Chrome Enterprise identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Chrome Enterprise, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Chrome Enterprise connector needs.
Checks (5)
severity: high Widely Deployed Extension With Risky Permissions fix difficulty: medium #
Review and restrict Chrome extensions with risky permissions deployed to more than 50 devices
- Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
- Identify the flagged extension and review its declared permissions
- Determine whether the extension is business-critical and the permissions are necessary
- If not justified, add the extension to the Blocked apps and extensions list
- If approved, document the risk acceptance and schedule a periodic review
- Consider replacing the extension with a less-privileged alternative
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: high Browser Running on Unsupported OS fix difficulty: hard #
Upgrade or decommission Chrome-managed devices still running end-of-life Windows versions
- Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
- Filter or search for browsers to identify the affected device
- Coordinate with the device owner or IT asset team to schedule an OS upgrade
- If the device cannot be upgraded, isolate it from sensitive network segments and plan decommission
- After upgrade, verify the device re-enrolls with the correct Chrome policies
- Update your asset inventory to reflect the OS change
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: high Admin-Forced Extension With Risky Permissions fix difficulty: medium #
Review admin-pushed Chrome extensions that carry high-risk permissions and cannot be removed by users
- Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
- Locate the extension marked as Force Installed and review its declared permissions
- Assess whether the risky permission (e.g., nativeMessaging, debugger, cookies) is required for its function
- If not required, replace the extension with a less-privileged version or switch to a different tool
- If the permission is required, document the risk acceptance and set up monitoring for abnormal behaviour
- Notify your security team of all admin-forced extensions with elevated privileges
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: medium Shadow IT Extension Widely Deployed fix difficulty: medium #
Evaluate and either formally approve or block non-managed extensions installed on more than 100 devices
- Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
- Identify the flagged extension and review its install count and publisher
- Determine whether the extension serves a legitimate business purpose
- If approved, add it to the managed catalog with appropriate install policy
- If not approved, add it to the Blocked apps and extensions list to prevent further spread
- Communicate the policy decision to affected users
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: high Device Running Outdated OS (Telemetry) fix difficulty: hard #
Upgrade devices reported via Chrome telemetry that are running end-of-support operating systems
- Navigate to Google Admin Console > Devices > Chrome > Devices
- Locate the flagged device using its machine name or serial number
- Confirm the OS version shown in the device detail view
- Coordinate with the device owner to schedule an OS upgrade (macOS 13+ or a supported Windows version)
- If the device cannot be upgraded, isolate it from sensitive systems and plan decommission
- After upgrade, verify the device appears with a supported OS version in the telemetry report
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.8 NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13