Chrome Enterprise access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Chrome Enterprise, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Chrome Enterprise connector needs.
Checks (4)
severity: medium Download Restrictions Not Set fix difficulty: easy #
Configure download restrictions in Chrome Enterprise to block dangerous file types
- Navigate to Google Admin Console > Devices > Chrome > Settings > User & Browser Settings
- Search for Download Restrictions in the policy search bar
- Set the policy to Block dangerous downloads or Block all downloads depending on your security posture
- Apply the policy to all relevant organizational units
- Save changes and verify the policy is active
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Incognito Mode Allowed fix difficulty: easy #
Disable Incognito Mode in Chrome Enterprise to ensure browsing activity is logged
- Navigate to Google Admin Console > Devices > Chrome > Settings > User & Browser Settings
- Search for Incognito Mode in the policy search bar
- Set the policy to Disallow Incognito Mode
- Apply the policy to all relevant organizational units
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Browser Without Organizational Unit Assignment fix difficulty: easy #
Assign all enrolled Chrome browsers to an appropriate organisational unit so they receive managed policies
- Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
- Identify the browser flagged as unassigned or assigned to the root OU
- Click the browser entry and select Move to move it to the correct OU
- Confirm the OU assignment reflects the device's department or function
- Verify that the browser receives the expected Chrome policies after the move
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.a.1 DORA (SaaS Security) DORA-9.1
severity: medium Extension With Excessive Permissions fix difficulty: easy #
Review Chrome extensions requesting more than 10 permissions and consider blocking or replacing them
- Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
- Locate the flagged extension in the installed apps list
- Review the permissions it requests and determine if all are necessary for its function
- If the extension requests excessive or unnecessary permissions, block it via the allowlist policy
- Suggest an alternative extension with fewer permission requirements to affected users
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2