How to Force-Install a Chrome Extension with Google Admin (Step by Step)

Push a Chrome extension to every managed browser from the Google Admin console: find the ID, pick the installation policy, verify it and fix problems.

Screshot Team10 min read
A Google Admin console policy pushing one Chrome extension to every managed browser, where it appears pinned and marked as installed by the administrator

Quick answer: in the Google Admin console, go to Menu > Chrome browser > Apps & extensions > Users & browsers (on some accounts it is Devices > Chrome > Apps & extensions), select an organizational unit, click Add > Add Chrome app or extension by ID, paste the extension ID and save. Then set Installation policy to Force install or Force install + pin to browser toolbar. Managed browsers install it automatically, and users can't remove it.

Asking 300 people to install an extension from a link in an email gets you maybe half of them. Force-installing it gets you all of them, on the right version, without a single support ticket. This guide covers who a force-install reaches, every step in the Admin console, which installation policy to choose, how to check it worked, and what to do when it doesn't.

Before you start: who will actually get the extension

A force-install only reaches browsers that the Admin console manages. Google lists three ways a browser comes under management:

Three ways a browser receives Admin console policy: users signed in to Chrome with a managed account, browsers enrolled in Chrome Enterprise Core, and enrolled ChromeOS devices
  • Users signed in with a managed account. Anyone who signs in to Chrome with their work Google account gets your user policies on any computer, including the extension.
  • Browsers enrolled in Chrome Enterprise Core. You can enroll Chrome on Windows, Mac and Linux with an enrollment token from Menu > Chrome browser > Managed browsers > Enroll. Policies then apply to the browser itself, whoever uses it. Chrome Enterprise Core, formerly Chrome Browser Cloud Management, is offered at no additional cost.
  • Enrolled ChromeOS devices. Users signing in with a managed account, and managed guest sessions, receive the extension too.

If people use Chrome without signing in to a work account and their browsers aren't enrolled, nothing you set in the Admin console reaches them. That is the most common reason a force-install "doesn't work".

You also need:

  • An administrator role that can manage Chrome settings.
  • The extension ID (next section).
  • A decision on where to apply it: the top-level organizational unit for everyone, a child unit for one department, or a group.

Step 1: Find the extension ID

Every Chrome Web Store extension has a 32-character ID made of the letters a to p. Two ways to find it:

1. From the Chrome Web Store. Open the extension's page. The ID is the last part of the address: chromewebstore.google.com/detail/<name>/<ID>.

2. From Chrome itself. Install the extension on your own browser, open chrome://extensions, turn on Developer mode and read the ID on its card.

For example, Screshot's ID is ikhdemckhflgmlijkaomcpdmljegkakh. Copy the ID exactly. A single wrong letter installs nothing and shows no error.

Step 2: Open Apps & extensions in the Admin console

1. Sign in to admin.google.com with an administrator account.

2. Open Menu > Chrome browser > Apps & extensions. On some accounts the same page is under Menu > Devices > Chrome > Apps & extensions.

3. Click the Users & browsers tab.

The Admin console path to Apps & extensions, an organizational unit selected on the left, and the Add menu open on "Add Chrome app or extension by ID"

Step 3: Choose who gets it

On the left, select the organizational unit that should receive the extension. Selecting the top-level unit applies it to everyone, and child units inherit it unless they override it. To target a team instead of a branch of your org chart, switch to Groups and pick a group.

Start with a small test unit. Google recommends trying settings on a few users or browsers before rolling them out widely, and it costs you five minutes.

Step 4: Add the extension by ID

1. Point at the Add button (the plus in the bottom-right corner).

2. Choose Add Chrome app or extension by ID.

3. Paste the extension ID, keep From the Chrome Web Store selected, and click Save.

The extension now appears in the list for that organizational unit.

Step 5: Set the installation policy

Click the extension in the list and open Installation policy. Choose Force install or Force install + pin to browser toolbar, then click Save.

That's the whole deployment. Managed browsers in that unit pick up the change the next time they fetch policy.

Which installation policy should you choose?

The Admin console offers six installation policies. Here is what each one does to the people you apply it to:

A comparison of six installation policies: Allow install, Force install, Force install + pin to browser toolbar, Force install allow users to disable, Block, and Block uninstall from Chrome
  • Allow install: users may install the extension themselves. Nothing happens automatically.
  • Force install: installed automatically, and users can't remove it.
  • Force install + pin to browser toolbar: the same, and the icon stays on the toolbar where people will actually use it.
  • Force install, allow users to disable: installed automatically, but users can turn it off.
  • Block: users can't install it, and copies already installed are disabled.
  • Block, uninstall from Chrome: removes it from browsers that have it, without a browser restart.

