Skip to main content
tkjkwmot00
New Member
July 26, 2026
Question

ProvisionManagedClientCertificateForUser is not available in Admin console for Chrome on iOS

  • July 26, 2026
  • 1 reply
  • 52 views

Hello,

I am trying to configure managed client certificate support for Chrome on iOS using Chrome Enterprise Core.

My environment is:

  • Chrome Enterprise Core is enabled

  • Chrome for iOS version 151.0

  • “Apply supported user settings to Chrome on iOS” is enabled

  • The user is signed in to Chrome with a managed Google Workspace account

  • I am checking: Devices → Chrome → Settings → User & browser settings

According to the Chrome Enterprise policy documentation, ProvisionManagedClientCertificateForUser supports Chrome on iOS and iPadOS starting with version 147.

The Chrome Enterprise release notes also state that administrators should configure the following policies:

  • ProvisionManagedClientCertificateForUser

  • ProvisionManagedClientCertificateForBrowser

  • AutoSelectCertificateForUrls

However, ProvisionManagedClientCertificateForUser and ProvisionManagedClientCertificateForBrowser do not appear in the Google Admin console. I searched using both the English policy names and the localized policy descriptions. I also cleared all filters and checked the recently added settings.

I confirmed the same behavior in more than one Google Workspace tenant.

Could someone please clarify the following?

  1. Has managed client certificate support for Chrome on iOS been generally rolled out?

  2. Is this feature limited to selected tenants or Trusted Tester participants?

  3. Is Chrome Enterprise Premium or another license required?

  4. Are there additional prerequisites before these policies appear in the Admin console?

  5. Can Microsoft Cloud PKI, Intune SCEP, or an on-premises CA be used as the certificate authority?

  6. Is there an official end-to-end configuration guide for this feature?

Official policy reference:
https://chromeenterprise.google/policies/provision-managed-client-certificate-for-user/

Chrome Enterprise release notes:
https://support.google.com/chrome/a/answer/7679408?hl=en

Thank you.

1 reply

nicolas
Google Team
July 27, 2026

Hi, Indeed ProvisionManagedClientCertificateForUser and ProvisionManagedClientCertificateForBrowser are not visible in the Admin Console, however, those policies are used for internal feature availability control so that we could oversee the provisioning based on the supported platforms. In short, these policies are set automatically when the server detects a policy fetch request from a platform that supports Client Certificates; there is no need to set them manually.

So it is fully launched and you don’t need to be part of a TT. You don’t need a CEP license. CEC is required. 

 

You will still need to configure the AutoSelectCertificateForUrls policy which you can find under Chrome Browser>Settings>Users and browsers>Client Certificates. 

 

So if your configuration is correct, you should automatically see these policies in the chrome://policy tab on your iOS device.  

 

You can find a guide for deployment here: https://support.google.com/chrome/a/answer/15223546?hl=en&visit_id=639195324626494204-1742868458&p=managed_profile_client_certificate&rd=1#zippy=

 

I hope this helps.