DeveloperToolsAvailabilityAllowlist or DeveloperToolsAvailabilityBlocklist policies. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
IncognitoModeUrlBlocklist  Block access to a list of URLs in Incognito mode.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\IncognitoModeUrlBlocklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the IncognitoModeUrlBlocklist policy stops web pages with prohibited URLs from loading in Incognito mode. Administrators can specify the list of URL patterns to be blocked. See how to format a URL pattern ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). If both this and the IncognitoModeUrlAllowlist are set, the allowlist takes precedence. If a URL matches a pattern on the allowlist, it will be allowed. If it matches a pattern on the blocklist but not the allowlist, it will be blocked. If a URL matches neither, the general URLBlocklist/URLAllowlist policies will be used as a fallback. If the IncognitoModeUrlAllowlist policy is set and this policy is not, any URL not on the allowlist will be blocked in Incognito mode. If IncognitoModeAvailability is set to disallow (value 1), but the IncognitoModeUrlAllowlist policy is configured, Incognito mode will be available only for the URLs matching the allowlist. This policy only affects Incognito mode. To block URLs for all user profiles, please use the URLBlocklist policy. This policy is limited to 1000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
BrowserLegacyExtensionPointsBlocked  Block Browser Legacy Extension Points
Boolean Machine + User
Setting the policy to Enabled or leaving it unset will permit Google Chrome to apply the additional extension point security mitigation to block legacy extension points in the Browser process.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserLegacyExtensionPointsBlocked
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset will permit Google Chrome to apply the additional extension point security mitigation to block legacy extension points in the Browser process. Setting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's browser process. Note: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).
BlockThirdPartyCookies  Block third party cookies
Boolean Machine + User
Leaving it unset allows third-party cookies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
BlockThirdPartyCookies
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting. Leaving it unset allows third-party cookies, but users can change this setting. Note: This policy doesn't apply in Incognito mode, where third-party cookies are blocked and can only be allowed at the site level. To allow cookies at the site level, use the CookiesAllowedForUrls policy.
BrowserLabsEnabled  Browser experiments icon in toolbar
Boolean Machine + User
Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar Setting the policy to Disabled removes the browser experimental features icon from the toolbar.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserLabsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar Setting the policy to Disabled removes the browser experimental features icon from the toolbar. chrome://flags and any other means of turning off and on browser features will still behave as expected regardless of whether this policy is Enabled or Disabled.
BrowserSignin  Browser sign in settings
Enum Machine + User
If this policy is not set then the user can decide if they want to enable browser sign-in in the Google Chrome settings and use it as they see fit.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSignin
Stated default
However, it does not mean that Google Chrome Sync will be turned on by default; the user must separately opt-in to use this feature.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Disable browser sign-in
1Enable browser sign-in
2Force users to sign-in to use the browser
This policy controls the sign-in behavior of the browser. It allows you to specify if the user can sign in to Google Chrome with their account and use account related services like Google Chrome Sync. If the policy is set to "Disable browser sign-in" then the user cannot sign in to the browser and use account-based services. In this case browser-level features like Google Chrome Sync cannot be used and will be unavailable. On iOS, if the user was signed in and the policy is set to "Disabled" they will be signed out immediately. On other platforms, they will be signed out the next time they run Google Chrome. On all platforms, their local profile data like bookmarks, passwords etc. will be preserved and still usable. The user will still be able to sign into and use Google web services like Gmail. If the policy is set to "Enable browser sign-in," then the user is allowed to sign in to the browser. On all platforms except iOS, the user is automatically signed in to the browser when signed in to Google web services like Gmail. Being signed in to the browser means the user's account information will be kept by the browser. However, it does not mean that Google Chrome Sync will be turned on by default; the user must separately opt-in to use this feature. Enabling this policy will prevent the user from turning off the setting that allows browser sign-in. To control the availability of Google Chrome Sync, use the SyncDisabled policy. If the policy is set to "Force browser sign-in" the user is presented with an account selection dialog and has to choose and sign in to an account to use the browser. This ensures that for managed accounts the policies associated with the account are applied and enforced. The default value of BrowserGuestModeEnabled will be set to disabled. Note that existing unsigned profiles will be locked and inaccessible after enabling this policy. For more information, see help center article: https://support.google.com/chrome/?p=force_browser_signin . This option is not supported on Google ChromeOS nor Android, where it will fall back to "Enable browser sign-in" if used. If this policy is not set then the user can decide if they want to enable browser sign-in in the Google Chrome settings and use it as they see fit.
BrowsingDataLifetime  Browsing Data Lifetime Settings
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
BrowsingDataLifetime
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. Warning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data. The available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'. 'download_history' and 'hosted_app_data' are not supported on Android. The browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour. The deletion of expired data will happen 15 seconds after the browser starts then every 30 minutes while the browser is running. The user will stay signed into their Google account when deleting cookies. Until Chrome 114, this policy required the SyncDisabled policy to be set to true. Starting Chrome 115, setting this policy will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled. See https://chromeenterprise.google/policies/?policy=BrowsingDataLifetime for more information about schema and formatting. Example value: [ { "data_types": [ "browsing_history" ], "time_to_live_in_hours": 24 }, { "data_types": [ "password_signin", "autofill" ], "time_to_live_in_hours": 12 } ]
MemorySaverModeSavings  Change Memory Saver Mode Savings
Enum Machine + User
If this policy is unset, the end user can control this setting in chrome://settings/performance.
Registry key
Software\Policies\Google\Chrome
Value name
MemorySaverModeSavings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Moderate memory savings.
1Balanced memory savings.
2Maximum memory savings.
This policy changes the savings level of Memory Saver. This only takes effect when Memory Saver is enabled through settings or through the HighEfficiencyModeEnabled policy, and will affect how heuristics are used to determine when to discard tabs. For example, reducing the lifetime of an inactive tab before discarding it can save memory, but it also means that tabs will be reloaded more frequently which can lead to bad user experience and cost more network traffic. Setting the policy to 0 - Memory Saver will get moderate memory savings. Tabs become inactive after a longer period of time Setting the policy to 1 - Memory Saver will get balanced memory savings. Tabs become inactive after an optimal period of time. Setting the policy to 2 - Memory Saver will get maximum memory savings. Tabs become inactive after a shorter period of time. If this policy is unset, the end user can control this setting in chrome://settings/performance.
ClearBrowsingDataOnExitList  Clear Browsing Data on Exit
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ClearBrowsingDataOnExitList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Configures a list of browsing data types that should be deleted when the user closes all browser windows. Warning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data. The available data types are browsing history (browsing_history), download history (download_history), cookies (cookies_and_other_site_data), cache(cached_images_and_files), autofill (autofill), passwords (password_signin), site settings (site_settings) and hosted apps data (hosted_app_data). This policy does not take precedence over AllowDeletingBrowserHistory. The user will stay signed into their Google account when deleting cookies. Until Chrome 114, this policy required the SyncDisabled policy to be set to true. Starting Chrome 115, setting this policy will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled. If for some reason the data deletion has started and did not complete, the browsing data will be cleared the next time the profile is loaded. If Google Chrome does not exit cleanly (for example, if the browser or the OS crashes), the browsing data will not be cleared since the browser closing was not a result of the use closing all the browser windows. Example value: browsing_history download_history cookies_and_other_site_data cached_images_and_files password_signin autofill site_settings hosted_app_data
WebAppInstallForceList  Configure list of force-installed Web Apps
String Machine + User
If disabled or unset, the web app at the given url will be installed normally.
Registry key
Software\Policies\Google\Chrome
Value name
WebAppInstallForceList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off. Each list item of the policy is an object with a mandatory member: url (the URL of the web app to install) and 6 optional members: - default_launch_container (for how the web app opens—a new tab is the default) - create_desktop_shortcut (True if you want to create Linux and Microsoft® Windows® desktop shortcuts). - fallback_app_name (Starting with Google Chrome version 90, allows you to override the app name if it is not a Progressive Web App (PWA), or the app name that is temporarily installed if it is a PWA but authentication is required before the installation can be completed. If both custom_name and fallback_app_name are provided, the latter will be ignored.) - custom_name (Starting with Google ChromeOS version 99, and version 112 on all other desktop operating systems, allows you to permanently override the app name for all web apps and PWAs.) - custom_icon (Starting with Google ChromeOS version 99, and version 112 on all other desktop operating systems, allows you to override the app icon of installed apps. The icons have to be square, maximal 1 MB in size, and in one of the following formats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256 hash of the icon file. The url should be accessible without authentication to ensure the icon can be used upon app installation.) - install_as_shortcut (Starting with Google Chrome version 107). If enabled the given url will be installed as a shortcut, as if done via the "Create Shortcut..." option in the desktop browser GUI. Note that when installed as a shortcut it won't be updated if the manifest in url changes. If disabled or unset, the web app at the given url will be installed normally. See PinnedLauncherApps for pinning apps to the Google ChromeOS shelf. See https://chromeenterprise.google/policies/?policy=WebAppInstallForceList for more information about schema and formatting. Example value: [ { "create_desktop_shortcut": true, "default_launch_container": "window", "url": "https://www.google.com/maps" }, { "default_launch_container": "tab", "url": "https://docs.google.com" }, { "default_launch_container": "window", "fallback_app_name": "Editor", "url": "https://docs.google.com/editor" }, { "custom_name": "My important document", "default_launch_container": "window", "install_as_shortcut": true, "url": "https://docs.google.com/document/d/ds187akjqih89" }, { "custom_icon": { "hash": "c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38", "url": "https://mydomain.example.com/sunny_icon.png" }, "url": "https://weather.example.com" } ]
BrowserThemeColor  Configure the color of the browser's theme
String Machine + User
Leaving the policy unset lets users change their browser's theme as preferred.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserThemeColor
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows admins to configure the color of Google Chrome's theme. The input string should be a valid hex color string matching the format "#RRGGBB". Setting the policy to a valid hex color causes a theme based on that color to be automatically generated and applied to the browser. Users won't be able to change the theme set by the policy. Leaving the policy unset lets users change their browser's theme as preferred. Example value: #FFFFFF
ForcedLanguages  Configure the content and order of preferred languages
List (values under a subkey) Machine + User
Leaving the policy unset lets users manipulate the entire list of preferred languages.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ForcedLanguages
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows admins to configure the order of the preferred languages in Google Chrome's settings. The order of the list will appear in the same order under the "Order languages based on your preference" section in chrome://settings/languages. Users won't be able to remove or reorder languages set by the policy, but will be able to add languages underneath those set by the policy. Users will also have full control over the browser's UI language and translation/spell check settings, unless enforced by other policies. Leaving the policy unset lets users manipulate the entire list of preferred languages. Example value: en-US
BackgroundModeEnabled  Continue running background apps when Google Chrome is closed
Boolean Machine + User
If unset, background mode is off at first, but users can change it.
Registry key
Software\Policies\Google\Chrome
Value name
BackgroundModeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there. Setting the policy to Disabled turns background mode off. If you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.
ReduceAcceptLanguageEnabled  Control Accept-Language Reduction
Boolean Machine + User
If this policy is set to enabled or left unset, Accept-Language Reduction will be applied through field trials.
Registry key
Software\Policies\Google\Chrome
Value name
ReduceAcceptLanguageEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
The Accept-Language HTTP request header and the JavaScript navigator.languages getter are planned for reduction for privacy reasons. To facilitate testing and ensure compatibility, this policy allows you to enable or disable the Accept-Language Reduction feature. If this policy is set to enabled or left unset, Accept-Language Reduction will be applied through field trials. If this policy is set to disabled, field trials will not be able to activate Accept-Language Reduction. For more information about this feature, please visit: https://github.com/explainers-by-googlers/reduce-accept-language. NOTE: Only newly-started renderer processes will reflect changes to this policy while the browser is running.
SafeSitesFilterBehavior  Control SafeSites adult content filtering.
Enum Machine + User
When this policy is set to: * Do not filter sites for adult content, or not set, sites aren't filtered * Filter sites for adult content, pornographic sites are filtered The policy applies to both the URL the user navigates to and to iframes.
Registry key
Software\Policies\Google\Chrome
Value name
SafeSitesFilterBehavior
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Do not filter sites for adult content
1Filter sites for adult content
Setting the policy controls the SafeSites URL filter, which uses the Google Safe Search API to classify URLs as pornographic or not. When this policy is set to: * Do not filter sites for adult content, or not set, sites aren't filtered * Filter sites for adult content, pornographic sites are filtered The policy applies to both the URL the user navigates to and to iframes. The URLAllowlist policy takes precedence over this policy and can be used to override verdicts from the Google Safe Search API.
XSLTEnabled  Control the availability of the XSLT feature
Boolean Machine + User
If this policy is left unset, XSLT availability will be determined by the browser's default settings and field trials.
Registry key
Software\Policies\Google\Chrome
Value name
XSLTEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the availability of the XSLT feature (the XSLTProcessor Javascript API and the XSL processing instruction). If this policy is set to Enabled, XSLT will be available, regardless of the default state of the feature in the browser. If this policy is set to Disabled, XSLT will be unavailable, regardless of the default state of the feature in the browser. If this policy is left unset, XSLT availability will be determined by the browser's default settings and field trials. This policy is a temporary measure, and will be removed in M164.
IntensiveWakeUpThrottlingEnabled  Control the IntensiveWakeUpThrottling feature.
Boolean Machine + User
If this policy is left unset then the feature will be controlled by its own internal logic, which can be manually configured by users.
Registry key
Software\Policies\Google\Chrome
Value name
IntensiveWakeUpThrottlingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When enabled the IntensiveWakeUpThrottling feature causes JavaScript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more. This is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details. If this policy is set to enabled then the feature will be force enabled, and users will not be able to override this. If this policy is set to disabled then the feature will be force disabled, and users will not be able to override this. If this policy is left unset then the feature will be controlled by its own internal logic, which can be manually configured by users. Note that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.
NTPFooterExtensionAttributionEnabled  Control the visibility of the extension attribution on the New Tab page
Boolean Machine + User
If this policy is left unset or set to true, the extension attribution will be visible on the NTP footer when an extension is controlling the NTP.
Registry key
Software\Policies\Google\Chrome
Value name
NTPFooterExtensionAttributionEnabled
Enabled / Disabled
1 / 0
Stated default
By default, if an extension has overridden the standard NTP, a message attributing this change to the specific extension will appear in the footer.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy determines whether an attribution to the extension modifying the New Tab Page (NTP) is displayed in the NTP's footer. By default, if an extension has overridden the standard NTP, a message attributing this change to the specific extension will appear in the footer. This attribution typically includes a link to the relevant extension in the Chrome Web Store. If this policy is left unset or set to true, the extension attribution will be visible on the NTP footer when an extension is controlling the NTP. If this policy is set to false, the attribution to the extension in the NTP footer will be suppressed.
NTPFooterManagementNoticeEnabled  Control the visibility of the management notice on the New Tab Page for managed browsers
Boolean Machine + User
If this policy is left unset or set to true, managed browsers will display a “Managed by…” notice with an icon.
Registry key
Software\Policies\Google\Chrome
Value name
NTPFooterManagementNoticeEnabled
Enabled / Disabled
1 / 0
Stated default
By default, the NTP footer displays information when the browser is managed by an organization (indicated by a building icon and "Managed by [domain name]").
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the visibility of the management notice within the footer of the New Tab Page (NTP). By default, the NTP footer displays information when the browser is managed by an organization (indicated by a building icon and "Managed by [domain name]"). This can be customized using the EnterpriseCustomLabelForBrowser and EnterpriseLogoUrlForBrowser policies. If this policy is left unset or set to true, managed browsers will display a “Managed by…” notice with an icon. If this policy is set to false, the management notice will be hidden. Note that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
HeadlessMode  Control use of the Headless Mode
Enum Machine + User
Setting this policy to Enabled or leaving the policy unset allows use of the headless mode.
Registry key
Software\Policies\Google\Chrome
Value name
HeadlessMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow use of the Headless Mode
2Do not allow use of the Headless Mode
Setting this policy to Enabled or leaving the policy unset allows use of the headless mode. Setting this policy to Disabled denies use of the headless mode.
DeveloperToolsAvailability  Control where Developer Tools can be used
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DeveloperToolsAvailability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Disallow usage of the Developer Tools on apps and extensions installed by enterprise policy or, since version 114 and if this is a managed user, extensions built into the browser. Allow usage of the Developer Tools in other contexts
1Allow usage of the Developer Tools
2Disallow usage of the Developer Tools
Setting the policy to 0 (the default) means you can access the developer tools and the JavaScript console, but not in the context of extensions installed by enterprise policy or, since version 114 and if this is a managed user, extensions built into the browser. Setting the policy to 1 means you can access the developer tools and the JavaScript console in all contexts, including that of extensions installed by enterprise policy. Setting the policy to 2 means you can't access developer tools, and you can't inspect website elements. This setting also turns off keyboard shortcuts and menu or context menu entries to open developer tools or the JavaScript console. As of Google Chrome version 99, this setting also controls entry points for the 'View page source' feature. If you set this policy to 'DeveloperToolsDisallowed' (value 2), users cannot access source viewing via keyboard shortcut or the context menu. To fully block source viewing, you must also add 'view-source:*' to the URLBlocklist policy. As of Google Chrome version 119, this setting also controls whether developer mode for Isolated Web Apps can be activated and used. As of Google Chrome version 128, this setting will not control developer mode on extensions page if ExtensionDeveloperModeSettings policy is set. The availability of Developer Tools is determined in the following order of precedence: 1. If a URL matches a pattern in the DeveloperToolsAvailabilityAllowlist policy, Developer Tools are allowed. 2. If the DeveloperToolsAvailabilityAllowlist is set and the DeveloperToolsAvailabilityBlocklist is not, any URL not on the allowlist is blocked. 3. If a URL matches a pattern in the DeveloperToolsAvailabilityBlocklist policy, Developer Tools are blocked. 4. If a URL is not covered by the allowlist or blocklist, this policy (DeveloperToolsAvailability) is the fallback.
StaticStorageQuotaEnabled  Control whether storage quota APIs will return static values
Boolean Machine + User
If unset, the storage quota APIs will use the default Chrome behavior.
Registry key
Software\Policies\Google\Chrome
Value name
StaticStorageQuotaEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When enabled, the storage quota APIs will return a static value equal to usage + min(10 GiB, disk rounded up to the nearest 1 GiB). When disabled, the storage quota APIs will generally return a dynamic value proportional to the total space available on the device, regardless of usage. If unset, the storage quota APIs will use the default Chrome behavior. Sites with unlimited storage permissions are unaffected by this setting. Enforced quota is also unaffected.
DnsOverHttpsMode  Controls the mode of DNS-over-HTTPS
Enum Machine + User
If this policy is unset, for managed devices DNS-over-HTTPS queries will not be sent.
Registry key
Software\Policies\Google\Chrome
Value name
DnsOverHttpsMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Disable DNS-over-HTTPS
Enable DNS-over-HTTPS with insecure fallback
Enable DNS-over-HTTPS without insecure fallback
Controls the mode of the DNS-over-HTTPS resolver. Please note that this policy will only set the default mode for each query. The mode may be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname. The "off" mode will disable DNS-over-HTTPS. The "automatic" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error. The "secure" mode will only send DNS-over-HTTPS queries and will fail to resolve on error. On Android Pie and above, if DNS-over-TLS is active, Google Chrome will not send insecure DNS requests. If this policy is unset, for managed devices DNS-over-HTTPS queries will not be sent. Otherwise, the browser may send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver. Example value: off
EnterpriseProfileBadgeToolbarSettings  Controls visibility of enterprise profile badge in the toolbar
Enum Machine + User
Leaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseProfileBadgeToolbarSettings
Stated default
For work and school profiles, the toolbar will show a "Work" or "School" label by default next to the toolbar avatar.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Show expanded enterprise toolbar badge
1Hide expanded enterprise toolbar badge
For work and school profiles, the toolbar will show a "Work" or "School" label by default next to the toolbar avatar. The label will only be shown if the signed in account is managed. Setting this policy to hide_expanded_enterprise_toolbar_badge (value 1) will hide the enterprise badge for a managed profile in the toolbar. Leaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge. The label is customizable via the EnterpriseCustomLabel policy.
ForcePermissionPolicyUnloadDefaultEnabled  Controls whether unload event handlers can be disabled.
Boolean Machine + User
If this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events.
Registry key
Software\Policies\Google\Chrome
Value name
ForcePermissionPolicyUnloadDefaultEnabled
Enabled / Disabled
1 / 0
Stated default
Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to remain as enabled. Pages may depend on unload event handlers to save data or signal the end of a user session to the server. This is not recommended as it is unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, however the unload event has been used for a long time. Some applications may still rely on them. If this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events. If this policy is set to true then unload event handlers will continue to work by default. NOTE: This policy had an incorrectly documented default of `true` in M117. The unload event did and will not change in M117, so this policy has no effect in that version.
CORSNonWildcardRequestHeadersSupport  CORS non-wildcard request headers support
Boolean Machine + User
If this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above.
Registry key
Software\Policies\Google\Chrome
Value name
CORSNonWildcardRequestHeadersSupport
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Configures support of CORS non-wildcard request headers. Google Chrome version 97 introduces support for CORS non-wildcard request headers. When scripts make a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. "Explicitly" here means that the wild card symbol "*" doesn't cover the Authorization header. See https://chromestatus.com/feature/5742041264816128 for more detail. If this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above. When this policy is set to False, chrome will allow the wildcard symbol ("*") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header. This Enterprise policy is temporary; it's intended to be removed in the future.
AutoLaunchProtocolsFromOrigins  Define a list of protocols that can launch an external application from listed origins without prompting the user
String Machine + User
If this policy is not set, no protocols can launch without a prompt by default.
Registry key
Software\Policies\Google\Chrome
Value name
AutoLaunchProtocolsFromOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol, so list "skype" instead of "skype:" or "skype://". If this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false the external protocol launch prompt will not be omitted by policy. If this policy is not set, no protocols can launch without a prompt by default. Users may opt out of prompts on a per-protocol/per-site basis unless the ExternalProtocolDialogShowAlwaysOpenCheckbox policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users. The origin matching patterns use a similar format to those for the 'URLBlocklist' policy, which are documented at https://support.google.com/chrome/a?p=url_blocklist_filter_format. However, origin matching patterns for this policy cannot contain "/path" or "@query" elements. Any pattern that does contain a "/path" or "@query" element will be ignored. See https://chromeenterprise.google/policies/?policy=AutoLaunchProtocolsFromOrigins for more information about schema and formatting. Example value: [ { "allowed_origins": [ "example.com", "http://www.example.com:8080" ], "protocol": "spotify" }, { "allowed_origins": [ "https://example.com", "https://.mail.example.com" ], "protocol": "teams" }, { "allowed_origins": [ "*" ], "protocol": "outlook" } ]
AllowedDomainsForApps  Define domains allowed to access Google Workspace
String Machine + User
Leaving this setting empty or unset means users can access Google Workspace with any account.
Registry key
Software\Policies\Google\Chrome
Value name
AllowedDomainsForApps
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy turns on Chrome's restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains (to allow gmail or googlemail accounts, add consumer_accounts to the list of domains). This setting prevents users from signing in and adding a Secondary Account on a managed device that requires Google authentication, if that account doesn't belong to one of the explicitly allowed domains. Leaving this setting empty or unset means users can access Google Workspace with any account. Users cannot change or override this setting. Note: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://support.google.com/a/answer/1668854. Example value: managedchrome.com,example.com
ChromeVariations  Determine the availability of variations
Enum Machine + User
Setting the VariationsEnabled (value 0), or leaving the policy not set allows all variations to be applied to the browser.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeVariations
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Enable all variations
1Enable variations concerning critical fixes only
2Disable all variations
Configuring this policy allows to specify which variations are allowed to be applied in Google Chrome. Variations provide a means for offering modifications to Google Chrome without shipping a new version of the browser by selectively enabling or disabling already existing features. See https://support.google.com/chrome/a?p=Manage_the_Chrome_variations_framework for more information. Setting the VariationsEnabled (value 0), or leaving the policy not set allows all variations to be applied to the browser. Setting the CriticalFixesOnly (value 1), allows only variations considered critical security or stability fixes to be applied to Google Chrome. Setting the VariationsDisabled (value 2), prevent all variations from being applied to the browser. Please note that this mode can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.
CertificateTransparencyEnforcementDisabledForCas  Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes
List (values under a subkey) Machine + User
Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CertificateTransparencyEnforcementDisabledForCas
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of subjectPublicKeyInfo hashes. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the hash must meet one of these conditions: * It's of the server certificate's subjectPublicKeyInfo. * It's of a subjectPublicKeyInfo that appears in a Certificate Authority (CA) certificate in the certificate chain. That CA certificate is constrained through the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName has an organizationName attribute. * It's of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate has the same number of organizationName attributes, in the same order, and with byte-for-byte identical values. Specify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored. Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates. Example value: sha256/AAAAAAAAAAAAAAAAAAAAAA== sha256//////////////////////w==
CertificateTransparencyEnforcementDisabledForUrls  Disable Certificate Transparency enforcement for a list of URLs
List (values under a subkey) Machine + User
Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CertificateTransparencyEnforcementDisabledForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy turns off Certificate Transparency disclosure requirements for the hostnames in the specified URLs. While making it harder to detect misissued certificates, hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). Leaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates. A URL pattern follows this format ( https://support.google.com/chrome/a?p=url_blocklist_filter_format ). However, because the validity of certificates for a given hostname is independent of the scheme, port, or path, Google Chrome only considers the hostname portion of the URL. Wildcard hosts aren't supported. Example value: example.com .example.com
ExemptDomainFileTypePairsFromFileTypeDownloadWarnings  Disable download file type extension-based warnings for specified file types on domains
String Machine + User
If you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.
Registry key
Software\Policies\Google\Chrome
Value name
ExemptDomainFileTypePairsFromFileTypeDownloadWarnings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the "jnlp" extension is associated with "website1.com", users would not see a warning when downloading "jnlp" files from "website1.com", but see a download warning when downloading "jnlp" files from "website2.com". Files with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Safe Browsing warnings. If you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user. If you enable this policy: * The URL pattern should be formatted according to https://chromeenterprise.google/policies/url-patterns/. * The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list "jnlp" should be used instead of ".jnlp". Example: The following example value would prevent file type extension-based download warnings on "exe" and "jnlp" extensions for *.example.com domains, and on "swf" extensions for all domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files. [ { "file_extension": "jnlp", "domains": ["example.com"] }, { "file_extension": "exe", "domains": ["example.com"] }, { "file_extension": "swf", "domains": ["*"] } ] Note that while the preceding example shows the suppression of file type extension-based download warnings for "swf" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so. If this policy is enabled alongside DownloadRestrictions, then the exemptions to file type extension-based warnings specified by this policy take precedence over a DownloadRestrictions setting that would block dangerous file types. The exemptions specified by this policy only apply to the "block dangerous file types" behavior specified by values 1 and 2 of DownloadRestrictions. For example, if this policy specifies an exemption for "exe" downloads from "website1.com", and DownloadRestrictions is set to block malicious downloads and dangerous file types (value 1), then "exe" downloads from "website1.com" will be exempt from file type extension-based blocking but will still be blocked if they are malicious. More information about DownloadRestrictions can be found at https://chromeenterprise.google/policies/?policy=DownloadRestrictions. See https://chromeenterprise.google/policies/?policy=ExemptDomainFileTypePairsFromFileTypeDownloadWarnings for more information about schema and formatting. Example value: [ { "domains": [ "https://example.com", "example2.com" ], "file_extension": "jnlp" }, { "domains": [ "*" ], "file_extension": "swf" } ]
SavingBrowserHistoryDisabled  Disable saving browser history
Boolean Machine + User
Setting the policy to Disabled or leaving it unset saves browsing history.
Registry key
Software\Policies\Google\Chrome
Value name
SavingBrowserHistoryDisabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means browsing history is not saved, tab syncing is off and users can't change this setting. Setting the policy to Disabled or leaving it unset saves browsing history.
Disable3DAPIs  Disable support for 3D graphics APIs
Boolean Machine + User
Setting the policy to False or leaving it unset lets webpages use the WebGL API, but the browser's default settings might still require command line arguments to use these APIs.
Registry key
Software\Policies\Google\Chrome
Value name
Disable3DAPIs
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True (or setting HardwareAccelerationModeEnabled to False) prevents webpages from accessing the WebGL API. Setting the policy to False or leaving it unset lets webpages use the WebGL API, but the browser's default settings might still require command line arguments to use these APIs.
SyncDisabled  Disable synchronization of data with Google
Boolean Machine + User
If the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync.
Registry key
Software\Policies\Google\Chrome
Value name
SyncDisabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns off data synchronization in Google Chrome using Google-hosted synchronization services. To fully turn off Chrome Sync services, we recommend that you turn off the service in the Google Admin console. If the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync. Note: Do not turn on this policy when RoamingProfileSupportEnabled is Enabled, because that feature shares the same client-side functionality. The Google-hosted synchronization is off completely in this case.
DisableScreenshots  Disable taking screenshots
Boolean Machine + User
Setting the policy to Disabled or not set allows screenshots.
Registry key
Software\Policies\Google\Chrome
Value name
DisableScreenshots
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled disallows screenshots taken with keyboard shortcuts or extension APIs. Setting the policy to Disabled or not set allows screenshots. Note that on Microsoft® Windows®, macOS and Linux, this does not prevent screenshots that are taken with operating system or third party applications.
DNSInterceptionChecksEnabled  DNS interception checks enabled
Boolean Machine + User
When this policy is not set, or is enabled, the DNS interception checks are performed.
Registry key
Software\Policies\Google\Chrome
Value name
DNSInterceptionChecksEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy configures a local switch that can be used to disable DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names. This detection may not be necessary in an enterprise environment where the network configuration is known, since it causes some amount of DNS and HTTP traffic on start-up and each DNS configuration change. When this policy is not set, or is enabled, the DNS interception checks are performed. When explicitly disabled, they're not.
DynamicCodeSettings  Dynamic Code Settings
Enum Machine + User
If the policy is set to 0 - Default or left unset then Google Chrome will use the default settings.
Registry key
Software\Policies\Google\Chrome
Value name
DynamicCodeSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Default dynamic code settings
1Prevent the browser process from creating dynamic code
This policy controls the dynamic code settings for Google Chrome. Disabling dynamic code improves the security of Google Chrome by preventing potentially hostile dynamic code and third-party code from making changes to Google Chrome's behavior, but might cause compatibility issues with third-party software (e.g. certain printer drivers) that must run inside the browser process. If the policy is set to 0 - Default or left unset then Google Chrome will use the default settings. If the policy is set to 1 - DisabledForBrowser then the Google Chrome browser process will be prevented from creating dynamic code. Note: Read more about process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).
WebAudioOutputBufferingEnabled  Enable adaptive buffering for Web Audio
Boolean Machine + User
Setting the policy to Disabled or not set will allow the browser feature launch process to decide if adaptive buffering is used.
Registry key
Software\Policies\Google\Chrome
Value name
WebAudioOutputBufferingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether the browser uses adaptive buffering for Web Audio, which may decrease audio glitches but may increase latency by a variable amount. Setting the policy to Enabled will always use adaptive buffering. Setting the policy to Disabled or not set will allow the browser feature launch process to decide if adaptive buffering is used.
BrowserAddPersonEnabled  Enable add person in user manager
Boolean Machine + User
If this policy is set to true or not configured, Google Chrome and Lacros will allow to add a new person from the user manager.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserAddPersonEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is set to true or not configured, Google Chrome and Lacros will allow to add a new person from the user manager. If this policy is set to false, Google Chrome and Lacros will not allow adding a new person from the user manager.
AdvancedProtectionAllowed  Enable additional protections for users enrolled in the Advanced Protection program
Boolean Machine + User
If set to True or not set, enrolled users will receive extra protections.
Registry key
Software\Policies\Google\Chrome
Value name
AdvancedProtectionAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether users enrolled in the Advanced Protection program receive extra protections. Some of these features may involve the sharing of data with Google (for example, Advanced Protection users will be able to send their downloads to Google for malware scanning). If set to True or not set, enrolled users will receive extra protections. If set to False, Advanced Protection users will receive only the standard consumer features.
AlternateErrorPagesEnabled  Enable alternate error pages
Boolean Machine + User
If not set, the policy is on, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
AlternateErrorPagesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True means Google Chrome uses alternate error pages built into (such as "page not found"). Setting the policy to False means Google Chrome never uses alternate error pages. If you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.
AmbientAuthenticationInPrivateModesEnabled  Enable Ambient Authentication for profile types.
Enum Machine + User
In Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.
Registry key
Software\Policies\Google\Chrome
Value name
AmbientAuthenticationInPrivateModesEnabled
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Enable ambient authentication in regular sessions only.
1Enable ambient authentication in incognito and regular sessions.
2Enable ambient authentication in guest and regular sessions.
3Enable ambient authentication in regular, incognito and guest sessions.
Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome. Ambient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes. Setting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate. Setting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate. Setting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate. Setting the All (value 3), allows ambient authentication for all sessions. Note that, ambient authentication is always allowed on regular profiles. In Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.
ApplicationBoundEncryptionEnabled  Enable Application Bound Encryption
Boolean Machine + User
Setting the policy to Enabled or leaving it unset binds encryption keys used for local data storage to Google Chrome whenever that is possible.
Registry key
Software\Policies\Google\Chrome
Value name
ApplicationBoundEncryptionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset binds encryption keys used for local data storage to Google Chrome whenever that is possible. Setting the policy to Disabled has a detrimental effect on Google Chrome's security as unknown and potentially hostile apps can retrieve encryption keys used to secure data. Only turn off the policy if there are compatibility issues, such as other applications that need legitimate access to Google Chrome's data, encrypted user data is expected to be fully portable between different computers or the integrity and location of Google Chrome's executable files is not consistent.
AutofillAddressEnabled  Enable AutoFill for addresses
Boolean Machine + User
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.
Registry key
Software\Policies\Google\Chrome
Value name
AutofillAddressEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI. Setting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.
AutofillCreditCardEnabled  Enable AutoFill for credit cards
Boolean Machine + User
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.
Registry key
Software\Policies\Google\Chrome
Value name
AutofillCreditCardEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI. Setting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.
HttpsUpgradesEnabled  Enable automatic HTTPS upgrades
Boolean Machine + User
If set to "true" or left unset, this feature will be enabled by default.
Registry key
Software\Policies\Google\Chrome
Value name
HttpsUpgradesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Google Chrome attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to "true" or left unset, this feature will be enabled by default. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. See also the HttpsOnlyMode policy.
BatterySaverModeAvailability  Enable Battery Saver Mode
Enum Machine + User
If this policy is unset, the end user can control this setting in chrome://settings/performance.
Registry key
Software\Policies\Google\Chrome
Value name
BatterySaverModeAvailability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Battery Saver Mode will be disabled.
1Battery Saver Mode will be enabled when the device is on battery power and battery level is low.
2This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.
This policy enables or disables the Battery Saver Mode setting. On Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance. On ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off. The different levels are: Disabled (0): Battery Saver Mode will be disabled. EnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low. EnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.
BookmarkBarEnabled  Enable Bookmark Bar
Boolean Machine + User
If not set, users decide whether to use this function.
Registry key
Software\Policies\Google\Chrome
Value name
BookmarkBarEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar. If you set the policy, users can't change it. If not set, users decide whether to use this function.
