For Chrome extension deployment by Group Policy, verify the policy in these locations first:
- In Group Policy Management Editor, open the policy linked to the target OU.
- Go to:
Computer/User configuration > Policies > Administrative templates > Classic administrative templates > Google > Google Chrome > Extensions
- Open Configure the list of force-installed extensions.
- Confirm the policy is Enabled.
- Select Show and verify the extension entry is present in this format:
echcggldkblhodogklpincgchnpgcdco;https://clients2.google.com/service/update2/crx
If the extension is still not installing, inspect the related Chrome native messaging host registry values when the affected extension is the Power Automate browser extension:
-
Computer\HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.robin.messagehost
-
Computer\HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.pad.messagehost
For those keys, verify the value points to the expected manifest path:
- MSI:
C:\Program Files (x86)\Power Automate Desktop\dotnet\PAD.ChromiumManifest.json
- MSIX Windows 11:
C:\Program Files\WindowsApps\Microsoft.PowerAutomateDesktop_X.Y.Z.0_x64__8wekyb3d8bbwe\PAD.ChromiumManifest.json
- MSIX Windows 10:
AppData\Local\Packages\Microsoft.PowerAutomateDesktop_8wekyb3d8bbwe\TempState\webextensions\PAD.ChromiumManifest.json
Also check whether cmd.exe execution is blocked by Group Policy, Intune, or registry restrictions. If it is blocked, the browser can’t launch the native messaging host and the extension can fail.
If the deployment uses a self-hosted .crx package instead of the Chrome Web Store update URL, verify the web server returns this HTTP header for the .crx file:
Content-Type: application/x-chrome-extension
On IIS, this is done by adding a MIME type mapping:
- Open IIS Manager.
- Select the site hosting the extension.
- Open MIME Types.
- Select Add....
- Set File name extension to
.crx.
- Set MIME type to
application/x-chrome-extension.
- Select OK, then recycle the site or app pool if needed.
If the extension package is self-hosted, also validate that the extension manifest.json and update manifest XML are valid. Invalid version formatting or malformed update XML can allow manual install in some cases but still break policy-based install and automatic updates.
References: