Managed Chrome browser failing to install required security extension via GPO

Sarah Williams 40 Reputation points
2026-09-18T17:50:38.27+00:00

I need to resolve an issue with managed Google Chrome browsers across our Windows workstations following a recent Group Policy rollout.

It says the enterprise policy fails to automatically push and install the required corporate security extension, leaving endpoints non-compliant and without the necessary security controls.

And our enterprise machines rely on these security policies for daily compliance and protection. How do we inspect and verify the enterprise policy registry keys to ensure the extension configuration is properly applied?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

2 answers

Sort by: Most helpful
  1. Tracy Le 13,050 Reputation points Independent Advisor
    2026-09-18T19:06:15.5666667+00:00

    Hello Sarah Williams,

    When Chrome fails to deploy mandatory extensions configured through Group Policy, the policy might not be written to the registry, or the extension ID and update URL syntax could be malformed. To verify policy application, open Registry Editor and navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist. You can also inspect this by running Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist' in PowerShell. Ensure each numbered string value accurately matches your extension ID followed by a semicolon and the valid update XML URL.

    If the registry key is missing, execute gpupdate /force and run rsop.msc to check for GPO replication failures or scoping conflicts. Inside Chrome, navigate to chrome://policy to verify if ExtensionInstallForcelist appears with a status of OK, and check chrome://extensions to confirm whether installation errors are reported. If this guidance helps you verify and deploy your extension successfully, please consider accepting this answer.

    Tracy Le

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-18T17:50:53.8133333+00:00

    For Chrome extension deployment by Group Policy, verify the policy in these locations first:

    1. In Group Policy Management Editor, open the policy linked to the target OU.
    2. Go to: Computer/User configuration > Policies > Administrative templates > Classic administrative templates > Google > Google Chrome > Extensions
    3. Open Configure the list of force-installed extensions.
    4. Confirm the policy is Enabled.
    5. Select Show and verify the extension entry is present in this format: echcggldkblhodogklpincgchnpgcdco;https://clients2.google.com/service/update2/crx

    If the extension is still not installing, inspect the related Chrome native messaging host registry values when the affected extension is the Power Automate browser extension:

    • Computer\HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.robin.messagehost
    • Computer\HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.pad.messagehost

    For those keys, verify the value points to the expected manifest path:

    • MSI: C:\Program Files (x86)\Power Automate Desktop\dotnet\PAD.ChromiumManifest.json
    • MSIX Windows 11: C:\Program Files\WindowsApps\Microsoft.PowerAutomateDesktop_X.Y.Z.0_x64__8wekyb3d8bbwe\PAD.ChromiumManifest.json
    • MSIX Windows 10: AppData\Local\Packages\Microsoft.PowerAutomateDesktop_8wekyb3d8bbwe\TempState\webextensions\PAD.ChromiumManifest.json

    Also check whether cmd.exe execution is blocked by Group Policy, Intune, or registry restrictions. If it is blocked, the browser can’t launch the native messaging host and the extension can fail.

    If the deployment uses a self-hosted .crx package instead of the Chrome Web Store update URL, verify the web server returns this HTTP header for the .crx file:

    Content-Type: application/x-chrome-extension
    

    On IIS, this is done by adding a MIME type mapping:

    1. Open IIS Manager.
    2. Select the site hosting the extension.
    3. Open MIME Types.
    4. Select Add....
    5. Set File name extension to .crx.
    6. Set MIME type to application/x-chrome-extension.
    7. Select OK, then recycle the site or app pool if needed.

    If the extension package is self-hosted, also validate that the extension manifest.json and update manifest XML are valid. Invalid version formatting or malformed update XML can allow manual install in some cases but still break policy-based install and automatic updates.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.