ComponentUpdatesEnabled  Enable component updates in Google Chrome
Boolean Machine + User
Enables component updates for all components in Google Chrome when not set or set to enabled.
Registry key
Software\Policies\Google\Chrome
Value name
ComponentUpdatesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enables component updates for all components in Google Chrome when not set or set to enabled. If set to disabled, updates to components are disabled. However, some components are exempt from this policy: updates to any component that does not contain executable code and is critical for the security of the browser will not be disabled. Examples of such components include the certificate revocation lists and subresource filters.
AllowDeletingBrowserHistory  Enable deleting browser and download history
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
AllowDeletingBrowserHistory
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting. Setting the policy to Disabled means browser history and download history can't be deleted. Even with this policy off, the browsing and download history are not guaranteed to be retained. Users may be able to edit or delete the history database files directly, and the browser itself may expire or archive any or all history items at any time.
DesktopSharingHubEnabled  Enable desktop sharing in the omnibox and 3-dot menu
Boolean Machine + User
Setting the policy to True or leaving it unset lets users share or save the current webpage using actions provided by the desktop sharing hub.
Registry key
Software\Policies\Google\Chrome
Value name
DesktopSharingHubEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset lets users share or save the current webpage using actions provided by the desktop sharing hub. The sharing hub is accessed through either an omnibox icon or the 3-dot menu. Setting the policy to False removes the sharing icon from the omnibox and the entry from the 3-dot menu.
TaskManagerEndProcessEnabled  Enable ending processes in Task Manager
Boolean Machine + User
Setting the policy to Enabled or leaving it unset lets users end processes in the Task Manager.
Registry key
Software\Policies\Google\Chrome
Value name
TaskManagerEndProcessEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Disabled prevents users from ending processes in the Task Manager. Setting the policy to Enabled or leaving it unset lets users end processes in the Task Manager.
SharedWorkerExtendedLifetimeEnabled  Enable extended lifetime for SharedWorkers
Boolean Machine + User
If this policy is set to Enabled or left unset, SharedWorkers can have an extended lifetime.
Registry key
Software\Policies\Google\Chrome
Value name
SharedWorkerExtendedLifetimeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
SharedWorkers can have an extended lifetime if the "extendedLifetime" option is set to true in the SharedWorker constructor. If this policy is set to Enabled or left unset, SharedWorkers can have an extended lifetime. If this policy is set to Disabled, SharedWorkers cannot have an extended lifetime, even if the option is set to true. This policy is intended to be temporary and will be removed in the future.
AccessibilityImageLabelsEnabled  Enable Get Image Descriptions from Google.
Boolean Machine + User
If this policy is not set, user can choose to use this feature or not.
Registry key
Software\Policies\Google\Chrome
Value name
AccessibilityImageLabelsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
The Get Image Descriptions from Google accessibility feature enables visually-impaired screen reader users to get descriptions of unlabeled images on the web. Users who choose to enable it will have the option of using an anonymous Google service to provide automatic descriptions for unlabeled images they encounter on the web. If this feature is enabled, the content of images will be sent to Google servers in order to generate a description. No cookies or other user data is sent, and Google does not save or log any image content. If this policy is set to Enabled, the Get Image Descriptions from Google feature will be enabled, though it will only affect users who are using a screen reader or other similar assistive technology. If this policy is set to Disabled, users will not have the option of enabling the feature. If this policy is not set, user can choose to use this feature or not.
GloballyScopeHTTPAuthCacheEnabled  Enable globally scoped HTTP auth cache
Boolean Machine + User
If this policy is unset or disabled, the browser will use the default behavior of cross-site auth, this behavior will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites.
Registry key
Software\Policies\Google\Chrome
Value name
GloballyScopeHTTPAuthCacheEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy configures a single global per profile cache with HTTP server authentication credentials. If this policy is unset or disabled, the browser will use the default behavior of cross-site auth, this behavior will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites. If the policy is enabled, HTTP auth credentials entered in the context of one site will automatically be used in the context of another. Enabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs. This policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures, and will be removed in the future.
DevToolsGoogleDeveloperProgramProfileAvailability  Enable Google Developer Program Profiles in Chrome DevTools
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DevToolsGoogleDeveloperProgramProfileAvailability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Enable Google Developer Program integration in Chrome DevTools.
1Enable Google Developer Program integration in Chrome DevTools, but without sharing tool usage (for awarding badges).
2Do not enable Google Developer Program integration in Chrome DevTools.
This policy controls the integration of the Google Developer Program with Chrome DevTools. The user's Google Developer Program profile is shown in Chrome DevTools, and users receive badges for performing specific actions within Chrome DevTools. Setting the policy to 0 - 'Enabled', or not setting any policy value, allows the integration of the Google Developer Program with Chrome DevTools, and allows sharing of Chrome DevTools tool usage in order to be able to award badges. Setting the policy to 1 - 'Enabled without badges', allows the integration of the Google Developer Program with Chrome DevTools, but does not allow sharing Chrome DevTools tool usage with the Google Developer Program. No badges will be awarded. Setting the policy to 2 - 'Disabled', does not allow the integration of the Google Developer Program with Chrome DevTools.
GoogleSearchSidePanelEnabled  Enable Google Search Side Panel
Boolean Machine + User
If set to Enabled or not set, Google Search Side Panel is allowed on all web pages.
Registry key
Software\Policies\Google\Chrome
Value name
GoogleSearchSidePanelEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If set to Enabled or not set, Google Search Side Panel is allowed on all web pages. If set to Disabled, Google Search Side Panel is not available on any webpage. GenAI capabilities that are part of this feature are not available for Educational or Enterprise accounts.
BrowserGuestModeEnabled  Enable guest mode in browser
Boolean Machine + User
If this policy is set to Enabled or not configured, Google Chrome will enable guest logins.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserGuestModeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is set to Enabled or not configured, Google Chrome will enable guest logins. Guest logins are Google Chrome profiles where all windows are in incognito mode. If this policy is set to Disabled, Google Chrome will not allow guest profiles to be started.
HighEfficiencyModeEnabled  Enable High Efficiency Mode
Boolean Machine + User
If this policy is unset, the end user can control this setting in chrome://settings/performance.
Registry key
Software\Policies\Google\Chrome
Value name
HighEfficiencyModeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy enables or disables the High Efficiency Mode setting. This setting makes it so that tabs are discarded after some period of time in the background to reclaim memory. If this policy is unset, the end user can control this setting in chrome://settings/performance.
CloudManagementEnrollmentMandatory  Enable mandatory cloud management enrollment
Boolean Machine + User
Setting the policy to Disabled or leaving it unset renders Chrome Enterprise Core browser enrollment optional and doesn't block Google Chrome launch process if failed.
Registry key
Software\Policies\Google\Chrome
Value name
CloudManagementEnrollmentMandatory
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled mandates Chrome Enterprise Core browser enrollment and blocks Google Chrome launch process if failed. Setting the policy to Disabled or leaving it unset renders Chrome Enterprise Core browser enrollment optional and doesn't block Google Chrome launch process if failed. Machine scope cloud policy enrollment on desktop uses this policy. See https://support.google.com/chrome/a/answer/9301891 for details.
MediaRecommendationsEnabled  Enable Media Recommendations
Boolean Machine + User
Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.
Registry key
Software\Policies\Google\Chrome
Value name
MediaRecommendationsEnabled
Enabled / Disabled
1 / 0
Stated default
By default the browser will show media recommendations that are personalized to the user.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.
NetworkPredictionOptions  Enable network prediction
Enum Machine + User
Leaving it unset turns on network prediction, but the user can change it.
Registry key
Software\Policies\Google\Chrome
Value name
NetworkPredictionOptions
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Predict network actions on any network connection
1Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)
2Do not predict network actions on any network connection
This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages. If you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.
EnableOnlineRevocationChecks  Enable online OCSP/CRL checks
Boolean Machine + User
Setting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later.
Registry key
Software\Policies\Google\Chrome
Value name
EnableOnlineRevocationChecks
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True means online OCSP/CRL checks are performed. Setting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later. Note: OCSP/CRL checks provide no effective security benefit.
DataUrlInWebWorkerOpaqueOriginEnabled  Enable opaque origins for data URLs in Web Workers
Boolean Machine + User
If this policy is set to Enabled or left unset, the new default (more secure) behavior is used, and Web Workers created from data URLs will have a unique opaque origin.
Registry key
Software\Policies\Google\Chrome
Value name
DataUrlInWebWorkerOpaqueOriginEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls whether Web Workers created from data URLs are assigned a unique opaque origin. Web Workers can be created using a data URL containing the worker's script. Previously, these workers inherited the origin of the page that created them, allowing them to access the same local storage, cookies, and other origin-bound data. To improve security and align with the HTML specification, Chrome is changing its default behavior in milestone 149 so that workers created from data URLs will now have a unique, opaque origin. This isolates them from the creator page's data. If this policy is set to Enabled or left unset, the new default (more secure) behavior is used, and Web Workers created from data URLs will have a unique opaque origin. If this policy is set to Disabled, Chrome reverts to the legacy behavior, and Web Workers created from data URLs will inherit the origin of their creator. This allows administrators to temporarily resolve compatibility issues if internal applications break due to the security change. This policy is intended to be temporary and will be removed in milestone 157.
EditBookmarksEnabled  Enable or disable bookmark editing
Boolean Machine + User
Setting the policy to True or leaving it unset lets users add, remove, modify, or upload bookmarks.
Registry key
Software\Policies\Google\Chrome
Value name
EditBookmarksEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset lets users add, remove, modify, or upload bookmarks. Setting the policy to False means users can't add, remove, modify or upload bookmarks. They can still use existing bookmarks.
SpellCheckServiceEnabled  Enable or disable spell checking web service
Boolean Machine + User
Leaving the policy unset lets users choose whether to use the spellcheck service.
Registry key
Software\Policies\Google\Chrome
Value name
SpellCheckServiceEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used. Leaving the policy unset lets users choose whether to use the spellcheck service. The spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.
PdfAnnotationsEnabled  Enable PDF Annotations
Boolean Machine + User
When this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs.
Registry key
Software\Policies\Google\Chrome
Value name
PdfAnnotationsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls if the PDF viewer in Google Chrome can annotate PDFs. When this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs. When this policy is set to false, then the PDF viewer will not be able to annotate PDFs.
ProcessIsolationEnabled  Enable Process Isolation
Boolean Machine + User
If this policy is unset, Google Chrome will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users.
Registry key
Software\Policies\Google\Chrome
Value name
ProcessIsolationEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the Process Isolation settings for Google Chrome. Enabling Process Isolation improves the security of Google Chrome by preventing authorized applications on the system from tampering with or reading the contents of Google Chrome's running processes. This helps prevent other applications on the system from gaining access to Google Chrome's encrypted data. Enabling Process Isolation may cause incompatibilities with third party applications that rely on being able to inject or tamper with Google Chrome's processes, such as antivirus, screen reader or window manager applications. Setting the policy to Enabled turns on process isolation in Google Chrome. Setting the policy to Disabled turns off process isolation in Google Chrome. If this policy is unset, Google Chrome will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users. Note: This policy is applied when Google Chrome starts. If the policy is changed while Google Chrome is running, the new setting will take effect on the next restart.
QRCodeGeneratorEnabled  Enable QR Code Generator
Boolean Machine + User
If you enable this policy or don't configure it, the QR Code Generator feature is enabled.
Registry key
Software\Policies\Google\Chrome
Value name
QRCodeGeneratorEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy enables the QR Code generator feature in Google Chrome. If you enable this policy or don't configure it, the QR Code Generator feature is enabled. If you disable this policy, the QR Code Generator feature is disabled.
RendererAppContainerEnabled  Enable Renderer App Container
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Renderer App Container configuration will be enabled on supported platforms.
Registry key
Software\Policies\Google\Chrome
Value name
RendererAppContainerEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means Renderer App Container configuration will be enabled on supported platforms. Setting the policy to Disabled has a detrimental effect on the security and stability of Google Chrome as it will weaken the sandbox that renderer processes use. Only turn off the policy if there are compatibility issues with third-party software that must run inside renderer processes. Note: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).
MetricsReportingEnabled  Enable reporting of usage and crash-related data
Boolean Machine + User
When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later.
Registry key
Software\Policies\Google\Chrome
Value name
MetricsReportingEnabled
Enabled / Disabled
1 / 0
Stated default
When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default. Users will still be able to change this setting. When this policy is Disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting. When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later. (For Google ChromeOS, see DeviceMetricsReportingEnabled.) On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
SafeBrowsingForTrustedSourcesEnabled  Enable Safe Browsing for trusted sources
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingForTrustedSourcesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source. Setting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source. These restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.
ScrollToTextFragmentEnabled  Enable scrolling to text specified in URL fragments
Boolean Machine + User
If you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.
Registry key
Software\Policies\Google\Chrome
Value name
ScrollToTextFragmentEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete. If you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled. If you disable this policy, web page scrolling to specific text fragments via URL will be disabled.
SearchSuggestEnabled  Enable search suggestions
Boolean Machine + User
If not set, search suggestions are on at first, but users can turn them off any time.
Registry key
Software\Policies\Google\Chrome
Value name
SearchSuggestEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions. Suggestions based on bookmarks or history are unaffected by the policy. If you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.
CommandLineFlagSecurityWarningsEnabled  Enable security warnings for command-line flags
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means security warnings appear when potentially dangerous command-line flags are used to launch Chrome.
Registry key
Software\Policies\Google\Chrome
Value name
CommandLineFlagSecurityWarningsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means security warnings appear when potentially dangerous command-line flags are used to launch Chrome. Setting the policy to Disabled prevents security warnings from appearing when Chrome is launched with potentially dangerous command-line flags. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
PromotionsEnabled  Enable showing promotional content
Boolean Machine + User
Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content.
Registry key
Software\Policies\Google\Chrome
Value name
PromotionsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content. Setting the policy to False prevents Google Chrome from showing product promotional content. Setting the policy controls the presentation of promotional content, including the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.
SignedHTTPExchangeEnabled  Enable Signed HTTP Exchange (SXG) support
Boolean Machine + User
Setting the policy to True or leaving it unset means Google Chrome will accept web contents served as Signed HTTP Exchanges.
Registry key
Software\Policies\Google\Chrome
Value name
SignedHTTPExchangeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset means Google Chrome will accept web contents served as Signed HTTP Exchanges. Setting the policy to False prevents Signed HTTP Exchanges from loading.
SigninInterceptionEnabled  Enable signin interception
Boolean Machine + User
When this policy not set or is enabled, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile.
Registry key
Software\Policies\Google\Chrome
Value name
SigninInterceptionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This settings enables or disables signin interception. When this policy not set or is enabled, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile. When this is disabled, the signin interception dialog does not trigger. When this is disabled, a dialog will still be shown if managed account profile separation is enforced by ManagedAccountsSigninRestriction.
SilentPrintingEnabled  Enable Silent Printing
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SilentPrintingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting this policy to true enables silent printing, which immediately closes print preview window when opened and prints to the default printer with default options. If the default printer is 'Save as PDF', the file will be saved to the Downloads folder. Not setting this policy or setting this policy to false disables silent printing, which doesn't automatically close print preview window and requires the user to make a selection as usual.
IsolateOrigins  Enable Site Isolation for specified origins
String Machine + User
Setting the policy to an empty string or leaving it unset means site isolation won't be required for any specific origins.
Registry key
Software\Policies\Google\Chrome
Value name
IsolateOrigins
Stated default
com) are already isolated by default on Desktop platforms, as noted in the SitePerProcess policy. Note that Android isolates certain sensitive sites by default starting in Google Chrome version 77, and this policy extends that mode to isolate specific additional origins.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Specify a list of origins that run in a dedicated process. On Android, this policy only works on devices with sufficient memory (strictly more than 3.2GB RAM), as isolating too many sites on resource-constrained devices may cause performance problems. For resource-constrained Android devices, please use IsolateOriginsShortlist instead. Devices with less than 1GB memory are not recommended to configure any process isolation specifically. Each named origin's process will only be allowed to contain documents from that origin and its subdomains. For example, specifying https://a1.example.com/ allows https://a2.a1.example.com/ in the same process, but not https://example.com or https://b.example.com. Since Google Chrome 77, you can also specify a range of origins to isolate using a wildcard. For example, specifying https://[*.]corp.example.com will give every origin underneath https://corp.example.com its own dedicated process, including https://corp.example.com itself, https://a1.corp.example.com, and https://a2.a1.corp.example.com. Note that all sites (i.e., scheme plus eTLD+1, such as https://example.com) are already isolated by default on Desktop platforms, as noted in the SitePerProcess policy. This IsolateOrigins policy is useful to isolate specific origins at a finer granularity (e.g., https://a.example.com). Note that Android isolates certain sensitive sites by default starting in Google Chrome version 77, and this policy extends that mode to isolate specific additional origins. Also note that origins isolated by this policy will be unable to script other origins in the same site, which is otherwise possible if two same-site documents modify their document.domain values to match. Administrators should confirm this uncommon behavior is not used on an origin before isolating it. Setting the policy to an empty string or leaving it unset means site isolation won't be required for any specific origins. Users can still turn on process isolation manually, through the command line flag. Example value: https://a.example.com/,https://othersite.org/,https://[*.]corp.example.com
SpellcheckEnabled  Enable spellcheck
Boolean Machine + User
Leaving the policy unset lets users turn spellcheck on or off in the language settings.
Registry key
Software\Policies\Google\Chrome
Value name
SpellcheckEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns spellcheck on, and users can't turn it off. On Microsoft® Windows®, Google ChromeOS and Linux®, spellcheck languages can be switched on or off individually, so users can still turn spellcheck off by switching off every spellcheck language. To avoid that, use the SpellcheckLanguage to force-enable specific spellcheck languages. Setting the policy to Disabled turns off spellcheck from all sources, and users can't turn it on. The SpellCheckServiceEnabled, SpellcheckLanguage and SpellcheckLanguageBlocklist policies have no effect when this policy is set to False. Leaving the policy unset lets users turn spellcheck on or off in the language settings.
StandardizedBrowserZoomEnabled  Enable Standardized Browser Zoom Behavior
Boolean Machine + User
When this policy is Enabled or unset, the CSS "zoom" property will adhere to the specification: https://drafts.
Registry key
Software\Policies\Google\Chrome
Value name
StandardizedBrowserZoomEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy enables conformance to the newly-adopted specification of CSS zoom. When this policy is Enabled or unset, the CSS "zoom" property will adhere to the specification: https://drafts.csswg.org/css-viewport/#zoom-property When Disabled, the CSS "zoom" property will fall back to its legacy pre-standardized behavior. This policy is a temporary reprieve to allow time to migrate web content to the new behavior. There is also an origin trial ("DisableStandardizedBrowserZoom") that corresponds to the behavior when this policy is Disabled. This policy will be removed and the "Enabled" behavior made permanent in milestone 134.
StrictMimetypeCheckForWorkerScriptsEnabled  Enable strict MIME type checking for worker scripts
Boolean Machine + User
When enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour.
Registry key
Software\Policies\Google\Chrome
Value name
StrictMimetypeCheckForWorkerScriptsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy enables strict MIME type checking for worker scripts. When enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour. Worker scripts with legacy MIME types will be rejected. When disabled, then worker scripts will use lax MIME type checking, so that worker scripts with legacy MIME types, e.g. text/ascii, will continue to be loaded and executed. Browsers traditionally used lax MIME type checking, so that resources with a number of legacy MIME types were supported. E.g. for JavaScript resources, text/ascii is a legacy supported MIME type. This may cause security issues, by allowing to load resources as scripts that were never intended to be used as such. Chrome will transition to use strict MIME type checking in the near future. The enabled policy will track the default behaviour. Disabling this policy allows administrators to retain the legacy behaviour, if desired. See https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage for details about JavaScript / ECMAScript media types.
ClickToCallEnabled  Enable the Click to Call Feature
Boolean Machine + User
If this policy is left unset, the Click to Call feature is enabled by default.
Registry key
Software\Policies\Google\Chrome
Value name
ClickToCallEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enable the Click to Call feature which allows users to send phone numbers from Chrome Desktops to an Android device when the user is Signed-in. For more information, see help center article: https://support.google.com/chrome/answer/9430554?hl=en. If this policy is set to enabled, the capability of sending phone numbers to Android devices will be enabled for the Chrome user. If this policy is set to disabled, the capability of sending phone numbers to Android devices will be disabled for the Chrome user. If you set this policy, users cannot change or override it. If this policy is left unset, the Click to Call feature is enabled by default.
NetworkServiceSandboxEnabled  Enable the network service sandbox
Boolean Machine + User
If this policy is not set, the default configuration for the network sandbox will be used.
Registry key
Software\Policies\Google\Chrome
Value name
NetworkServiceSandboxEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether or not the network service process runs sandboxed. If this policy is enabled, the network service process will run sandboxed. If this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed. If this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Google Chrome release, currently running field trials, and platform. This policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.
SharedClipboardEnabled  Enable the Shared Clipboard Feature
Boolean Machine + User
If this policy is left unset, the shared clipboard feature is enabled by default.
Registry key
Software\Policies\Google\Chrome
Value name
SharedClipboardEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enable the Shared Clipboard feature which allows users to send text between Chrome Desktops and an Android device when Sync is enabled and the user is Signed-in. If this policy is set to true, the capability of sending text, cross device, for chrome user is enabled. If this policy is set to false, the capability of sending text, cross device, for chrome user is disabled. If you set this policy, users cannot change or override it. If this policy is left unset, the shared clipboard feature is enabled by default. It is up to the admins to set policies in all platforms they care about. It's recommended to set this policy to one value in all platforms.
TLS13EarlyDataEnabled  Enable TLS 1.3 Early Data
Boolean Machine + User
If this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.
Registry key
Software\Policies\Google\Chrome
Value name
TLS13EarlyDataEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
TLS 1.3 Early Data is an extension to TLS 1.3 to send an HTTP request simultaneously with the TLS handshake. If this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.3 Early Data. If it is enabled, Google Chrome will enable TLS 1.3 Early Data. If it is disabled, Google Chrome will not enable TLS 1.3 Early Data. When the feature is enabled, Google Chrome may or may not use TLS 1.3 Early Data depending on server support. TLS 1.3 Early Data is an established protocol. Existing TLS servers, middleboxes, and security software are expected to either handle or reject TLS 1.3 Early Data without dropping the connection. However, devices that do not correctly implement TLS may malfunction and disconnect when TLS 1.3 Early Data is in use. If this occurs, administrators should contact the vendor for a fix. This policy is a temporary measure to control the feature and will be removed afterwards. The policy may be enabled to allow you to test for issues and disabled while issues are being resolved.
EncryptedClientHelloEnabled  Enable TLS Encrypted ClientHello
Boolean Machine + User
If this policy is not configured, or is set to enabled, Google Chrome will follow the default rollout process for ECH.
Registry key
Software\Policies\Google\Chrome
Value name
EncryptedClientHelloEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Encrypted ClientHello (ECH) is an extension to TLS to encrypt sensitive fields of the ClientHello and improve privacy. If this policy is not configured, or is set to enabled, Google Chrome will follow the default rollout process for ECH. If it is disabled, Google Chrome will not enable ECH. When the feature is enabled, Google Chrome may or may not use ECH depending on server support, availability of the HTTPS DNS record, or rollout status. ECH is an evolving protocol, so Google Chrome's implementation is subject to change. As such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.
TranslateEnabled  Enable Translate
Boolean Machine + User
Leaving it unset lets them change the setting.
Registry key
Software\Policies\Google\Chrome
Value name
TranslateEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features. If you set the policy, users can't change this function. Leaving it unset lets them change the setting.
UrlKeyedAnonymizedDataCollectionEnabled  Enable URL-keyed anonymized data collection
Boolean Machine + User
If this policy is left unset, the user will be able to change this setting manually. If this policy is unset for Google ChromeOS Kiosk, URL-keyed anonymized data collection is always active.
Registry key
Software\Policies\Google\Chrome
Value name
UrlKeyedAnonymizedDataCollectionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means URL-keyed anonymized data collection, which sends URLs of pages the user visits to Google to make searches and browsing better, is always active. Setting the policy to Disabled results in no URL-keyed anonymized data collection. If this policy is left unset, the user will be able to change this setting manually. In Google ChromeOS Kiosk, this policy doesn't offer the option to "Allow the user to decide". If this policy is unset for Google ChromeOS Kiosk, URL-keyed anonymized data collection is always active. When set for Google ChromeOS Kiosk, this policy enables URL-keyed metrics collection for kiosk apps.
WebAppInstallByUserEnabled  Enable User Web App Install From Browser
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebAppInstallByUserEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether users can install web apps through the browser. If you enable or don’t configure this policy, users can install web apps through the browser. If you disable this policy, users can’t install web apps through the browser and the "apps" data type will be excluded from synchronization for Chrome Sync. This policy doesn't support dynamic refresh. Any changes, whether enabling, disabling or unsetting, become effective only after the browser is restarted. This policy doesn't affect the 'WebAppInstallForceList' policy.
WindowOcclusionEnabled  Enable Window Occlusion
Boolean Machine + User
If this policy is left not set, occlusion detection will be enabled.
Registry key
Software\Policies\Google\Chrome
Value name
WindowOcclusionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enables window occlusion in Google Chrome. If you enable this setting, to reduce CPU and power consumption Google Chrome will detect when a window is covered by other windows, and will suspend work painting pixels. If you disable this setting Google Chrome will not detect when a window is covered by other windows. If this policy is left not set, occlusion detection will be enabled.
WPADQuickCheckEnabled  Enable WPAD optimization
Boolean Machine + User
Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome.
Registry key
Software\Policies\Google\Chrome
Value name
WPADQuickCheckEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome. Setting the policy to Disabled turns off WPAD optimization, causing Google Chrome to wait longer for DNS-based WPAD servers. Whether or not this policy is set, users can't change the WPAD optimization setting.
EnableExperimentalPolicies  Enables experimental policies
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\EnableExperimentalPolicies
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows Google Chrome to load experimental policies. WARNING: Experimental policies are unsupported and subject to change or be removed without notice in future version of the browser! An experimental policy may not be finished or still have known or unknown defects. It may be changed or even removed without any notification. By enabling experimental policies, you could lose browser data or compromise your security or privacy. If a policy is not in the list and it's not officially released, its value will be ignored on Beta and Stable channel. If a policy is in the list and it's not officially released, its value will be applied. This policy has no effect on already released policies. Example value: ExtensionInstallAllowlist ExtensionInstallBlocklist
EnterpriseHardwarePlatformAPIEnabled  Enables managed extensions to use the Enterprise Hardware Platform API
Boolean Machine + User
Setting the policy to False or leaving it unset prevents extensions from using this API.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseHardwarePlatformAPIEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API. Setting the policy to False or leaving it unset prevents extensions from using this API. Note: This policy also applies to component extensions, such as the Hangout Services extension.
CloudUserPolicyMerge  Enables merging of user cloud policies into machine-level policies
Boolean Machine + User
Setting the policy to Disabled or leaving it unset prevents user-level cloud policies from being merged with policies from any other sources.
Registry key
Software\Policies\Google\Chrome
Value name
CloudUserPolicyMerge
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled allows policies associated with a managed account to be merged into machine-level policies. Setting the policy to Disabled or leaving it unset prevents user-level cloud policies from being merged with policies from any other sources. Only policies originating from secure users can take precedence. A secure user is affiliated with the organization that manages their browser using Chrome Enterprise Core. All other user-level policies will have default precedence. Policies that need to be merged also need to be set in either PolicyListMultipleSourceMergeList or PolicyDictionaryMultipleSourceMergeList. This policy will be ignored if neither of the two aforementioned policies is configured.
PolicyAtomicGroupsEnabled  Enables the concept of policy atomic groups
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PolicyAtomicGroupsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored. Setting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority. If this policy is set from a cloud source, it can't target a specific user.
BrowserGuestModeEnforced  Enforce browser guest mode
Boolean Machine + User
Setting the policy to Disabled, leaving it unset, or disabling browser Guest mode (through BrowserGuestModeEnabled) allows the use of new and existing profiles.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserGuestModeEnforced
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means Google Chrome enforces guest sessions and prevents profile sign-ins. Guest sign-ins are Google Chrome profiles where windows are in Incognito mode. Setting the policy to Disabled, leaving it unset, or disabling browser Guest mode (through BrowserGuestModeEnabled) allows the use of new and existing profiles.
EnterpriseLogoUrlForBrowser  Enterprise Logo URL for a managed browser
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseLogoUrlForBrowser
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A URL to an image that will be used as an enterprise badge for a managed browser. The URL must point to an image. It is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px. Note that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://example.com/image.png
EnterpriseLogoUrl  Enterprise Logo URL for a managed profile
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseLogoUrl
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A URL to an image that will be used as an enterprise badge for a managed profile. The URL must point to an image. This policy can only be set as a user policy. It is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px. Example value: https://example.com/image.png
EnterpriseSearchAggregatorSettings  Enterprise search aggregator settings
String Machine + User
A default icon will be used when this field is not set. If this field is not set, the address bar shortcut is not required.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseSearchAggregatorSettings
Stated default
By default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows administrators to set a designated enterprise search aggregator that will provide search recommendations and results within the omnibox (address bar) and the search box on the New Tab page. By default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations. Users can explicitly scope their search to just the enterprise search aggregator by typing the keyword specified in the shortcut field with or without the @ prefix (e.g. @work) followed by Space or Tab in the omnibox. Scoped enterprise searches (triggered by a keyword) are currently only supported in the omnibox and not in the search box on the New Tab page. The following fields are required: name, shortcut, search_url, suggest_url. The name field corresponds to the search engine name shown to the user in the address bar. The shortcut field corresponds to the keyword that the user enters to trigger the search. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must be unique. The search_url field specifies the URL on which to search. Enter the web address for the search engine's results page, and use '{searchTerms}' in place of the query. The suggest_url field specifies the URL that provides search suggestions. A POST request will be made and the user's query will be passed in the POST params under key 'query'. The icon_url field specifies the URL to an image that will be used on the search suggestions. A default icon will be used when this field is not set. It's recommended to use a favicon (example https://www.google.com/favicon.ico). Supported image file formats: JPEG, PNG, and ICO. The require_shortcut field specifies whether the address bar shortcut is required to see search recommendations. If required, suggestions will not be shown in the search box on the New Tab page, but will continue to be shown in the omnibox (address bar) in scoped search mode. If this field is not set, the address bar shortcut is not required. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. See https://chromeenterprise.google/policies/?policy=EnterpriseSearchAggregatorSettings for more information about schema and formatting. Example value: { "name": "My Search Aggregator", "shortcut": "work", "search_url": "https://www.aggregator.com/search?q={searchTerms}", "suggest_url": "https://www.aggregator.com/suggest", "icon_url": "https://www.google.com/favicon.ico", "require_shortcut": true }
ForceEphemeralProfiles  Ephemeral profile
Boolean Machine + User
If the policy is set to disabled or left not set signing in leads to regular profiles.
Registry key
Software\Policies\Google\Chrome
Value name
ForceEphemeralProfiles
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If set to enabled this policy forces the profile to be switched to ephemeral mode. If this policy is specified as an OS policy (e.g. GPO on Windows) it will apply to every profile on the system; if the policy is set as a Cloud policy it will apply only to a profile signed in with a managed account. In this mode the profile data is persisted on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies and web databases are not preserved after the browser is closed. However this does not prevent the user from downloading any data to disk manually, save pages or print them. If the user has enabled sync all this data is preserved in their sync profile just like with regular profiles. Incognito mode is also available if not explicitly disabled by policy. If the policy is set to disabled or left not set signing in leads to regular profiles.
ExplicitlyAllowedNetworkPorts  Explicitly allowed network ports
List (values under a subkey) Machine + User
Leaving the value empty or unset means that all restricted ports will be blocked.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExplicitlyAllowedNetworkPorts
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
There is a list of restricted ports built into Google Chrome. Connections to these ports will fail. This setting permits bypassing that list. The value is a comma-separated list of zero or more ports that outgoing connections will be permitted on. Ports are restricted to prevent Google Chrome being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for errors with code "ERR_UNSAFE_PORT" while migrating a service running on a blocked port to a standard port (ie. port 80 or 443). Malicious websites can easily detect that this policy is set, and for what ports, and use that information to target attacks. Each port here is labelled with a date that it can be unblocked until. After that date the port will be restricted regardless of this setting. Leaving the value empty or unset means that all restricted ports will be blocked. If there is a mixture of valid and invalid values, the valid ones will be applied. This policy overrides the "--explicitly-allowed-ports" command-line option. Example value: 10080
FetchKeepaliveDurationSecondsOnShutdown  Fetch keepalive duration on Shutdown
Integer Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
FetchKeepaliveDurationSecondsOnShutdown
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls the duration (in seconds) allowed for keepalive requests on browser shutdown. When specified, browser shutdown can be blocked up to the specified seconds, to process keepalive (https://fetch.spec.whatwg.org/#request-keepalive-flag) requests. The default value (0) means this feature is disabled.
SpellcheckLanguageBlocklist  Force disable spellcheck languages
List (values under a subkey) Machine + User
If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SpellcheckLanguageBlocklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Force-disables spellcheck languages. Unrecognized languages in that list will be ignored. If you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list. If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences. If the SpellcheckEnabled policy is set to false, this policy will have no effect. If a language is included in both this policy and the SpellcheckLanguage policy, the latter is prioritized and the spellcheck language will be enabled. The currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi. Example value: fr es
SpellcheckLanguage  Force enable spellcheck languages
List (values under a subkey) Machine + User
If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SpellcheckLanguage
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Force-enables spellcheck languages. Unrecognized languages in the list will be ignored. If you enable this policy, spellcheck will be enabled for the languages specified, in addition to the languages for which the user has enabled spellcheck. If you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences. If the SpellcheckEnabled policy is set to false, this policy will have no effect. If a language is included in both this policy and the SpellcheckLanguageBlocklist policy, this policy is prioritized and the spellcheck language is enabled. The currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi. Example value: fr es
ForceForegroundPriorityForAllTabs  Force foreground priority for all tabs
Boolean Machine + User
If this policy is set to Disabled or not set, the browser determines priority based on standard heuristics (e.
Registry key
Software\Policies\Google\Chrome
Value name
ForceForegroundPriorityForAllTabs
Enabled / Disabled
1 / 0
Stated default
By default, the browser optimizes resources by deprioritizing content in background tabs.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether background web content is forced to run at foreground priority. By default, the browser optimizes resources by deprioritizing content in background tabs. Enabling this policy overrides that behavior, causing background tabs to be scheduled the same way as the active tab. Note that forcing background content to run at foreground priority may slightly impact the responsiveness of the active tab. If this policy is set to Enabled, all web content runs at foreground priority regardless of its visibility state. If this policy is set to Disabled or not set, the browser determines priority based on standard heuristics (e.g., deprioritizing content that is not visible, not playing audio, not participating in video calls...).
ForceForegroundPriorityForUrls  Force foreground priority for specific URLs
List (values under a subkey) Machine + User
If ForceForegroundPriorityForAllTabs is disabled or unset, only content matching the patterns in this list will be forced. If this list is empty or not set, no background content is forced to foreground priority.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ForceForegroundPriorityForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows you to specify a list of URL patterns. Background web content matching these patterns will be forced to run at foreground priority. If the ForceForegroundPriorityForAllTabs policy is enabled, this list is ignored as all tabs will be forced to foreground priority. If ForceForegroundPriorityForAllTabs is disabled or unset, only content matching the patterns in this list will be forced. For detailed information on valid URL patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. If this list is empty or not set, no background content is forced to foreground priority. Example value: https://www.example.com/path?query=val example.edu https://example.com:8080 *://example.org:*/
ForceGoogleSafeSearch  Force Google SafeSearch
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means SafeSearch in Google Search is not enforced.
Registry key
Software\Policies\Google\Chrome
Value name
ForceGoogleSafeSearch
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means SafeSearch in Google Search is always active, and users can't change this setting. Setting the policy to Disabled or leaving it unset means SafeSearch in Google Search is not enforced.
ForceYouTubeRestrict  Force minimum YouTube Restricted Mode
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceYouTubeRestrict
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Do not enforce Restricted Mode on YouTube
1Enforce at least Moderate Restricted Mode on YouTube
2Enforce Strict Restricted Mode for YouTube
Setting the policy enforces a minimum Restricted mode on YouTube and prevents users from picking a less restricted mode. If you set it to: * Strict, Strict Restricted mode on YouTube is always active. * Moderate, the user may only pick Moderate Restricted mode and Strict Restricted mode on YouTube, but can't turn off Restricted mode. * Off or if no value is set, Restricted mode on YouTube isn't enforced by Chrome. External policies such as YouTube policies might still enforce Restricted mode.
NativeHostsExecutablesLaunchDirectly  Force Windows executable Native Messaging hosts to launch directly
Boolean Machine + User
Leaving the policy unset allows Google Chrome to decide which approach to use.
Registry key
Software\Policies\Google\Chrome
Value name
NativeHostsExecutablesLaunchDirectly
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether native host executables launch directly on Windows. Setting the policy to Enabled forces Google Chrome to launch native messaging hosts implemented as executables directly. Setting the policy to Disabled will result in Google Chrome launching hosts using cmd.exe as an intermediary process. Leaving the policy unset allows Google Chrome to decide which approach to use.
CloudPolicyOverridesPlatformPolicy  Google Chrome cloud policy overrides Platform policy.
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy.
Registry key
Software\Policies\Google\Chrome
Value name
CloudPolicyOverridesPlatformPolicy
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means cloud policy takes precedence if it conflicts with platform policy. Setting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy. This mandatory policy affects machine scope cloud policies. This policy is specific to Google Chrome and does not affect Google Update because they are independent applications. Google Update has a separate policy with the same name.
HideWebStoreIcon  Hide the web store from the New Tab Page and app launcher
Boolean Machine + User
When this policy is set to false or is not configured, the icons are visible.
Registry key
Software\Policies\Google\Chrome
Value name
HideWebStoreIcon
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Hide the Chrome Web Store app and footer link from the New Tab Page and Google ChromeOS app launcher. When this policy is set to true, the icons are hidden. When this policy is set to false or is not configured, the icons are visible.
HttpAllowlist  HTTP Allowlist
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\HttpAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable HTTPS Upgrades and/or HTTPS-First Mode. Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. Blanket host wildcards (i.e., "*" or "[*]") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies. Note: This policy does not apply to HSTS upgrades. Example value: testserver.example.com [*.]example.org
ImportAutofillFormData  Import autofill form data from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.
Registry key
Software\Policies\Google\Chrome
Value name
ImportAutofillFormData
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run. Users can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.
ImportBookmarks  Import bookmarks from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.
Registry key
Software\Policies\Google\Chrome
Value name
ImportBookmarks
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run. Users can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.
ImportHistory  Import browsing history from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.
Registry key
Software\Policies\Google\Chrome
Value name
ImportHistory
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run. Users can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.
ImportHomepage  Import of homepage from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run.
Registry key
Software\Policies\Google\Chrome
Value name
ImportHomepage
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports the homepage from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run. Users can trigger an import dialog and the homepage checkbox will be checked or unchecked to match this policy's value.
ImportSavedPasswords  Import saved passwords from default browser on first run
Boolean Machine + User
Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
Registry key
Software\Policies\Google\Chrome
Value name
ImportSavedPasswords
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls only the first run import behavior after installation. It enables more seamless transition to Google Chrome in environments where a different browser was extensively used prior to installing the browser. This policy does not affect password manager capabilities for Google accounts. Setting the policy to Enabled imports saved passwords from the previous default browser on first run and manual importing from the settings page is also possible. Setting the policy to Disabled means no saved passwords are imported on first run and manual importing from the Settings page is blocked. Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
ImportSearchEngine  Import search engines from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.
Registry key
Software\Policies\Google\Chrome
Value name
ImportSearchEngine
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run. Users can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.
IncognitoModeAvailability  Incognito mode availability
Enum Machine + User
If 'Enabled' is selected or the policy is left unset, pages may be opened in Incognito mode.
Registry key
Software\Policies\Google\Chrome
Value name
IncognitoModeAvailability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Incognito mode available
1Incognito mode disabled
2Incognito mode forced
Specifies whether the user may open pages in Incognito mode in Google Chrome. If 'Enabled' is selected or the policy is left unset, pages may be opened in Incognito mode. If 'Disabled' is selected, pages may not be opened in Incognito mode. If 'Forced' is selected, pages may be opened ONLY in Incognito mode. Note that 'Forced' does not work for Android-on-Chrome The IncognitoModeUrlAllowlist policy takes precedence over this policy and can re-enable Incognito mode for specific URLs. When Incognito mode is disabled by this policy when an allowlist is provided, Incognito mode is available only for URLs matching the allowlist, while all other pages are blocked. Note: On iOS, if the policy is changed during a session, it will only take effect on relaunch.
IntranetRedirectBehavior  Intranet Redirection Behavior
Enum Machine + User
If this policy is not set, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions.
Registry key
Software\Policies\Google\Chrome
Value name
IntranetRedirectBehavior
Stated default
In M88, they are enabled by default but will be disabled by default in the future release.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Use default browser behavior.
1Disable DNS interception checks and did-you-mean "http://intranetsite/" infobars.
2Disable DNS interception checks; allow did-you-mean "http://intranetsite/" infobars.
3Allow DNS interception checks and did-you-mean "http://intranetsite/" infobars.
This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names. If this policy is not set, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release. DNSInterceptionChecksEnabled is a related policy that may also disable DNS interception checks; this policy is a more flexible version which may separately control intranet redirection infobars and may be expanded in the future. If either DNSInterceptionChecksEnabled or this policy requests to disable interception checks, the checks will be disabled.
EnterpriseProfileCreationKeepBrowsingData  Keep browsing data when creating enterprise profile by default
Boolean Machine + User
If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseProfileCreationKeepBrowsingData
Enabled / Disabled
1 / 0
Stated default
If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default. Regardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile. This policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.
UserDataSnapshotRetentionLimit  Limits the number of user data snapshots retained for use in case of emergency rollback.
Integer Machine + User
If this policy is not set, the default value of 3 is used If the policy is set, old snapshots are deleted as needed to respect the limit.
Registry key
Software\Policies\Google\Chrome
Value name
UserDataSnapshotRetentionLimit
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Following each major version update, Chrome will create a snapshot of certain portions of the user's browsing data for use in case of a later emergency version rollback. If an emergency rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This allows users to retain such settings as bookmarks and autofill data. If this policy is not set, the default value of 3 is used If the policy is set, old snapshots are deleted as needed to respect the limit. If the policy is set to 0, no snapshots will be taken
AutoOpenFileTypes  List of file types that should be automatically opened on download
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutoOpenFileTypes
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of file types that should be automatically opened on download. The leading separator should not be included when listing the file type, so list "txt" instead of ".txt". Files with types that should be automatically opened will still be subject to the enabled safe browsing checks and won't be opened if they fail those checks. If this policy isn't set, only file types that a user has already specified to automatically be opened will do so when downloaded. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: exe txt
HSTSPolicyBypassList  List of names that will bypass the HSTS policy check
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\HSTSPolicyBypassList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies a list of hostnames that bypass preloaded HSTS upgrades from http to https. Only single-label hostnames are allowed in this policy, and this policy only applies to "static" HSTS-preloaded entries (for instance, "app", "new", "search", "play"). This policy does not prevent HSTS upgrades for servers that have "dynamically" requested HSTS upgrades using a Strict-Transport-Security response header. Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified, not to subdomains of those names. Example value: meet
SyncTypesListDisabled  List of types that should be excluded from synchronization
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SyncTypesListDisabled
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is set all specified data types will be excluded from synchronization both for Chrome Sync as well as for roaming profile synchronization. This can be beneficial to reduce the size of the roaming profile or limit the type of data uploaded to the Chrome Sync Servers. The current data types for this policy are: "apps", "autofill", "bookmarks", "extensions", "preferences", "passwords", "payments", "productComparison", "readingList", "tabs", "themes", "typedUrls", "wifiConfigurations". Those names are case sensitive! Notes: Dynamic Policy Refresh is supported only in Google Chrome version 123 and later. Disabling "autofill" also disables "payments". "typedUrls" refers to all browsing history. Example value: bookmarks
DeveloperToolsAvailabilityAllowlist  List of URL patterns for which Chrome DevTools are allowed to be opened
List (values under a subkey) Machine + User
If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityBlocklist and DeveloperToolsAvailability policies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\DeveloperToolsAvailabilityAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy can be used to allow Chrome DevTools on specific URLs. URL patterns are matched against the URL of every frame on the page being inspected. The resulting behavior depends on whether the DeveloperToolsAvailabilityBlocklist policy is also set. If this policy is set and DeveloperToolsAvailabilityBlocklist is not, every frame's URL must match a pattern on this allowlist for Chrome DevTools to be allowed. If any frame's URL does not match, DevTools will be blocked for the entire page. For information on the URL format, see https://support.google.com/chrome/a?p=url_blocklist_filter_format. If both this and the DeveloperToolsAvailabilityBlocklist policies are set, this allowlist takes precedence. If a frame's URL matches a pattern on this allowlist, it will be allowed, even if it also matches a pattern in the blocklist. If a URL matches a pattern on the blocklist (but not the allowlist), it will be blocked. If a URL matches neither, the DeveloperToolsAvailability policy will be used as a fallback. If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityBlocklist and DeveloperToolsAvailability policies. This policy also applies to Chrome DevTools opened for extensions and web applications. This policy is limited to 1,000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://*
DeveloperToolsAvailabilityBlocklist  List of URL patterns for which Chrome DevTools are blocked
List (values under a subkey) Machine + User
If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityAllowlist and DeveloperToolsAvailability policies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\DeveloperToolsAvailabilityBlocklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy can be used to block Chrome DevTools on specific URLs. For information on the URL format, see https://support.google.com/chrome/a?p=url_blocklist_filter_format. URL patterns are matched against the URL of every frame on the page being inspected. The resulting behavior depends on whether the DeveloperToolsAvailabilityAllowlist policy is also set. If this policy is set and DeveloperToolsAvailabilityAllowlist is not, any frame's URL matching a pattern on this blocklist will block Chrome DevTools for the entire page. If a frame's URL doesn't match any pattern, the availability is determined by the DeveloperToolsAvailability policy. If both this and the DeveloperToolsAvailabilityAllowlist policies are set, the allowlist takes precedence. If a frame's URL matches a pattern on the allowlist, it will be allowed, even if it also matches a pattern in this blocklist. If a URL matches a pattern on this blocklist (but not the allowlist), it will be blocked. If a URL matches neither, the DeveloperToolsAvailability policy will be used as a fallback. If this policy is not set, the availability of Chrome DevTools is determined by the DeveloperToolsAvailabilityAllowlist and DeveloperToolsAvailability policies. This policy is limited to 1,000 entries. Example value: https://example.com example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com * file://*
SharedWorkerBlobURLFixEnabled  Make SharedWorker blob URL behavior aligned with the specification
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Google Chrome inherit the controller if a blob URL is used as a SharedWorker URL.
Registry key
Software\Policies\Google\Chrome
Value name
SharedWorkerBlobURLFixEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Upon https://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers should inherit controllers for the blob URL. However, existing code allows only DedicatedWorkers to inherit the controller, and SharedWorkers do not inherit the controller. Setting the policy to Enabled or leaving it unset means Google Chrome inherit the controller if a blob URL is used as a SharedWorker URL. Setting the policy to Disabled leaves the behavior not aligned with the specification as-is. This policy is intended to be temporary and will be removed in the future.
ManagedBookmarks  Managed Bookmarks
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ManagedBookmarks
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets up a list of bookmarks where each one is a dictionary with the keys "name" and "url". These keys hold the bookmark's name and target. Admins can set up a subfolder by defining a bookmark without a "url" key, but with an additional "children" key. This key also has a list of bookmarks, some of which can also be folders. Chrome amends incomplete URLs as if they were submitted through the address bar. For example, "google.com" becomes "https://google.com/". Users can't change the folders the bookmarks are placed in (though they can hide it from the bookmark bar). The default folder name for managed bookmarks is "Managed bookmarks" but it can be changed by adding a new sub-dictionary to the policy with a single key named "toplevel_name" with the desired folder name as its value. Managed bookmarks are not synced to the user account and extensions can't modify them. See https://chromeenterprise.google/policies/?policy=ManagedBookmarks for more information about schema and formatting. Example value: [ { "toplevel_name": "My managed bookmarks folder" }, { "name": "Google", "url": "google.com" }, { "name": "Youtube", "url": "youtube.com" }, { "children": [ { "name": "Chromium", "url": "chromium.org" }, { "name": "Chromium Developers", "url": "dev.chromium.org" } ], "name": "Chrome links" } ]
MaxConnectionsPerProxy  Maximal number of concurrent connections per proxy server for non-WebSocket requests
Integer Machine + User
Leaving the policy unset means a default of 128 is used.
Registry key
Software\Policies\Google\Chrome
Value name
MaxConnectionsPerProxy
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the maximal number of simultaneous connections per proxy server for non-WebSocket requests. To modify WebSocket request limits, see MaxConnectionsPerProxyForWebSocket. Leaving the policy unset means a default of 128 is used. Some web apps are known to consume many connections with hanging GETs, so setting a value below 128 may lead to browser networking hangs if there are too many web apps with hanging connections open. Some proxy servers can't handle a high number of concurrent connections per client, which is solved by setting this policy to a lower value. The value should be equal to or higher than 6. Setting a value below that limit will cause 6 to be used. Lower below the default (128) at your own risk. The value should be equal to or lower than 256 (99 in Google Chrome 147 and earlier). Setting a value above that limit will cause 256 (99 in Google Chrome 147 and earlier) to be used. Raise above the default (128) at your own risk. Please note that the enforced limits are impacted by AllowSocketPoolSizeRandomizationForProxies.
MaxConnectionsPerProxyForWebSocket  Maximal number of concurrent connections per proxy server for WebSocket requests
Integer Machine + User
Leaving the policy unset means a default of 128 is used.
Registry key
Software\Policies\Google\Chrome
Value name
MaxConnectionsPerProxyForWebSocket
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the maximal number of simultaneous connections per proxy server for WebSocket requests. To modify non-WebSocket request limits, see MaxConnectionsPerProxy. Leaving the policy unset means a default of 128 is used. Some web apps are known to consume many connections with hanging GETs, so setting a value below 128 may lead to browser networking hangs if there are too many web apps with hanging connections open. Some proxy servers can't handle a high number of concurrent connections per client, which is solved by setting this policy to a lower value. The value should be equal to or higher than 6. Setting a value below that limit will cause 6 to be used. Lower below the default (128) at your own risk. The value should be equal to or lower than 256. Setting a value above that limit will cause 256 to be used. Raise above the default (128) at your own risk. Please note that the enforced limits are impacted by AllowSocketPoolSizeRandomizationForProxies.
MaxInvalidationFetchDelay  Maximum fetch delay after a policy invalidation
Integer Machine + User
Leaving the policy unset means Google Chrome uses the default value of 10 seconds.
Registry key
Software\Policies\Google\Chrome
Value name
MaxInvalidationFetchDelay
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service. Valid values range from 1,000 (1 second) to 300,000 (5 minutes). Values outside this range will be clamped to the respective boundary. Leaving the policy unset means Google Chrome uses the default value of 10 seconds.
RelaunchNotification  Notify a user that a browser relaunch or device restart is recommended or required
Enum Machine + User
If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google ChromeOS indicates such via a notification in the system tray.
Registry key
Software\Policies\Google\Chrome
Value name
RelaunchNotification
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Show a recurring prompt to the user indicating that a relaunch is recommended
2Show a recurring prompt to the user indicating that a relaunch is required
Notify users that Google Chrome must be relaunched or Google ChromeOS must be restarted to apply a pending update. This policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google ChromeOS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google ChromeOS, and may be configured via the RelaunchNotificationPeriod policy setting. The user's session is restored following the relaunch/restart.
OverrideSecurityRestrictionsOnInsecureOrigin  Origins or hostname patterns for which restrictions on insecure origins should not apply
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\OverrideSecurityRestrictionsOnInsecureOrigin
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies a list of origins (URLs) or hostname patterns (such as *.example.com) for which security restrictions on insecure origins won't apply. Patterns are only accepted for hostnames; URLs/origins with schemes must be exact strings. Organizations can specify origins for legacy applications that can't deploy TLS or set up a staging server for internal web development, so developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled "Not Secure" in the address bar. Setting a list of URLs in this policy amounts to setting the command-line flag --unsafely-treat-insecure-origin-as-secure to a comma-separated list of the same URLs. The policy overrides the command-line flag and UnsafelyTreatInsecureOriginAsSecure, if present. For more information on secure contexts, see Secure Contexts ( https://www.w3.org/TR/secure-contexts ). Example value: http://testserver.example.com/ *.example.org
CpuPerformanceTierOverride  Override for the CPU performance tier
Integer Machine + User
If the policy is not set, then the default performance tier calculation is used.
Registry key
Software\Policies\Google\Chrome
Value name
CpuPerformanceTierOverride
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting this policy allows enterprises to override the value returned by the CPU Performance API (i.e., navigator.cpuPerformance, please see https://github.com/WICG/cpu-performance for details). If this policy is set, the value of navigator.cpuPerformance will be overridden to the specified value. If the policy is not set, then the default performance tier calculation is used. The possible values for this policy are 0 to 4.
ProfilePickerOnStartupAvailability  Profile picker availability on startup
Enum Machine + User
If 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it.
Registry key
Software\Policies\Google\Chrome
Value name
ProfilePickerOnStartupAvailability
Stated default
By default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true. If 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Profile picker available at startup
1Profile picker disabled at startup
2Profile picker forced at startup
Specifies whether the profile picker is enabled, disabled or forced at the browser startup. By default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true. If 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it. If 'Disabled' (1) is selected, the profile picker will never be shown, and users will not be able to change the setting. If 'Forced' (2) is selected, the profile picker cannot be suppressed by the user. The profile picker will be shown even if there is only one profile available.
ProfileReauthPrompt  Prompt users to re-authenticate to the profile
Enum Machine + User
When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.
Registry key
Software\Policies\Google\Chrome
Value name
ProfileReauthPrompt
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Do not prompt for reauth
1Prompt for reauth in a tab
When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser. When set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.
PromptOnMultipleMatchingCertificates  Prompt when multiple certificates match
Boolean Machine + User
If this policy is set to Disabled or not set, the user may only be prompted when no certificate matches the auto-selection.
Registry key
Software\Policies\Google\Chrome
Value name
PromptOnMultipleMatchingCertificates
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether the user is prompted to select a client certificate when more than one certificate matches AutoSelectCertificateForUrls. If this policy is set to Enabled, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates. If this policy is set to Disabled or not set, the user may only be prompted when no certificate matches the auto-selection.
ProxySettings  Proxy settings
String Machine + User
Leaving the policy unset lets users choose their proxy settings.
Registry key
Software\Policies\Google\Chrome
Value name
ProxySettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy configures the proxy settings for Chrome and ARC-apps, which ignore all proxy-related options specified from the command line. Leaving the policy unset lets users choose their proxy settings. Setting the ProxySettings policy accepts the following fields: * ProxyMode, which lets you specify the proxy server Chrome uses and prevents users from changing proxy settings * ProxyPacUrl, a URL to a proxy .pac file, or a PAC script encoded as a data URL with MIME type application/x-ns-proxy-autoconfig * ProxyPacMandatory, which prevents the network stack from falling back to direct connections with invalid or unavailable PAC script * ProxyServer, a URL of the proxy server * ProxyBypassList, a list of hosts for which the proxy will be bypassed The ProxyServerMode field is deprecated in favor of the ProxyMode field. For ProxyMode, if you choose the value: * direct, a proxy is never used and all other fields are ignored. * system, the systems's proxy is used and all other fields are ignored. * auto_detect, all other fields are ignored. * fixed_servers, the ProxyServer and ProxyBypassList fields are used. * pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used. Note: For more detailed examples, visit The Chromium Projects ( https://www.chromium.org/developers/design-documents/network-settings/#command-line-options-for-proxy-settings ). See https://chromeenterprise.google/policies/?policy=ProxySettings for more information about schema and formatting. Example value: { "ProxyBypassList": "https://www.example1.com,https://www.example2.com,https://internalsite/", "ProxyMode": "fixed_servers", "ProxyServer": "123.123.123.123:8080" }
PolicyRefreshRate  Refresh rate for user policy
Integer Machine + User
Leaving the policy unset uses the default value of 3 hours.
Registry key
Software\Policies\Google\Chrome
Value name
PolicyRefreshRate
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the period in milliseconds at which the device management service is queried for user policy information. Valid values range from 1,800,000 (30 minutes) to 86,400,000 (1 day). Values outside this range will be clamped to the respective boundary. Leaving the policy unset uses the default value of 3 hours. Note: Policy notifications force a refresh when the policy changes, making frequent refreshes unnecessary. So, if the platform supports these notifications, the refresh delay is 24 hours (ignoring defaults and the value of this policy).
RelaunchFastIfOutdated  Relaunch fast if outdated
Integer Machine + User
If not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.
Registry key
Software\Policies\Google\Chrome
Value name
RelaunchFastIfOutdated
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Specifies the minimum release age beyond which relaunch notifications are more aggressive. The age is calculated from the time the currently-running version was last served to clients. If a browser relaunch or device restart is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), users will be forced to relaunch or restart at the end of the period. If not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.
RequireOnlineRevocationChecksForLocalAnchors  Require online OCSP/CRL checks for local trust anchors
Boolean Machine + User
Setting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings.
Registry key
Software\Policies\Google\Chrome
Value name
RequireOnlineRevocationChecksForLocalAnchors
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True means Google Chrome always performs revocation checking for successfully validated server certificates signed by locally installed CA certificates. If Google Chrome can't get revocation status information, Google Chrome treats these certificates as revoked (hard-fail). Setting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings. On macOS, this policy has no effect if the ChromeRootStoreEnabled policy is set to False.
SitePerProcess  Require Site Isolation for every site
Boolean Machine + User
Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out.
Registry key
Software\Policies\Google\Chrome
Value name
SitePerProcess
Enabled / Disabled
1 / 0
Stated default
Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process. A site is a scheme plus eTLD+1 (e.g., https://example.com). Setting this policy to Enabled does not change that behavior; it only prevents users from opting out (for example, using Disable site isolation in chrome://flags). Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out. IsolateOrigins might also be useful for isolating specific origins at a finer granularity than site (e.g., https://a.example.com). On Google ChromeOS version 76 and earlier, set the DeviceLoginScreenSitePerProcess device policy to the same value. (If the values don't match, a delay can occur when entering a user session.) Note: For Android, use the SitePerProcessAndroid policy instead.
RestrictBackgroundFetchFromServiceWorkerEnabled  Restrict Background Fetch API when called from a Service Worker
Boolean Machine + User
If this policy is set to Enabled, or left unset, the restriction is active, and background fetch requests from Service Worker contexts may be blocked.
Registry key
Software\Policies\Google\Chrome
Value name
RestrictBackgroundFetchFromServiceWorkerEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether background fetch requests from Service Workers are restricted. If a feature that downloads files in the background is affected, this policy may be relevant. If this policy is set to Enabled, or left unset, the restriction is active, and background fetch requests from Service Worker contexts may be blocked. If this policy is set to Disabled, the restriction is bypassed, allowing all Service Workers to make background fetch requests. This enterprise policy is temporary, and will be removed after M152.
RestrictCoreSharingOnRenderer  Restrict CPU core sharing for renderer process
Boolean Machine + User
If this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core.
Registry key
Software\Policies\Google\Chrome
Value name
RestrictCoreSharingOnRenderer
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy If this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running. If this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it. If this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.
RestrictPdfSaveToGoogleDriveAccountsToPattern  Restrict eligible Google accounts for saving PDF files to Google Drive from the Google Chrome PDF Viewer
String Machine + User
If this policy is left not set or blank, then the user can use any Google account to save PDF files to Google Drive.
Registry key
Software\Policies\Google\Chrome
Value name
RestrictPdfSaveToGoogleDriveAccountsToPattern
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Contains a regular expression to determine eligible Google accounts for saving PDF files to Google Drive from the Google Chrome PDF Viewer. An error is displayed if a user tries to upload a PDF file to Google Drive using an account that does not match this pattern. If this policy is left not set or blank, then the user can use any Google account to save PDF files to Google Drive. Example value: .*@example\.com
WebRtcUdpPortRange  Restrict the range of local UDP ports used by WebRTC
String Machine + User
If the policy is not set, or if it is set to the empty string or an invalid port range, WebRTC is allowed to use any available local UDP port.
Registry key
Software\Policies\Google\Chrome
Value name
WebRtcUdpPortRange
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If the policy is set, the UDP port range used by WebRTC is restricted to the specified port interval (endpoints included). If the policy is not set, or if it is set to the empty string or an invalid port range, WebRTC is allowed to use any available local UDP port. Example value: 10000-11999
RestrictSigninToPattern  Restrict which Google accounts are allowed to be set as browser primary accounts in Google Chrome
String Machine + User
If this policy is left not set or blank, then the user can set any Google account as a browser primary account in Google Chrome.
Registry key
Software\Policies\Google\Chrome
Value name
RestrictSigninToPattern
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Contains a regular expression which is used to determine which Google accounts can be set as browser primary accounts in Google Chrome (i.e. the account that is chosen during the Sync opt-in flow). An appropriate error is displayed if a user tries to set a browser primary account with a username that does not match this pattern. If this policy is left not set or blank, then the user can set any Google account as a browser primary account in Google Chrome. Example value: .*@example\.com
EnterpriseCustomLabelForBrowser  Set a custom enterprise label for a managed browser
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseCustomLabelForBrowser
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls a custom label used to indicate a managed browser. For managed browsers, this label will be shown in a management disclaimer on a footer on the New Tab page. The custom label will not be translated. Note that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: Chromium
EnterpriseCustomLabel  Set a custom enterprise label for a managed profile
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseCustomLabel
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls a custom label used to identify managed profiles. For managed profiles, this label will be shown next to the avatar in the toolbar. The custom label will not be translated. When this policy is applied, any strings that surpass 16 characters will be truncated with a “...” Please refrain from using extended names. This policy can only be set as a user policy. Note that this policy has no effect if the EnterpriseProfileBadgeToolbarSettings policy is set to hide_expanded_enterprise_toolbar_badge (value 1). Example value: Chromium
DiskCacheDir  Set disk cache directory
String Machine + User
If not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes.
Registry key
Software\Policies\Google\Chrome
Value name
DiskCacheDir
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy has Google Chrome use the directory you provide for storing cached files on the disk—whether or not users specify the --disk-cache-dir flag. If not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag. Google Chrome manages the contents of a volume's root directory. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes. See the variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: ${user_home}/Chrome_cache
DiskCacheSize  Set disk cache size in bytes
Integer Machine + User
) If not set, Google Chrome uses the default size.
Registry key
Software\Policies\Google\Chrome
Value name
DiskCacheSize
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to None has Google Chrome use the default cache size for storing cached files on the disk. Users can't change it. If you set the policy, Google Chrome uses the cache size you provide—whether or not users specify the --disk-cache-size flag. (Values below a few megabytes are rounded up.) If not set, Google Chrome uses the default size. Users can change that setting using the --disk-cache-size flag. Note: The value specified in this policy is used as a hint to various cache subsystems in the browser. Therefore the actual total disk consumption of all caches will be higher but within the same order of magnitude as the value specified.
DownloadDirectory  Set download directory
String Machine + User
Leaving the policy unset means Chrome uses the default download directory, and users can change it.
Registry key
Software\Policies\Google\Chrome
Value name
DownloadDirectory
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time. This policy overrides the DefaultDownloadDirectory policy. Leaving the policy unset means Chrome uses the default download directory, and users can change it. On Google ChromeOS it's possible to set it only to Google Drive directories. Note: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: /home/${user_name}/Downloads
DefaultBrowserSettingEnabled  Set Google Chrome as Default Browser
Boolean Machine + User
Leaving the policy unset means Google Chrome lets users control whether it's the default and, if not, whether user notifications should appear.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultBrowserSettingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7
Template
chrome.admx
Setting the policy to True has Google Chrome always check whether it's the default browser on startup and, if possible, automatically register itself. Setting the policy to False stops Google Chrome from ever checking if it's the default and turns user controls off for this option. Leaving the policy unset means Google Chrome lets users control whether it's the default and, if not, whether user notifications should appear. Note: For Microsoft®Windows® administrators, turning this setting on only works for machines running Windows 7. For later versions, you must deploy a "default application associations" file that makes Google Chrome the handler for the https and http protocols (and, optionally, the ftp protocol and other file formats). See Chrome Help ( https://support.google.com/chrome?p=make_chrome_default_win ).
TotalMemoryLimitMb  Set limit on megabytes of memory a single Chrome instance can use.
Integer Machine + User
If this policy is not set, the browser will only begin attempts to save memory once it has detected that the amount of physical memory on its machine is low.
Registry key
Software\Policies\Google\Chrome
Value name
TotalMemoryLimitMb
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Configures the amount of memory that a single Google Chrome instance can use before tabs start being discarded (I.E. the memory used by the tab will be freed and the tab will have to be reloaded when switched to) to save memory. If the policy is set, browser will begin to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024. If this policy is not set, the browser will only begin attempts to save memory once it has detected that the amount of physical memory on its machine is low.
RelaunchWindow  Set the time interval for relaunch
String Machine + User
If this policy is not set, the default target time window for Google ChromeOS is between 2 AM and 4 AM.
Registry key
Software\Policies\Google\Chrome
Value name
RelaunchWindow
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Specify a target time window for the end of the relaunch notification period. Users are notified of the need for a browser relaunch or device restart based on the RelaunchNotification and RelaunchNotificationPeriod policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the RelaunchNotification policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window. If this policy is not set, the default target time window for Google ChromeOS is between 2 AM and 4 AM. The default target time window for Google Chrome is the whole day (i.e., the end of the notification period is never deferred). Note: Though the policy can accept multiple items in entries, all but the first item are ignored. Warning: Setting this policy may delay application of software updates. See https://chromeenterprise.google/policies/?policy=RelaunchWindow for more information about schema and formatting. Example value: { "entries": [ { "duration_mins": 240, "start": { "hour": 2, "minute": 15 } } ] }
RelaunchNotificationPeriod  Set the time period for update notifications
Integer Machine + User
If not set, the default period of 604800000 milliseconds (one week) is used.
Registry key
Software\Policies\Google\Chrome
Value name
RelaunchNotificationPeriod
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set the time period, in milliseconds, over which users are notified that Google Chrome must be relaunched or that a Google ChromeOS device must be restarted to apply a pending update. Over this time period, the user will be repeatedly informed of the need for an update. For Google ChromeOS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Google Chrome browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the RelaunchNotification policy follow this same schedule. If not set, the default period of 604800000 milliseconds (one week) is used.
UserDataDir  Set user data directory
String Machine + User
If this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag.
Registry key
Software\Policies\Google\Chrome
Value name
UserDataDir
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Configures the directory that Google Chrome will use for storing user data. If you set this policy, Google Chrome will use the provided directory regardless whether the user has specified the '--user-data-dir' flag or not. To avoid data loss or other unexpected errors this policy should not be set to a directory used for other purposes, because Google Chrome manages its contents. See https://support.google.com/chrome/a?p=Supported_directory_variables for a list of variables that can be used. If this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag. Example value: ${users}/${user_name}/Chrome
ManagedConfigurationPerOrigin  Sets managed configuration values to websites to specific origins
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ManagedConfigurationPerOrigin
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy defines the return value of Managed Configuration API for given origin. Managed configuration API is a key-value configuration that can be accessed via navigator.managed.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via WebAppInstallForceList. See https://chromeenterprise.google/policies/?policy=ManagedConfigurationPerOrigin for more information about schema and formatting. Example value: [ { "managed_configuration_hash": "asd891jedasd12ue9h", "managed_configuration_url": "https://gstatic.google.com/configuration.json", "origin": "https://www.google.com" }, { "managed_configuration_hash": "djio12easd89u12aws", "managed_configuration_url": "https://gstatic.google.com/configuration2.json", "origin": "https://www.example.com" } ]
NTPShortcuts  Setting shortcuts on the New Tab Page
String Machine + User
If set to false or unset, users cannot edit the name. If set to false or unset, users cannot remove the shortcut.
Registry key
Software\Policies\Google\Chrome
Value name
NTPShortcuts
Stated default
If set, users will see these shortcuts by default, in addition to their personal shortcuts.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy pre-configures up to 10 custom shortcuts on the Google Chrome New Tab page. If set, users will see these shortcuts by default, in addition to their personal shortcuts. Users can control visibility of their organization's shortcuts on the "Customize Chrome" panel. Shortcut URLs must be unique. If allow_user_edit is set to true, users can change the name of the shortcut. If set to false or unset, users cannot edit the name. If allow_user_delete is set to true, users can remove the shortcut. If set to false or unset, users cannot remove the shortcut. See https://chromeenterprise.google/policies/?policy=NTPShortcuts for more information about schema and formatting. Example value: [ { "name": "Google", "url": "https://www.google.com" }, { "name": "YouTube", "url": "https://www.youtube.com" }, { "name": "Google Drive", "url": "https://www.drive.google.com", "allow_user_edit": true, "allow_user_delete": true } ]
HistoryClustersVisible  Show a view of Chrome history with groups of pages
Boolean Machine + User
If the policy is left unset, a Chrome history page organized into groups will be visible at chrome://history/grouped by default. Please note, if ComponentUpdatesEnabled policy is set to Disabled, but HistoryClustersVisible is set to Enabled or unset, a Chrome history page organized into groups will still be available at chrome://history/grouped, but may be less relevant to the user.
Registry key
Software\Policies\Google\Chrome
Value name
HistoryClustersVisible
Enabled / Disabled
1 / 0
Stated default
If the policy is left unset, a Chrome history page organized into groups will be visible at chrome://history/grouped by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the visibility of the Chrome history page organized into groups of pages. If the policy is set to Enabled, a Chrome history page organized into groups will be visible at chrome://history/grouped. If the policy is set to Disabled, a Chrome history page organized into groups will not be visible at chrome://history/grouped. If the policy is left unset, a Chrome history page organized into groups will be visible at chrome://history/grouped by default. Please note, if ComponentUpdatesEnabled policy is set to Disabled, but HistoryClustersVisible is set to Enabled or unset, a Chrome history page organized into groups will still be available at chrome://history/grouped, but may be less relevant to the user.
ExternalProtocolDialogShowAlwaysOpenCheckbox  Show an "Always open" checkbox in external protocol dialog.
Boolean Machine + User
If this policy is set to True or not set, when an external protocol confirmation is shown, the user can select "Always allow" to skip all future confirmation prompts for the protocol on this site.
Registry key
Software\Policies\Google\Chrome
Value name
ExternalProtocolDialogShowAlwaysOpenCheckbox
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether or not the "Always open" checkbox is shown on external protocol launch confirmation prompts. If this policy is set to True or not set, when an external protocol confirmation is shown, the user can select "Always allow" to skip all future confirmation prompts for the protocol on this site. If this policy is set to False, the "Always allow" checkbox is not displayed and the user will be prompted each time an external protocol is invoked.
NTPCardsVisible  Show cards on the New Tab Page
Boolean Machine + User
If the policy is not set, the user can control the card visibility.
Registry key
Software\Policies\Google\Chrome
Value name
NTPCardsVisible
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the visibility of cards on the New Tab Page. Cards surface entry points to launch common user journeys based on the user's browsing behavior. If the policy is set to Enabled, the New Tab Page will show cards if content is available. If the policy is set to Disabled, the New Tab Page won't show cards. If the policy is not set, the user can control the card visibility. The default is visible.
ShowFullUrlsInAddressBar  Show Full URLs
Boolean Machine + User
If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
Registry key
Software\Policies\Google\Chrome
Value name
ShowFullUrlsInAddressBar
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This feature enables display of the full URL in the address bar. If this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains. If this policy is set to False, then the default URL display will apply. If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
NTPOutlookCardVisible  Show Outlook Calendar card on the New Tab Page
Boolean Machine + User
If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
Registry key
Software\Policies\Google\Chrome
Value name
NTPOutlookCardVisible
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the visibility of the Outlook Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the Outlook Calendar data in the browser. Outlook data will not be stored by the browser. The Outlook card shows the next calendar event, along with a glanceable look at the rest of the day's meetings. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their next meeting. The Microsoft Outlook card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Outlook, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards. If the NTPCardsVisible is disabled, the Outlook Card will not be shown. If NTPCardsVisible is enabled, the Outlook card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
NTPSharepointCardVisible  Show SharePoint and OneDrive File Card on the New Tab Page
Boolean Machine + User
If NTPCardsVisible is unset, the SharePoint and OneDrive card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
Registry key
Software\Policies\Google\Chrome
Value name
NTPSharepointCardVisible
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the visibility of the SharePoint and OneDrive File Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the SharePoint and OneDrive File data in the browser. SharePoint and OneDrive data will not be stored by the browser. The SharePoint and OneDrive Files recommendation card shows a list of recommended files. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their most important documents. The Microsoft SharePoint and OneDrive card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Sharepoint, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards. If the NTPCardsVisible is disabled, the SharePoint and OneDrive Card will not be shown. If NTPCardsVisible is enabled, the SharePoint and OneDrive card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the SharePoint and OneDrive card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.
ShowAppsShortcutInBookmarkBar  Show the apps shortcut in the bookmark bar
Boolean Machine + User
If not set, users decide to show or hide the apps shortcut from the bookmark bar context menu.
Registry key
Software\Policies\Google\Chrome
Value name
ShowAppsShortcutInBookmarkBar
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True displays the apps shortcut. Setting the policy to False means this shortcut never appears. If you set the policy, users can't change it. If not set, users decide to show or hide the apps shortcut from the bookmark bar context menu.
NTPMiddleSlotAnnouncementVisible  Show the middle slot announcement on the New Tab Page
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
NTPMiddleSlotAnnouncementVisible
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the visibility of the middle slot announcement on the New Tab Page. If the policy is set to Enabled, the New Tab Page will show the middle slot announcement if it is available. If the policy is set to Disabled, the New Tab Page will not show the middle slot announcement even if it is available.
SiteSearchSettings  Site search settings
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SiteSearchSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy provides a list of sites that users can quickly search using shortcuts in the address bar. Users can initiate a search by typing the shortcut or @shortcut (e.g. @work), followed by Space or Tab, in the address bar. The following fields are required for each site: name, shortcut, url. The name field corresponds to the site or search engine name to be shown to the user in the address bar. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must also be unique. For each entry, the url field specifies the URL of the search engine used during a search with the corresponding keyword. The URL must include the string '{searchTerms}', replaced in the query by the user's search terms. Invalid entries and entries with duplicate shortcuts are ignored. Site search entries configured as featured are displayed in the address bar when the user types "@". Up to three entries can be selected as featured. For a site search entry where allow_user_override is true, users have the ability to edit or disable that entry. However, featured engines (beginning with "@") can only be disabled. If a user modifies an entry that was initially created by this policy, it will no longer be managed by policy and will be treated like a user-created shortcut. When allow_user_override is false or unspecified for a site search entry, users cannot edit or disable that entry. The setting to allow user override is only supported on M139 and later; earlier versions will default to disabling user override. Users cannot create new site search entries with a shortcut previously created via this policy unless allow_user_override is set to true for the site search entry. In case of a conflict with a shortcut previously created by the user, the user setting takes precedence. However, users can still trigger the option created by the policy by typing "@" in the search bar. For example, if the user already defined "work" as a shortcut to URL1 and the policy defines "work" as a shortcut to URL2, then typing "work" in the search bar will trigger a search to URL1, but typing "@work" in the search bar will trigger a search to URL2. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. See https://chromeenterprise.google/policies/?policy=SiteSearchSettings for more information about schema and formatting. Example value: [ { "featured": true, "name": "Google Wikipedia", "shortcut": "wikipedia", "url": "https://www.google.com/search?q=site%3Awikipedia.com+%s" }, { "name": "YouTube", "shortcut": "youtube", "url": "https://www.youtube.com/results?search_query=%s" }, { "name": "Google Drive", "shortcut": "drive", "url": "https://drive.google.com/?q=%s", "allow_user_override": true } ]
FeedbackSurveysEnabled  Specifies whether in-product Google Chrome surveys are shown to users.
Boolean Machine + User
When this policy is Enabled or not set, in-product surveys may be shown to users.
Registry key
Software\Policies\Google\Chrome
Value name
FeedbackSurveysEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Google Chrome in-product surveys collect user feedback for the browser. Survey responses are not associated with user accounts. When this policy is Enabled or not set, in-product surveys may be shown to users. When this policy is Disabled, in-product surveys are not shown to users. This policy has no effect if MetricsReportingEnabled is set to Disabled, which disables in-product surveys as well.
SharedArrayBufferUnrestrictedAccessAllowed  Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context
Boolean Machine + User
When set to Disabled or not set, sites can only use SharedArrayBuffers when cross-origin isolated.
Registry key
Software\Policies\Google\Chrome
Value name
SharedArrayBufferUnrestrictedAccessAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. Google Chrome will require cross-origin isolation when using SharedArrayBuffers from Google Chrome 91 onward (2021-05-25) for Web Compatibility reasons. Additional details can be found on: https://developer.chrome.com/blog/enabling-shared-array-buffer/. When set to Enabled, sites can use SharedArrayBuffer with no restrictions. When set to Disabled or not set, sites can only use SharedArrayBuffers when cross-origin isolated.
DnsOverHttpsTemplates  Specify URI template of desired DNS-over-HTTPS resolver
String Machine + User
If the DnsOverHttpsMode is set to "automatic" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.
Registry key
Software\Policies\Google\Chrome
Value name
DnsOverHttpsTemplates
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces. If the DnsOverHttpsMode is set to "secure" then this policy must be set and not empty. On Google ChromeOS only, either this policy or the DnsOverHttpsTemplatesWithIdentifiers must be set, otherwise the DNS resolution will fail. If the DnsOverHttpsMode is set to "automatic" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider. If the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST. Incorrectly formatted templates will be ignored. Example value: https://dns.example.net/dns-query{?dns}
SuppressDifferentOriginSubframeDialogs  Suppress JavaScript Dialogs triggered from different origin subframes
Boolean Machine + User
If the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.
Registry key
Software\Policies\Google\Chrome
Value name
SuppressDifferentOriginSubframeDialogs
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin. This policy allows overriding that change. If the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked. If the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked. This policy will be removed from Google Chrome in the future.
LookalikeWarningAllowlistDomains  Suppress lookalike domain warnings on domains
List (values under a subkey) Machine + User
If the policy is not set, or set to an empty list, warnings may appear on any site the user visits.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LookalikeWarningAllowlistDomains
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with. If the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain. If the policy is not set, or set to an empty list, warnings may appear on any site the user visits. A hostname can be allowed with a complete host match, or any domain match. For example, a URL like "https://foo.example.com/bar" may have warnings suppressed if this list includes either "foo.example.com" or "example.com". Example value: foo.example.com example.org
SuppressUnsupportedOSWarning  Suppress the unsupported OS warning
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.
Registry key
Software\Policies\Google\Chrome
Value name
SuppressUnsupportedOSWarning
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled suppresses the warning that appears when Google Chrome is running on an unsupported computer or operating system. Setting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.
CloudManagementEnrollmentToken  The enrollment token of cloud policy
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CloudManagementEnrollmentToken
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy means Google Chrome tries to register itself with Chrome Enterprise Core browser management. The value of this policy is an enrollment token you can retrieve from the Google Admin console. See https://support.google.com/chrome/a/answer/9301891 for details. Example value: 37185d02-e055-11e7-80c1-9a214cf093ae
CacheEncryptionEnabled  This policy allows administrators to encrypt http cache on disk.
Boolean Machine + User
When this policy is Disabled or not set, browser cache will not be encrypted.
Registry key
Software\Policies\Google\Chrome
Value name
CacheEncryptionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows the administrators to encrypt browser http cache on disk. When this policy is Enabled, browser cache will be encrypted. When this policy is Disabled or not set, browser cache will not be encrypted. Browser cache encryption may result in a performance impact.
TabDiscardingExceptions  URL pattern Exceptions to tab discarding
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\TabDiscardingExceptions
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser. This applies to memory pressure and high efficiency mode discarding. A discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload. Example value: example.com https://* *
WebRtcLocalIpsAllowedUrls  URLs for which local IPs are exposed in WebRTC ICE candidates
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebRtcLocalIpsAllowedUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Patterns in this list will be matched against the security origin of the requesting URL. If a match is found or chrome://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, the local IP addresses are shown in WebRTC ICE candidates. Otherwise, local IP addresses are concealed with mDNS hostnames. Please note that this policy weakens the protection of local IPs if needed by administrators. Example value: https://www.example.com *example.com*
AudioCaptureAllowedUrls  URLs that will be granted access to audio capture devices without prompt
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AudioCaptureAllowedUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to audio capture devices without prompt For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. Note, however, that the pattern "*", which matches any URL, is not supported by this policy. Example value: https://www.example.com/ https://[*.]example.edu/
VideoCaptureAllowedUrls  URLs that will be granted access to video capture devices without prompt
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\VideoCaptureAllowedUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to video capture devices without prompt For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. Note, however, that the pattern "*", which matches any URL, is not supported by this policy. Example value: https://www.example.com/ https://[*.]example.edu/
AutoOpenAllowedForURLs  URLs where AutoOpenFileTypes can apply
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutoOpenAllowedForURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of URLs specifying which urls AutoOpenFileTypes will apply to. This policy has no impact on automatically open values set by users. If this policy is set, files will only automatically open by policy if the url is part of this set and the file type is listed in AutoOpenFileTypes. If either condition is false the download won't automatically open by policy. If this policy isn't set, all downloads where the file type is in AutoOpenFileTypes will automatically open. A URL pattern has to be formatted according to https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
SecurityKeyPermitAttestation  URLs/domains automatically permitted direct Security Key attestation
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SecurityKeyPermitAttestation
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies WebAuthn RP IDs for which no prompt appears when attestation certificates from security keys are requested. A signal is also sent to the security key indicating that enterprise attestation may be used. Without this, when sites request attestation of security keys, users are prompted in Google Chrome version 65 and later. Example value: example.com
BuiltInDnsClientEnabled  Use built-in DNS client
Boolean Machine + User
If this policy is set to Enabled or is left unset, the built-in DNS client will be used.
Registry key
Software\Policies\Google\Chrome
Value name
BuiltInDnsClientEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls which software stack is used to communicate with the DNS server: the Operating System DNS client, or Google Chrome's built-in DNS client. This policy does not affect which DNS servers are used: if, for example, the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It also does not control if DNS-over-HTTPS is used; Google Chrome will always use the built-in resolver for DNS-over-HTTPS requests. Please see the DnsOverHttpsMode policy for information on controlling DNS-over-HTTPS. If this policy is set to Enabled or is left unset, the built-in DNS client will be used. If this policy is set to Disabled, the built-in DNS client will only be used when DNS-over-HTTPS is in use.
HardwareAccelerationModeEnabled  Use graphics acceleration when available
Boolean Machine + User
Setting the policy to Enabled or leaving it unset turns on graphics acceleration, if available.
Registry key
Software\Policies\Google\Chrome
Value name
HardwareAccelerationModeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset turns on graphics acceleration, if available. Setting the policy to Disabled turns off graphics acceleration.
PdfViewerOutOfProcessIframeEnabled  Use out-of-process iframe PDF Viewer
Boolean Machine + User
When this policy is set to Enabled or not set, Google Chrome will be able to use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Google Chrome.
Registry key
Software\Policies\Google\Chrome
Value name
PdfViewerOutOfProcessIframeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls whether the PDF viewer in Google Chrome uses an out-of-process iframe (OOPIF). This will be the new PDF viewer architecture in the future, as it is simpler and makes adding new features easier. The existing GuestView PDF viewer is an outdated, complex architecture that is being deprecated. When this policy is set to Enabled or not set, Google Chrome will be able to use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Google Chrome. When this policy is set to Disabled, Google Chrome will strictly use the existing GuestView PDF viewer. It embeds a web page with a separate frame tree into another web page. This policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.
PdfUseSkiaRendererEnabled  Use Skia renderer for PDF rendering
Boolean Machine + User
When this policy is not set, the PDF renderer will be chosen by the browser.
Registry key
Software\Policies\Google\Chrome
Value name
PdfUseSkiaRendererEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls whether the PDF viewer in Google Chrome uses Skia renderer. When this policy is enabled, the PDF viewer uses Skia renderer. When this policy is disabled, the PDF viewer uses its current AGG renderer. When this policy is not set, the PDF renderer will be chosen by the browser.
WebAppSettings  Web App management settings
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebAppSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy. The manifest_id field is the Manifest ID for the Web App. See https://developer.chrome.com/blog/pwa-manifest-id/ for instructions on how to determine the Manifest ID for an installed web app. The run_on_os_login field specifies if a web app can be run during OS login. If this field is set to blocked, the web app will not run during OS login and the user will not be able to enable this later. If this field is set to run_windowed, the web app will run during OS login and the user will not be able to disable this later. If this field is set to allowed, the user will be able to configure the web app to run at OS login. The default configuration only allows the allowed and blocked values. (Since version 117) The prevent_close_after_run_on_os_login field specifies if a web app shall be prevented from closing in any way (e.g. by the user, task manager, web APIs). This behavior can only be enabled if run_on_os_login is set to run_windowed. If the app were already running, this property will only come into effect after the app is restarted. If this field is not defined, apps will be closable by users. (Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, i.e. shortcuts, file handlers, protocol handlers etc will be removed or not. If an app is already running, this property will come into effect after the app has restarted. This should be used with caution, since this can override any OS integration that is set automatically during the startup of the web applications system. Currently only works on Windows, Mac and Linux platforms. See https://chromeenterprise.google/policies/?policy=WebAppSettings for more information about schema and formatting. Example value: [ { "manifest_id": "https://foo.example/index.html", "run_on_os_login": "allowed" }, { "manifest_id": "https://bar.example/index.html", "run_on_os_login": "allowed" }, { "manifest_id": "https://foobar.example/index.html", "run_on_os_login": "run_windowed", "prevent_close_after_run_on_os_login": true }, { "manifest_id": "*", "run_on_os_login": "blocked" }, { "manifest_id": "https://foo.example/index.html", "force_unregister_os_integration": true } ]
Google:Cat_Google / Google Chrome - Default Settings (users can override)
DefaultSearchProviderContextMenuAccessAllowed  Allow default search provider context menu search access
Boolean Machine + User
If this policy is set to enabled or not set, the context menu item for your default search provider will be available.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderContextMenuAccessAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enables the use of a default search provider on the context menu. If you set this policy to disabled the search context menu item that relies on your default search provider will not be available. If this policy is set to enabled or not set, the context menu item for your default search provider will be available. The policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.
DownloadRestrictions  Allow download restrictions
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DownloadRestrictions
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0No special restrictions. Default.
1Block malicious downloads and dangerous file types.
2Block malicious downloads, uncommon or unwanted downloads and dangerous file types.
3Block all downloads.
4Block malicious downloads. Recommended.
Setting the policy means users can't bypass download security decisions. There are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked): * Malicious, as flagged by the Safe Browsing server * Uncommon or unwanted, as flagged by the Safe Browsing server * A dangerous file type (e.g. all SWF downloads and many EXE downloads) Setting the policy blocks different subsets of these, depending on it's value: 0: No special restrictions. Default. 1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives. 3: Blocks all downloads. Not recommended, except for special use cases. 4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended. Note: These restrictions apply to downloads triggered from webpage content, as well as the Download link… menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).
HttpsOnlyMode  Allow HTTPS-Only Mode to be enabled
Enum Machine + User
If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
HttpsOnlyMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Do not restrict users' HTTPS-Only Mode setting
Disable HTTPS-Only Mode
Enable HTTPS-Only Mode in Strict mode
Enable HTTPS-Only Mode in Balanced Mode
This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode upgrades all navigations to HTTPS. If this setting is not set or set to "allowed", users will be allowed to enable HTTPS-Only Mode. If this setting is set to "disallowed", HTTPS-Only Mode will be disabled. If this setting is set to "force_enabled", HTTPS-Only Mode will be enabled in Strict mode. If this setting is set to "force_balanced_enabled", HTTPS-Only Mode will be enabled in Balanced mode. "force_enabled" is supported from M112 onwards, "force_balanced_enabled" is supported from M129 onwards. "force_enabled" and "force_balanced_enabled" can be recommended to users too. HTTPS-Only Mode will be set Strict or Balanced initially but users are allowed to change it. If you set this policy to a value that is not supported by the version of Chrome that receives the policy, Chrome will default to the allowed setting. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. Example value: disallowed
DomainReliabilityAllowed  Allow reporting of domain reliability related data
Boolean Machine + User
If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DomainReliabilityAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google. If this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.
AlwaysOpenPdfExternally  Always Open PDF files externally
Boolean Machine + User
If not set, users can choose whether to open PDF externally or not.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
AlwaysOpenPdfExternally
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application. Setting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files. If you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.
ApplicationLocaleValue  Application locale
String Machine + User
Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured).
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ApplicationLocaleValue
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the locale Google Chrome uses. Turning it off or leaving it unset means the locale will be the first valid locale from: 1) The user specified locale (if configured). 2) The system locale. 3) The fallback locale (en-US). Example value: en
BlockThirdPartyCookies  Block third party cookies
Boolean Machine + User
Leaving it unset allows third-party cookies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
BlockThirdPartyCookies
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting. Leaving it unset allows third-party cookies, but users can change this setting. Note: This policy doesn't apply in Incognito mode, where third-party cookies are blocked and can only be allowed at the site level. To allow cookies at the site level, use the CookiesAllowedForUrls policy.
BackgroundModeEnabled  Continue running background apps when Google Chrome is closed
Boolean Machine + User
If unset, background mode is off at first, but users can change it.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
BackgroundModeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there. Setting the policy to Disabled turns background mode off. If you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.
AutofillAddressEnabled  Enable AutoFill for addresses
Boolean Machine + User
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
AutofillAddressEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI. Setting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.
AutofillCreditCardEnabled  Enable AutoFill for credit cards
Boolean Machine + User
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
AutofillCreditCardEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI. Setting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.
BatterySaverModeAvailability  Enable Battery Saver Mode
Enum Machine + User
If this policy is unset, the end user can control this setting in chrome://settings/performance.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
BatterySaverModeAvailability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Battery Saver Mode will be disabled.
1Battery Saver Mode will be enabled when the device is on battery power and battery level is low.
2This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.
This policy enables or disables the Battery Saver Mode setting. On Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance. On ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off. The different levels are: Disabled (0): Battery Saver Mode will be disabled. EnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low. EnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.
BookmarkBarEnabled  Enable Bookmark Bar
Boolean Machine + User
If not set, users decide whether to use this function.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
BookmarkBarEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar. If you set the policy, users can't change it. If not set, users decide whether to use this function.
NetworkPredictionOptions  Enable network prediction
Enum Machine + User
Leaving it unset turns on network prediction, but the user can change it.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
NetworkPredictionOptions
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Predict network actions on any network connection
1Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)
2Do not predict network actions on any network connection
This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages. If you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.
SpellCheckServiceEnabled  Enable or disable spell checking web service
Boolean Machine + User
Leaving the policy unset lets users choose whether to use the spellcheck service.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
SpellCheckServiceEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used. Leaving the policy unset lets users choose whether to use the spellcheck service. The spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.
OriginKeyedProcessesEnabled  Enable origin-keyed process isolation by default.
Boolean Machine + User
, those assigned to an origin-keyed agent cluster by default).
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
OriginKeyedProcessesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enables origin-keyed process isolation for most pages (i.e., those assigned to an origin-keyed agent cluster by default). This improves security but also increases the number of processes created. Users are allowed to override the set policy value via the command-line flags or chrome://flags (both to turn this feature on or off). Setting the policy to Enabled results in most origins being isolated, even from other origins in the same site. See also the IsolateOrigins and SitePerProcess policies. Setting the policy to Disabled results in no origins being isolated from the rest of their site unless an origin explicitly asks to. Not setting the policy results in the browser determining which origins to isolate and when to isolate them.
MetricsReportingEnabled  Enable reporting of usage and crash-related data
Boolean Machine + User
When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
MetricsReportingEnabled
Enabled / Disabled
1 / 0
Stated default
When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When this policy is Enabled, anonymous reporting of usage and crash-related data about Google Chrome to Google is recommended to be enabled by default. Users will still be able to change this setting. When this policy is Disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting. When this policy is not set, users can choose the anonymous reporting behavior at installation or first run, and can change this setting later. (For Google ChromeOS, see DeviceMetricsReportingEnabled.) On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
SearchSuggestEnabled  Enable search suggestions
Boolean Machine + User
If not set, search suggestions are on at first, but users can turn them off any time.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
SearchSuggestEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions. Suggestions based on bookmarks or history are unaffected by the policy. If you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.
TranslateEnabled  Enable Translate
Boolean Machine + User
Leaving it unset lets them change the setting.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
TranslateEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features. If you set the policy, users can't change this function. Leaving it unset lets them change the setting.
ImportAutofillFormData  Import autofill form data from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ImportAutofillFormData
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run. Users can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.
ImportBookmarks  Import bookmarks from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ImportBookmarks
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run. Users can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.
ImportHistory  Import browsing history from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ImportHistory
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run. Users can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.
ImportSavedPasswords  Import saved passwords from default browser on first run
Boolean Machine + User
Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ImportSavedPasswords
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls only the first run import behavior after installation. It enables more seamless transition to Google Chrome in environments where a different browser was extensively used prior to installing the browser. This policy does not affect password manager capabilities for Google accounts. Setting the policy to Enabled imports saved passwords from the previous default browser on first run and manual importing from the settings page is also possible. Setting the policy to Disabled means no saved passwords are imported on first run and manual importing from the Settings page is blocked. Leaving the policy unset means no saved passwords are imported on first run but the user can choose to do that from the settings page.
ImportSearchEngine  Import search engines from default browser on first run
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ImportSearchEngine
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run. Users can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.
EnterpriseProfileCreationKeepBrowsingData  Keep browsing data when creating enterprise profile by default
Boolean Machine + User
If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
EnterpriseProfileCreationKeepBrowsingData
Enabled / Disabled
1 / 0
Stated default
If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default. If this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default. Regardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile. This policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.
DefaultDownloadDirectory  Set default download directory
String Machine + User
Leaving the policy unset means Chrome uses its platform-specific default directory.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultDownloadDirectory
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory. Leaving the policy unset means Chrome uses its platform-specific default directory. This policy has no effect if the policy DownloadDirectory is set. Note: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: /home/${user_name}/Downloads
DownloadDirectory  Set download directory
String Machine + User
Leaving the policy unset means Chrome uses the default download directory, and users can change it.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DownloadDirectory
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time. This policy overrides the DefaultDownloadDirectory policy. Leaving the policy unset means Chrome uses the default download directory, and users can change it. On Google ChromeOS it's possible to set it only to Google Drive directories. Note: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ). Example value: /home/${user_name}/Downloads
ShowFullUrlsInAddressBar  Show Full URLs
Boolean Machine + User
If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ShowFullUrlsInAddressBar
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This feature enables display of the full URL in the address bar. If this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains. If this policy is set to False, then the default URL display will apply. If this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Accessibility settings
LiveCaptionEnabled  Enable Live Caption
Boolean Machine + User
If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
LiveCaptionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enable the Live Caption feature. If this policy is set to Enabled, Live Caption will always be turned on. If this policy is set to Disabled, Live Caption will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
LiveTranslateEnabled  Enable Live Translate
Boolean Machine + User
If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
LiveTranslateEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enable translation of live captions. Captions will be sent to Google for translation. If this policy is set to Enabled, Live Translate will always be turned on. If this policy is set to Disabled, Live Translate will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime. In LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Content settings
RegisteredProtocolHandlers  Register protocol handlers
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
RegisteredProtocolHandlers
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy (as recommended only) lets you register a list of protocol handlers, which merge with the ones that the user registers, putting both sets in use. Set the property "protocol" to the scheme, such as "mailto", and set the property "URL" to the URL pattern of the application that handles the scheme specified in the "protocol" field. The pattern can include a "%s" placeholder, which the handled URL replaces. Users can't remove a protocol handler registered by policy. However, by installing a new default handler, they can change the protocol handlers installed by policy. See https://chromeenterprise.google/policies/?policy=RegisteredProtocolHandlers for more information about schema and formatting. Example value: [ { "default": true, "protocol": "mailto", "url": "https://mail.google.com/mail/?extsrc=mailto&url=%s" } ]
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Default search provider
DefaultSearchProviderEncodings_recommended  Default search provider encodings
List (values under a subkey) Machine + User
Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use.
Registry key
Software\Policies\Google\Chrome\Recommended
List subkey
Software\Policies\Google\Chrome\Recommended\DefaultSearchProviderEncodings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided. Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use. Example value: UTF-8 UTF-16 GB2312 ISO-8859-1
DefaultSearchProviderKeyword  Default search provider keyword
String Machine + User
Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderKeyword
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider. Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider. Example value: mis
DefaultSearchProviderName  Default search provider name
String Machine + User
Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderName
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name. Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used. Example value: My Intranet Search
DefaultSearchProviderNewTabURL  Default search provider new tab page URL
String Machine + User
Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderNewTabURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page. Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided. Example value: https://search.my.company/newtab
DefaultSearchProviderSearchURL  Default search provider search URL
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderSearchURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'. Example value: https://search.my.company/search?q={searchTerms}
DefaultSearchProviderSuggestURL  Default search provider suggest URL
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderSuggestURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'. Example value: https://search.my.company/suggest?q={searchTerms}
DefaultSearchProviderEnabled  Enable the default search provider
Boolean Machine + User
If not set, the default search provider is on, and users can set the search provider list.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar. The Disabled value is not supported by the Google Admin console. If you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
DefaultSearchProviderAlternateURLs_recommended  List of alternate URLs for the default search provider
List (values under a subkey) Machine + User
Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.
Registry key
Software\Policies\Google\Chrome\Recommended
List subkey
Software\Policies\Google\Chrome\Recommended\DefaultSearchProviderAlternateURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'. Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms. Example value: https://search.my.company/suggest#q={searchTerms} https://search.my.company/suggest/search#q={searchTerms}
DefaultSearchProviderImageURL  Parameter providing search-by-image feature for the default search provider
String Machine + User
) Leaving DefaultSearchProviderImageURL unset means no image search is used.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderImageURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.) Leaving DefaultSearchProviderImageURL unset means no image search is used. If image search uses the GET method, then the URL must specify image parameters using a valid combination of the following placeholders: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: https://search.my.company/searchbyimage/upload
DefaultSearchProviderImageURLPostParams  Parameters for image URL which uses POST
String Machine + User
Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderImageURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it. Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method. The URL must specify the image parameter using a valid combination of the following placeholders depending on what the search provider supports: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: content={google:imageThumbnail},url={google:imageURL},sbisrc={google:imageSearchSource}
DefaultSearchProviderSearchURLPostParams  Parameters for search URL which uses POST
String Machine + User
Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderSearchURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
DefaultSearchProviderSuggestURLPostParams  Parameters for suggest URL which uses POST
String Machine + User
Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderSuggestURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Deprecated policies
AutoFillEnabled  Enable AutoFill
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
AutoFillEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingEnabled  Enable Safe Browsing
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
SafeBrowsingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Password manager
PasswordManagerEnabled  Enable saving passwords to the password manager
Boolean Machine + User
If not set, the user can turn off password saving.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
PasswordManagerEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the browser's ability to automatically remember passwords on websites and save them in the built-in password manager. It does not limit access or change the contents of passwords saved in the password manager and possibly synchronized to the Google account profile and Android. Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site. Setting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work. If the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Printing
PrintHeaderFooter  Print Headers and Footers
Boolean Machine + User
If unset, users decides whether headers and footers appear.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
PrintHeaderFooter
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview. If you set the policy, users can't change it. If unset, users decides whether headers and footers appear.
PrintPreviewUseSystemDefaultPrinter  Use System Default Printer as Default
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
PrintPreviewUseSystemDefaultPrinter
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview. Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Removed policies
ClearSiteDataOnExit  Clear site data on browser shutdown (deprecated)
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ClearSiteDataOnExit
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderIconURL  Default search provider icon
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderIconURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURL  Default search provider instant URL
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderInstantURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InstantEnabled  Enable Instant
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
InstantEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DnsPrefetchingEnabled  Enable network prediction
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DnsPrefetchingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderSearchTermsReplacementKey  Parameter controlling search term placement for the default search provider
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderSearchTermsReplacementKey
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURLPostParams  Parameters for instant URL which uses POST
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
DefaultSearchProviderInstantURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Safe Browsing settings
SafeBrowsingProtectionLevel  Safe Browsing Protection Level
Enum Machine + User
If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
SafeBrowsingProtectionLevel
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Safe Browsing is never active.
1Safe Browsing is active in the standard mode.
2Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.
Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in. If this policy is set to 'NoProtection' (value 0), Safe Browsing is never active. If this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode. If this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google. If you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome. If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting. See https://support.google.com/chrome?p=safe_browsing_preferences for more info on Safe Browsing.
Google:Cat_Google / Google Chrome - Default Settings (users can override) / Startup, Home page and New Tab page
RestoreOnStartup  Action on startup
Enum Machine + User
Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If not set, users can change it.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
RestoreOnStartup
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
5Open New Tab Page
1Restore the last session
4Open a list of URLs
6Open a list of URLs and restore the last session
Setting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If you set the policy, users can't change it in Google Chrome. If not set, users can change it. Setting this policy to RestoreOnStartupIsLastSession or RestoreOnStartupIsLastSessionAndURLs turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies. If this policy is set to RestoreOnStartupIsLastSessionAndURLs, browser will restore previous session and open a separate window to show URLs that are set from RestoreOnStartupURLs. Note that users can choose to keep those URLs open and they will also be restored in the future session. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
HomepageLocation  Configure the home page URL
String Machine + User
Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
HomepageLocation
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup. If the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect. The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome. Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://www.chromium.org
ShowHomeButton  Show Home button on toolbar
Boolean Machine + User
If not set, users chooses whether to show the Home button.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
ShowHomeButton
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing. If you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.
RestoreOnStartupURLs_recommended  URLs to open on startup
List (values under a subkey) Machine + User
If not set, the New Tab page opens on start up.
Registry key
Software\Policies\Google\Chrome\Recommended
List subkey
Software\Policies\Google\Chrome\Recommended\RestoreOnStartupURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open. If not set, the New Tab page opens on start up. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://example.com https://www.chromium.org
HomepageIsNewTabPage  Use New Tab Page as homepage
Boolean Machine + User
If not set, the user decides whether or not the New Tab page is their homepage.
Registry key
Software\Policies\Google\Chrome\Recommended
Value name
HomepageIsNewTabPage
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab. If you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
Google:Cat_Google / Google Chrome / Accessibility settings
LiveCaptionEnabled  Enable Live Caption
Boolean Machine + User
If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
Registry key
Software\Policies\Google\Chrome
Value name
LiveCaptionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enable the Live Caption feature. If this policy is set to Enabled, Live Caption will always be turned on. If this policy is set to Disabled, Live Caption will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.
LiveTranslateEnabled  Enable Live Translate
Boolean Machine + User
If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.
Registry key
Software\Policies\Google\Chrome
Value name
LiveTranslateEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enable translation of live captions. Captions will be sent to Google for translation. If this policy is set to Enabled, Live Translate will always be turned on. If this policy is set to Disabled, Live Translate will always be turned off. If you set this policy as mandatory, users cannot change or override it. If this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime. In LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.
Google:Cat_Google / Google Chrome / Allow or deny screen capture
ScreenCaptureAllowedByOrigins  Allow Desktop, Window, and Tab capture by these origins
List (values under a subkey) Machine + User
Leaving the policy unset means that sites will not be considered for an override at this level of Capture.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ScreenCaptureAllowedByOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture. Leaving the policy unset means that sites will not be considered for an override at this level of Capture. This policy is not considered if a site matches a URL pattern in any of the following policies: WindowCaptureAllowedByOrigins, TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins. If a site matches a URL pattern in this policy, the ScreenCaptureAllowed will not be considered. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
ScreenCaptureAllowed  Allow or deny screen capture
Boolean Machine + User
If enabled or not configured (default), a Web page can use screen-share APIs (e.
Registry key
Software\Policies\Google\Chrome
Value name
ScreenCaptureAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If enabled or not configured (default), a Web page can use screen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API) to prompt the user to select a tab, window or desktop to capture. When this policy is disabled, any calls to screen-share APIs will fail with an error; however this policy is not considered (and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies: ScreenCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins.
SameOriginTabCaptureAllowedByOrigins  Allow Same Origin Tab capture by these origins
List (values under a subkey) Machine + User
Leaving the policy unset means that sites will not be considered for an override at this level of capture.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SameOriginTabCaptureAllowedByOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin. Leaving the policy unset means that sites will not be considered for an override at this level of capture. Note that windowed Chrome Apps with the same origin as this site will still be allowed to be captured. If a site matches a URL pattern in this policy, the following policies will not be considered: TabCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
TabCaptureAllowedByOrigins  Allow Tab capture by these origins
List (values under a subkey) Machine + User
Leaving the policy unset means that sites will not be considered for an override at this level of capture.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\TabCaptureAllowedByOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that can use Tab Capture. Leaving the policy unset means that sites will not be considered for an override at this level of capture. Note that windowed Chrome Apps will still be allowed to be captured. This policy is not considered if a site matches a URL pattern in the SameOriginTabCaptureAllowedByOrigins policy. If a site matches a URL pattern in this policy, the following policies will not be considered: WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
WindowCaptureAllowedByOrigins  Allow Window and Tab capture by these origins
List (values under a subkey) Machine + User
Leaving the policy unset means that sites will not be considered for an override at this level of Capture.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WindowCaptureAllowedByOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture. Leaving the policy unset means that sites will not be considered for an override at this level of Capture. This policy is not considered if a site matches a URL pattern in any of the following policies: TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins. If a site matches a URL pattern in this policy, the following policies will not be considered: ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns/. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
Google:Cat_Google / Google Chrome / Certificate management settings
CACertificateManagementAllowed  Allow users to manage installed CA certificates.
Enum Machine + User
Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager.
Registry key
Software\Policies\Google\Chrome
Value name
CACertificateManagementAllowed
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow users to manage all certificates
1Allow users to manage user certificates
2Disallow users from managing certificates
Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.
CAHintCertificates  TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CAHintCertificates
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A list of certificates that are not trusted or distrusted in Google Chrome but can be used as hints for path-building. Certificates should be base64-encoded. Example value: MIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd
CADistrustedCertificates  TLS certificates that should be distrusted by Google Chrome for server authentication
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CADistrustedCertificates
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A list of certificate public keys that should be distrusted by Google Chrome for TLS server authentication. The policy value is a list of base64-encoded X.509 certificates. Any certificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted. Example value: MIIB/TCCAaOgAwIBAgIUQthnWVsd1jWpUCNBf/uILjXC+t4wCgYIKoZIzj0EAwIwVDELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFZpcmdpbmlhMQ8wDQYDVQQHDAZSZXN0b24xITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMzEyMDcxNjE5NTVaFw0yMzEyMjExNjE5NTVaMFQxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhWaXJnaW5pYTEPMA0GA1UEBwwGUmVzdG9uMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ9Akav/KB0aVA9FM1QK4J1CEHn5rFOyY/nxcr5HG3+Fom0Kwu5zTR/kz9eOYgtG/1NmCzbiEKaULDfzA8V9aJ7o1MwUTAdBgNVHQ4EFgQUq37bLKiuw8Y/G+rurMf46hw7EekwHwYDVR0jBBgwFoAUq37bLKiuw8Y/G+rurMf46hw7EekwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAgNIADBFAiEA/JhtLSgtVOcXkgFJ9V5Vb6lhGdiKQFfzO9wTxPeCxCECIFePYPucys2n/r9MOBMHiX/8068ssv+uceqokzUg0mAb
CACertificates  TLS certificates that should be trusted by Google Chrome for server authentication
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CACertificates
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A list of TLS certificates that should be trusted by Google Chrome for server authentication. Certificates should be base64-encoded. Example value: MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X
CACertificatesWithConstraints  TLS certificates that should be trusted by Google Chrome for server authentication with constraints
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CACertificatesWithConstraints
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A list of TLS certificates that should be trusted by Google Chrome for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed. Certificates should be base64-encoded. At least one constraint must be specified for each certificate. See https://chromeenterprise.google/policies/?policy=CACertificatesWithConstraints for more information about schema and formatting. Example value: [ { "certificate": "MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X", "constraints": { "permitted_dns_names": [ "example.org" ], "permitted_cidrs": [ "10.1.1.0/24" ] } } ]
CAPlatformIntegrationEnabled  Use user-added TLS certificates from platform trust stores for server authentication
Boolean Machine + User
If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.
Registry key
Software\Policies\Google\Chrome
Value name
CAPlatformIntegrationEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication. If disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.
Google:Cat_Google / Google Chrome / Content settings
SensorsAllowedForUrls  Allow access to sensors on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SensorsAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can access sensors like motion and light sensors. Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies. If the same URL pattern exists in both this policy and the SensorsBlockedForUrls policy, the latter is prioritized and access to motion or light sensors will be blocked. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
AutomaticDownloadsAllowedForUrls  Allow automatic downloads on these sites
List (values under a subkey) Machine + User
If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutomaticDownloadsAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of URL patterns that specify sites which are allowed to download multiple files automatically. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns. If a URL matches both AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls, AutomaticDownloadsBlockedForUrls takes precedence. If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set. If not, the user's personal setting applies. Example value: https://www.example.com [*.]example.edu
AutomaticFullscreenAllowedForUrls  Allow automatic fullscreen on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutomaticFullscreenAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
For security reasons, the requestFullscreen() web API requires a prior user gesture ("transient activation") to be called or will otherwise fail. Users' personal settings may allow certain origins to call this API without a prior user gesture, as described in https://chromestatus.com/feature/6218822004768768. This policy supersedes users' personal settings and allows matching origins to call the API without a prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Origins matching both blocked and allowed policy patterns will be blocked. Origins not specified by policy nor user settings will require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
ClipboardAllowedForUrls  Allow clipboard on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ClipboardAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that can use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission. Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
CookiesAllowedForUrls  Allow cookies on these sites
List (values under a subkey) Machine + User
If this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting or BlockThirdPartyCookies policies if they are set, or the user's personal configuration otherwise.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CookiesAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of url patterns that specify sites which are allowed to set cookies. URL patterns may be a single URL indicating that the site may use cookies on all top-level sites. Patterns may also be two URLs delimited by a comma. The first specifies the site that should be allowed to use cookies. The second specifies the top-level site that the first value should be applied on. If you use a pair of URLs, the first value in the pair supports * but the second value does not. Using * for the first value indicates that all sites may use cookies when the second URL is the top-level site. If this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting or BlockThirdPartyCookies policies if they are set, or the user's personal configuration otherwise. See also policies CookiesBlockedForUrls and CookiesSessionOnlyForUrls. Note that there must be no conflicting URL patterns between these three policies - it is unspecified which policy takes precedence. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu https://www.example.com/,https://www.toplevel.com/ *,https://www.toplevel.com/
IdleDetectionAllowedForUrls  Allow idle detection on these sites
List (values under a subkey) Machine + User
If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\IdleDetectionAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of URL patterns that specify the sites that are allowed to use the Idle Detection API witout asking the user. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise. Example value: https://www.example.com [*.]example.edu
ImagesAllowedForUrls  Allow images on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ImagesAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that may display images. Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Note that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android. Example value: https://www.example.com [*.]example.edu
InsecureContentAllowedForUrls  Allow insecure content on these sites
List (values under a subkey) Machine + User
If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\InsecureContentAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled. If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
JavaScriptAllowedForUrls  Allow JavaScript on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\JavaScriptAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can run JavaScript. Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
JavaScriptOptimizerAllowedForSites  Allow JavaScript optimization on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise Javascript optimization is enabled for the site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\JavaScriptOptimizerAllowedForSites
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations enabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise Javascript optimization is enabled for the site. Example value: [*.]example.edu
JavaScriptJitAllowedForSites  Allow JavaScript to use JIT on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\JavaScriptJitAllowedForSites
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled. If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site. Example value: [*.]example.edu
PdfLocalFileAccessAllowedForDomains  Allow local file access to file:// URLs on these sites in the PDF Viewer
List (values under a subkey) Machine + User
Leaving the policy unset disallows all domains from accessing file:// URLs in the PDF Viewer.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PdfLocalFileAccessAllowedForDomains
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting this policy allows the domains listed to access file:// URLs in the PDF Viewer. Adding to the policy allows the domain to access file:// URLs in the PDF Viewer. Removing from the policy disallows the domain from accessing file:// URLs in the PDF Viewer. Leaving the policy unset disallows all domains from accessing file:// URLs in the PDF Viewer. Example value: example.com google.com
LocalFontsAllowedForUrls  Allow Local Fonts permission on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LocalFontsAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Sets a list of site url patterns that specify sites which will automatically grant the local fonts permission. This will extend the ability of sites to see information about local fonts. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. Example value: https://www.example.com [*.]example.edu
NotificationsAllowedForUrls  Allow notifications on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\NotificationsAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can display notifications. Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
PopupsAllowedForUrls  Allow pop-ups on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PopupsAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can open pop-ups. Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
PreciseGeolocationAllowedForUrls  Allow precise geolocation on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PreciseGeolocationAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that are allowed to access the user's high accuracy geolocation without first having to request the user's permission to do so. Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
FileSystemReadAskForUrls  Allow read access via the File System API on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\FileSystemReadAskForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API. Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns must not conflict with FileSystemReadBlockedForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
SerialAskForUrls  Allow the Serial API on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SerialAskForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a serial port. Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. For URL patterns which do not match the policy SerialBlockedForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order. If URL patterns conflict with SerialBlockedForUrls they will be ignored. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WebHidAskForUrls  Allow the WebHID API on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebHidAskForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device. Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. For URL patterns which do not match the policy, the following take precedence, in this order: * WebHidBlockedForUrls (if there is a match), * DefaultWebHidGuardSetting (if set), or * Users' personal settings. URL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://google.com https://chromium.org
WebUsbAskForUrls  Allow WebUSB on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebUsbAskForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a USB device. Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns must not conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WindowManagementAllowedForUrls  Allow Window Management permission on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WindowManagementAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of site url patterns that specify sites which will automatically grant the window management permission. This will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. This replaces the deprecated WindowPlacementAllowedForUrls policy. Example value: https://www.example.com [*.]example.edu
FileSystemWriteAskForUrls  Allow write access to files and directories on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\FileSystemWriteAskForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system. Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns must not conflict with FileSystemWriteBlockedForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
SerialAllowAllPortsForUrls  Automatically grant permission to sites to connect all serial ports.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SerialAllowAllPortsForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports. The URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered. On Google ChromeOS, this policy only applies to affiliated users. This policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences. Example value: https://www.example.com
WebHidAllowAllDevicesForUrls  Automatically grant permission to sites to connect to any HID device.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebHidAllowAllDevicesForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy allows you to list sites which are automatically granted permission to access all available devices. The URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered. On ChromeOS, this policy only applies to affiliated users. This policy overrides DefaultWebHidGuardSetting, WebHidAskForUrls, WebHidBlockedForUrls and the user's preferences. Example value: https://google.com https://chromium.org
SerialAllowUsbDevicesForUrls  Automatically grant permission to sites to connect to USB serial devices.
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SerialAllowUsbDevicesForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy allows you to list sites which are automatically granted permission to access USB serial devices with vendor and product IDs matching the vendor_id and product_id fields. Omitting the product_id field allows the given sites permission to access devices with a vendor ID matching the vendor_id field and any product ID. The URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered. On ChromeOS, this policy only applies to affiliated users. This policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences. This policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the WebUsbAllowDevicesForUrls policy. See https://chromeenterprise.google/policies/?policy=SerialAllowUsbDevicesForUrls for more information about schema and formatting. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://specific-device.example.com" ] }, { "devices": [ { "vendor_id": 1234 } ], "urls": [ "https://all-vendor-devices.example.com" ] } ]
WebHidAllowDevicesWithHidUsagesForUrls  Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage.
String Machine + User
Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set.
Registry key
Software\Policies\Google\Chrome
Value name
WebHidAllowDevicesWithHidUsagesForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage. Each item in the list requires both usages and urls fields for the policy to be valid. Each item in the usages field must have a usage_page and may have a usage field. Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page. An item which has a usage field without a usage_page field is invalid and is ignored. Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies. URLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls. See https://chromeenterprise.google/policies/?policy=WebHidAllowDevicesWithHidUsagesForUrls for more information about schema and formatting. Example value: [ { "urls": [ "https://google.com", "https://chromium.org" ], "usages": [ { "usage": 5678, "usage_page": 1234 } ] } ]
WebHidAllowDevicesForUrls  Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs.
String Machine + User
Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set.
Registry key
Software\Policies\Google\Chrome
Value name
WebHidAllowDevicesForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored. Each item in the devices field must have a vendor_id and may have a product_id field. Omitting the product_id field will create a policy matching any device with the specified vendor ID. An item which has a product_id field without a vendor_id field is invalid and is ignored. Leaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies. URLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls. See https://chromeenterprise.google/policies/?policy=WebHidAllowDevicesForUrls for more information about schema and formatting. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://google.com", "https://chromium.org" ] } ]
WebUsbAllowDevicesForUrls  Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs.
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebUsbAllowDevicesForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites are automatically granted permission to access a USB device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the policy to be valid. Each item in the devices field can have a vendor_id and product_id field. Omitting the vendor_id field will create a policy matching any device. Omitting the product_id field will create a policy matching any device with the given vendor ID. A policy which has a product_id field without a vendor_id field is invalid. The USB permission model will grant the specified URL permission to access the USB device as a top-level origin. If embedded frames need to access USB devices, the 'usb' feature-policy header should be used to grant access. The URL must be valid, otherwise the policy is ignored. Deprecated: The USB permission model used to support specifying both the requesting and embedding URLs. This is deprecated and only supported for backwards compatibility in this manner: if both a requesting and embedding URL is specified, then the embedding URL will be granted the permission as top-level origin and the requesting URL will be ignored entirely. This policy overrides DefaultWebUsbGuardSetting, WebUsbAskForUrls, WebUsbBlockedForUrls and the user's preferences. This policy only affects access to USB devices through the WebUSB API. To grant access to USB devices through the Web Serial API see the SerialAllowUsbDevicesForUrls policy. See https://chromeenterprise.google/policies/?policy=WebUsbAllowDevicesForUrls for more information about schema and formatting. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://google.com" ] } ]
AutoSelectCertificateForUrls  Automatically select client certificates for these sites
List (values under a subkey) Machine + User
Leaving the policy unset means there's no autoselection for any site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutoSelectCertificateForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you make a list of URL patterns that specify sites for which Chrome can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { "pattern": "$URL_PATTERN", "filter" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected. On Android and iOS, Chrome can only select client certificates that it has provisioned itself; it cannot access certificates installed at the operating system level. Examples for the usage of the $FILTER section: * When $FILTER is set to { "ISSUER": { "CN": "$ISSUER_CN" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected. * When $FILTER contains both the "ISSUER" and the "SUBJECT" sections, only client certificates that satisfy both conditions are selected. * When $FILTER contains a "SUBJECT" section with the "O" value, a certificate needs at least one organization matching the specified value to be selected. * When $FILTER contains a "SUBJECT" section with a "OU" value, a certificate needs at least one organizational unit matching the specified value to be selected. * When $FILTER is set to {}, the selection of client certificates is not additionally restricted. Note that filters provided by the web server still apply. Leaving the policy unset means there's no autoselection for any site. See https://chromeenterprise.google/policies/?policy=AutoSelectCertificateForUrls for more information about schema and formatting. Example value: {"pattern":"https://www.example.com","filter":{"ISSUER":{"CN":"certificate issuer name", "L": "certificate issuer location", "O": "certificate issuer org", "OU": "certificate issuer org unit"}, "SUBJECT":{"CN":"certificate subject name", "L": "certificate subject location", "O": "certificate subject org", "OU": "certificate subject org unit"}}}
SensorsBlockedForUrls  Block access to sensors on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SensorsBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't access sensors like motion and light sensors. Leaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies. If the same URL pattern exists in both this policy and the SensorsAllowedForUrls policy, this policy is prioritized and access to motion or light sensors will be blocked. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
AutomaticDownloadsBlockedForUrls  Block automatic downloads on these sites
List (values under a subkey) Machine + User
If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutomaticDownloadsBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of URL patterns that specify sites which are not allowed to download multiple files automatically. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns. If a URL matches both AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls, AutomaticDownloadsBlockedForUrls takes precedence. If this policy is not set, DefaultAutomaticDownloadsSetting applies for all sites, if it is set. If not, the user's personal setting applies. Example value: https://www.example.com [*.]example.edu
AutomaticFullscreenBlockedForUrls  Block automatic fullscreen on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutomaticFullscreenBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
For security reasons, the requestFullscreen() web API requires a prior user gesture ("transient activation") to be called or will otherwise fail. Users' personal settings may allow certain origins to call this API without a prior user gesture, as described in https://chromestatus.com/feature/6218822004768768. This policy supersedes users' personal settings and blocks matching origins from calling the API without a prior user gesture. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Origins matching both blocked and allowed policy patterns will be blocked. Origins not specified by policy nor user settings will require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
ClipboardBlockedForUrls  Block clipboard on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ClipboardBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that can't use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission. Leaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
CookiesBlockedForUrls  Block cookies on these sites
List (values under a subkey) Machine + User
Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CookiesBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you make a list of URL patterns that specify sites that can't set cookies. Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. While no specific policy takes precedence, see CookiesAllowedForUrls and CookiesSessionOnlyForUrls. URL patterns among these 3 policies must not conflict. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
GeolocationBlockedForUrls  Block geolocation on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\GeolocationBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that are not allowed to access the user's geolocation, and are also prevented from requesting user permission to do so. Leaving the policy unset means DefaultGeolocationSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
IdleDetectionBlockedForUrls  Block idle detection on these sites
List (values under a subkey) Machine + User
If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\IdleDetectionBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of URL patterns that specify the sites that are not allowed to use the Idle Detection API. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set, the global default value will be used for all sites, which is configured by the DefaultIdleDetectionSetting (Default idle detection setting) policy, if set, or by the user's personal configuration otherwise. Example value: https://www.example.com [*.]example.edu
ImagesBlockedForUrls  Block images on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ImagesBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify sites that can't display images. Leaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Note that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android. Example value: https://www.example.com [*.]example.edu
InsecureContentBlockedForUrls  Block insecure content on these sites
List (values under a subkey) Machine + User
If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\InsecureContentBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded. If this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
JavaScriptJitBlockedForSites  Block JavaScript from using JIT on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\JavaScriptJitBlockedForSites
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled. Disabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT disabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled. If this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site. Example value: [*.]example.edu
JavaScriptBlockedForUrls  Block JavaScript on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\JavaScriptBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't run JavaScript. Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Note that this policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that is also displayed in the address bar) matches any of the patterns. Therefore this policy is not appropriate for mitigating web supply-chain attacks. For example, supplying the pattern "https://[*.]foo.com/" will not prevent a page hosted on, say, https://example.com from running a script loaded from https://www.foo.com/example.js. Furthermore, supplying the pattern "https://example.com/" will not prevent a document from https://example.com from running scripts if it is not the top-level document, but embedded as a sub-frame into a page hosted on another origin, say, https://www.bar.com. Example value: https://www.example.com [*.]example.edu
JavaScriptOptimizerBlockedForSites  Block JavaScript optimizations on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise JavaScript optimization is enabled for the site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\JavaScriptOptimizerBlockedForSites
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled. Disabling JavaScript optimizations will mean that Google Chrome may render web content more slowly. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. JavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com. This policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations disabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. If this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise JavaScript optimization is enabled for the site. Example value: [*.]example.edu
LocalFontsBlockedForUrls  Block Local Fonts permission on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LocalFontsBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Sets a list of site url patterns that specify sites which will automatically deny the local fonts permission. This will limit the ability of sites to see information about local fonts. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. Example value: https://www.example.com [*.]example.edu
NotificationsBlockedForUrls  Block notifications on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\NotificationsBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't display notifications. Leaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
PopupsBlockedForUrls  Block pop-ups on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PopupsBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you set a list of URL patterns that specify the sites that can't open pop-ups. Leaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
FileSystemReadBlockedForUrls  Block read access via the File System API on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\FileSystemReadBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API. Leaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns can't conflict with FileSystemReadAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
SerialBlockedForUrls  Block the Serial API on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SerialBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a serial port. Leaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies. For URL patterns which do not match the policy SerialAskForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order. If URL patterns conflict with SerialAskForUrls this policy will take precedence. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WebHidBlockedForUrls  Block the WebHID API on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebHidBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device. Leaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. For URL patterns which do not match the policy, the following take precedence, in this order: * WebHidAskForUrls (if there is a match), * DefaultWebHidGuardSetting (if set), or * Users' personal settings. URL patterns can't conflict with WebHidAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://google.com https://chromium.org
WebUsbBlockedForUrls  Block WebUSB on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebUsbBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a USB device. Leaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies. URL patterns can't conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WindowManagementBlockedForUrls  Block Window Management permission on these sites
List (values under a subkey) Machine + User
If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WindowManagementBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to set a list of site url patterns that specify sites which will automatically deny the window management permission. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. For detailed information on valid site url patterns, please see https://chromeenterprise.google/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. If this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site. This replaces the deprecated WindowPlacementBlockedForUrls policy. Example value: https://www.example.com [*.]example.edu
FileSystemWriteBlockedForUrls  Block write access to files and directories on these sites
List (values under a subkey) Machine + User
Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\FileSystemWriteBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system. Leaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply. URL patterns can't conflict with FileSystemWriteAskForUrls. Neither policy takes precedence if a URL matches with both. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
PartitionedBlobUrlUsage  Choose whether Blob URLs are partitioned during fetching and navigations
Boolean Machine + User
If this policy is set to Enabled or not set, Blob URLs will be partitioned.
Registry key
Software\Policies\Google\Chrome
Value name
PartitionedBlobUrlUsage
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether Blob URLs are partitioned during fetching and navigation. If this policy is set to Enabled or not set, Blob URLs will be partitioned. If this policy is set to Disabled, Blob URLs won't be partitioned. If you must use the policy, please file a bug at Google Chrome explaining your use case. The policy is scheduled to be offered through Google Chrome version 146, after which the old implementation will be removed. NOTE: Only newly-started renderer processes will reflect changes to this policy while the browser is running. For detailed information on third-party storage partitioning, please see https://developers.google.com/privacy-sandbox/cookies/storage-partitioning.
DefaultInsecureContentSetting  Control use of insecure content exceptions
Enum Machine + User
If this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultInsecureContentSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to load mixed content
3Allow users to add exceptions to allow mixed content
Allows you to set whether users can add exceptions to allow mixed content for specific sites. This policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' and 'InsecureContentBlockedForUrls' policies. If this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.
DefaultJavaScriptJitSetting  Control use of JavaScript JIT
Enum Machine + User
If this policy is left not set, JavaScript JIT is enabled.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultJavaScriptJitSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow any site to run JavaScript JIT
2Do not allow any site to run JavaScript JIT
Allows you to set whether Google Chrome will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not. Disabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration. This policy can be overridden for specific URL patterns using the JavaScriptJitAllowedForSites and JavaScriptJitBlockedForSites policies. If this policy is left not set, JavaScript JIT is enabled.
DefaultJavaScriptOptimizerSetting  Control use of JavaScript optimizers
Enum Machine + User
If this policy is left not set, JavaScript optimizations are enabled.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultJavaScriptOptimizerSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Enable advanced JavaScript optimizations on all sites
2Disable advanced JavaScript optimizations on all sites
Allows you to set whether Google Chrome will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled. Disabling JavaScript optimizations (by setting this policy's value to 2) will mean that Google Chrome may render web content more slowly. This policy can be overridden for specific URL patterns using the JavaScriptOptimizerAllowedForSites and JavaScriptOptimizerBlockedForSites policies. If this policy is left not set, JavaScript optimizations are enabled.
DefaultFileSystemReadGuardSetting  Control use of the File System API for reading
Enum Machine + User
Leaving it unset lets websites ask for access, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultFileSystemReadGuardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to request read access to files and directories via the File System API
3Allow sites to ask the user to grant read access to files and directories via the File System API
Setting the policy to 3 lets websites ask for read access to files and directories in the host operating system's file system via the File System API. Setting the policy to 2 denies access. Leaving it unset lets websites ask for access, but users can change this setting.
DefaultFileSystemWriteGuardSetting  Control use of the File System API for writing
Enum Machine + User
Leaving it unset lets websites ask for access, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultFileSystemWriteGuardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to request write access to files and directories
3Allow sites to ask the user to grant write access to files and directories
Setting the policy to 3 lets websites ask for write access to files and directories in the host operating system's file system. Setting the policy to 2 denies access. Leaving it unset lets websites ask for access, but users can change this setting.
DefaultSerialGuardSetting  Control use of the Serial API
Enum Machine + User
Leaving it unset lets websites ask for access, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSerialGuardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to request access to serial ports via the Serial API
3Allow sites to ask the user to grant access to a serial port
Setting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports. Leaving it unset lets websites ask for access, but users can change this setting.
DefaultWebBluetoothGuardSetting  Control use of the Web Bluetooth API
Enum Machine + User
Leaving the policy unset lets sites ask for access, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultWebBluetoothGuardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API
3Allow sites to ask the user to grant access to a nearby Bluetooth device
Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices. Leaving the policy unset lets sites ask for access, but users can change this setting.
DefaultWebHidGuardSetting  Control use of the WebHID API
Enum Machine + User
Leaving it unset lets websites ask for access, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultWebHidGuardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to request access to HID devices via the WebHID API
3Allow sites to ask the user to grant access to a HID device
Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices. Leaving it unset lets websites ask for access, but users can change this setting. This policy can be overridden for specific url patterns using the WebHidAskForUrls and WebHidBlockedForUrls policies.
DefaultWebUsbGuardSetting  Control use of the WebUSB API
Enum Machine + User
Leaving it unset lets websites ask for access, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultWebUsbGuardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to request access to USB devices via the WebUSB API
3Allow sites to ask the user to grant access to a connected USB device
Setting the policy to 3 lets websites ask for access to connected USB devices. Setting the policy to 2 denies access to connected USB devices. Leaving it unset lets websites ask for access, but users can change this setting.
DataUrlInSvgUseEnabled  Data URL support for SVGUseElement.
Boolean Machine + User
If this policy is set to Disabled or not set, Data URLs won't work in SVGUseElement.
Registry key
Software\Policies\Google\Chrome
Value name
DataUrlInSvgUseEnabled
Enabled / Disabled
1 / 0
Stated default
This policy enables Data URL support for SVGUseElement, which will be disabled by default starting in M119.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy enables Data URL support for SVGUseElement, which will be disabled by default starting in M119. If this policy is set to Enabled, Data URLs will continue to work in SVGUseElement. If this policy is set to Disabled or not set, Data URLs won't work in SVGUseElement.
DefaultAutomaticDownloadsSetting  Default automatic downloads setting
Enum Machine + User
Leaving the policy unset means the AskAutomaticDownloads policy applies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultAutomaticDownloadsSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow sites to download multiple files automatically
2Do not allow any site to download multiple files automatically
3Ask whenever a site wants to download multiple files automatically
Setting the policy to 1 lets websites download multiple files automatically. Setting the policy to 2 denies this permission. You can set the policy to ask whenever a website wants to download multiple files automatically. Leaving the policy unset means the AskAutomaticDownloads policy applies, but users can change this setting.
DefaultClipboardSetting  Default clipboard setting
Enum Machine + User
Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use one.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultClipboardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to use the clipboard site permission
3Allow sites to ask the user to grant the clipboard site permission
Setting the policy to 2 blocks sites from using the clipboard site permission. Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use one. This policy can be overridden for specific URL patterns using the ClipboardAllowedForUrls and ClipboardBlockedForUrls policies. This policy only affects clipboard operations controlled by the clipboard site permission, and does not affect sanitized clipboard writes or trusted copy and paste operations.
DefaultCookiesSetting  Default cookies setting
Enum Machine + User
Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultCookiesSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow all sites to set local data
2Do not allow any site to set local data
4Keep cookies for the duration of the session
Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session. Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults. While no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.
DefaultGeolocationSetting  Default geolocation setting
Enum Machine + User
Leaving the policy unset means the AskGeolocation policy applies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultGeolocationSetting
Stated default
Setting the policy to 2 denies this tracking by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow sites to track the users' physical location
2Do not allow any site to track the users' physical location
3Ask whenever a site wants to track the users' physical location
Setting the policy to 1 lets sites track the users' physical location as the default state. Setting the policy to 2 denies this tracking by default. You can set the policy to ask whenever a site wants to track the users' physical location. Leaving the policy unset means the AskGeolocation policy applies, but users can change this setting.
DefaultIdleDetectionSetting  Default idle detection setting
Enum Machine + User
When this policy is set to 3 - AskIdleDetection or not set, websites can't use the API without the user's permission.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultIdleDetectionSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow sites to detect idle state without asking the user
2Do not allow any site to detect the user's idle state
3Ask every time a site wants to detect the user's idle state
Allows you to set whether websites are allowed to use the Idle Detection API. When this policy is set to 1 - AllowIdleDetection, websites can use the API without asking the user for permission. When this policy is set to 2 - BlockIdleDetection, websites can't use the API, regardless of the user's permission. When this policy is set to 3 - AskIdleDetection or not set, websites can't use the API without the user's permission.
DefaultImagesSetting  Default images setting
Enum Machine + User
Leaving it unset allows images, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultImagesSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow all sites to show all images
2Do not allow any site to show images
Setting the policy to 1 lets all websites display images. Setting the policy to 2 denies image display. Leaving it unset allows images, but users can change this setting.
DefaultJavaScriptSetting  Default JavaScript setting
Enum Machine + User
Leaving it unset allows JavaScript, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultJavaScriptSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow all sites to run JavaScript
2Do not allow any site to run JavaScript
Setting the policy to 1 lets websites run JavaScript. Setting the policy to 2 denies JavaScript. Leaving it unset allows JavaScript, but users can change this setting.
DefaultLocalFontsSetting  Default Local Fonts permission setting
Enum Machine + User
Setting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. Setting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultLocalFontsSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Denies the Local Fonts permission on all sites by default
3Ask every time a site wants obtain the Local Fonts permission
Setting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. This will limit the ability of sites to see information about local fonts. Setting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about local fonts. Leaving the policy unset means the default behavior applies which is to prompt the user, but users can change this setting
DefaultNotificationsSetting  Default notification setting
Enum Machine + User
Leaving it unset means AskNotifications applies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultNotificationsSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow sites to show desktop notifications
2Do not allow any site to show desktop notifications
3Ask every time a site wants to show desktop notifications
Setting the policy to 1 lets websites display desktop notifications. Setting the policy to 2 denies desktop notifications. Leaving it unset means AskNotifications applies, but users can change this setting.
DefaultPopupsSetting  Default pop-ups setting
Enum Machine + User
Leaving it unset means BlockPopups applies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultPopupsSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow all sites to show pop-ups
2Do not allow any site to show pop-ups
Setting the policy to 1 lets websites display pop-ups. Setting the policy to 2 denies pop-ups. Leaving it unset means BlockPopups applies, but users can change this setting.
DefaultSensorsSetting  Default sensors setting
Enum Machine + User
Leaving it unset means AllowSensors applies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSensorsSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow sites to access sensors
2Do not allow any site to access sensors
3Ask whenever a site wants to access sensors
Setting the policy to 1 lets websites access and use sensors such as motion and light. Setting the policy to 2 denies access to sensors. When the policy is set to 3 it will ask the user when a site requests access to sensors if the tri-state feature flag is enabled, otherwise it will default to allowing access to sensors. Leaving it unset means AllowSensors applies, but users can change this setting.
DefaultWindowManagementSetting  Default Window Management permission setting
Enum Machine + User
Leaving the policy unset means the AskWindowManagement policy applies, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultWindowManagementSetting
Stated default
Setting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. Setting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Denies the Window Management permission on all sites by default
3Ask every time a site wants obtain the Window Management permission
Setting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. Setting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. Leaving the policy unset means the AskWindowManagement policy applies, but users can change this setting. This replaces the deprecated DefaultWindowPlacementSetting policy.
CookiesSessionOnlyForUrls  Limit cookies from matching URLs to the current session
List (values under a subkey) Machine + User
Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CookiesSessionOnlyForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session. Leaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults. While no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict. For detailed information on valid url patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
RestrictYouTubeCookiesDeletion  Restrict YouTube cookies deletion
Boolean Machine + User
Setting the policy to Disabled or not set allows YouTube cookies to be deleted normally.
Registry key
Software\Policies\Google\Chrome
Value name
RestrictYouTubeCookiesDeletion
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Prevents the manual deletion of YouTube cookies. This policy is intended to prevent users from accessing unauthorized YouTube after manually clearing their YouTube cookies from the site settings page. Setting the policy to Enabled prevents YouTube cookies from being manually deleted. Setting the policy to Disabled or not set allows YouTube cookies to be deleted normally. Note: This policy only prevents manual deletion from the site settings UI. It does not prevent automated deletion by the ClearBrowsingDataOnExitList or BrowsingDataLifetime policies. Furthermore, if the AllowDeletingBrowserHistory policy is enabled, users can still clear all their cookies via the Clear Browsing Data dialog.
Google:Cat_Google / Google Chrome / Cryptography compliance policies
PreferSlowCiphers  Prefer specific encryption cipher algorithms for TLS
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PreferSlowCiphers
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0
Use Google Chrome's default cipher order
This policy configures Google Chrome to order its preferred encryption ciphers in TLS 1.3 to reflect a preference for algorithms that have been approved by a specific compliance regime. Setting this policy does not guarantee that any specific algorithms will be negotiated. This policy exists to allow server operators who wish to support clients with and without compliance requirements to differentiate between those clients, and only use certain non-default algorithms with increased cryptographic strength for those explicitly configured to prefer them. Setting the policy to 'cnsa' configures Google Chrome to prefer ciphers required for compliance with the Commercial National Security Algorithm Suite versions 1.0 and 2.0 (CNSA 1.0 and 2.0). Not setting the policy, or setting it to 'default', configures Google Chrome to use its default ciphers. Setting this policy is not required for security. The default cryptography used by Google Chrome is strong enough to withstand a brute force attack using the entire power of the Sun. Setting this policy will cause Google Chrome to be slower when accessing websites. This policy only affects TLS 1.3 and QUIC; it does not affect earlier versions of TLS. Example value: cnsa
PreferSlowKexAlgorithms  Prefer specific key exchange algorithms for TLS
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PreferSlowKexAlgorithms
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Prefer key exchange methods satisfying the requirements of CNSA 2.0
Use Google Chrome's default supported groups
This policy configures Google Chrome to order its preferred key agreement algorithms (supported groups) in TLS 1.3 to reflect a preference for algorithms that have been approved by a specific compliance regime. Setting this policy does not guarantee that any specific algorithms will be negotiated. This policy exists to allow server operators who wish to support clients with and without compliance requirements to differentiate between those clients, and only use certain non-default algorithms with increased cryptographic strength for those explicitly configured to prefer them. Setting the policy to 'cnsa2' configures Google Chrome to prefer key exchange methods required for compliance with the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0). Not setting the policy, or setting it to 'default', configures Google Chrome to use its default key exchange methods. Setting this policy is not required for security. The default cryptography used by Google Chrome is strong enough to withstand a brute force attack using the entire power of the Sun. Setting this policy will cause Google Chrome to be slower when accessing websites. This policy only affects TLS 1.3 and QUIC; it does not affect earlier versions of TLS. Example value: cnsa2
Google:Cat_Google / Google Chrome / Default search provider
DefaultSearchProviderEncodings  Default search provider encodings
List (values under a subkey) Machine + User
Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\DefaultSearchProviderEncodings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided. Leaving DefaultSearchProviderEncodings unset puts UTF-8 in use. Example value: UTF-8 UTF-16 GB2312 ISO-8859-1
DefaultSearchProviderKeyword  Default search provider keyword
String Machine + User
Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderKeyword
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider. Leaving DefaultSearchProviderKeyword unset means no keyword activates the search provider. Example value: mis
DefaultSearchProviderName  Default search provider name
String Machine + User
Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderName
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name. Leaving DefaultSearchProviderName unset means the hostname specified by the search URL is used. Example value: My Intranet Search
DefaultSearchProviderNewTabURL  Default search provider new tab page URL
String Machine + User
Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderNewTabURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page. Leaving DefaultSearchProviderNewTabURL unset means no new tab page is provided. Example value: https://search.my.company/newtab
DefaultSearchProviderSearchURL  Default search provider search URL
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderSearchURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'. Example value: https://search.my.company/search?q={searchTerms}
DefaultSearchProviderSuggestURL  Default search provider suggest URL
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderSuggestURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms. You can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'. Example value: https://search.my.company/suggest?q={searchTerms}
DefaultSearchProviderEnabled  Enable the default search provider
Boolean Machine + User
If not set, the default search provider is on, and users can set the search provider list.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar. The Disabled value is not supported by the Google Admin console. If you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
DefaultSearchProviderAlternateURLs  List of alternate URLs for the default search provider
List (values under a subkey) Machine + User
Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\DefaultSearchProviderAlternateURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'. Leaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms. Example value: https://search.my.company/suggest#q={searchTerms} https://search.my.company/suggest/search#q={searchTerms}
DefaultSearchProviderImageURL  Parameter providing search-by-image feature for the default search provider
String Machine + User
) Leaving DefaultSearchProviderImageURL unset means no image search is used.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderImageURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.) Leaving DefaultSearchProviderImageURL unset means no image search is used. If image search uses the GET method, then the URL must specify image parameters using a valid combination of the following placeholders: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: https://search.my.company/searchbyimage/upload
DefaultSearchProviderImageURLPostParams  Parameters for image URL which uses POST
String Machine + User
Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderImageURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it. Leaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method. The URL must specify the image parameter using a valid combination of the following placeholders depending on what the search provider supports: '{google:imageURL}', '{google:imageOriginalHeight}', '{google:imageOriginalWidth}', '{google:processedImageDimensions}', '{google:imageSearchSource}', '{google:imageThumbnail}', '{google:imageThumbnailBase64}'. Example value: content={google:imageThumbnail},url={google:imageURL},sbisrc={google:imageSearchSource}
DefaultSearchProviderSearchURLPostParams  Parameters for search URL which uses POST
String Machine + User
Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderSearchURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
DefaultSearchProviderSuggestURLPostParams  Parameters for suggest URL which uses POST
String Machine + User
Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderSuggestURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it. Leaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method. Example value: q={searchTerms},ie=utf-8,oe=utf-8
Google:Cat_Google / Google Chrome / Deprecated policies
ManagedAccountsSigninRestriction  Add restrictions on managed accounts
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ManagedAccountsSigninRestriction
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
A Managed account must be a primary account and importing existing browsing data is allowed at the time of profile creation
A Managed account must be a primary account and have no secondary accounts and importing existing browsing data is allowed at the time of profile creation
No restrictions on managed accounts
A Managed account must be a primary account and the user can import existing data at the time of its creation
A Managed account must be a primary account and have no secondary accounts and the user can import existing data at the time of its creation
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: primary_account
ProxyServer  Address or URL of proxy server
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ProxyServer
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: 123.123.123.123:8080
LensDesktopNTPSearchEnabled  Allow Google Lens button to be shown in the search box on the New Tab page if supported.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LensDesktopNTPSearchEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
LensRegionSearchEnabled  Allow Google Lens region search menu item to be shown in context menu if supported.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LensRegionSearchEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
SigninAllowed  Allow sign in to Google Chrome
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SigninAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
WindowPlacementAllowedForUrls  Allow Window Placement permission on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WindowPlacementAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://www.example.com [*.]example.edu
WindowPlacementBlockedForUrls  Block Window Placement permission on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WindowPlacementBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://www.example.com [*.]example.edu
ProxyMode  Choose how to specify proxy server settings
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ProxyMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Never use a proxy
Auto detect proxy settings
Use a .pac proxy script
Use fixed proxy servers
Use system proxy settings
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: direct
ProxyServerMode  Choose how to specify proxy server settings
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ProxyServerMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Never use a proxy
1Auto detect proxy settings
2Manually specify proxy settings
3Use system proxy settings
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxAdMeasurementEnabled  Choose whether the Privacy Sandbox ad measurement setting can be disabled
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrivacySandboxAdMeasurementEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxAdTopicsEnabled  Choose whether the Privacy Sandbox Ad topics setting can be disabled
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrivacySandboxAdTopicsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxPromptEnabled  Choose whether the Privacy Sandbox prompt can be shown to your users
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrivacySandboxPromptEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxSiteEnabledAdsEnabled  Choose whether the Privacy Sandbox Site-suggested ads setting can be disabled
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrivacySandboxSiteEnabledAdsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostClientDomain  Configure the required domain name for remote access clients
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostClientDomain
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: my-awesome-domain.com
RemoteAccessHostDomain  Configure the required domain name for remote access hosts
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostDomain
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: my-awesome-domain.com
DefaultMediaStreamSetting  Default mediastream setting
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultMediaStreamSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any site to access the camera and microphone
3Ask every time a site wants to access the camera and/or microphone
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultWindowPlacementSetting  Default Window Placement permission setting
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultWindowPlacementSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Denies the Window Placement permission on all sites by default
3Ask every time a site wants obtain the Window Placement permission
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
DeveloperToolsDisabled  Disable Developer Tools
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DeveloperToolsDisabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
DisabledSchemes  Disable URL protocol schemes
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\DisabledSchemes
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: file https
AutoFillEnabled  Enable AutoFill
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AutoFillEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
FirstPartySetsEnabled  Enable First-Party Sets.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
FirstPartySetsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ForceBrowserSignin  Enable force sign in for Google Chrome
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceBrowserSignin
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
IncognitoEnabled  Enable Incognito mode
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
IncognitoEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
JavascriptEnabled  Enable JavaScript
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
JavascriptEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
RelatedWebsiteSetsEnabled  Enable Related Website Sets
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RelatedWebsiteSetsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingEnabled  Enable Safe Browsing
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
PromotionalTabsEnabled  Enable showing full-tab promotional content
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PromotionalTabsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
RoamingProfileSupportEnabled  Enable the creation of roaming copies for Google Chrome profile data
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RoamingProfileSupportEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
InsecureFormsWarningsEnabled  Enable warnings for insecure forms
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
InsecureFormsWarningsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ForceSafeSearch  Force SafeSearch
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceSafeSearch
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ForceYouTubeSafetyMode  Force YouTube Safety Mode
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceYouTubeSafetyMode
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
UnsafelyTreatInsecureOriginAsSecure  Origins or hostname patterns for which restrictions on insecure origins should not apply
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\UnsafelyTreatInsecureOriginAsSecure
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: http://testserver.example.com/ *.example.org
FirstPartySetsOverrides  Override First-Party Sets.
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
FirstPartySetsOverrides
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 See https://chromeenterprise.google/policies/?policy=FirstPartySetsOverrides for more information about schema and formatting. Example value: { "additions": [ { "associatedSites": [ "https://associate2.test" ], "ccTLDs": { "https://associate2.test": [ "https://associate2.com" ] }, "primary": "https://primary2.test", "serviceSites": [ "https://associate2-content.test" ] } ], "replacements": [ { "associatedSites": [ "https://associate1.test" ], "ccTLDs": { "https://associate1.test": [ "https://associate1.co.uk" ] }, "primary": "https://primary1.test", "serviceSites": [ "https://associate1-content.test" ] } ] }
RelatedWebsiteSetsOverrides  Override Related Website Sets.
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RelatedWebsiteSetsOverrides
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 See https://chromeenterprise.google/policies/?policy=RelatedWebsiteSetsOverrides for more information about schema and formatting. Example value: { "additions": [ { "associatedSites": [ "https://associate2.test" ], "ccTLDs": { "https://associate2.test": [ "https://associate2.com" ] }, "primary": "https://primary2.test", "serviceSites": [ "https://associate2-content.test" ] } ], "replacements": [ { "associatedSites": [ "https://associate1.test" ], "ccTLDs": { "https://associate1.test": [ "https://associate1.co.uk" ] }, "primary": "https://primary1.test", "serviceSites": [ "https://associate1-content.test" ] } ] }
ProxyBypassList  Proxy bypass rules
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ProxyBypassList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://www.example1.com,https://www.example2.com,https://internalsite/
RoamingProfileLocation  Set the roaming profile directory
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RoamingProfileLocation
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: ${roaming_app_data}\chrome-profile
LensOverlaySettings  Settings for the Lens Overlay feature
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LensOverlaySettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow
1Do not allow
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500
ProxyPacUrl  URL to a proxy .pac file
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ProxyPacUrl
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500 Example value: https://internal.site/example.pac
Google:Cat_Google / Google Chrome / Extensions
ExtensionInstallTypeBlocklist  Blocklist for install types of extensions
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionInstallTypeBlocklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
The blocklist controls which extensions install types are disallowed. Setting "command_line" will block extension from being loaded from command line. Example value: command_line
BlockExternalExtensions  Blocks external extensions from being installed
Boolean Machine + User
Setting this policy to Disabled or leaving it unset allows external extensions to be installed.
Registry key
Software\Policies\Google\Chrome
Value name
BlockExternalExtensions
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls external extensions installation. Setting this policy to Enabled blocks external extensions from being installed. Setting this policy to Disabled or leaving it unset allows external extensions to be installed. External extensions and their installation are documented at https://developer.chrome.com/docs/extensions/how-to/distribute/install-extensions. Note: This policy only applies to platforms that support extensions.
ExtensionExtendedBackgroundLifetimeForPortConnectionsToUrls  Configure a list of origins that grant extended background lifetime to the connecting extensions.
List (values under a subkey) Machine + User
If unset, the policy's default values will be used.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionExtendedBackgroundLifetimeForPortConnectionsToUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Extensions that connect to one of these origins will be be kept running as long as the port is connected. If unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state: - Smart Card Connector - Citrix Receiver (stable, beta, back-up) - VMware Horizon (stable, beta) If set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected. Example value: chrome-extension://abcdefghijklmnopabcdefghijklmnop/ chrome-extension://bcdefghijklmnopabcdefghijklmnopa/
ExtensionAllowedTypes  Configure allowed app/extension types
List (values under a subkey) Machine + User
Leaving the policy unset results in no restrictions on the acceptable extension and app types.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionAllowedTypes
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy controls which apps and extensions may be installed in Google Chrome, which hosts they can interact with, and limits runtime access. Leaving the policy unset results in no restrictions on the acceptable extension and app types. Extensions and apps which have a type that's not on the list won't be installed. Each value should be one of these strings: * "extension" * "theme" * "user_script" * "hosted_app" * "legacy_packaged_app" * "platform_app" See the Google Chrome extensions documentation for more information on these types. Versions earlier than 75 that use multiple comma separated extension IDs aren't supported and are skipped. The rest of the policy applies. Note: This policy also affects extensions and apps to be force-installed using ExtensionInstallForcelist. Note: This policy only applies to platforms that support extensions. Example value: hosted_app
ExtensionInstallAllowlist  Configure extension installation allow list
List (values under a subkey) Machine + User
By default, all extensions are allowed.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionInstallAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies which extensions are not subject to the blocklist. A blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list. By default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy. Note: This policy only applies to platforms that support extensions. Example value: extension_id1 extension_id2
ExtensionInstallBlocklist  Configure extension installation blocklist
List (values under a subkey) Machine + User
If this policy is left not set the user can install any extension in Google Chrome.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionInstallBlocklist
Stated default
A blocklist value of '*' means all extensions are blocked by default.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. Once an extension disabled due to the blocklist is removed from it, it will automatically get re-enabled. A blocklist value of '*' means all extensions are blocked by default. Extensions that are explicitly listed in the allowlist are allowed if they are signed (packed). All unpacked extensions are blocked. If this policy is left not set the user can install any extension in Google Chrome. Note: This policy only applies to platforms that support extensions. Example value: extension_id1 extension_id2
ExtensionInstallSources  Configure extension, app, and user script install sources
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionInstallSources
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow. Each item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns. ExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list. Note: This policy only applies to platforms that support extensions. Example value: https://corp.mycompany.com/*
ExtensionInstallForcelist  Configure the list of force-installed apps and extensions
List (values under a subkey) Machine + User
Leaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionInstallForcelist
Stated default
By default, the Chrome Web Store's update URL is used.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies a list of apps and extensions that install silently, without user interaction, and which users can't uninstall or turn off through the Google Chrome interface. Permissions are granted implicitly, including for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These 2 APIs aren't available to apps and extensions that aren't force-installed.) Although Google Chrome aims to prevent users from uninstalling these extensions, some operating systems make it impossible for Google Chrome to defend robustly against extensions being modified externally, so this prevention is best efforts. Leaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome. This policy supersedes ExtensionInstallBlocklist policy. If a previously force-installed app or extension is removed from this list, Google Chrome automatically uninstalls it. The source code of any extension may be altered by users through developer tools, potentially rendering the extension dysfunctional. If this is a concern, set the DeveloperToolsDisabled policy. Each list item of the policy is a string that contains an extension ID and, optionally, an update URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on chrome://extensions when in Developer mode. If specified, the update URL should point to an Update Manifest XML document ( https://developer.chrome.com/extensions/autoupdate ). The update URL should use one of the following schemes: http, https or file. By default, the Chrome Web Store's update URL is used. The update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest. The update url for subsequent updates can be overridden using the ExtensionSettings policy, see http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy. On Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Note: This policy doesn't apply to Incognito mode. Read about hosting extensions ( https://developer.chrome.com/extensions/hosting ). Note: This policy only applies to platforms that support extensions. Example value: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa;https://clients2.google.com/service/update2/crx abcdefghijklmnopabcdefghijklmnop
ExtensionUnpublishedAvailability  Control availability of extensions unpublished on the Chrome Web Store.
Enum Machine + User
If the policy is set to AllowUnpublished (0) or not set, extensions that are unpublished on the Chrome Web Store are allowed.
Registry key
Software\Policies\Google\Chrome
Value name
ExtensionUnpublishedAvailability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow unpublished extensions
1Disable unpublished extensions
If this policy is enabled, extensions that are unpublished on the Chrome Web Store will be disabled in Google Chrome. This policy only applies to extensions that are installed and updated from the Chrome Web Store. Off-store extensions such as unpacked extensions installed using developer mode and extensions installed using the command-line switch are ignored. Force-installed extensions that are self-hosted are ignored. All version-pinned extensions are also ignored. If the policy is set to AllowUnpublished (0) or not set, extensions that are unpublished on the Chrome Web Store are allowed. If the policy is set to DisableUnpublished (1), extensions that are unpublished on the Chrome Web Store are disabled.
ExtensionDeveloperModeSettings  Control the availability of developer mode on extensions page
Enum Machine + User
If the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).
Registry key
Software\Policies\Google\Chrome
Value name
ExtensionDeveloperModeSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow the usage of developer mode on extensions page
1Do not allow the usage of developer mode on extensions page
Control if users can turn on Developer Mode on chrome://extensions. If the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2). If the policy is set to Allow (0), users can turn on developer mode on extensions page. If the policy is set to Disallow (1), users can not turn on developer mode on extensions page. If this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode. Note: This policy only applies to platforms that support extensions.
ExtensionSettings  Extension management settings
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ExtensionSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy controls extension management settings for Google Chrome, including any controlled by existing extension-related policies. This policy maps an extension ID or an update URL to its specific setting only. A default configuration can be set for the special ID "*", which applies to all extensions without a custom configuration in this policy. This policy can override per-extension config from legacy policies. Note that any per-ID extension setting from either ExtensionInstallForcelist, ExtensionInstallAllowlist, ExtensionInstallBlocklist, or ExtensionSettings will only inherit 'installation_mode' and 'update_url' from the "*" defaults. It will not inherit any other properties. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest ( http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy ). If the 'override_update_url' flag is set to true, the extension is installed and updated using the "update" URL specified in the ExtensionInstallForcelist policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is a Chrome Web Store url. On Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Note: This policy only applies to platforms that support extensions. See https://chromeenterprise.google/policies/?policy=ExtensionSettings for more information about schema and formatting. Example value: { "*": { "allowed_types": [ "hosted_app" ], "blocked_install_message": "Custom error message.", "blocked_permissions": [ "downloads", "bookmarks" ], "install_sources": [ "https://company-intranet/chromeapps" ], "installation_mode": "blocked", "runtime_allowed_hosts": [ "*://good.example.com" ], "runtime_blocked_hosts": [ "*://*.example.com" ] }, "abcdefghijklmnopabcdefghijklmnop": { "blocked_permissions": [ "history" ], "installation_mode": "allowed", "minimum_version_required": "1.0.1", "toolbar_pin": "force_pinned", "file_url_navigation_allowed": true }, "bcdefghijklmnopabcdefghijklmnopa": { "allowed_permissions": [ "downloads" ], "installation_mode": "force_installed", "runtime_allowed_hosts": [ "*://good.example.com" ], "runtime_blocked_hosts": [ "*://*.example.com" ], "update_url": "https://example.com/update_url" }, "cdefghijklmnopabcdefghijklmnopab": { "blocked_install_message": "Custom error message.", "installation_mode": "blocked" }, "defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd": { "blocked_install_message": "Custom error message.", "installation_mode": "blocked" }, "fghijklmnopabcdefghijklmnopabcde": { "blocked_install_message": "Custom removal message.", "installation_mode": "removed" }, "ghijklmnopabcdefghijklmnopabcdef": { "installation_mode": "force_installed", "override_update_url": true, "update_url": "https://example.com/update_url" }, "update_url:https://www.example.com/update.xml": { "allowed_permissions": [ "downloads" ], "blocked_permissions": [ "wallpaper" ], "installation_mode": "allowed" } }
Google:Cat_Google / Google Chrome / Generative AI
GeminiActOnWebAllowedForURLs  Allow Gemini app integrations to directly act on specified sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\GeminiActOnWebAllowedForURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows to set a list of URL patterns that specify on which sites Gemini app integrations can directly act on web pages. URLs matching neither the allowlist or the blocklist use GeminiActOnWebSettings. URLs matching both the allowlist and the blocklist are allowed. For detailed information on valid url patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
GeminiActOnWebSettings  Allows Gemini app integrations to directly act on web pages
Enum Machine + User
0/unset = Gemini app is allowed to take action on the web pages.
Registry key
Software\Policies\Google\Chrome
Value name
GeminiActOnWebSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow the Gemini app to take action on the web pages.
1Disallow the Gemini app to take action on the web pages.
Controls if the Gemini app is allowed to take action on the web pages on behalf of the user. 0/unset = Gemini app is allowed to take action on the web pages. 1 = Gemini app is not allowed to take action on the web pages. This policy has no effect when the Gemini app is disabled. For example, the Gemini app can be disabled by GeminiSettings policy. For more information on Gemini in Chrome, please see https://support.google.com/chrome/a/answer/16291696. Gemini's actuation is not available in all countries or all languages. Setting this policy does not guarantee the feature will be enabled; it remains subject to availability. For more info on the roll-out, check the Enterprise Release Notes: https://support.google.com/chrome/a/answer/7679408?hl=en
GeminiSparkSettings  Allows Gemini Spark to connect to and use Google Chrome auto browse
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
GeminiSparkSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Gemini Spark is allowed to connect to and use Google Chrome auto browse.
1Gemini Spark is not allowed to connect to or use Google Chrome auto browse.
Controls if the Gemini Spark agent is allowed to connect to Google Chrome and use auto browse. 0 = Gemini Spark is allowed to connect to and use Google Chrome auto browse 1 = Gemini Spark is not allowed to connect to or use Google Chrome auto browse Warning: Enabling Gemini Spark to connect to Google Chrome and use auto browse permits the Gemini Spark agent to perform autonomous, multi-step actions on Google Chrome clients using the active browser session. This entails significant security risks, including credential risks, Local Network Ingress and loss of context aware signals. Existing management and security controls might not be respected. Administrators are advised to carefully evaluate their organization's network threat model, compliance and privacy guidelines before enabling this feature. This policy has no effect when the Google Gemini app or Google Chrome auto browse policies are disabled. For example, the Google Gemini app can be disabled by GeminiSettings policy. For more information on Google Gemini in Google Chrome, please see https://support.google.com/chrome/a?p=gemini_in_chrome. Google Chrome auto browse and Gemini Spark are not available in all countries or all languages. Setting this policy to 0 - Enabled does not guarantee the feature will be enabled; it remains subject to availability. For more info on the roll-out, check the Enterprise Release Notes: https://chromeenterprise.google/resources/release-notes/.
GeminiActOnWebBlockedForURLs  Block Gemini app integrations to directly act on specified sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\GeminiActOnWebBlockedForURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allows to set a list of URL patterns that specify on which sites Gemini app integrations cannot directly act on web pages. URLs matching neither the allowlist or the blocklist use GeminiActOnWebSettings. URLs matching both the allowlist and the blocklist are allowed. For detailed information on valid url patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com
SearchContentSharingSettings  Enable content sharing with Google AI Mode and Lens integrations
Enum Machine + User
If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
SearchContentSharingSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow content sharing with Google AI Mode integrations.
1Do not allow content sharing with Google AI Mode integrations.
This policy controls sharing of page and file content with Google AI Mode and Lens through Google Chrome side panel or tabs. Note that this policy doesn't affect Google AI Mode on the web. It only controls how users can share information with it when using Google Chrome. 0 = users can share page or file content with Google AI Mode. 1 = users cannot share page or file content with Google AI Mode. The entry points for sharing context and the side panel will be disabled or hidden. This policy will be ignored when Google Search is not users' default search engine as the feature is disabled. This policy is independent of the AIModeSettings policy. The AIModeSettings policy only controls entry points on omnibox or NTP search box, while this policy controls context sharing through side panel or tabs. This policy also doesn't control Google Gemini integration which can be disabled by GeminiSettings. If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
ThirdPartyAiChatSettings  Settings for 3rd party AI Mode integrations in the address bar and New Tab page search box.
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
ThirdPartyAiChatSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow 3rd party AI Mode integrations.
1Do not allow 3rd party AI Mode integrations.
This policy controls 3rd party AI Mode integrations in the address bar and the New Tab page search box. To access this feature, a 3rd party search engine that supports AI Mode must be set as the user's default search engine. 0 = The feature will be available to users. 1 = The feature will not be available to users. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
HistorySearchSettings  Settings for AI-powered History Search
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
HistorySearchSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow AI History Search and improve AI models.
1Allow AI History Search without improving AI models.
2Do not allow AI History Search.
AI History Search is a feature that allows users to search their browsing history and receive generated answers based on page contents and not just the page title and URL. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
DevToolsGenAiSettings  Settings for Chrome DevTools Generative AI Features
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
DevToolsGenAiSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow Chrome DevTools Generative AI Features and improve AI models.
1Allow Chrome DevTools Generative AI Features without improving AI models.
2Do not allow Chrome DevTools Generative AI Features.
These features in Chrome DevTools employ generative AI models to provide additional debugging information. To use these features, Google Chrome has to collect data such as error messages, stack traces, code snippets, and network requests and send them to a server owned by Google, which runs a generative AI model. Response body or authentication and cookie headers in network requests are not included in the data sent to the server. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. Chrome DevTools Generative AI features include: - Console Insights: explains console messages and offers suggestions on how to fix console errors. - AI assistance: get help with understanding CSS styles (since version 131), network requests, performance, and files (all since version 132). For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
ChromeSuggestionsSettings  Settings for ChromeSuggestions
Integer Machine + User
0/unset = Chrome suggestions will be enabled for users.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeSuggestionsSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This setting allows Chrome to suggest AI capabilities at relevant moments. 0/unset = Chrome suggestions will be enabled for users. 1 = Chrome suggestions are disabled for users. For more information, please check the help center article: https://support.google.com/chrome/a?p=chrome_suggestions
CreateThemesSettings  Settings for Create Themes with AI
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
CreateThemesSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow Create Themes and improve AI models.
1Allow Create Themes without improving AI models.
2Do not allow Create Themes.
Create Themes with AI lets users create custom themes/wallpapers by preselecting from a list of options. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
AutofillPredictionSettings  Settings for enhanced autofill
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
AutofillPredictionSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow enhanced autofill and improve AI models.
1Allow enhanced autofill without improving AI models.
2Do not allow enhanced autofill.
Specifies whether users can let Google Chrome use Generative AI to better understand forms and help them fill more fields. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
GeminiSettings  Settings for Gemini integration
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
GeminiSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow Gemini integrations.
1Do not allow Gemini integrations.
This setting allows Gemini app integrations. 0 = Gemini integration will be available for users. 1 = Gemini integration will not be available for users. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information, please check the Help Center article https://support.google.com/chrome/a?p=gemini_in_chrome.
GenAILocalFoundationalModelSettings  Settings for GenAI local foundational model
Enum Machine + User
When the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference.
Registry key
Software\Policies\Google\Chrome
Value name
GenAILocalFoundationalModelSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Downloads model automatically
1Do not download model
Configure how Google Chrome downloads the foundational GenAI model and uses for inference locally. When the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference. When the policy is set to Disabled (1), the model will not be downloaded, and the existing model (if already downloaded) will be deleted. On desktop platforms, model downloading can also be disabled by setting ComponentUpdatesEnabled to false.
AIModeSettings  Settings for Google's AI Mode integrations in the address bar and New Tab page search box.
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
AIModeSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow AI Mode integrations.
1Do not allow AI Mode integrations.
This policy controls Google's AI Mode integrations in the address bar and the New Tab page search box. To access this feature, Google must be set as the user's default search engine. 0 = The feature will be available to users. 1 = The feature will not be available to users. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
HelpMeWriteSettings  Settings for Help Me Write
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
HelpMeWriteSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow Help Me Write and improve AI models.
1Allow Help Me Write without improving AI models.
2Do not allow Help Me Write.
Help Me Write is an AI-based writing assistant for short-form content on the web. Suggested content is based on prompts entered by the user and the content of the web page. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
VoiceTypingSettings  Settings for Voice Typing
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
VoiceTypingSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow Voice Typing.
1Allow Voice Typing without data collection.
2Do not allow Voice Typing.
Voice Typing is an AI-based feature that allows users to input and edit text using their voice, powered by generative AI models to provide high-quality transcription and formatting. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
SmartTabSharingSettings  Smart tab sharing settings
Enum Machine + User
If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
SmartTabSharingSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow smart tab sharing with Google AI Mode integrations.
1Do not allow smart tab sharing with Google AI Mode integrations.
This policy controls the smart tab sharing feature of Google AI Mode through Google Chrome side panel or tabs. Note that this policy doesn't affect Google AI Mode on the web. It only controls how users can share information with it when using Google Chrome. 0 = users can share page or file content with Google AI Mode. 1 = users cannot share page or file content with Google AI Mode. The entry points for sharing context and the side panel will be disabled or hidden. This policy will be ignored when Google Search is not users' default search engine as the feature is disabled. This policy is independent of the AIModeSettings policy. The AIModeSettings policy only controls entry points on omnibox or NTP search box, while this policy controls context sharing through side panel or tabs. This policy also doesn't control Google Gemini integration which can be disabled by GeminiSettings. Note that if SearchContentSharingSettings is disabled, this policy will be ignored. If this policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
TabCompareSettings  Tab Compare settings
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
TabCompareSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow Tab Compare and improve AI models.
1Allow Tab Compare without improving AI models.
2Do not allow Tab Compare.
Tab Compare is an AI-powered tool for comparing information across a user's tabs. As an example, the feature can be offered to the user when multiple tabs with products in a similar category are open. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
Google:Cat_Google / Google Chrome / Google Cast
MediaRouterCastAllowAllIPs  Allow Google Cast to connect to Cast devices on all IP addresses.
Boolean Machine + User
Leaving the policy unset connects Google Cast to Cast devices only on RFC1918/RFC4193, unless the CastAllowAllIPs feature is turned on.
Registry key
Software\Policies\Google\Chrome
Value name
MediaRouterCastAllowAllIPs
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Unless EnableMediaRouter is set to Disabled, setting MediaRouterCastAllowAllIPs to Enabled connects Google Cast to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses. Setting the policy to Disabled connects Google Cast to Cast devices only on RFC1918/RFC4193. Leaving the policy unset connects Google Cast to Cast devices only on RFC1918/RFC4193, unless the CastAllowAllIPs feature is turned on.
AccessCodeCastEnabled  Allow users to select cast devices with an access code or QR code from within the Google Cast menu.
Boolean Machine + User
When this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.
Registry key
Software\Policies\Google\Chrome
Value name
AccessCodeCastEnabled
Enabled / Disabled
1 / 0
Stated default
By default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired.
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether a user will be presented with an option, within the Google Cast menu which allows them to cast to cast devices that do not appear in the Google Cast menu, using either the access code or QR code displayed on the cast devices's screen. By default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired. When this policy is set to Enabled, users will be presented with the option to select cast devices by using an access code or by scanning a QR code. When this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.
EnableMediaRouter  Enable Google Cast
Boolean Machine + User
Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.
Registry key
Software\Policies\Google\Chrome
Value name
EnableMediaRouter
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon. Setting the policy to Disabled turns off Google Cast.
ShowCastSessionsStartedByOtherDevices  Show media controls for Google Cast sessions started by other devices on the local network
Boolean Machine + User
When this policy is unset for enterprise users or is disabled, media playback controls UI is unavailable for Google Cast sessions started by other devices on the local network.
Registry key
Software\Policies\Google\Chrome
Value name
ShowCastSessionsStartedByOtherDevices
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When this policy is enabled, media playback controls UI is available for Google Cast sessions started by other devices on the local network. When this policy is unset for enterprise users or is disabled, media playback controls UI is unavailable for Google Cast sessions started by other devices on the local network. If the policy EnableMediaRouter is disabled, then this policy's value has no effect, as the entire Google Cast functionality is disabled.
ShowCastIconInToolbar  Show the Google Cast toolbar icon
Boolean Machine + User
Setting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu.
Registry key
Software\Policies\Google\Chrome
Value name
ShowCastIconInToolbar
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled displays the Cast toolbar icon on the toolbar or the overflow menu, and users can't remove it. Setting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu. If the policy EnableMediaRouter is set to Disabled, then this policy's value has no effect, and the toolbar icon doesn't appear.
AccessCodeCastDeviceDuration  Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.
Integer Machine + User
By default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session.
Registry key
Software\Policies\Google\Chrome
Value name
AccessCodeCastDeviceDuration
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy specifies how long (in seconds) a cast device that was previously selected via an access code or QR code can be seen within the Google Cast menu of cast devices. The lifetime of an entry starts at the time the access code was first entered or the QR code was first scanned. During this period the cast device will appear in the Google Cast menu's list of cast devices. After this period, in order to use the cast device again the access code must be reentered or the QR code must be rescanned. By default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session. Note that this policy only affects how long a cast devices appears in the Google Cast menu, and has no effect on any ongoing cast session which will continue even if the period expires. This policy has no effect unless the AccessCodeCastEnabled policy is Enabled.
Google:Cat_Google / Google Chrome / HTTP authentication
BasicAuthOverHttpEnabled  Allow Basic authentication for HTTP
Boolean Machine + User
Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP.
Registry key
Software\Policies\Google\Chrome
Value name
BasicAuthOverHttpEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP. Setting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed. This policy setting is ignored (and Basic is always forbidden) if the AuthSchemes policy is set and does not include Basic.
AuthServerAllowlist  Authentication server allowlist
String Machine + User
Leaving the policy unset means Google Chrome tries to detect if a server is on the intranet.
Registry key
Software\Policies\Google\Chrome
Value name
AuthServerAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies which servers should be allowed for integrated authentication. Integrated authentication is only on when Google Chrome gets an authentication challenge from a proxy or from a server in this permitted list. Leaving the policy unset means Google Chrome tries to detect if a server is on the intranet. Only then will it respond to IWA requests. If a server is detected as internet, then Google Chrome ignores IWA requests from it. Note: Separate multiple server names with commas. Wildcards, *, are allowed. Example value: *.example.com,example.com
AllowCrossOriginAuthPrompt  Cross-origin HTTP Authentication prompts
Boolean Machine + User
Setting the policy to Disabled or leaving it unset renders third-party images unable to show an authentication prompt.
Registry key
Software\Policies\Google\Chrome
Value name
AllowCrossOriginAuthPrompt
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled allows third-party images on a page to show an authentication prompt. Setting the policy to Disabled or leaving it unset renders third-party images unable to show an authentication prompt. Typically, this policy is Disabled as a phishing defense.
DisableAuthNegotiateCnameLookup  Disable CNAME lookup when negotiating Kerberos authentication
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.
Registry key
Software\Policies\Google\Chrome
Value name
DisableAuthNegotiateCnameLookup
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN. Setting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.
EnableAuthNegotiatePort  Include non-standard port in Kerberos SPN
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means the generated Kerberos SPN won't include a port.
Registry key
Software\Policies\Google\Chrome
Value name
EnableAuthNegotiatePort
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled and entering a nonstandard port (in other words, a port other than 80 or 443) includes it in the generated Kerberos SPN. Setting the policy to Disabled or leaving it unset means the generated Kerberos SPN won't include a port.
AuthNegotiateDelegateAllowlist  Kerberos delegation server allowlist
String Machine + User
Leaving the policy unset means Google Chrome won't delegate user credentials, even if a server is detected as intranet.
Registry key
Software\Policies\Google\Chrome
Value name
AuthNegotiateDelegateAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy assigns servers that Google Chrome may delegate to. Separate multiple server names with commas. Wildcards, *, are allowed. Leaving the policy unset means Google Chrome won't delegate user credentials, even if a server is detected as intranet. Example value: *.example.com,foobar.example.com
AllHttpAuthSchemesAllowedForOrigins  List of origins allowing all HTTP authentication
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AllHttpAuthSchemesAllowedForOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies for which origins to allow all the HTTP authentication schemes Google Chrome supports regardless of the AuthSchemes policy. Format the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in AllHttpAuthSchemesAllowedForOrigins. Wildcards are allowed for the host component (e.g., '*:8000' matches all hosts on port 8000). To match all schemes or all ports, omit the component entirely (e.g., 'example.com' matches any scheme and any port). A hostname (e.g., 'example.com') also matches its subdomains. To match a host exactly and exclude its subdomains, prepend it with a dot (e.g., '.example.com'). To match all origins, use a single asterisk ('*'). Example value: https://example.com example.com *:8000 *
AuthSchemes  Supported authentication schemes
String Machine + User
Leaving the policy unset employs all 4 schemes.
Registry key
Software\Policies\Google\Chrome
Value name
AuthSchemes
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies which HTTP authentication schemes Google Chrome supports. Leaving the policy unset employs all 4 schemes. Valid values: * basic * digest * ntlm * negotiate Note: Separate multiple values with commas. Example value: basic,digest,ntlm,negotiate
Google:Cat_Google / Google Chrome / Idle Browser Actions
IdleTimeoutActions  Actions to run when the computer is idle
List (values under a subkey) Machine + User
If the IdleTimeout policy is unset, this policy has no effect. If this policy is empty or left unset, the IdleTimeout policy has no effect.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\IdleTimeoutActions
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of actions to run when the timeout from the IdleTimeout policy is reached. Warning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data. If the IdleTimeout policy is unset, this policy has no effect. When the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy. If this policy is empty or left unset, the IdleTimeout policy has no effect. Supported actions are: 'close_browsers': close all browser windows and PWAs for this profile. Not supported on Android and iOS. 'close_tabs': close all open tabs in open windows. Only supported on iOS. 'show_profile_picker': show the Profile Picker window. Not supported on Android and iOS. 'sign_out': Signs out the current signed in user. Only supported on iOS. 'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings', 'clear_hosted_app_data': clear the corresponding browsing data. See the ClearBrowsingDataOnExitList policy for more details. The types supported on iOS are 'clear_browsing_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', and 'clear_autofill' 'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first. Not supported on iOS. The user will stay signed into their Google account when deleting cookies using 'clear_cookies_and_other_site_data'. Setting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled. Example value: close_browsers show_profile_picker
IdleTimeout  Delay before running idle actions
Integer Machine + User
If this policy is not set, no action will be ran.
Registry key
Software\Policies\Google\Chrome
Value name
IdleTimeout
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Triggers an action when the computer is idle. If this policy is set, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy. If this policy is not set, no action will be ran. The minimum threshold is 1 minute. "User input" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.
Google:Cat_Google / Google Chrome / Legacy Browser Support
AlternativeBrowserPath  Alternative browser to launch for configured websites.
String Machine + User
Leaving the policy unset puts a platform-specific default in use: Internet Explorer® for Microsoft® Windows®, or Safari® for macOS.
Registry key
Software\Policies\Google\Chrome
Value name
AlternativeBrowserPath
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy controls which command to use to open URLs in an alternative browser. The policy can be set to one of ${ie}, ${firefox}, ${safari}, ${opera}, ${edge} or a file path. When this policy is set to a file path, that file is used as an executable file. ${ie} is only available on Microsoft® Windows®. ${safari} and ${edge} are only available on Microsoft® Windows® and macOS. Leaving the policy unset puts a platform-specific default in use: Internet Explorer® for Microsoft® Windows®, or Safari® for macOS. On Linux®, launching an alternative browser will fail. Example value: ${ie}
BrowserSwitcherChromeParameters  Command-line parameters for switching from the alternative browser.
List (values under a subkey) Machine + User
Leaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\BrowserSwitcherChromeParameters
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If a parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line. Environment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable. Leaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter. Note: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect. Example value: --force-dark-mode
AlternativeBrowserParameters  Command-line parameters for the alternative browser.
List (values under a subkey) Machine + User
Leaving the policy unset means only the URL is passed as a command-line parameter.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AlternativeBrowserParameters
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to a list of strings means each string is passed to the alternative browser as separate command-line parameters. On Microsoft® Windows®, the parameters are joined with spaces. On macOS and Linux®, a parameter can have spaces and still be treated as a single parameter. If a parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line. Environment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable. On macOS and Linux®, ${ABC} is replaced with the value of the ABC environment variable. Leaving the policy unset means only the URL is passed as a command-line parameter. Example value: -foreground -new-window ${url} -profile %HOME%\browser_profile
BrowserSwitcherDelay  Delay before launching alternative browser (milliseconds)
Integer Machine + User
Leaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherDelay
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to a number has Google Chrome show a message for that number of milliseconds, then it opens an alternative browser. Leaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.
BrowserSwitcherEnabled  Enable the Legacy Browser Support feature.
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means Google Chrome won't try to launch designated URLs in an alternate browser.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means Google Chrome will try to launch some URLs in an alternate browser, such as Internet Explorer®. This feature is set using the policies in the Legacy Browser support group. Setting the policy to Disabled or leaving it unset means Google Chrome won't try to launch designated URLs in an alternate browser.
BrowserSwitcherKeepLastChromeTab  Keep last tab open in Chrome.
Boolean Machine + User
Setting the policy to Enabled or leaving it unset has Google Chrome keep at least one tab open, after switching to an alternate browser.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherKeepLastChromeTab
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset has Google Chrome keep at least one tab open, after switching to an alternate browser. Setting the policy to Disabled has Google Chrome close the tab after switching to an alternate browser, even if it was the last tab. This causes Google Chrome to exit completely.
BrowserSwitcherChromePath  Path to Chrome for switching from the alternative browser.
String Machine + User
Leaving the policy unset means Internet Explorer® autodetects Google Chrome's own executable path when launching Google Chrome from Internet Explorer.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherChromePath
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the command to use to open URLs in Google Chrome when switching from Internet Explorer®. This policy can be set to an executable file path or ${chrome} to autodetect the location of Google Chrome. Leaving the policy unset means Internet Explorer® autodetects Google Chrome's own executable path when launching Google Chrome from Internet Explorer. Note: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect. Example value: ${chrome}
BrowserSwitcherParsingMode  Sitelist parsing mode
Enum Machine + User
If 'Default' (0) or unset, URL matching is less strict.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherParsingMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Default behavior for LBS.
1More compatible with Microsoft IE/Edge enterprise mode sitelists.
This policy controls how Google Chrome interprets sitelist/greylist policies for the Legacy Browser Support feature. It affects the following policies: BrowserSwitcherUrlList, BrowserSwitcherUrlGreylist, BrowserSwitcherUseIeSitelist, BrowserSwitcherExternalSitelistUrl, and BrowserSwitcherExternalGreylistUrl. If 'Default' (0) or unset, URL matching is less strict. Rules that do not contain "/" look for a substring anywhere in the URL's hostname. Matching the path component of a URL is case-sensitive. If 'IESiteListMode' (1), URL matching is more strict. Rules that do not contain "/" only match at the end of the hostname. They must also be at a domain name boundary. Matching the path component of a URL is case-insensitive. This is more compatible with Microsoft® Internet Explorer® and Microsoft® Edge®. For example, with the rules "example.com" and "acme.com/abc": "http://example.com/", "http://subdomain.example.com/" and "http://acme.com/abc" match regardless of parsing mode. "http://notexample.com/", "http://example.com.invalid.com/", "http://example.comabc/" only match in 'Default' mode. "http://acme.com/ABC" only matches in 'IESiteListMode'.
BrowserSwitcherExternalGreylistUrl  URL of an XML file that contains URLs that should never trigger a browser switch.
String Machine + User
Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for not switching browsers.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherExternalGreylistUrl
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlGreylist policy. These policies prevent Google Chrome and the alternative browser from opening one another. Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for not switching browsers. Note: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode ) Example value: http://example.com/greylist.xml
BrowserSwitcherExternalSitelistUrl  URL of an XML file that contains URLs to load in an alternative browser.
String Machine + User
Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherExternalSitelistUrl
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlList policy. Leaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers. Note: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode) Example value: http://example.com/sitelist.xml
BrowserSwitcherUseIeSitelist  Use Internet Explorer's SiteList policy for Legacy Browser Support.
Boolean Machine + User
When this policy is false or unset, Google Chrome does not use Internet Explorer®'s SiteList policy as a source of rules for switching browsers.
Registry key
Software\Policies\Google\Chrome
Value name
BrowserSwitcherUseIeSitelist
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether to load rules from Internet Explorer®'s SiteList policy. When this policy is set to true, Google Chrome reads Internet Explorer®'s SiteList to obtain the site list's URL. Google Chrome then downloads the site list from that URL, and applies the rules as if they had been configured with the BrowserSwitcherUrlList policy. When this policy is false or unset, Google Chrome does not use Internet Explorer®'s SiteList policy as a source of rules for switching browsers. For more information on Internet Explorer's SiteList policy: https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode
BrowserSwitcherUrlGreylist  Websites that should never trigger a browser switch.
List (values under a subkey) Machine + User
Leaving the policy unset adds no websites to the list.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\BrowserSwitcherUrlGreylist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy controls the list of websites that will never cause a browser switch. Each item is treated as a rule. Those rules that match won't open an alternative browser. Unlike the BrowserSwitcherUrlList policy, rules apply to both directions. When the Internet Explorer® add-in is on, it also controls whether Internet Explorer® should open these URLs in Google Chrome. Leaving the policy unset adds no websites to the list. Note: Elements can also be added to this list through the BrowserSwitcherExternalGreylistUrl policy. Example value: ie.com !open-in-chrome.ie.com foobar.com/ie-only/
BrowserSwitcherUrlList  Websites to open in alternative browser
List (values under a subkey) Machine + User
Leaving the policy unset adds no websites to the list.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\BrowserSwitcherUrlList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy controls the list of websites to open in an alternative browser. Each item is treated as a rule for something to open in an alternative browser. Google Chrome uses those rules when choosing if a URL should open in an alternative browser. When the Internet Explorer® add-in is on, Internet Explorer® switches back to Google Chrome when the rules don't match. If rules contradict each other, Google Chrome uses the most specific rule. Leaving the policy unset adds no websites to the list. Note: Elements can also be added to this list through the BrowserSwitcherUseIeSitelist and BrowserSwitcherExternalSitelistUrl policies. Example value: ie.com !open-in-chrome.ie.com foobar.com/ie-only/
Google:Cat_Google / Google Chrome / Local Network Access settings
LocalNetworkAccessPermissionsPolicyDefaultEnabled  Allow Local Network Access (LNA) requests in subframes without explicit delegation
Boolean Machine + User
If this policy is set to disabled or not set, then subframes must be explicitly delegated the permissions policy feature in order make local network requests and trigger the permission prompt.
Registry key
Software\Policies\Google\Chrome
Value name
LocalNetworkAccessPermissionsPolicyDefaultEnabled
Enabled / Disabled
1 / 0
Stated default
By default, the permissions for Local Network Access (LNA) are only allowed to be requested in cross-origin subframes if they are explicitly delegated. If this policy is set to enabled, then subframes are by default delegated all LNA permissions policy features and can make local network requests (triggering the permission prompt).
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
By default, the permissions for Local Network Access (LNA) are only allowed to be requested in cross-origin subframes if they are explicitly delegated. This policy can be used to override this default behavior so that LNA permissions are default inherited into subframes, unless explicitly denied in permissions policy. If this policy is set to enabled, then subframes are by default delegated all LNA permissions policy features and can make local network requests (triggering the permission prompt). If this policy is set to disabled or not set, then subframes must be explicitly delegated the permissions policy feature in order make local network requests and trigger the permission prompt. This policy applies to the permissions policy features "local-network-access", "loopback-network", and "local-network". For more information on Local Network Access, see https://wicg.github.io/local-network-access/ and https://developer.chrome.com/blog/local-network-access. For more information on permissions policy, see https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Permissions_Policy.
LocalNetworkAccessAllowedForUrls  Allow sites to make network requests to local devices and local network endpoints.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LocalNetworkAccessAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins are not subject to Local Network Access checks. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local device and local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkAccessBlockedForUrls - LoopbackNetworkAccessAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAllowedForUrls  Allow sites to make network requests to local network endpoints.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LocalNetworkAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to local network endpoints are not subject to Local Network Access checks. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LoopbackNetworkAllowedForUrls  Allow sites to make network requests to the local device.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LoopbackNetworkAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to the local device are not subject to Local Network Access checks. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to the local device. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAccessBlockedForUrls  Block sites from making network requests to local devices and local network endpoints.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LocalNetworkAccessBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local device and local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkAccessBlockedForUrls - LoopbackNetworkAccessAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkBlockedForUrls  Block sites from making network requests to local network endpoints.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LocalNetworkBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to local network endpoints are blocked from issuing Local Network Access requests. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to local network endpoints. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LoopbackNetworkBlockedForUrls  Block sites from making network requests to the local device.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LoopbackNetworkBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
List of URL patterns. Network requests initiated from websites served by matching origins to the local device are blocked from issuing Local Network Access requests. For origins not covered by the patterns specified here, the user's personal configuration will apply. For detailed information on valid URL patterns, please see https://chromeenterprise.google/policies/url-patterns/. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. There are multiple policies listing origins that impact requests to the local device. If an origin is matched by more than one of the following policies, the policies take precedence in the following order: - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAccessIpAddressSpaceOverrides  Override IP address space mappings
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LocalNetworkAccessIpAddressSpaceOverrides
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This can be used to treat certain internal address ranges as "public" and thus not subject to Local Network Access checks. Conversely, this can be used to treat certain public address ranges that might be used internally as "local" so that they are protected by Local Network Access checks. IP address space overrides have two forms: [cidr]=[public|local|loopback] where [cidr] is a IP address range in CIDR notation (see section 3.1 of https://tools.ietf.org/html/rfc4632 for IPv4 and section 2.3 of https://tools.ietf.org/html/rfc4291 for IPv6). IPv6 addresses must be specified in URL-safe (bracketed) format. CIDR overrides apply to all ports. or [ip-address]:[port]=[public|local|loopback] For more information on Local Network Access, see https://wicg.github.io/local-network-access/ and https://developer.chrome.com/blog/local-network-access. This policy does not support dynamic refresh. Overrides from the command-line switch --ip-address-space-overrides take precedence over overrides set by this policy. Example value: 100.64.0.0/10=public [2001:db8::]/32=local 192.168.0.1:8000=public [2001:DB8::8:800:200C:417A]:8080=local
LocalNetworkAccessRestrictionsTemporaryOptOut  Specifies whether to (temporarily) opt out of Local Network Access restrictions
Boolean Machine + User
When this policy is set to Disabled or unset, Local Network Access requests will use the default handling of these requests.
Registry key
Software\Policies\Google\Chrome
Value name
LocalNetworkAccessRestrictionsTemporaryOptOut
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When this policy is set to Enabled, Local Network Access requests will only display warnings in Chrome DevTools due to Local Network Access checks failing. When this policy is set to Disabled or unset, Local Network Access requests will use the default handling of these requests. See https://wicg.github.io/local-network-access/ for Local Network Access restrictions. This enterprise policy is temporary, and will be removed after M152. Long term, the policy LocalNetworkAccessAllowedForUrls can be used to allowlist URL patterns that should be automatically granted the Local Network Access permission.
Google:Cat_Google / Google Chrome / Microsoft® Active Directory® management settings
CloudAPAuthEnabled  Allow automatic sign-in to Microsoft® cloud identity providers
Enum Machine + User
By setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled.
Registry key
Software\Policies\Google\Chrome
Value name
CloudAPAuthEnabled
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Disable Microsoft® cloud authentication
1Enable Microsoft® cloud authentication
Configures automatic user sign-in for accounts backed by a Microsoft® cloud identity provider. By setting this policy to 1 (Enabled), users who sign into their computer with an account backed by a Microsoft® cloud identity provider (i.e., Microsoft® Azure® Active Directory® or the consumer Microsoft® account identity provider) or who have added a work or school account to Microsoft® Windows® can be signed into web properties using that identity automatically. Information pertaining to the user's device and account is transmitted to the user's cloud identity provider for each authentication event. By setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled. This feature is available starting in Microsoft® Windows® 10. Note: This policy doesn't apply to Incognito or Guest modes.
Google:Cat_Google / Google Chrome / Native Messaging
NativeMessagingUserLevelHosts  Allow user-level Native Messaging hosts (installed without admin permissions)
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level.
Registry key
Software\Policies\Google\Chrome
Value name
NativeMessagingUserLevelHosts
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level. Setting the policy to Disabled means Google Chrome can only use these hosts if installed at the system level.
NativeMessagingAllowlist  Configure native messaging allowlist
List (values under a subkey) Machine + User
All native messaging hosts are allowed by default.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\NativeMessagingAllowlist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies which native messaging hosts aren't subject to the deny list. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed. All native messaging hosts are allowed by default. But, if all native messaging hosts are denied by policy, the admin can use the allow list to change that policy. Example value: com.native.messaging.host.name1 com.native.messaging.host.name2
NativeMessagingBlocklist  Configure native messaging blocklist
List (values under a subkey) Machine + User
Leaving the policy unset means Google Chrome loads all installed native messaging hosts.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\NativeMessagingBlocklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies which native messaging hosts shouldn't be loaded. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed. Leaving the policy unset means Google Chrome loads all installed native messaging hosts. Example value: com.native.messaging.host.name1 com.native.messaging.host.name2
Google:Cat_Google / Google Chrome / Network settings
DataURLWhitespacePreservationEnabled  DataURL Whitespace Preservation for all media types
Boolean Machine + User
If this policy is left unset or is set to True, the new behavior is enabled.
Registry key
Software\Policies\Google\Chrome
Value name
DataURLWhitespacePreservationEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy provides a temporary opt-out for changes to how Chrome handles whitepsace in data URLS. Previously, whitespace would be kept only if the top level media type was text or contained the media type string xml. Now, whitespace will be preserved in all data URLs, regardless of media type. If this policy is left unset or is set to True, the new behavior is enabled. When this policy is set to False, the old behavior is enabled.
CompressionDictionaryTransportEnabled  Enable compression dictionary transport support
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means Google Chrome will accept web contents using the compression dictionary transport feature.
Registry key
Software\Policies\Google\Chrome
Value name
CompressionDictionaryTransportEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header ("sbr" and "zst-d") when dictionaries are available for use. Setting the policy to Enabled or leaving it unset means Google Chrome will accept web contents using the compression dictionary transport feature. Setting the policy to Disabled turns off the compression dictionary transport feature.
IPv6ReachabilityOverrideEnabled  Enable IPv6 reachability check override
Boolean Machine + User
Setting the policy to false or leaving it unset does not overrides the IPv6 reachability check.
Registry key
Software\Policies\Google\Chrome
Value name
IPv6ReachabilityOverrideEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to true overrides the IPv6 reachability check. This means that the system will always query AAAA records when resolving host names. It applies to all users and interfaces on the device. Setting the policy to false or leaving it unset does not overrides the IPv6 reachability check. The system only queries AAAA records when it is reachable to a global IPv6 host.
AccessControlAllowMethodsInCORSPreflightSpecConformant  Make Access-Control-Allow-Methods matching in CORS preflight spec conformant
Boolean Machine + User
If the policy is Enabled or not set, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.
Registry key
Software\Policies\Google\Chrome
Value name
AccessControlAllowMethodsInCORSPreflightSpecConformant
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight. If the policy is Disabled, request methods are uppercased. This is the behavior on or before Google Chrome 108. If the policy is Enabled or not set, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT. This would reject fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: FOO" response header, and would accept fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: Foo" response header. Note: request methods "post" and "put" are not affected, while "patch" is affected. This policy is intended to be temporary and will be removed in the future.
HappyEyeballsV3Enabled  Use the Happy Eyeballs V3 algorithm
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
HappyEyeballsV3Enabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This feature enables the Happy Eyeballs V3 algorithm to make connection attempts. See https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3 for details. Setting the policy to Enabled means Google Chrome will use the Happy Eyeballs V3 algorithm for connection attempts. Setting the policy to Disabled turns off the Happy Eyeballs V3 algorithm. Not setting the policy, Google Chrome will turn on or off the Happy Eyeballs V3 algorithm based on chrome://flags/#happy-eyeballs-v3. This policy supports dynamic refresh. This policy is a temporary measure and will be removed in future versions of Google Chrome.
Google:Cat_Google / Google Chrome / Password manager
PasswordManagerBlocklist  Configure the list of domains for which the Password Manager (Save and Fill) will be disabled
List (values under a subkey) Machine + User
If the policy is unset, the Password Manager will be available for all domains.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PasswordManagerBlocklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Configure the list of domains where Google Chrome should disable the Password Manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms. If a domain is present in the list, the Password Manager will be disabled for it. If a domain is not present in the list, the Password Manager will be available for it. If the policy is unset, the Password Manager will be available for all domains. For detailed information on valid URL patterns, please see https://support.google.com/chrome/a?p=url_blocklist_filter_format. Example value: example.com login.example.com
AutomatedPasswordChangeSettings  Enable automated password change
Enum Machine + User
If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.
Registry key
Software\Policies\Google\Chrome
Value name
AutomatedPasswordChangeSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow feature use and improving AI models
1Allow feature use without improving AI models
2Do not allow feature
This policy controls the availability of Google Chrome's automated password change feature. If enabled, a user can trigger a process where the browser attempts to change their password on a website automatically. This process is managed by Generative AI. The new password is saved in the browser's password manager. 0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below. 1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace. 2 = Do not allow the feature. If the policy is unset, its behavior is determined by the GenAiDefaultSettings policy. For more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.
DeletingUndecryptablePasswordsEnabled  Enable deleting undecryptable passwords
Boolean Machine + User
Setting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them.
Registry key
Software\Policies\Google\Chrome
Value name
DeletingUndecryptablePasswordsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions. Setting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched. Setting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality. If the policy is set, users can't change it in Google Chrome.
PasswordDismissCompromisedAlertEnabled  Enable dismissing compromised password alerts for entered credentials
Boolean Machine + User
Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordDismissCompromisedAlertEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts. If you disable this setting, users will not be able to dismiss alerts about compromised passwords. If enabled, users will be able to dismiss alerts about compromised passwords.
PasswordLeakDetectionEnabled  Enable leak detection for entered credentials
Boolean Machine + User
If not set, credential leak checking is allowed, but the user can turn it off.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordLeakDetectionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak. Setting the policy to Disabled does not let users have this functionality. If the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.
PasswordManagerPasskeysEnabled  Enable saving passkeys to the password manager
Boolean Machine + User
Setting the policy to Enabled or leaving unset means that users can save passkeys in the built-in password manager if signed into Google Chrome.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordManagerPasskeysEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the browser's ability to save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager. If the PasswordManagerEnabled policy is set to Disabled then saving in the built-in password manager is disabled in general, including passkeys and passwords, and thus this policy is not applicable. Setting the policy to Enabled or leaving unset means that users can save passkeys in the built-in password manager if signed into Google Chrome. Setting the policy to Disabled means users can't save passkeys to the built-in password manager, but previously saved passkeys will still work.
PasswordManagerEnabled  Enable saving passwords to the password manager
Boolean Machine + User
If not set, the user can turn off password saving.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordManagerEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy controls the browser's ability to automatically remember passwords on websites and save them in the built-in password manager. It does not limit access or change the contents of passwords saved in the password manager and possibly synchronized to the Google account profile and Android. Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site. Setting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work. If the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.
PasswordSharingEnabled  Enable sharing user credentials with other users
Boolean Machine + User
When the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordSharingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled lets users send to and receive from family members (according to Family Service) their passwords. When the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password. The received passwords are stored into user's account and are available in the Password Manager. Setting the policy to Disabled means users can't send passwords from Password Manager to other users, and can't receive passwords from other users. The feature is not available if synchronization of Passwords is turned off (either via user settings or SyncDisabled policy is Enabled). Managed accounts aren't eligible to join or create a family group and therefore cannot share passwords.
Google:Cat_Google / Google Chrome / Printing
PrintingBackgroundGraphicsDefault  Default background graphics printing mode
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrintingBackgroundGraphicsDefault
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Enable background graphics printing mode by default
Disable background graphics printing mode by default
Overrides default background graphics printing mode. Example value: enabled
DefaultPrinterSelection  Default printer selection rules
String Machine + User
Leaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultPrinterSelection
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets the rules for selecting the default printer in Google Chrome, overriding the default rules. Printer selection occurs the first time users try to print, when Google Chrome seeks a printer matching the specified attributes. In case of a less than perfect match, Google Chrome can be set to select any matching printer, depending on the order printers are discovered. Leaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default. If there's no PDF printer, Google Chrome defaults to none. Currently, all printers are classified as "local". Printers connected to Google Cloud Print are considered "cloud", but Google Cloud Print is no longer supported. Note: Omitting a field means all values match for that particular field. For example, not specifying idPattern means Print Preview accepts all printer IDs. Regular expression patterns must follow the JavaScript RegExp syntax, and matches are case sensistive. See https://chromeenterprise.google/policies/?policy=DefaultPrinterSelection for more information about schema and formatting. Example value: { "kind": "local", "idPattern": ".*public", "namePattern": ".*Color" }
PrintingPaperSizeDefault  Default printing page size
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrintingPaperSizeDefault
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Overrides default printing page size. name should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored. If the page size is unavailable on the printer chosen by the user this policy is ignored. See https://chromeenterprise.google/policies/?policy=PrintingPaperSizeDefault for more information about schema and formatting. Example value: { "custom_size": { "height": 297000, "width": 210000 }, "name": "custom" }
DisablePrintPreview  Disable Print Preview
Boolean Machine + User
Setting the policy to Disabled or leaving it unset has print commands trigger the print preview screen.
Registry key
Software\Policies\Google\Chrome
Value name
DisablePrintPreview
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled has Google Chrome open the system print dialog instead of the built-in print preview when users request a printout. Setting the policy to Disabled or leaving it unset has print commands trigger the print preview screen.
PrinterTypeDenyList  Disable printer types on the deny list
List (values under a subkey) Machine + User
If the policy is not set, or is set to an empty list, all printer types will be available for discovery.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PrinterTypeDenyList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
The printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched. Placing all printer types on the deny list effectively disables printing, as there would be no available destinations to send a document for printing. In versions before 102, including cloud on the deny list has the same effect as setting the CloudPrintSubmitEnabled policy to false. In order to keep Google Cloud Print destinations discoverable, the CloudPrintSubmitEnabled policy must be set to true and cloud must not be on the deny list. Beginning in version 102, Google Cloud Print destinations are not supported and will not appear regardless of policy values. If the policy is not set, or is set to an empty list, all printer types will be available for discovery. Extension printers are also known as print provider destinations, and include any destination that belongs to a Google Chrome extension. Local printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers. Example value: local pdf
PrintingEnabled  Enable printing
Boolean Machine + User
Setting the policy to Enabled or leaving it unset lets users print in Google Chrome, and users can't change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
PrintingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset lets users print in Google Chrome, and users can't change this setting. Setting the policy to Disabled means users can't print from Google Chrome. Printing is off in the three dots menu, extensions, and JavaScript applications.
PrintingLPACSandboxEnabled  Enable Printing LPAC Sandbox
Boolean Machine + User
Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it.
Registry key
Software\Policies\Google\Chrome
Value name
PrintingLPACSandboxEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it. Setting the policy to Disabled has a detrimental effect on Google Chrome's security as services used for printing might run in a weaker sandbox configuration. Only turn off the policy if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.
OopPrintDriversAllowed  Out-of-process print drivers allowed
Boolean Machine + User
When this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.
Registry key
Software\Policies\Google\Chrome
Value name
OopPrintDriversAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview. When this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks. When this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks. This policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.
PrintHeaderFooter  Print Headers and Footers
Boolean Machine + User
If unset, users decides whether headers and footers appear.
Registry key
Software\Policies\Google\Chrome
Value name
PrintHeaderFooter
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview. If you set the policy, users can't change it. If unset, users decides whether headers and footers appear.
PrintPdfAsImageAvailability  Print PDF as Image Available
Boolean Machine + User
When this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.
Registry key
Software\Policies\Google\Chrome
Value name
PrintPdfAsImageAvailability
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls how Google Chrome makes the Print as image option available on Microsoft® Windows® and macOS when printing PDFs. When printing a PDF on Microsoft® Windows® or macOS, sometimes print jobs need to be rasterized to an image for certain printers to get correct looking output. When this policy is set to Enabled, Google Chrome will make the Print as image option available in the Print Preview when printing a PDF. When this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.
PrintPdfAsImageDefault  Print PDF as Image Default
Boolean Machine + User
When this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset.
Registry key
Software\Policies\Google\Chrome
Value name
PrintPdfAsImageDefault
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls if Google Chrome makes the Print as image option default to set when printing PDFs. When this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF. When this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available. For Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.
PrintPostScriptMode  Print PostScript Mode
Enum Machine + User
When this policy is not set, Google Chrome will be in Default mode.
Registry key
Software\Policies\Google\Chrome
Value name
PrintPostScriptMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Default
1Type42
Controls how Google Chrome prints on Microsoft® Windows®. When printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance. When this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts. When this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers. When this policy is not set, Google Chrome will be in Default mode.
PrintRasterizationMode  Print Rasterization Mode
Enum Machine + User
When this policy is not set, Google Chrome will be in Full mode.
Registry key
Software\Policies\Google\Chrome
Value name
PrintRasterizationMode
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Full
1Fast
Controls how Google Chrome prints on Microsoft® Windows®. When printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly. When this policy is set to Full, Google Chrome will do full page rasterization if necessary. When this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed. When this policy is not set, Google Chrome will be in Full mode.
PrintRasterizePdfDpi  Print Rasterize PDF DPI
Integer Machine + User
If this policy is set to zero or not set at all then the system default resolution will be used during rasterization of page images.
Registry key
Software\Policies\Google\Chrome
Value name
PrintRasterizePdfDpi
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls print image resolution when Google Chrome prints PDFs with rasterization. When printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality. This policy allows a particular resolution to be specified for use when rasterizing PDFs for printing. If this policy is set to zero or not set at all then the system default resolution will be used during rasterization of page images.
PrintingAllowedBackgroundGraphicsModes  Restrict background graphics printing mode
Enum Machine + User
Unset policy is treated as no restriction.
Registry key
Software\Policies\Google\Chrome
Value name
PrintingAllowedBackgroundGraphicsModes
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Allow printing both with and without background graphics
Allow printing only with background graphics
Allow printing only without background graphics
Restricts background graphics printing mode. Unset policy is treated as no restriction. Example value: enabled
PrintPreviewUseSystemDefaultPrinter  Use System Default Printer as Default
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
Registry key
Software\Policies\Google\Chrome
Value name
PrintPreviewUseSystemDefaultPrinter
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview. Setting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.
Google:Cat_Google / Google Chrome / Protected Content
ProtectedContentIdentifiersAllowed  Allows web pages to use identifiers for the purpose of protected content playback
Boolean Machine + User
If the policy is set to true or unset, the use of protected content identifiers is allowed, which can help enable higher quality of protected content playback.
Registry key
Software\Policies\Google\Chrome
Value name
ProtectedContentIdentifiersAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If the policy is set to true or unset, the use of protected content identifiers is allowed, which can help enable higher quality of protected content playback. If the policy is set to false, protected content identifiers are not allowed to be used.
Google:Cat_Google / Google Chrome / Proxy server
EnableProxyOverrideRulesForAllUsers  Controls which managed users can set the ProxyOverrideRules policy.
Integer Machine + User
When this policy is set to 0 or left unset, the ProxyOverrideRules policy will only be applied at the user scope for affiliated users.
Registry key
Software\Policies\Google\Chrome
Value name
EnableProxyOverrideRulesForAllUsers
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When this policy is set to 0 or left unset, the ProxyOverrideRules policy will only be applied at the user scope for affiliated users. When this policy is set to 1, the ProxyOverrideRules policy will be applied at the user scope, even that user is unaffiliated.
Google:Cat_Google / Google Chrome / Remote access
RemoteAccessHostAllowPinAuthentication  Allow PIN and pairing authentication methods for remote access hosts
Boolean Machine + User
Leaving it unset lets the host decide whether PIN and/or pairing authentications can be used.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowPinAuthentication
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled allows the remote access host to use PIN and pairing authentications when accepting client connections. Setting the policy to Disabled disallows PIN or pairing authentications. Leaving it unset lets the host decide whether PIN and/or pairing authentications can be used. Note: If the setting results in no mutually supported authentication methods by both the host and the client, then the connection will be rejected.
RemoteAccessHostAllowRemoteAccessConnections  Allow remote access connections to this machine
Boolean Machine + User
This policy has no effect if it is set to Enabled, left empty, or is not set.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowRemoteAccessConnections
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is Disabled, the remote access host service cannot be started or configured to accept incoming connections. This policy does not affect remote support scenarios. This policy has no effect if it is set to Enabled, left empty, or is not set.
RemoteAccessHostAllowUrlForwarding  Allow remote access users to open host-side URLs in their local client browser
Boolean Machine + User
Setting the policy to Enabled or leaving it unset may allow users connected to a remote access host to open host-side URLs in their local client browser.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowUrlForwarding
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset may allow users connected to a remote access host to open host-side URLs in their local client browser. Setting the policy to Disabled will prevent the remote access host from sending URLs to the client. This setting doesn't apply to remote assistance connections as the feature is not supported for that connection mode. Note: This feature is not yet generally available so enabling it does not mean that the feature will be visible in the client UI.
RemoteAccessHostAllowFileTransfer  Allow remote access users to transfer files to/from the host
Boolean Machine + User
Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowFileTransfer
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer. Setting the policy to Disabled disallows file transfer.
RemoteAccessHostAllowRemoteSupportConnections  Allow remote support connections to this machine
Boolean Machine + User
This policy has no effect if enabled, left empty, or is not set.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowRemoteSupportConnections
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is disabled, the remote support host cannot be started or configured to accept incoming connections. This policy does not affect remote access scenarios. This policy does not prevent enterprise admins from connecting to managed Google ChromeOS devices. This policy has no effect if enabled, left empty, or is not set.
RemoteAccessHostAllowUiAccessForRemoteAssistance  Allow remote users to interact with elevated windows in remote assistance sessions
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means the remote assistance host runs in the user's context, and remote users can't interact with elevated windows on the desktop.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowUiAccessForRemoteAssistance
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means the remote assistance host runs in a process with uiAccess permissions. This lets remote users interact with elevated windows on the local user's desktop. Setting the policy to Disabled or leaving it unset means the remote assistance host runs in the user's context, and remote users can't interact with elevated windows on the desktop.
RemoteAccessHostClientDomainList  Configure the required domain names for remote access clients
List (values under a subkey) Machine + User
Setting the policy to an empty list or leaving it unset applies the default policy for the connection type.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\RemoteAccessHostClientDomainList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the client domain names that are imposed on remote access clients, and users can't change them. Only clients from one of the specified domains can connect to the host. Setting the policy to an empty list or leaving it unset applies the default policy for the connection type. For remote assistance, this allows clients from any domain to connect to the host. For anytime remote access, only the host owner can connect. See also RemoteAccessHostDomainList. Note: This setting overrides RemoteAccessHostClientDomain, if present. Example value: my-awesome-domain.com my-auxiliary-domain.com
RemoteAccessHostDomainList  Configure the required domain names for remote access hosts
List (values under a subkey) Machine + User
Setting the policy to an empty list or leaving it unset means hosts can be shared using any account.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\RemoteAccessHostDomainList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy specifies the host domain names that are imposed on remote access hosts, and users can't change them. Hosts can be shared only using accounts registered on one of the specified domain names. Setting the policy to an empty list or leaving it unset means hosts can be shared using any account. See also RemoteAccessHostClientDomainList. Note: This setting will override RemoteAccessHostDomain, if present. Example value: my-awesome-domain.com my-auxiliary-domain.com
RemoteAccessHostRequireCurtain  Enable curtaining of remote access hosts
Boolean Machine + User
Setting the policy to Disabled or leaving it unset lets both local and remote users interact with the host while it's shared.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostRequireCurtain
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns off remote access hosts' physical input and output devices during a remote connection. Setting the policy to Disabled or leaving it unset lets both local and remote users interact with the host while it's shared.
RemoteAccessHostFirewallTraversal  Enable firewall traversal from remote access host
Boolean Machine + User
Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostFirewallTraversal
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall. Setting the policy to Disabled when outgoing UDP connections are filtered by the firewall means the machine only allows connections from client machines within the local network.
RemoteAccessHostAllowClientPairing  Enable or disable PIN-less authentication for remote access hosts
Boolean Machine + User
Setting the policy to Enabled or leaving it unset lets users pair clients and hosts at connection time, eliminating the need to enter a PIN every time.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowClientPairing
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled or leaving it unset lets users pair clients and hosts at connection time, eliminating the need to enter a PIN every time. Setting the policy to Disabled makes this feature unavailable.
RemoteAccessHostAllowRelayedConnection  Enable the use of relay servers by the remote access host
Boolean Machine + User
If RemoteAccessHostFirewallTraversal is set to Enabled, setting RemoteAccessHostAllowRelayedConnection to Enabled or leaving it unset allows the use of remote clients to use relay servers to connect to this machine when a direct connection is not available, for example, because of firewall restrictions.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostAllowRelayedConnection
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If RemoteAccessHostFirewallTraversal is set to Enabled, setting RemoteAccessHostAllowRelayedConnection to Enabled or leaving it unset allows the use of remote clients to use relay servers to connect to this machine when a direct connection is not available, for example, because of firewall restrictions. Setting the policy to Disabled doesn't turn remote access off, but only allows connections from the same network (not NAT traversal or relay).
RemoteAccessHostMaximumSessionDurationMinutes  Maximum session duration allowed for remote access connections
Integer Machine + User
This policy has no effect if it is not set.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostMaximumSessionDurationMinutes
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is set, remote access connections will automatically disconnect after the number of minutes defined in the policy have elapsed. This does not prevent the client from reconnecting after the maximum session duration has been reached. Setting the policy to a value that is not within the min/max range may prevent the host from starting. This policy does not affect remote support scenarios. This policy has no effect if it is not set. In this case, remote access connections will have no maximum duration on this machine.
RemoteAccessHostUdpPortRange  Restrict the UDP port range used by the remote access host
String Machine + User
Leaving the policy unset or set to an empty string means the remote access host can use any available port.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostUdpPortRange
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy restricts the UDP port range used by the remote access host in this machine. Leaving the policy unset or set to an empty string means the remote access host can use any available port. Note: If RemoteAccessHostFirewallTraversal is Disabled, the remote access host will use UDP ports in the 12400-12409 range. Example value: 12400-12409
RemoteAccessHostClipboardSizeBytes  The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization
Integer Machine + User
This policy has no effect if it is not set.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostClipboardSizeBytes
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is set, clipboard data sent to and from the host will be truncated to the limit set by this policy. If a value of 0 is set, then clipboard sync is disabled. This policy affects both remote access and remote support scenarios. This policy has no effect if it is not set. Setting the policy to a value that is not within the min/max range may prevent the host from starting. Please note that the actual upper bound for the clipboard size is based on the maximum WebRTC data channel message size which this policy does not control.
Google:Cat_Google / Google Chrome / Removed policies
URLWhitelist  Allow access to a list of URLs
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\URLWhitelist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TabFreezingEnabled  Allow background tabs freeze
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
TabFreezingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableCommonNameFallbackForLocalAnchors  Allow certificates issued by local trust anchors without subjectAlternativeName extension
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnableCommonNameFallbackForLocalAnchors
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionAllowInsecureUpdates  Allow insecure algorithms in integrity checks on extension updates and installs
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ExtensionAllowInsecureUpdates
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
KeygenAllowedForUrls  Allow key generation on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\KeygenAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebRtcAllowLegacyTLSProtocols  Allow legacy TLS/DTLS downgrade in WebRTC
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebRtcAllowLegacyTLSProtocols
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AutoplayWhitelist  Allow media autoplay on a allowlist of URL patterns
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\AutoplayWhitelist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PPAPISharedImagesSwapChainAllowed  Allow modern buffer allocation for Graphics3D APIs PPAPI plugin.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PPAPISharedImagesSwapChainAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UseMojoVideoDecoderForPepperAllowed  Allow Pepper to use a new decoder for hardware accelerated video decoding.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UseMojoVideoDecoderForPepperAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AllowOutdatedPlugins  Allow running plugins that are outdated
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AllowOutdatedPlugins
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableSha1ForLocalAnchors  Allow SHA-1 signed certificates issued by local trust anchors
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnableSha1ForLocalAnchors
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TabUnderAllowed  Allow sites to simultaneously navigate and open pop-ups
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
TabUnderAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
FileHandlingAllowedForUrls  Allow the File Handling API on these web apps
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\FileHandlingAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PluginsAllowedForUrls  Allow the Flash plugin on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PluginsAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InsecurePrivateNetworkRequestsAllowedForUrls  Allow the listed sites to make requests to more-private network endpoints in an insecure manner.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\InsecurePrivateNetworkRequestsAllowedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingExtendedReportingOptInAllowed  Allow users to opt in to Safe Browsing extended reporting
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingExtendedReportingOptInAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PasswordManagerAllowShowPasswords  Allow users to show passwords in Password Manager (deprecated)
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordManagerAllowShowPasswords
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AssistantWebEnabled  Allow using Google Assistant on the web, e.g. to enable changing passwords automatically
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AssistantWebEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
U2fSecurityKeyApiEnabled  Allow using the deprecated U2F Security Key API
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
U2fSecurityKeyApiEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebDriverOverridesIncompatiblePolicies  Allow WebDriver to Override Incompatible Policies
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebDriverOverridesIncompatiblePolicies
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AllowSyncXHRInPageDismissal  Allows a page to perform synchronous XHR requests during page dismissal.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AllowSyncXHRInPageDismissal
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AllowPopupsDuringPageUnload  Allows a page to show pop-ups during its unloading
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AllowPopupsDuringPageUnload
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NewBaseUrlInheritanceBehaviorAllowed  Allows enabling the feature NewBaseUrlInheritanceBehavior
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
NewBaseUrlInheritanceBehaviorAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ThrottleNonVisibleCrossOriginIframesAllowed  Allows enabling throttling of non-visible, cross-origin iframes
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ThrottleNonVisibleCrossOriginIframesAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AppCacheForceEnabled  Allows the AppCache feature to be re-enabled even if it is off by default.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AppCacheForceEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AlwaysAuthorizePlugins  Always runs plugins that require authorization (deprecated)
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AlwaysAuthorizePlugins
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AuthServerWhitelist  Authentication server allowlist
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AuthServerWhitelist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
URLBlacklist  Block access to a list of URLs
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\URLBlacklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
KeygenBlockedForUrls  Block key generation on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\KeygenBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
FileHandlingBlockedForUrls  Block the File Handling API on these web apps
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\FileHandlingBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PluginsBlockedForUrls  Block the Flash plugin on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PluginsBlockedForUrls
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
BlockTruncatedCookies  Block truncated cookies
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
BlockTruncatedCookies
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CECPQ2Enabled  CECPQ2 post-quantum key-agreement enabled for TLS
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CECPQ2Enabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RSAKeyUsageForLocalAnchorsEnabled  Check RSA key usage for server certificates issued by local trust anchors
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RSAKeyUsageForLocalAnchorsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxFingerprintingProtectionEnabled  Choose whether the Privacy Sandbox Fingerprinting Protection feature is to be enabled in Incognito mode.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrivacySandboxFingerprintingProtectionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrivacySandboxIpProtectionEnabled  Choose whether the Privacy Sandbox IP Protection feature should be enabled.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrivacySandboxIpProtectionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ClearSiteDataOnExit  Clear site data on browser shutdown (deprecated)
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ClearSiteDataOnExit
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionInstallWhitelist  Configure extension installation allowlist
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionInstallWhitelist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionInstallBlacklist  Configure extension installation blocklist
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ExtensionInstallBlacklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeMessagingWhitelist  Configure native messaging allowlist
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\NativeMessagingWhitelist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeMessagingBlacklist  Configure native messaging blocklist
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\NativeMessagingBlacklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SafeBrowsingWhitelistDomains  Configure the list of domains on which Safe Browsing will not trigger warnings.
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SafeBrowsingWhitelistDomains
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostTalkGadgetPrefix  Configure the TalkGadget prefix for remote access hosts
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostTalkGadgetPrefix
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeCleanupReportingEnabled  Control how Chrome Cleanup reports data to Google
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeCleanupReportingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SetTimeoutWithout1MsClampEnabled  Control Javascript setTimeout() function minimum timeout.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SetTimeoutWithout1MsClampEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionManifestV2Availability  Control Manifest v2 extension availability
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ExtensionManifestV2Availability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Default browser behavior
1Manifest v2 is disabled
2Manifest v2 is enabled
3Manifest v2 is enabled for forced extensions only
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
BeforeunloadEventCancelByPreventDefaultEnabled  Control new behavior for the cancel dialog produced by the beforeunload event
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
BeforeunloadEventCancelByPreventDefaultEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UnthrottledNestedTimeoutEnabled  Control the nesting threshold before which Javascript setTimeout() function start being clamped
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UnthrottledNestedTimeoutEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SendMouseEventsDisabledFormControlsEnabled  Control the new behavior for event dispatching on disabled form controls
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SendMouseEventsDisabledFormControlsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
OffsetParentNewSpecBehaviorEnabled  Control the new behavior of HTMLElement.offsetParent
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
OffsetParentNewSpecBehaviorEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UrlParamFilterEnabled  Control the URL parameter filter feature
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UrlParamFilterEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UserAgentClientHintsEnabled  Control the User-Agent Client Hints feature.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UserAgentClientHintsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UserAgentClientHintsGREASEUpdateEnabled  Control the User-Agent Client Hints GREASE Update feature.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UserAgentClientHintsGREASEUpdateEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultFileHandlingGuardSetting  Control use of the File Handling API
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultFileHandlingGuardSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
2Do not allow any web app to access file types via the File Handling API
3Allow web apps to ask the user to grant access to file types via the File Handling API
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CSSCustomStateDeprecatedSyntaxEnabled  Controls whether the deprecated :--foo syntax for CSS custom state is enabled
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CSSCustomStateDeprecatedSyntaxEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SelectParserRelaxationEnabled  Controls whether the new HTML parser behavior for the <select> element is enabled
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SelectParserRelaxationEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultPluginsSetting  Default Flash setting
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultPluginsSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow all sites to automatically run the Flash plugin
2Block the Flash plugin
3Click to play
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultKeygenSetting  Default key generation setting
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultKeygenSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow all sites to use key generation
2Do not allow any site to use key generation
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LegacySameSiteCookieBehaviorEnabled  Default legacy SameSite cookie behavior setting
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LegacySameSiteCookieBehaviorEnabled
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Revert to legacy SameSite behavior for cookies on all sites
2Use SameSite-by-default behavior for cookies on all sites
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderIconURL  Default search provider icon
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderIconURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURL  Default search provider instant URL
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderInstantURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultThirdPartyStoragePartitioningSetting  Default third-party storage partitioning setting
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultThirdPartyStoragePartitioningSetting
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
1Allow third-party storage partitioning by default.
2Disable third-party storage partitioning.
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnforceLocalAnchorConstraintsEnabled  Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnforceLocalAnchorConstraintsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeRootStoreEnabled  Determines whether the Chrome Root Store and built-in certificate verifier will be used to verify server certificates
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeRootStoreEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CertificateTransparencyEnforcementDisabledForLegacyCas  Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CertificateTransparencyEnforcementDisabledForLegacyCas
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisableSpdy  Disable SPDY protocol
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DisableSpdy
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ThirdPartyStoragePartitioningBlockedForOrigins  Disable third-party storage partitioning for specific top-level origins
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ThirdPartyStoragePartitioningBlockedForOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisableSSLRecordSplitting  Disable TLS False Start
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DisableSSLRecordSplitting
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TargetBlankImpliesNoOpener  Do not set window.opener for links targeting _blank
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
TargetBlankImpliesNoOpener
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TripleDESEnabled  Enable 3DES cipher suites in TLS
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
TripleDESEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TLS13HardeningForLocalAnchorsEnabled  Enable a TLS 1.3 security feature for local trust anchors.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
TLS13HardeningForLocalAnchorsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeCleanupEnabled  Enable Chrome Cleanup on Windows
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeCleanupEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LocalDiscoveryEnabled  Enable chrome://devices
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LocalDiscoveryEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CorsMitigationList  Enable CORS check mitigations in the new CORS implementation
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\CorsMitigationList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SupervisedUserCreationEnabled  Enable creation of supervised users
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SupervisedUserCreationEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableDeprecatedPrivetPrinting  Enable deprecated privet printing
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnableDeprecatedPrivetPrinting
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableDeprecatedWebPlatformFeatures  Enable deprecated web platform features for a limited time
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\EnableDeprecatedWebPlatformFeatures
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DHEEnabled  Enable DHE cipher suites in TLS
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DHEEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DownloadBubbleEnabled  Enable download bubble UI
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DownloadBubbleEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessClientFirewallTraversal  Enable firewall traversal from remote access client
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessClientFirewallTraversal
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ExtensionForceInstallWithNonMalwareViolationsEnabled  Enable Force-installed Extensions With Non-Malware Violations
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ExtensionForceInstallWithNonMalwareViolationsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CloudPrintProxyEnabled  Enable Google Cloud Print proxy
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CloudPrintProxyEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
Http09OnNonDefaultPortsEnabled  Enable HTTP/0.9 support on non-default ports
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
Http09OnNonDefaultPortsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InstantEnabled  Enable Instant
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
InstantEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
KeyboardFocusableScrollersEnabled  Enable keyboard focusable scrollers
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
KeyboardFocusableScrollersEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LockIconInAddressBarEnabled  Enable lock icon in the omnibox for secure connections
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LockIconInAddressBarEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeWindowOcclusionEnabled  Enable Native Window Occlusion
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
NativeWindowOcclusionEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DnsPrefetchingEnabled  Enable network prediction
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DnsPrefetchingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
OptimizationGuideFetchingEnabled  Enable Optimization Guide Fetching
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
OptimizationGuideFetchingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UserAgentReduction  Enable or disable the User-Agent Reduction.
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UserAgentReduction
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Reduced User Agent.
1Full (legacy) User Agent.
2Reduced User Agent.
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PacHttpsUrlStrippingEnabled  Enable PAC URL stripping (for https://)
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PacHttpsUrlStrippingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PostQuantumKeyAgreementEnabled  Enable post-quantum key agreement for TLS
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PostQuantumKeyAgreementEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RC4Enabled  Enable RC4 cipher suites in TLS
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RC4Enabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RendererCodeIntegrityEnabled  Enable Renderer Code Integrity
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RendererCodeIntegrityEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AdvancedProtectionDeepScanningEnabled  Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AdvancedProtectionDeepScanningEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WelcomePageOnOSUpgradeEnabled  Enable showing the welcome page on the first browser launch following OS upgrade
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WelcomePageOnOSUpgradeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
StricterMixedContentTreatmentEnabled  Enable stricter treatment for mixed content
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
StricterMixedContentTreatmentEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CloudPrintSubmitEnabled  Enable submission of documents to Google Cloud Print
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CloudPrintSubmitEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceEnablePepperVideoDecoderDevAPI  Enable support for the PPB_VideoDecoder(Dev) API.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceEnablePepperVideoDecoderDevAPI
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UiAutomationProviderEnabled  Enable the browser's UI Automation accessibility framework provider on Windows
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UiAutomationProviderEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableDeprecatedWebBasedSignin  Enable the old web-based signin flow
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnableDeprecatedWebBasedSignin
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ThirdPartyBlockingEnabled  Enable third party software injection blocking
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ThirdPartyBlockingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnableSymantecLegacyInfrastructure  Enable trust in Symantec Corporation's Legacy PKI Infrastructure
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnableSymantecLegacyInfrastructure
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostRequireTwoFactor  Enable two-factor authentication for remote access hosts
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostRequireTwoFactor
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ZstdContentEncodingEnabled  Enable zstd content-encoding support
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ZstdContentEncodingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnterpriseWebStoreName  Enterprise web store name (deprecated)
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseWebStoreName
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnterpriseWebStoreURL  Enterprise web store URL (deprecated)
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EnterpriseWebStoreURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RunAllFlashInAllowMode  Extend Flash content setting to all content (deprecated)
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RunAllFlashInAllowMode
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeAppsEnabled  Extend support for Chrome Apps on Microsoft® Windows®, macOS, and Linux.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeAppsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SpellcheckLanguageBlacklist  Force disable spellcheck languages
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SpellcheckLanguageBlacklist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceNetworkInProcess  Force networking code to run in the browser process
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceNetworkInProcess
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PersistentQuotaEnabled  Force persistent quota to be enabled
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PersistentQuotaEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebSQLNonSecureContextEnabled  Force WebSQL in non-secure contexts to be enabled.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebSQLNonSecureContextEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebSQLInThirdPartyContextEnabled  Force WebSQL in third-party contexts to be re-enabled.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebSQLInThirdPartyContextEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebSQLAccess  Force WebSQL to be enabled.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebSQLAccess
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
NativeClientForceAllowed  Forces Native Client (NaCl) to be allowed to run.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
NativeClientForceAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceMajorVersionToMinorPositionInUserAgent  Freeze User-Agent string major version at 99
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceMajorVersionToMinorPositionInUserAgent
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Default to browser settings for User-Agent string version.
1The User-Agent string will not freeze the major version.
2The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InsecureHashesInTLSHandshakesEnabled  Insecure Hashes in TLS Handshakes Enabled
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
InsecureHashesInTLSHandshakesEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
AuthNegotiateDelegateWhitelist  Kerberos delegation server allowlist
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
AuthNegotiateDelegateWhitelist
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LoadCryptoTokenExtension  Load the CryptoToken component extension at startup
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LoadCryptoTokenExtension
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrefixedVideoFullscreenApiAvailability  Manage the deprecated prefixed video fullscreen API's availability
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrefixedVideoFullscreenApiAvailability
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Follows regular deprecation timelines for the PrefixedVideoFullscreen API
Disables prefixed video fullscreen APIs
Enables prefixed video fullscreen APIs
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ToolbarAvatarLabelSettings  Managed toolbar avatar label setting
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ToolbarAvatarLabelSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Always display management label
1Display management labels for 30s
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SSLVersionMax  Maximum SSL version enabled
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SSLVersionMax
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
TLS 1.2
TLS 1.3
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SSLVersionMin  Minimum SSL version enabled
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SSLVersionMin
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
TLS 1.0
TLS 1.1
TLS 1.2
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
SSLVersionFallbackMin  Minimum TLS version to fallback to
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
SSLVersionFallbackMin
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
TLS 1.1
TLS 1.2
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderSearchTermsReplacementKey  Parameter controlling search term placement for the default search provider
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderSearchTermsReplacementKey
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DefaultSearchProviderInstantURLPostParams  Parameters for instant URL which uses POST
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DefaultSearchProviderInstantURLPostParams
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
RemoteAccessHostDebugOverridePolicies  Policy overrides for Debug builds of the remote access host
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
RemoteAccessHostDebugOverridePolicies
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
HideWebStorePromo  Prevent app promotions from appearing on the new tab page
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
HideWebStorePromo
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
MutationEventsEnabled  Re-enable deprecated/removed Mutation Events
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
MutationEventsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
FileSystemSyncAccessHandleAsyncInterfaceEnabled  Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
FileSystemSyncAccessHandleAsyncInterfaceEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrefixedStorageInfoEnabled  Re-enable the deprecated window.webkitStorageInfo API
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrefixedStorageInfoEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EventPathEnabled  Re-enable the Event.path API until M115.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
EventPathEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
WebComponentsV0Enabled  Re-enable Web Components v0 API until M84.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebComponentsV0Enabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ChromeAppsWebViewPermissiveBehaviorAllowed  Restore permissive Chrome Apps <webview> behavior
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ChromeAppsWebViewPermissiveBehaviorAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LegacySameSiteCookieBehaviorEnabledForDomainList  Revert to legacy SameSite behavior for cookies on these sites
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\LegacySameSiteCookieBehaviorEnabledForDomainList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
MediaCacheSize  Set media disk cache size in bytes
Integer Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
MediaCacheSize
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
TabOrganizerSettings  Settings for Tab Organizer
Enum Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
TabOrganizerSettings
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Allow Tab Organizer and improve AI models.
1Allow Tab Organizer without improving AI models.
2Do not allow Tab Organizer.
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisplayCapturePermissionsPolicyEnabled  Specifies whether the display-capture permissions-policy is checked or skipped.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DisplayCapturePermissionsPolicyEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
InsecurePrivateNetworkRequestsAllowed  Specifies whether to allow websites to make requests to more-private network endpoints in an insecure manner
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
InsecurePrivateNetworkRequestsAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
LocalNetworkAccessRestrictionsEnabled  Specifies whether to apply restrictions to requests to local network endpoints
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
LocalNetworkAccessRestrictionsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
PrivateNetworkAccessRestrictionsEnabled  Specifies whether to apply restrictions to requests to more-private network endpoints
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
PrivateNetworkAccessRestrictionsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CrossOriginWebAssemblyModuleSharingEnabled  Specifies whether WebAssembly modules can be sent cross-origin
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CrossOriginWebAssemblyModuleSharingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisabledPlugins  Specify a list of disabled plugins
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\DisabledPlugins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
EnabledPlugins  Specify a list of enabled plugins
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\EnabledPlugins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisabledPluginsExceptions  Specify a list of plugins that the user can enable or disable
List (values under a subkey) Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\DisabledPluginsExceptions
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
DisablePluginFinder  Specify whether the plugin finder should be disabled (deprecated)
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
DisablePluginFinder
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CloudPrintWarningsSuppressed  Suppress Google Cloud Print deprecation messages
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CloudPrintWarningsSuppressed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
MachineLevelUserCloudPolicyEnrollmentToken  The enrollment token of cloud policy on desktop
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
MachineLevelUserCloudPolicyEnrollmentToken
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
ForceLegacyDefaultReferrerPolicy  Use a default referrer policy of no-referrer-when-downgrade.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
ForceLegacyDefaultReferrerPolicy
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
UseLegacyFormControls  Use Legacy Form Controls until M84.
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
UseLegacyFormControls
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
CorsLegacyModeEnabled  Use the legacy CORS implementation rather than new CORS
Boolean Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
CorsLegacyModeEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500
Google:Cat_Google / Google Chrome / Safe Browsing settings
SafeBrowsingDeepScanningEnabled  Allow download deep scanning for Safe Browsing-enabled users
Boolean Machine + User
When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingDeepScanningEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives. When this policy is disabled, this scanning will not be performed. This policy does not impact download content analysis configured by Chrome Enterprise Connectors.
SafeBrowsingProxiedRealTimeChecksAllowed  Allow Safe Browsing Proxied Real Time Checks
Boolean Machine + User
Setting the policy to Enabled or leaving it unset allows the higher-protection proxied lookups.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingProxiedRealTimeChecksAllowed
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This controls whether Safe Browsing's standard protection mode is allowed to send partial hashes of URLs to Google through a proxy via Oblivious HTTP in order to determine whether they are safe to visit. The proxy allows browsers to upload partial hashes of URLs to Google without them being linked to the user's IP address. The policy also allows browsers to upload the partial hashes of URLs with higher frequency for better Safe Browsing protection quality. This policy will be ignored if Safe Browsing is disabled or set to enhanced protection mode. Setting the policy to Enabled or leaving it unset allows the higher-protection proxied lookups. Setting the policy to Disabled disallows the higher-protection proxied lookups. Partial hashes of URLs will be uploaded to Google directly with much lower frequency, which will degrade protection.
SafeBrowsingSurveysEnabled  Allow Safe Browsing Surveys
Boolean Machine + User
When this policy is enabled or left unset, the user may receive surveys related to Safe Browsing.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingSurveysEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
When this policy is enabled or left unset, the user may receive surveys related to Safe Browsing. When this policy is disabled, the user will not receive surveys related to Safe Browsing.
PasswordProtectionChangePasswordURL  Configure the change password URL.
String Machine + User
Turning the policy off or leaving it unset means the service sends users to https://myaccount.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordProtectionChangePasswordURL
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets the URL for users to change their password after seeing a warning in the browser. The password protection service sends users to the URL (HTTP and HTTPS protocols only) you designate through this policy. For Google Chrome to correctly capture the salted hash of the new password on this change password page, make sure your change password page follows these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ). Turning the policy off or leaving it unset means the service sends users to https://myaccount.google.com to change their password. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://mydomain.com/change_password.html
SafeBrowsingAllowlistDomains  Configure the list of domains on which Safe Browsing will not trigger warnings.
List (values under a subkey) Machine + User
Leaving the policy unset means default Safe Browsing protection applies to all resources.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\SafeBrowsingAllowlistDomains
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled means Safe Browsing will trust the domains you designate. It won't check them for dangerous resources such as phishing, malware, or unwanted software. Safe Browsing's download protection service won't check downloads hosted on these domains. Its password protection service won't check for password reuse. Leaving the policy unset means default Safe Browsing protection applies to all resources. This policy does not support regular expressions; however, subdomains of a given domain are allowlisted. Fully qualified domain names (FQDNs) are not required. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: mydomain.com myuniversity.edu
PasswordProtectionLoginURLs  Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords.
List (values under a subkey) Machine + User
Turning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\PasswordProtectionLoginURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets the list of enterprise login URLs (HTTP and HTTPS protocols only). Password protection service will capture salted hashes of passwords on these URLs and use them for password reuse detection. For Google Chrome to correctly capture password salted hashes, ensure your sign-in pages follow these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ). Turning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.google.com. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://mydomain.com/login.html https://login.mydomain.com
DisableSafeBrowsingProceedAnyway  Disable proceeding from the Safe Browsing warning page
Boolean Machine + User
Setting the policy to Disabled or leaving it unset means users can choose to proceed to the flagged site after the warning appears.
Registry key
Software\Policies\Google\Chrome
Value name
DisableSafeBrowsingProceedAnyway
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled prevents users from proceeding past the warning page the Safe Browsing service shows to the malicious site. This policy only prevents users from proceeding on Safe Browsing warnings such as malware and phishing, not for SSL certificate-related issues such as invalid or expired certificates. Setting the policy to Disabled or leaving it unset means users can choose to proceed to the flagged site after the warning appears. See more about Safe Browsing ( https://developers.google.com/safe-browsing ).
SafeBrowsingExtendedReportingEnabled  Enable Safe Browsing Extended Reporting
Boolean Machine + User
If not set, users can decide whether to send reports or not.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingExtendedReportingEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled turns on Google Chrome's Safe Browsing Extended Reporting, which sends some system information and page content to Google servers to help detect dangerous apps and sites. Setting the policy to Disabled means reports are never sent. If you set this policy, users can't change it. If not set, users can decide whether to send reports or not. See more about Safe Browsing ( https://developers.google.com/safe-browsing ).
PasswordProtectionWarningTrigger  Password protection warning trigger
Enum Machine + User
Leaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
PasswordProtectionWarningTrigger
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Password protection warning is off
1Password protection warning is triggered by password reuse
2Password protection warning is triggered by password reuse on phishing page
Setting the policy lets you control the triggering of password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites. Use PasswordProtectionLoginURLs and PasswordProtectionChangePasswordURL to set which password to protect. If this policy is set to: * PasswordProtectionWarningOff, no password protection warning will be shown. * PasswordProtectionWarningOnPasswordReuse, password protection warning will be shown when the user reuses their protected password on a non-allowed site. * PasswordProtectionWarningOnPhishingReuse, password protection warning will be shown when the user reuses their protected password on a phishing site. Leaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.
SafeBrowsingProtectionLevel  Safe Browsing Protection Level
Enum Machine + User
If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.
Registry key
Software\Policies\Google\Chrome
Value name
SafeBrowsingProtectionLevel
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
0Safe Browsing is never active.
1Safe Browsing is active in the standard mode.
2Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.
Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in. If this policy is set to 'NoProtection' (value 0), Safe Browsing is never active. If this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode. If this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google. If you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome. If this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting. See https://support.google.com/chrome?p=safe_browsing_preferences for more info on Safe Browsing.
Google:Cat_Google / Google Chrome / Sign-in settings
BoundSessionCredentialsEnabled  Bind Google credentials to a device
Boolean Machine + User
If this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.
Registry key
Software\Policies\Google\Chrome
Value name
BoundSessionCredentialsEnabled
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Controls the state of the Device Bound Session Credentials feature. Device Bound Session Credentials protects Google authentication cookies against cookie theft by regularly providing a cryptographic proof of device possession to Google servers. If this policy is set to false, Device Bound Session Credentials feature will be disabled. If this policy is set to true, Device Bound Session Credentials feature will be enabled. If this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.
ProfileSeparationDomainExceptionList  Enterprise profile separation secondary domain allowlist
List (values under a subkey) Machine + User
If this policy is unset, account logins will not be required to create a new separate profile.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\ProfileSeparationDomainExceptionList
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If this policy is unset, account logins will not be required to create a new separate profile. If this policy is set, account logins from the listed domains will not be required to create a new separate profile. This policy can be set to an empty string so that all account logins are required to create a new separate profile. Example value: domain.com otherdomain.com
Google:Cat_Google / Google Chrome / Startup, Home page and New Tab page
RestoreOnStartup  Action on startup
Enum Machine + User
Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If not set, users can change it.
Registry key
Software\Policies\Google\Chrome
Value name
RestoreOnStartup
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
5Open New Tab Page
1Restore the last session
4Open a list of URLs
6Open a list of URLs and restore the last session
Setting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior. If you set the policy, users can't change it in Google Chrome. If not set, users can change it. Setting this policy to RestoreOnStartupIsLastSession or RestoreOnStartupIsLastSessionAndURLs turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies. If this policy is set to RestoreOnStartupIsLastSessionAndURLs, browser will restore previous session and open a separate window to show URLs that are set from RestoreOnStartupURLs. Note that users can choose to keep those URLs open and they will also be restored in the future session. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
HomepageLocation  Configure the home page URL
String Machine + User
Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.
Registry key
Software\Policies\Google\Chrome
Value name
HomepageLocation
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup. If the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect. The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome. Leaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://www.chromium.org
NewTabPageLocation  Configure the New Tab page URL
String Machine + User
Leaving the policy unset or empty puts the default New Tab page in use.
Registry key
Software\Policies\Google\Chrome
Value name
NewTabPageLocation
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy configures the default New Tab page URL and prevents users from changing it. The New Tab page opens with new tabs and windows. This policy doesn't decide which pages open on start up. Those are controlled by the RestoreOnStartup policies. This policy does affect the homepage, if that's set to open the New Tab page, as well as the startup page if it's set to open the New Tab page. It is a best practice to provide fully canonicalized URL, if the URL is not fully canonicalized Google Chrome will default to https://. Leaving the policy unset or empty puts the default New Tab page in use. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://www.chromium.org
ShowHomeButton  Show Home button on toolbar
Boolean Machine + User
If not set, users chooses whether to show the Home button.
Registry key
Software\Policies\Google\Chrome
Value name
ShowHomeButton
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing. If you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.
RestoreOnStartupURLs  URLs to open on startup
List (values under a subkey) Machine + User
If not set, the New Tab page opens on start up.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\RestoreOnStartupURLs
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open. If not set, the New Tab page opens on start up. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core. Example value: https://example.com https://www.chromium.org
HomepageIsNewTabPage  Use New Tab Page as homepage
Boolean Machine + User
If not set, the user decides whether or not the New Tab page is their homepage.
Registry key
Software\Policies\Google\Chrome
Value name
HomepageIsNewTabPage
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab. If you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage. On Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core. On macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.
Google:Cat_Google / Google Chrome / WebRtc settings
WebRtcPostQuantumKeyAgreement  Enable post-quantum key agreement for WebRTC
Boolean Machine + User
If this policy is not set, the value would be set by the default rollout process for post-quantum key agreement offered for WebRTC.
Registry key
Software\Policies\Google\Chrome
Value name
WebRtcPostQuantumKeyAgreement
Enabled / Disabled
1 / 0
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows controlling post-quantum key agreement for WebRTC. If this policy is set to Enabled, post-quantum key agreement would be offered for WebRTC. If this policy is set to Disabled, post-quantum key agreement would not be offered for WebRTC. If this policy is not set, the value would be set by the default rollout process for post-quantum key agreement offered for WebRTC. Offering a post-quantum key agreement is backwards-compatible. Existing DTLS peers and networking middleware are expected to ignore the new option and continue selecting previous options. However, devices that do not correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or the resulting larger messages. Such devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If encountered, administrators should contact the vendor for a fix. This policy is a temporary measure and will be removed after some milestones.
WebRtcDiagnosticLogCollectionAllowedForOrigins  Enable WebRTC diagnostic log collection for specific origins
List (values under a subkey) Machine + User
If the policy is not set, diagnostic log collection will be disabled by default.
Registry key
Software\Policies\Google\Chrome
List subkey
Software\Policies\Google\Chrome\WebRtcDiagnosticLogCollectionAllowedForOrigins
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows enabling diagnostic log collection for WebRTC for specific origins. For detailed information on valid input patterns, please see https://chromeenterprise.google/policies/url-patterns. * is not an accepted value for this policy. This policy only matches based on origin, so any path in the URL pattern is ignored. Scheme and subdomains are supported. If the policy is set, diagnostic log collection will be enabled for the origins matched by the patterns in the list. If the policy is not set, diagnostic log collection will be disabled by default. Example value: https://www.example.com example.com [*.]example.com *://example.edu:*/ https://example.com:8080
WebRtcIPHandling  WebRTC IP handling
Enum Machine + User
When unset, defaults to using all available network interfaces.
Registry key
Software\Policies\Google\Chrome
Value name
WebRtcIPHandling
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
WebRTC will use all available interfaces when searching for the best path.
WebRTC will only use the interface connecting to the public Internet, but may connect using private IP addresses.
WebRTC will only use the interface connecting to the public Internet, and will not connect using private IP addresses.
WebRTC will use TCP on the public-facing interface, and will only use UDP if supported by a configured proxy.
This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. Valid values: * default - WebRTC uses all available network interfaces. * default_public_and_private_interfaces - WebRTC uses all public and private interfaces. * default_public_interface_only - WebRTC uses all public interfaces, but not private ones. * disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying. When unset, defaults to using all available network interfaces. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values. Example value: default
WebRtcIPHandlingUrl  WebRTC per URL IP Handling
String Machine + User
Unset behaviour not stated in the ADMX — leaving it Not Configured means Chrome's built-in behaviour applies.
Registry key
Software\Policies\Google\Chrome
Value name
WebRtcIPHandlingUrl
Supported on
Microsoft Windows 7 or later
Template
chrome.admx
This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection for each specific URL pattern. It accepts a list of URL patterns and handling type pairs. The URL patterns are checked in order and the first match will configure which handling is used by WebRTC for the domain. When the URL of the current document is not matched against any entry, it uses the configuration set by the policy WebRtcIPHandling. For detailed information on valid input patterns, please see https://chromeenterprise.google/policies/url-patterns/. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored. Valid handling values: * default - WebRTC uses all network interfaces. * default_public_and_private_interfaces - WebRTC uses all public and private interfaces. * default_public_interface_only - WebRTC uses all public interfaces, but not private ones. * disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values. See https://chromeenterprise.google/policies/?policy=WebRtcIPHandlingUrl for more information about schema and formatting. Example value: [ { "url": "https://www.example.com", "handling": "default_public_and_private_interfaces" }, { "url": "https://[*.]example.edu", "handling": "default_public_interface_only" }, { "url": "*", "handling": "disable_non_proxied_udp" } ]