Chrome Enterprise lifecycle & offboarding security checks
Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.
On Chrome Enterprise, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Chrome Enterprise connector needs.
Checks (4)
severity: medium Stale Browser (90+ Days Inactive) fix difficulty: medium #
Decommission or re-enroll Chrome browsers that have been inactive for 90 or more days
- Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
- Filter browsers by last activity date to identify browsers inactive for 90+ days
- Verify with device owners whether the machine is still in use
- If the device is decommissioned, delete the browser enrollment record
- If the device should be active, re-enroll it and ensure Chrome policies are applied
- Update your asset inventory to reflect decommissioned devices
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.3 DORA (SaaS Security) DORA-8.1
severity: low Unmanaged Browser (30+ Days Inactive) fix difficulty: easy #
Review and clean up Chrome browser enrollments that have been inactive for 30 or more days
- Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
- Filter browsers by last activity date to identify browsers inactive for 30+ days
- Confirm with the assigned user or IT asset inventory whether the device is still active
- Delete the enrollment record for decommissioned or reassigned devices
- If the device is still in use, ensure the Chrome management policy is applied correctly
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.3 DORA (SaaS Security) DORA-8.1
severity: low Orphaned Extension With Zero Installs fix difficulty: easy #
Remove stale extension catalog entries that have zero active installations
- Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions
- Locate the flagged extension with zero install count
- Confirm the extension is no longer needed by your organisation
- Remove the extension from the managed catalog or allowed list
- Save changes and verify the extension no longer appears in the inventory
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.3 DORA (SaaS Security) DORA-8.1
severity: medium Browser Flagged as Needing Attention fix difficulty: medium #
Investigate and resolve the condition causing Chrome to flag the browser as needing attention
- Navigate to Google Admin Console > Devices > Chrome > Managed Browsers
- Locate the flagged browser and open its detail view
- Review the attention reason reported by Chrome Enterprise (e.g., policy conflict, outdated OS, unenrolled)
- Remediate the underlying issue according to the specific reason shown
- Verify the browser no longer appears in the needing-attention report after remediation
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.i.3 DORA (SaaS Security) DORA-8.1