Jump to content

Recommended Posts

Posted

Dear Google ChromeOS for Education administrator,

Ensuring the security and integrity of your devices and users is paramount. We are writing to inform you about two potential scenarios where users could bypass forced re-enrollment on ChromeOS devices, and what you can do to prevent these scenarios.

Please review the details below, as you can effectively address both scenarios with the following recommendations.

What this means for your organization

Understanding how these scenarios can occur can help you protect your devices and maintain a fully managed, secure environment for your users.

Scenario / Setting Potential risk Mitigation status and Required action
Sensitive Chrome URLs Users access sensitive device management tokens via internal URLs (such as chrome://policy/logs or chrome://net-export). You should not need to take action. Google has updated the default setting for the Block sensitive internal Chrome URLs policy to Enabled at the top-level Organizational Unit (OUs) to automatically protect your fleet.
User-initiated enrollment Users utilize device enrollment permissions to bypass forced re-enrollment protections. We advise you to take action. Restrict manual username/password device enrollment specifically for student-facing Organizational Units (OUs).

What you need to do

Action required:
We recommend that you restrict user-initiated enrollment, specifically for Organizational Units (OUs) containing students or users who might attempt to bypass enrollment policies.

  1. Navigate to Devices > Chrome > Settings > Users & browsers
  2. Select the Organizational Unit(s) containing the students or users you want to prevent from removing devices from management
  3. Locate the User-Initiated Enrollment setting
  4. Set it to "Do not allow users to enroll new or re-enroll existing devices"
  5. Click Save

Note: You should not apply this restriction to OUs containing staff or administrators who still need the ability to manually enroll new devices.

Additionally, you may choose to configure Chromebooks used by these users to automatically re-enroll after wiping, without user credentials.

  1. Navigate to Devices > Chrome > Settings > Device settings
  2. Select the Organizational Unit(s) with devices that need to re-enroll after wipe
  3. Locate the Forced re-enrollment setting
  4. Set it to "Force device to automatically re-enroll after wiping"
  5. Click Save

Important: Unless you have previously disabled this setting, you do not need to take further action for the Block sensitive internal Chrome URLs policy, as Google has updated the default to Enabled at the top-level OU to ensure your fleet remains protected. You can still choose to update this policy for specific OUs by navigating to Devices > Chrome > Settings > Users & browsers and locating the Block sensitive internal Chrome URLs policy.

We are here to help

Please review the following resources for more information on managing ChromeOS device settings:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...