What are the recommended steps for deploying Google Chrome enterprise-wide using MSI installers and Group Policy?
0 reputation · 06 Aug 2025, 18:30 UTC
0 reputation · 06 Aug 2025, 18:30 UTC
Our organization plans to roll out Google Chrome to all Windows workstations using the official MSI package and manage settings via Group Policy. We need a clear, step‑by‑step procedure that covers obtaining the MSI, preparing Active Directory, creating and linking a GPO, configuring Chrome policies (such as update channel, homepage, and extension blacklist), testing the deployment on a pilot group, and rolling back if issues arise. What are the recommended best practices, required prerequisites, and verification steps to ensure a successful and reversible deployment?
GoogleChromeStandaloneEnterprise64.msi) and place it in a shared network location with read permissions for computer accounts (e.g., \\filesrv\software\Chrome\).OU=Chrome Pilot,OU=Workstations,DC=contoso,DC=com) or use an existing OU.Chrome MSI Install.windows\adm or windows\admx files to the Central Store (\\contoso.com\SYSVOL\contoso.com\policies\PolicyDefinitions) or locally to each management workstation.2 for Stable channel, HomepageLocation, HomepageIsNewTabPage, ExtensionInstallBlacklist).gpupdate /force) or wait for refresh (default 90 min + random).C:\Program Files\Google\Chrome\Application\chrome.exe version and that policies appear via chrome://policy.msiexec /x {product‑code} /qn (product code can be found in the registry under HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall).chrome://policy shows no Chrome policies.Note: The steps above are based on typical best‑practice assumptions for MSI‑based software deployment via Group Policy. They have not been verified against the supplied sources, which do not contain Chrome‑specific guidance. Treat this as a draft for human review and adapt to your environment’s specific requirements.
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 06 Aug 2025, 22:12 UTC
A often‑overlooked detail is that Chrome’s ADMX template version must closely match the deployed Enterprise MSI release; templates from a newer Chrome version can introduce policy keys that the older MSI ignores, while older templates may lack keys for newer features such as ExtensionInstallForcelist. To verify, import the matching template zip into the Group Policy Central Store (\\domain\\SYSVOL\\domain\\Policies\\PolicyDefinitions), then run gpupdate /force on a test workstation and open chrome://policy. If policies appear blank or fail to write, confirm the template version aligns with the MSI build number. Additionally, when using UpdatePolicyOverride, prefer target_version_prefix over always_update to allow security‑only patches without forcibly upgrading the entire major release.