A place for questions, discussions and knowledge-sharing across all things ChromeOS. Hit 'Subscribe' to stay in the loop.
Recently active
Hi everyone, With more and more work happening directly in the browser, it’s becoming a bigger part of how organisations think about security, access, and user experience. Recent industry research points to this shift quite clearly: Gartner predicts that 25% of organisations will adopt a secure enterprise browser by 2028 as part of their endpoint and remote access strategy. Multiple security reports highlight that most breaches now involve a web or browser-based vector, often tied to unmanaged devices, identities, or access paths. At the same time, work is increasingly distributed — with contractors, hybrid workers, and non-traditional endpoints becoming the norm — which puts even more pressure on browser-level controls. That said, there’s no single right approach and I know teams are at very different stages, so I’m curious to hear how this looks in practice for you: Is browser management something your organisation actively focuses on today, or is it still largely handled elsewher
Hey everyone, In a recent discussion, we talked about how teams are using automatic enrollment to deploy and scale ChromeOS fleets more easily — whether that’s zero-touch for new devices or Flex for existing hardware. That got me thinking about another decision many admins are navigating right now: how they’re thinking about fleet strategy as they plan for 2026. Some organisations prefer a highly standardised fleet, sticking to one vendor or model to keep things predictable — from user experience and support, to lifecycle planning. Others lean towards a multi-vendor approach, mixing devices (and sometimes ChromeOS Flex) to stay flexible on procurement, optimise costs, or extend the life of existing hardware. Both approaches can work well on ChromeOS, but the trade-offs are something to take into consideration. I’d be interested to hear from the community: Do you lean more towards a standardised fleet, a multi-vendor strategy, or a mix of both? What factors te
Hi everyone, AI tools are quickly becoming part of everyday workflows — and with Gemini now integrated into ChromeOS, many IT teams are having to make decisions sooner rather than later. For some organisations, enabling AI features is about boosting productivity and helping users work smarter. For others, questions around data governance, security, user readiness, and change management mean a more cautious approach makes sense. Google has been framing this shift around the idea of the browser becoming an intelligent, secure control point for work — where AI assistance lives closer to the user, but within managed boundaries. On ChromeOS, that shows up through Gemini being embedded into the OS experience, helping with things like summarising content, drafting text, or getting contextual assistance, without stepping outside enterprise controls. I’m curious how people are thinking about this in practice: What’s your current stance on Gemini or AI tools f
Hello, we have observed a regression in location tracking for third party applications after updating ChromeOS on HP Chromebook G1m 11 inch. Device details are ChromeOS version 144.0.7559.108 with previous working version 131.x on the stable channel. After upgrading from version 131 to 144.0.7559.108, third party applications are no longer able to detect or receive location data while Google Maps continues to report the correct location. This behavior was working as expected prior to the OS update, which indicates a possible regression or policy change introduced in ChromeOS 144 affecting third party application access to location services. Thanks Vishal
Our product is for AI security and one of the main challenges we have is how do we make sure the extension will always run even in Incogntio mode.I'm talking about the Chrome browser.There is a flag that seems to be not supported MandatoryExtensionsForIncognitoNavigation while Edge do support this. This is very critical to us and I assume all enterprises that would like to keep Incognito mode but still keep security.If this is no an option can we at least have a formal way to check from command line if an extension is allowed in Incognito mode so we can disable Incognito for these users if our ext isn't allowed?
Hello everybody, We know how important it is for users to quickly access the tools and resources they rely on every day. That’s why I wanted to highlight a recent update that many admins have been asking for. Administrators can now set shortcuts on Chrome’s New Tab Page (NTP) via policy. Using the NTPShortcuts policy, you can curate and prioritise up to 10 organisation-defined shortcuts, which appear alongside any shortcuts users have already set themselves and whose visibility users can still control. This makes it easier to surface key internal tools or web apps, guide users toward essential resources, and create a more consistent, helpful starting point when Chrome is opened — without removing user choice. If you’re curious about the technical details or want to explore how the policy works, you can find more information here. I’d be interested to hear from you: How are you thinking about using managed NTP shortcuts in your organisation? Are there specific internal tools or resour
Hi All,I'm trying to remove completly the option of AI mode in Google chrome.I was able to use these settings. AIModeSettings=1 GenAiDefaultSettings=2 How ever it doesn't remove the AI mode from the Google.com search bar that is inside the page. Any formal way to remove this option?
