Jump to content

Recommended Posts

Posted (edited)

Afternoon all,

Just after a little bit of advice, we have quite a few managed chromebooks and was wondering if anybody here has managed to successfully restrict them in a way where only google apps are allowed.

 

We have a few students who go off task easily, restricting them to google apps and no other websites would be benficial.

 

I have managed to achieve this partially by url blocking at a device level , url excepting the google urls that are needed but it feels messy, the blocking restricts a lot of the chromebook system pages (which im slowly unblocking)

 

Any advice would be greatly apreciated

 

Thanks!

Edited by pfl
Posted

Hi yes there is a way to cleanly do it as we have it set up here so they can only "see" the apps in play store and web store that we deem - they can't install other random apps.

 

I cant remember where the setting is I'll have a look for you.

 

In the mean time you can set your apps up on your organisational units by going Devices > Chrome > Apps and Extentions > Users and Browsers and adding the apps you want them to access in the right OU for them.

 

You can aforce install which makes the app install for every user in that OU or you can do allow install which makes it show up in the play store on each device and they can click and install if they want. (i use that mostly as forcing app installs uses a lot of HDD space on each chromebook).

Posted
Hi yes there is a way to cleanly do it as we have it set up here so they can only "see" the apps in play store and web store that we deem - they can't install other random apps.

 

I cant remember where the setting is I'll have a look for you.

 

In the mean time you can set your apps up on your organisational units by going Devices > Chrome > Apps and Extentions > Users and Browsers and adding the apps you want them to access in the right OU for them.

 

You can aforce install which makes the app install for every user in that OU or you can do allow install which makes it show up in the play store on each device and they can click and install if they want. (i use that mostly as forcing app installs uses a lot of HDD space on each chromebook).

Thanks for the reply, after reading my post i now realise it was poorly explained.

 

I want to only allow students access to google apps with no other access to any other website or URLs

Ive managed to partially achieve this by wildcarding ("*") the setting for blockedurls at the device level and then excepting the needed google urls

But its messy, im still hitting hurdles with some signin screens being blocked.

 

 

blockedurls.PNG

Posted
Thanks for the reply, after reading my post i now realise it was poorly explained.

 

I want to only allow students access to google apps with no other access to any other website or URLs

Ive managed to partially achieve this by wildcarding ("*") the setting for blockedurls at the device level and then excepting the needed google urls

But its messy, im still hitting hurdles with some signin screens being blocked.

 

 

[ATTACH=CONFIG]67336[/ATTACH]

heres a complete url list - should help your whitelist

 

https://support.google.com/a/answer/9012184?product_name=UnuFlow&hl=en&visit_id=638055694104176748-1477552912&rd=1&src=supportwidget0&hl=en#new&toplevel&optional&zippy=%2Ctop-level-urls

Posted
Thanks again, that is a new list that i have not seen but unfortunaltey all those URLs I have already added, my exception list is now growing very big!
Posted

Does anybody know the built in url for instigating chromes "inspect" element?

With wild card blocking right clicking and inspecting a page does not work (im guessing its a url block)

 

Dev tools is enabled and I can get inspect to work while url blocking is in place I can view any errors in realtime.

 

Thanks

Posted
Is there any mileage in leveraging your web filter for achieveing this? With ours, we maintain a walled garden filtering profile that is used for this purpose (allowing pupils to access Gmail, Classroom, Docs, EduLink, etc. but no web search or wider web access) which is applied when a user is configured to use the corresponding proxy port. To do this with Chrome users, you'd need the users in a particular OU, where a per-user WiFi network is then configured for that OU. Quite cumbersome, but would mean you don't have to maintain URL allowlists in Google Admin.
  • 7 months later...
Posted (edited)

We whitelisted all the URL's in that page but still had problems with the sign in, or certain Google apps not working - I will test again and see what happens

 

edit - in the new Devices/Browsers settings section of Google Admin there are a billion new settings but can't see one for whitelisting only of sites?

Edited by mikes
Posted
We whitelisted all the URL's in that page but still had problems with the sign in, or certain Google apps not working - I will test again and see what happens

 

edit - in the new Devices/Browsers settings section of Google Admin there are a billion new settings but can't see one for whitelisting only of sites?

 

Yeh it's slightly renamed.

 

"URL blocking" and then you have to click it to get more settings.

Posted (edited)

Thanks, got it now! I'm having trouble putting in the wildcard whitelists such as https://*.googleusercontent.com/* - seems it'll allow site.com/* but it won't allow *.site.com (field is not a valid URL). Got some more fiddling to do (- edit yeah can't even accept the EULA at the moment)

 

Might look into using Impero for it although my concern is how easy Impero might be to bypass on the Chromebooks

Edited by mikes

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...