As a Chrome Enterprise administrator, you can manage Chrome Browser on Microsoft® Windows® computers using Microsoft® Intune, we will look at one such functionality of restricting url's on the managed devices, lets see how this works.
- Access to the Azure Intune portal where you will be creating the policies.
- Chrome Browser version on the managed device should be 69 or later.
- Any edition of Windows 10 except Windows Home
Lets get startetd !!
- Ingest the Chrome ADMX file into Intune, ADM/ADMX templates contain user and device policies, you can download the essential tool from here
In my case I have downloaded the Chrome bundle for Windows 64‑bit as majority of the systems in my organisation are 64 bit chrome installed is aslo 64 bit.
- In the downloaded Chrome bundle go to : GoogleChromeEnterpriseBundle64.zip\Configuration\admx. Copy the text from chrome.admx from that location and paste it in a notepad.
- Sign in to the Microsoft Azure portal
- Go to Intune >Device configuration > Profiles.
- Next to Devices configuration – Profiles, click Create profile.
- Enter the following text in these fields:
- Selecting Custom in the step above opens a new menu for OMA-URI settings. Click Add to add specific policies you can configure and enter the following text(adding screenshot)FieldText to enterName
Chrome ADMX IngestionDescription (optional)OMA-URI ./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Chrome/Policy/ChromeAdmxData type String (select from drop-down list)
- Once you select String, a Value text field opens below. Copy the text from chrome.admx that you copied in step 2. In the Value field, paste the copied content. Attaching the Chrome.admx file for Chrome bundle for Windows 64‑bit for your reference.
- Click OK and OK again to save the Custom OMA-URI settings.
- Click Create to create the new profile.
- Go to Intune >Device configuration >Profiles again
- Click the Windows 10 – Chrome configuration profile you created.
- Select Properties >Settings >Configure to open the Custom OMA-URI settings.
- Click Add to add a row.
- Enter text into the fields, as below for URL blacklist(adding screenshot)Field
Text to enterName Chrome – ADMX – URLBlacklist Description List of URLs to blacklist OMA-URI ./Device/Vendor/MSFT/Policy/Config/Chrome~Policy~googlechrome/URLBlacklist Data type String Value
Important: When creating a key-value pair list (to list URLs for a blacklist or cookies allowed for specific URLs), use  as the separator.
- After you’ve set the policies you want to configure, click OK and OK again to save the Custom OMA-URI settings.
- At the top, click Save to save the Windows 10 – Chrome configuration settings. You will see a Profile saved notification when successful.
- Go to Assignment and select the group of users/devices where you wish to apply this policy to:
- Allow time for Intune to propagate the policy to Chrome on one of the devices you’re managing. If the policy is taking time to push, verify that the device is enrolled and you have synced the device to get the latest policies from Intune.
- On a managed device, open Chrome Browser.
- In the address bar, enter chrome://policy and verify that the policy you set is enabled.
- Now, when the user tries to browse youtube.com, they get the following error: