Skip to content

Chrome Enterprise access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Chrome Enterprise, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Chrome Enterprise connector needs.

Checks (4)

severity: medium Download Restrictions Not Set fix difficulty: easy #

Configure download restrictions in Chrome Enterprise to block dangerous file types

  1. Navigate to Google Admin Console > Devices > Chrome > Settings > User & Browser Settings
  2. Search for Download Restrictions in the policy search bar
  3. Set the policy to Block dangerous downloads or Block all downloads depending on your security posture
  4. Apply the policy to all relevant organizational units
  5. Save changes and verify the policy is active

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Incognito Mode Allowed fix difficulty: easy #

Disable Incognito Mode in Chrome Enterprise to ensure browsing activity is logged

  1. Navigate to Google Admin Console > Devices > Chrome > Settings > User & Browser Settings
  2. Search for Incognito Mode in the policy search bar
  3. Set the policy to Disallow Incognito Mode
  4. Apply the policy to all relevant organizational units
  5. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Browser Without Organizational Unit Assignment fix difficulty: easy #

Assign all enrolled Chrome browsers to an appropriate organisational unit so they receive managed policies

  1. Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
  2. Identify the browser flagged as unassigned or assigned to the root OU
  3. Click the browser entry and select Move to move it to the correct OU
  4. Confirm the OU assignment reflects the device's department or function
  5. Verify that the browser receives the expected Chrome policies after the move

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.a.1 DORA (SaaS Security) DORA-9.1

severity: medium Extension With Excessive Permissions fix difficulty: easy #

Review Chrome extensions requesting more than 10 permissions and consider blocking or replacing them

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
  2. Locate the flagged extension in the installed apps list
  3. Review the permissions it requests and determine if all are necessary for its function
  4. If the extension requests excessive or unnecessary permissions, block it via the allowlist policy
  5. Suggest an alternative extension with fewer permission requirements to affected users

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Chrome Enterprise checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial