A place for questions, discussions and knowledge-sharing across all things ChromeOS. Hit 'Subscribe' to stay in the loop.
Recently active
Hello Chrome OS Enterprise Community and Google Product Team, I am an administrator and developer using a managed Chromebook for Android development. For over a month, I have been unable to toggle "Enable ADB debugging" in the Linux (Crostini) settings because it remains grayed out, despite my having full admin access. After weeks of back-and-forth with Google Workspace Support, it has become clear that this is not just a bug, but a profound architectural issue regarding how managed Chrome OS handles policy dependencies and how we navigate the Admin Console. Technical Environment & Stability ContextIt is important to note that my development environment is not a fresh install, but a long-running, stable workspace. I have been using the same Crostini container for over a year, and recently performed a successful dist-upgrade from Debian 12 (Bookworm) to Debian 13 (Trixie), which is the current Stable release.The fact that Crostini handled this major OS upgrade without
Anyone here using Entra ID for IDP and Chrome Password Notifier for local password sync on ChromeOS? There are some known issues and if anyone is experiencing this issue please let us know. Thanks!
Morning all, I'm a bit stuck with a policy configuration issue - I have a managed device/user where access to websites is strictly controlled and so i have blocked access to URL's unless whitelisted, but its painful keep adding variations of these websites....I have played with the wild card option to allow full access to a URL but cannot get it to work for me. Has anyone successfully used this policy before in the way I have described? Any pointers/tips would be gratefully received.
Hello,There is a distinct difference in how Google manages Android versus Chrome OS, and as a developer, I think it is important to recognize why the Chrome OS strategy is superior for productivity.The Android Approach: Android is a commercial product first. It focuses on features, consumer appeal, and running on everything. The priority is "It works now."The Chrome OS Approach: Chrome OS started small and humble. It has grown slowly, not by chasing trends, but by building a foundation of trust and robustness.I see this robustness daily in the Crostini environment. Recently, upgrading my VM from Debian 12 (Bookworm) to Debian 13 (Trixie) was a pleasure—a real upgrade requiring no reinstallation. This level of stability is rare in the OS world. It proves that Chrome OS is engineered with a long-term vision of quality.The RiskThe current rumors about new operating systems or "Android on PC" threaten to undermine this stability. If Google tries to make Chrome OS behave
Our organization uses PaperCut MF and PaperCut Mobility Print as our Print to MFP solution (with a virtual hold / release queue) for all of our end users. While a small number of Staff still use a Windows PC, a vast majority of Teachers and Students have been migrated over to managed Chromebooks as their daily driver device. While Mobility Print does well to support simple print jobs from a Chromebook, our users are frustrated with their inability to select / adjust more advanced finishing Settings, such as staple and hole punch. As I understand it, the lack of MFP-specific (non-generic) print driver support on Chrome OS compared to Windows or Mac is to blame for the lack of additional print / finishing functionality, and there isn't currently much of anything our organization can do to make the Chromebook print experience better for our users at this time. With that being said, as part of the IT Team for our organization, I wanted to reach out here to Google Suppor
Hi folks, This post relates to a recent change in the DnsOverHttpsTemplatesWithIdentifiers setting, which appears to no longer allow for plaintext variables to be passed to the DNS-over-HTTPS resolver, and everything is now forcibly hashed, with no ability to turn this off and restore original behavior. While I understand the reason for this, when it comes to public DNS resolvers, this change now poses a major hindrance to end users who use private DNS resolvers, and WANT to pass plaintext identifying information (USER_EMAIL specifically) to the DNS-over-HTTPS resolver, so they can see who is responsible for the DNS traffic on the other end, in the Analytics and DNS logs that are streamed into the SIEM. Considering DNS payload is already encrypted (DOH is used) and the org admin wants to see the plaintext identifiers, this poses a major UX issue since now they cannot correlate activity easily, and requires creation of mapping files, and constant need to sync
Hi all, In talks with a customer recently about cost-effective, Chromebook-compatible, web-based PDF solutions and they mentioned www.foxit.com Just wondered if any other customers had experience with this solution and could share their experience? Thanks!
Calling all IT Admins! Your voice is our most powerful tool for improvement. We are currently running our bi-annual ChromeOS Admin Survey, and we need your insights to help us prioritize the features and fixes that matter most to your organization. This is your direct line to our Product Managers to tell us what’s working and where we can do better. How to Participate It’s easy! The next time you log in to manage your fleet, look for the survey announcement banner within the ChromeOS section of the Google Admin Console. Global Access: The survey is available in 6 languages. Quick Impact: It only takes a few minutes to complete. Proven Results: Previous feedback from this community has directly influenced our product roadmap and helped us double our engagement efforts. Why Your Input Matters We want to ensure we are hearing from a diverse range of global perspectives. Whether you manage 10 devices or 10,000, your experience is vital to making
I'm really interested in adopting this for our business but am wondering how many businesses in this group have already adopted it but more importantly what are the top two/three security benefits or productivity gains being realised that justify the monthly cost.
At some point of the company, i may plan to have my own cloud, is that something I can negotiate with google? I don't intend to take all cloud, but at least for the clients that utilizes my X8 Synergy System.
We are testing the ephemeral mode functionality on Chromebooks and have observed an unexpected behavior. On devices with ephemeral mode enabled, the Chrome browser automatically launches immediately after the desktop loads. This auto-launch then initiates the extension installation process for the user profile. This automatic launch does not occur on a standard Chromebook (not in ephemeral mode), where Chrome remains closed upon login. The current behavior on ephemeral devices is problematic because the spontaneous Chrome launch creates a race condition that disrupts some of our device automation processes. Trying to see if there is a policy that can be set to explicitly prevent Chrome from auto-launching upon login in ephemeral mode. Thanks
I didn't mind when Chrome added archived tabs. I had recipes and things I was going to buy in there. suddenly they've all disappeared without warning. Google did not announce that it would be deleting tabs after 3 months or else I would have took action.Please give me my tabs back....
This issue was documented in 2021 but with no solution.My Chromebook is managed by my company and I am the manager.But Google tries to find the managed option to unlock for this to work in the administration interface for more than 15 days without success.By the way there are thousands of options in the admin interface it could be a clever feature to number them.If you are in front of the same issue please add your comments to this post.I hope that Google support will succeed to solve the issue soon because I developed my first app for Android on my Chromebook with Android Studio and I was able to download it to my phone before these 15 days.
We are excited to announce an opportunity to join a new Trusted Tester program for a feature coming to ChromeOS that will help administrators manage device licensing more effectively: Device Enrollment Limits. What is the Feature? Currently, there is no easy way to prevent one team or organizational unit (OU) from consuming too many device licenses, which can leave other parts of your organization short.The ChromeOS TT for Device Enrollment Limits is designed to give you, as an administrator, more control over license consumption within your OUs. This pre-General Availability (GA) pilot will allow you to: Set specific enrollment limits per OU. Ensure fair access to licenses across your organization. Optimize resource allocation and prevent overconsumption. Once you request to be part of the TT (more details below) and we set you up for it, you'll find and manage this feature in the Google Admin Console under Devices > Chrome > Reports.For more information, head on over to our Pro
Hello, I am wondering if there is any way to re-enroll a unit automatically after it's been deprovisioned from the Google Admin console. I believe the answer is no, but I would like to confirm, as this would save time if possible. I would also like to know if the answer is the same for units that used zero-touch enrollment. Thank you!
I've never had chrome os before is it anything different then any of the other versions
Hey ChromeOS Community, We are excited to announce two exclusive, invitation-only Chrome Summit events coming up in the next two months for IT professionals in North America and EMEA. Join us to get an exclusive preview of our latest innovations, connect with IT leaders, and experience hands-on demos focused on how Google is delivering connected work experiences with AI at the core, built on a secure, silicon-to-services stack. North America Location: New York City Date: November 12, 2025 Register here: Chrome Summit NYC 2025 EMEA Location: Paris Date: December 11, 2025 Register here: Chrome Summit EMEA 2025 Note: All registrations will be reviewed and approved accordingly based upon certain criteria. We hope to see you there!
This has worked in the past... years ago. Our domain is having an issue regarding Locked Mode in Google Forms (Quiz). The form acts as it is supposed to, popup when the student tries to open the quiz more than once using a Chromebook, however... Emails are never sent to teacher. I have checked the Google Email log. The emails are not being marked as SPAM or not making it to the INBOX. It is like the emails are never being generated. I have had multiple tickets open with Google and no resolution.Any help is appreciated.
Hi everyone, I’m hoping to get some clarification on the differences between Google Workspace Context-Aware Access (CAA) and Chrome Enterprise Premium Context-Aware Access. From what I understand, both allow conditional access controls based on user, device, and context, but I’m not fully clear on where the separation lies between them. For example:Does Workspace CAA mainly govern access to Google Workspace apps like Gmail and Drive, while Chrome Enterprise Premium CAA extends those controls to managed browsers and web apps?How do policy management and enforcement differ between the two?Are there separate admin configurations, or do they integrate within the same console?I also noticed that Context-Aware Access now supports OIDC, and that CAA for OIDC apps can be configured at the OU level. Does this capability apply to both Workspace and Chrome Enterprise CAA, or is it specific to one of them?If anyone has experience managing both solutions — or can share any official docume
Since my Chromebook updated to Chrome OS, I am unable to download apps onto my device immediately; I get a message saying that "your app will download soon" and then nothing downloads. This is causing major issues with using my Chromebook. How do I resolve this?
On Wed 1st October we held an essential session on Secure your business continuity with Google focusing on Google Lifeboat - a combination of existing Google products that can help organizations maintain operational resilience and secure communication during a cyber breach. Cyber incidents like ransomware attacks and phishing are increasing in complexity and cost. Our speakers, Dean Paterek and Matt Stevens, highlighted how Google Lifeboat and its component products provide a robust, pre-planned strategy to defend against these threats and swiftly recover when they occur. The Four Core Pillars of Google Lifeboat The platform is not a one-size-fits-all product but a configurable solution built around four core components: Mandiant Incident Response Retainer What it is: A proactive agreement that provides an SLA (Service Level Agreement) for rapid incident response from Mandiant's global team of experts. Key Benefit: It provides pre-paid funds that can
What does 3x faster login speed mean to your business? Read how TELUS, a communications technology company, transformed their digital Workspace.For TELUS, it meant empowering their 60,000+ team members to be more productive and serve customers better. By switching to ChromeOS, TELUS gets quick access to the tools they need, transforming their call center efficiency and employee satisfaction. Speed isn’t a feature, it’s a foundation for growth. Read the full story here.
Hello, After my ChromeOS device updated on September 25, 2025 (though not certain this is the direct cause), custom protocol handlers (web+collab:// and collab://) for my Isolated Web App (IWA) stopped working. Triggering these links in Chrome no longer launches the app—they simply do nothing. This was functional until two days ago. App Type: Isolated Web App (IWA) Manifest excerpt: { "name": "someapp", "id": "/", "short_name": "some-app", "version": "0.1.0", "update_manifest_url": "https://github.com/--some-repo--/iwa-release/releases/latest/download/update.json", "icons": [ { "src": "/192x192.png", "sizes": "192x192", "type": "image/png", "purpose": "any maskable" }, { "src": "/144x144.png", "sizes": "144x144", "type": "image/png", "purpose": "any maskable" } ], "start_url": "/", "scope": "/", "display": "standalone", "display_override": ["borderless"], "background_color": "#ffffff", "theme_color": "#3B82F6", "isolated_storage": true, "per
This month, we hosted our first, dedicated ChromeOS Enterprise Upgrade onboarding webinar led by @Emiliano from the ChromeOS team to help new IT admins. The session focused on essential, step-by-step actions within the Google Admin Console to quickly set up, manage, and secure their Chromebook fleet. The workshop covered the critical foundational steps for IT teams: Intro to the Admin Console We covered off some of the first tasks to be completed and got familiar with the management interface. Domain Verification We walked through this critical requirement to unlock advanced identity and management features. Organizational Units (OUs) Learn to create OUs for devices and users, which is the key to applying unique policies based on location, role, or use case. User & Device Enrollment Best practises for adding new devices and users to OUs. App Deployment & Management Admins learned how to centrally manage applications. Policy Configuration The platform separates policies into t
Hello, We currently manage a growing fleet of ChromeOS devices (Chromebooks and Chromeboxes) through our Google Workspace domain. All devices are enrolled, updated to the latest ChromeOS version, and centrally configured via the Admin Console. Our VPN of choice is WireGuard, which ChromeOS now supports natively. We followed Google’s official documentation to configure WireGuard per user: Configure VPNs on ChromeOS (Google Support) The challenge we are running into is scalability: configuring WireGuard individually on a per-user basis is becoming increasingly tedious as our organization grows. Ideally, we would like to achieve one of the following: - System-wide tunnel setup - Assign a WireGuard key per device, rather than per user. This would allow the VPN configuration to apply regardless of who logs into the machine.- Admin Console integration - Ability to push or preconfigure WireGuard VPN settings (similar to how Wi-Fi networks or other VPN types can b
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.