TwistedHelixis Posted February 10, 2025 Posted February 10, 2025 Just having a play with GCPW. All seems OK. Security setting deploy and a few test policies apply. Should GCPW automatically (SSO) log me into Chrome Browser? As its not doing this.
dhicks Posted February 11, 2025 Posted February 11, 2025 Should GCPW automatically (SSO) log me into Chrome Browser? Hmm. I thought so, yes. I haven't looked at this for a year or so, so the current version could be different, but I'm reasonably sure that logging on to Windows via GCPW used to then pass login cookies to Chrome, so your user session would then be logged on when you started Chrome. The same was not true for the Google Drive client, and I spent some time fiddling around with the Windows startup mechanism to try and figure out a solution: https://github.com/dhicks6345789/application-starter I can't remember if Chrome maybe needed some specific registry settings or similar to say "use the cookies provided by GCPW", or possibly GCPW might also have registry settings that control its handling of cookies, too.
TheHyperTechie Posted February 11, 2025 Posted February 11, 2025 Yes, it does log you in automatically to Chrome. Once you log in and open Chrome, it should ask if you want to continue with your profile. You should then see the sync prompt. In my experience, sometimes I've had to open and close Chrome, then reopen it, to see the prompts.
TwistedHelixis Posted February 11, 2025 Author Posted February 11, 2025 Its just not working. I first tried it on a Win 11 pro laptop, but now testing on Hyper-V > Windows 11 Edu VM. Literally everything else is working.
lorzeni Posted February 14, 2025 Posted February 14, 2025 Hi everyone, I'm a sysadmin of a school in Italy. I have been using GCPW since this year and confirm that the automatic login works. However, I noticed some things that do not make the login transparent for the user. When a user logs in to Windows for the first time and starts chrome, they are immediately presented with the screen to log in to their account, if they click on "log in" chrome will make them re-enter their credentials, vice versa if they click on "do not log in" then chorme takes the user credentials passed by GCPW, which is not intuitive for the user. To bypass this, in my case, I used ADMX on Windows server and disabled this option https://admx.help/?Category=Chrome&Policy=Google.Policies.Chrome::PromotionalTabsEnabledThe same thing can also be done from the Google console if you use managed Chrome Enterprise. In this way chrome does not show the login screen at startup when it opens the user only has to confirm that they want to activate synchronization 2
rogerdnixon Posted February 14, 2025 Posted February 14, 2025 You want this set to false: https://chromeenterprise.google/policies/#PromotionsEnabled - its new and the old policy is depreciated. 2
TwistedHelixis Posted February 14, 2025 Author Posted February 14, 2025 Its half term next week, so ill have another go then. Thanks
lorzeni Posted February 14, 2025 Posted February 14, 2025 you are right, really. I tested both but at the end i setted that in the admin console - - - Updated - - - You want this set to false: https://chromeenterprise.google/policies/#PromotionsEnabled - its new and the old policy is depreciated. you are right, really. I tested both but at the end i setted that in the admin console
TwistedHelixis Posted February 14, 2025 Author Posted February 14, 2025 (edited) You want this set to false: https://chromeenterprise.google/poli...motionsEnabled - its new and the old policy is depreciated. If this removes the welcome login page with sign in info for Chrome Browser, how does this effect users that are not logging into GCPW, but still need to log into Chrome Browser? EDITED Edited February 14, 2025 by TwistedHelixis
lorzeni Posted February 14, 2025 Posted February 14, 2025 If this removes the welcome login page with sign in info for Chrome Browser, how does this effect users that are not logging into GCPW, but still need to log into Chrome Browser? EDITED I needed this setting to access Chrome quickly with a user already logged in because I use GCPW but I believe that a user who logs in normally can continue to do so by logging in once they have started Chrome, at the top right. Or maybe I didn't understand the question?
TwistedHelixis Posted February 14, 2025 Author Posted February 14, 2025 I needed this setting to access Chrome quickly with a user already logged in because I use GCPW but I believe that a user who logs in normally can continue to do so by logging in once they have started Chrome, at the top right. Or maybe I didn't understand the question? I think that has answered my question. Basically not all my users are using GCPW. If I have this policy set and a new users logs onto a windows laptop that doesnt have GCPW installed, then opens Chrome Browser, previously they would then get asked to log in to Chrome, but with this policy I am guessing that doesn't happen. So you are saying they can still log in, but they will need to click login at the top right?
lorzeni Posted February 15, 2025 Posted February 15, 2025 I think that has answered my question. Basically not all my users are using GCPW. If I have this policy set and a new users logs onto a windows laptop that doesnt have GCPW installed, then opens Chrome Browser, previously they would then get asked to log in to Chrome, but with this policy I am guessing that doesn't happen. So you are saying they can still log in, but they will need to click login at the top right? Yes, if you set or leave the browser sign in policy as it is without deactive it, they can sign as usually
TwistedHelixis Posted February 26, 2025 Author Posted February 26, 2025 So, I am still no further on with this. I cant seem to find this setting in our Workspace > Chrome Browser settings https://chromeenterprise.google/policies/#PromotionsEnabled Also https://admx.help/?Category=Chrome&P...TabsEnabledThe same thing can also be done from the Google console if you use managed Chrome Enterprise. In this way chrome does not show the login screen at startup when it opens the user only has to confirm that they want to activate synchronization But under that policy it says that disabling this policy the user cannot sign in to the browser and use account-based services. In this case browser-level features like Google Chrome Sync cannot be used and will be unavailable. Which doesn't sound right. Last question. Should logging into GCPW also add the browser to the Chrome managed browser listed in Workspace? Currently we are not using the managed browser system. Or do we still need to generate a token and deploy that independently?
TwistedHelixis Posted February 26, 2025 Author Posted February 26, 2025 Think I might give up on this and get the users to login twice
TwistedHelixis Posted February 26, 2025 Author Posted February 26, 2025 Still playing around with this, so a few things I have noticed... The installer sometimes misses adding reg keys, especially the domain locking one. So I might just create a script that adds the correct reg keys. Also, what is the point of having devices sent to 'Device Approvals'? The device I am testing with has not been approved (this time), but is still getting all of its policies and settings applied from Workspace. Still not managed to get the one thing I actually wanted working, auto log into Chrome Browser.
dhicks Posted February 27, 2025 Posted February 27, 2025 Still not managed to get the one thing I actually wanted working, auto log into Chrome Browser. If it's any help (which it probably isn't, but you never know), we had to give up on using GCPW as we found it doesn't support the use of USB 2FA dongles, which we issue to staff. We are currently logging in to Windows machines with Google credentials using pGina: pGina - Open source Windows authentication The user logs in to Windows with their Google username / password, checked against Google's ldap service. No 2FA step is carried out, so the user then has to log in (with 2FA) to Chrome separately. 1
TwistedHelixis Posted February 27, 2025 Author Posted February 27, 2025 If it's any help (which it probably isn't, but you never know), we had to give up on using GCPW as we found it doesn't support the use of USB 2FA dongles, which we issue to staff. Is that still the case. I have been watching a videos about setting up GCPW (been watching loads of these lately, lol) and I seem to remember in one they used a fido style usb key. Possibly wrong. Ill rebuild my test Windows VM and see if my key works.
TwistedHelixis Posted February 28, 2025 Author Posted February 28, 2025 @dhicks just logged in to Windows using GCPW and my yubikey key as the 2 step. 1
dhicks Posted February 28, 2025 Posted February 28, 2025 just logged in to Windows using GCPW and my yubikey key as the 2 step. Ooh! Thanks - I think we last tried a year or so ago, and I understood the problem then to be that the Windows login provider was sandboxed off from accessing the USB ports. It sounds like that has changed (or I was doing something wrong), so sounds like it might be worth us trying again.
TheHyperTechie Posted February 28, 2025 Posted February 28, 2025 They did (finally) release an update for GCPW on the 22nd of July last year. It doesn't state that support for security key(s) was added though. Although, it does list "Security Improvements" so maybe they did....Game changer! 1
whartomt01 Posted February 28, 2025 Posted February 28, 2025 I'm having this issue at the moment too actually. No longer passing the sign in through from GCPW login to Chrome. The update doesn't allow hardware token sign in either. I did that last year. Anyone have any tips of whats changed recently to stop the sign in pass through
rogerdnixon Posted March 1, 2025 Posted March 1, 2025 I've got a Google Workspace support ticket open about this and have referenced this thread. I'd recommend people raise there own ticket to get more traction in this. 1
whartomt01 Posted March 1, 2025 Posted March 1, 2025 I've got a Google Workspace support ticket open about this and have referenced this thread. I'd recommend people raise there own ticket to get more traction in this. Brill glad it’s not just me. Will do the same. Thanks
whartomt01 Posted March 7, 2025 Posted March 7, 2025 @RogerNixon - Did you get anywhere with your Google ticket. Support always seems very slow.
rogerdnixon Posted March 7, 2025 Posted March 7, 2025 Google have reproduced the issue and are working on a fix - that's the latest I've got. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now