Jump to content

Should GCPW (Google Credential Provider) automatically log me into Chrome Browser?


Recommended Posts

Posted
Should GCPW automatically (SSO) log me into Chrome Browser?

 

Hmm. I thought so, yes. I haven't looked at this for a year or so, so the current version could be different, but I'm reasonably sure that logging on to Windows via GCPW used to then pass login cookies to Chrome, so your user session would then be logged on when you started Chrome. The same was not true for the Google Drive client, and I spent some time fiddling around with the Windows startup mechanism to try and figure out a solution:

 

https://github.com/dhicks6345789/application-starter

 

I can't remember if Chrome maybe needed some specific registry settings or similar to say "use the cookies provided by GCPW", or possibly GCPW might also have registry settings that control its handling of cookies, too.

Posted
Yes, it does log you in automatically to Chrome. Once you log in and open Chrome, it should ask if you want to continue with your profile. You should then see the sync prompt. In my experience, sometimes I've had to open and close Chrome, then reopen it, to see the prompts.
Posted
Hi everyone, I'm a sysadmin of a school in Italy. I have been using GCPW since this year and confirm that the automatic login works. However, I noticed some things that do not make the login transparent for the user. When a user logs in to Windows for the first time and starts chrome, they are immediately presented with the screen to log in to their account, if they click on "log in" chrome will make them re-enter their credentials, vice versa if they click on "do not log in" then chorme takes the user credentials passed by GCPW, which is not intuitive for the user. To bypass this, in my case, I used ADMX on Windows server and disabled this option https://admx.help/?Category=Chrome&Policy=Google.Policies.Chrome::PromotionalTabsEnabledThe same thing can also be done from the Google console if you use managed Chrome Enterprise. In this way chrome does not show the login screen at startup when it opens the user only has to confirm that they want to activate synchronization
  • Thanks 2
Posted
If this removes the welcome login page with sign in info for Chrome Browser, how does this effect users that are not logging into GCPW, but still need to log into Chrome Browser?

EDITED

 

I needed this setting to access Chrome quickly with a user already logged in because I use GCPW but I believe that a user who logs in normally can continue to do so by logging in once they have started Chrome, at the top right. Or maybe I didn't understand the question?

Posted
I needed this setting to access Chrome quickly with a user already logged in because I use GCPW but I believe that a user who logs in normally can continue to do so by logging in once they have started Chrome, at the top right. Or maybe I didn't understand the question?

I think that has answered my question.

Basically not all my users are using GCPW. If I have this policy set and a new users logs onto a windows laptop that doesnt have GCPW installed, then opens Chrome Browser, previously they would then get asked to log in to Chrome, but with this policy I am guessing that doesn't happen. So you are saying they can still log in, but they will need to click login at the top right?

Posted
I think that has answered my question.

Basically not all my users are using GCPW. If I have this policy set and a new users logs onto a windows laptop that doesnt have GCPW installed, then opens Chrome Browser, previously they would then get asked to log in to Chrome, but with this policy I am guessing that doesn't happen. So you are saying they can still log in, but they will need to click login at the top right?

 

 

Yes, if you set or leave the browser sign in policy as it is without deactive it, they can sign as usually

  • 2 weeks later...
Posted

So, I am still no further on with this.

 

I cant seem to find this setting in our Workspace > Chrome Browser settings

https://chromeenterprise.google/policies/#PromotionsEnabled

 

Also

 

https://admx.help/?Category=Chrome&P...TabsEnabledThe same thing can also be done from the Google console if you use managed Chrome Enterprise. In this way chrome does not show the login screen at startup when it opens the user only has to confirm that they want to activate synchronization

But under that policy it says that disabling this policy the user cannot sign in to the browser and use account-based services. In this case browser-level features like Google Chrome Sync cannot be used and will be unavailable. Which doesn't sound right.

 

Last question.

Should logging into GCPW also add the browser to the Chrome managed browser listed in Workspace? Currently we are not using the managed browser system. Or do we still need to generate a token and deploy that independently?

Posted

Still playing around with this, so a few things I have noticed...

 

The installer sometimes misses adding reg keys, especially the domain locking one. So I might just create a script that adds the correct reg keys.

 

Also, what is the point of having devices sent to 'Device Approvals'? The device I am testing with has not been approved (this time), but is still getting all of its policies and settings applied from Workspace.

 

Still not managed to get the one thing I actually wanted working, auto log into Chrome Browser.

Posted
Still not managed to get the one thing I actually wanted working, auto log into Chrome Browser.

 

If it's any help (which it probably isn't, but you never know), we had to give up on using GCPW as we found it doesn't support the use of USB 2FA dongles, which we issue to staff. We are currently logging in to Windows machines with Google credentials using pGina:

 

pGina - Open source Windows authentication

 

The user logs in to Windows with their Google username / password, checked against Google's ldap service. No 2FA step is carried out, so the user then has to log in (with 2FA) to Chrome separately.

  • Thanks 1
Posted
If it's any help (which it probably isn't, but you never know), we had to give up on using GCPW as we found it doesn't support the use of USB 2FA dongles, which we issue to staff.

 

Is that still the case. I have been watching a videos about setting up GCPW (been watching loads of these lately, lol) and I seem to remember in one they used a fido style usb key. Possibly wrong. Ill rebuild my test Windows VM and see if my key works.

Posted
just logged in to Windows using GCPW and my yubikey key as the 2 step.

 

Ooh! Thanks - I think we last tried a year or so ago, and I understood the problem then to be that the Windows login provider was sandboxed off from accessing the USB ports. It sounds like that has changed (or I was doing something wrong), so sounds like it might be worth us trying again.

Posted
They did (finally) release an update for GCPW on the 22nd of July last year. It doesn't state that support for security key(s) was added though. Although, it does list "Security Improvements" so maybe they did....Game changer!
  • Thanks 1
Posted
I'm having this issue at the moment too actually. No longer passing the sign in through from GCPW login to Chrome. The update doesn't allow hardware token sign in either. I did that last year. Anyone have any tips of whats changed recently to stop the sign in pass through
Posted
I've got a Google Workspace support ticket open about this and have referenced this thread. I'd recommend people raise there own ticket to get more traction in this.
  • Thanks 1
Posted
I've got a Google Workspace support ticket open about this and have referenced this thread. I'd recommend people raise there own ticket to get more traction in this.

 

Brill glad it’s not just me. Will do the same. Thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...