For a tool you want everyone to use, such as a password manager, a security add-on or a screenshot tool, choose Force install + pin to browser toolbar. An extension hidden behind the puzzle-piece menu is an extension people forget they have.

Two details from Google's documentation worth knowing: force-installed extensions bypass your blocked apps and extensions list, and there is a limit of 500 for the number of apps multiplied by the number of groups you configure.

Step 6: Verify the install

Policy changes usually reach browsers within minutes. Google notes that some changes can take up to 24 hours to propagate, so don't panic if the first check comes up empty. To check a test machine:

1. Open chrome://policy and click Reload policies to fetch the latest settings now.

2. Search for Extension. Your extension ID should appear in an extension policy, with Cloud in the Source column.

3. Open chrome://extensions. The extension should be listed and marked as installed by your administrator, without a Remove option.

chrome://policy showing the extension ID delivered from the cloud with status OK, and the extension card on chrome://extensions marked as installed by the administrator

If the extension doesn't appear after a reload, restart Chrome. Some policy changes only apply on restart.

Troubleshooting: the extension isn't installing

  • The browser isn't managed. In chrome://policy, check the top of the page. If no cloud policies are listed, the user isn't signed in with a managed account and the browser isn't enrolled. Fix that first.
  • Wrong organizational unit. The user, or the enrolled browser, sits in a different unit than the one you configured. For enrolled browsers, check the unit under Managed browsers, which can differ from the user's unit.
  • A child unit overrides the setting. A unit that has its own setting for the extension doesn't inherit yours. Look for it in the child unit's list.
  • Another tool sets the same policy. If Group Policy, Intune or a Mac profile also manages Chrome extensions, check the Source column in chrome://policy to see which one wins.
  • A typo in the ID. Compare it character by character with the Chrome Web Store address.
  • The network blocks Google's update servers. Chrome downloads force-installed extensions from Google's update service. Strict proxies or firewalls that block it stop the download.
  • The extension was removed from the Chrome Web Store. A force-install can't install something that is no longer published.

How to remove a force-installed extension

Change its installation policy rather than leaving a gap:

  • To let people decide for themselves, switch it to Allow install.
  • To take it away from everyone, use Block, uninstall from Chrome, which removes it from managed browsers without a restart.

Rolling out a screenshot tool company-wide

Screenshot tools are a good example of why force-installing matters. When every team picks its own, customer data ends up in a dozen apps, some of which upload every capture to their own cloud.

Screshot is built for this kind of rollout. It captures the visible area or a full page, blurs sensitive data and annotates screenshots on the user's device, and nothing is uploaded when people capture, blur, copy or download. Use the ID ikhdemckhflgmlijkaomcpdmljegkakh and Force install + pin to browser toolbar. Force-installed users don't see the welcome tab.

For Intune, Group Policy and macOS profiles, see the deployment guide. If your security team needs answers first, the security review pack has the data flow, permissions and questionnaire answers on one page.

FAQ

Can users remove a force-installed extension?

No. Google states that users can't remove items that are force-installed. With Force install, allow users to disable, they can turn it off but not remove it.

Does force-installing work for personal Gmail accounts?

No. Policies only reach users signed in with a managed account, enrolled browsers and enrolled ChromeOS devices. A personal profile on the same computer is not affected, unless the whole browser is enrolled.

Do I need a paid license to force-install extensions on Windows and Mac?

Managing Chrome browsers with Chrome Enterprise Core is offered at no additional cost. Managing ChromeOS devices has its own licensing.

How long does it take for the extension to appear?

Usually minutes. Google notes that some changes can take up to 24 hours. On a test machine, click Reload policies on chrome://policy and restart Chrome to apply changes right away.

Can I force-install an extension that isn't in the Chrome Web Store?

Yes, if you host it yourself. When adding it, choose From a custom URL and enter the URL where it is hosted.

Does a force-installed extension get its permissions automatically?

It is installed without asking the user, so review what an extension can access before you push it to everyone. A narrow permission set and a clear data flow make that review quick.

Sources

Written by

Screshot Team

Product & security team

The team that builds Screshot, the private screenshot tool for Chrome. We write about keeping customer data out of screenshots, rolling out tools across a company, and getting work done faster with your screen.

Keep customer data out of your screenshots

Screshot captures a screen or a full page, blurs sensitive details and annotates, all on your device. Free for every team.