Have purchased the Trial Chrome upgrade on our existing workspace account. Our backend api failing with below error:Request call: POST https://chromedevicemanagement.googleapis.com/v1/enterprises//devices//devicePolicyerror response:{ "code" : 400, "errors" : [ { "domain" : "global", "message" : "Device does not have CDM API enabled. Enable CDM API for the corresponding OU in Google Admin Console.", "reason" : "failedPrecondition" } ], "message" : "Device does not have CDM API enabled. Enable CDM API for the corresponding OU in Google Admin Console.", "status" : "FAILED_PRECONDITION"}Can you confirm what this error means?As same API works for our paid chrome account, is it an restriction on trial accounts from your end? or we are missing something here?Note: Same client Id and scope is used in Domain-wide delegation setting in admin console.
Hi everyone, Automatic enrollment can be a real game changer when you’re deploying at scale — whether that’s ChromeOS zero-touch enrollment for new devices or ChromeOS Flex remote enrollment for existing fleets. I’d love to hear how it’s been working for you in the real world: What did your rollout look like (drop-ship to users, office-based, hybrid, global)? What’s one tip or best practice you’d share with someone setting up their next automatic enrollment deployment? If you’ve used both ChromeOS zero-touch and ChromeOS Flex, what factors usually influence your decision in practice? If useful, we’ve got a great community guide on ChromeOS enrollment essentials and an informative ChromeOS Flex case study that’s worth a read too! Looking forward to learning from your experiences 👀 Speak soon,Rafa
Hi everyone, I’m writing this to start a discussion about a major bottleneck for the ChromeOS ecosystem: the lack of high-performance hardware for developers.I’ve been a "ChromeOS-first" developer for a while now. I love the security, the simplicity, and how far Crostini (Linux) has come. However, I’ve hit a wall. I am currently using a machine with an **Intel i5, 16GB RAM, and a 1TB SSD**. On any "Consumer" list, this is a top-tier machine. But for professional development—compiling large C++ or Rust projects, running multiple Docker containers, and keeping a heavy IDE open—it is simply **under-dimensioned.** Compilation times are 2x to 3x slower than my peers on high-end macOS or Linux workstations. The Search for the "Unicorn" Chromebox I’ve been searching for a "Workstation Class" Chromebox. My target specs are: * **Processor:** Intel Core i7 (13th/14th Gen) or ideally an i9. * **RAM:** 32GB or 64GB (Crucial for virtualization and containers). * **Storage:** 1TB+ NVMe SSD. If you g
Hi Lynda and the Community, Thank you for the thoughtful response to my previous post regarding the stability of the platform. After reviewing the 2024 blog post, “Building a Faster, Smarter Chromebook Experience with the Best of Google,” I’ve been reflecting on how Google can best navigate its engineering direction while protecting that "robust foundation" we discussed. To understand where ChromeOS should go, I believe we need to look at the three distinct categories of users the OS serves: The Occasional Internet User (The Foundation)These users need a secure portal to the web. ChromeOS already masters this category through the Chrome Browser. It is fast, simple, and the entry point for millions. The Developer (The Strategic Intermediary)This is where the platform shows its true engineering strength. Through Crostini and the Debian VM, ChromeOS is a dream for Linux-experienced users. We can take a relatively affordable Chromebook and turn it into a powerful, dual-purpose mach
Hello Chrome OS Engineering Team,After extensive troubleshooting regarding the "Enable ADB debugging" toggle remaining grayed out on managed devices, I have isolated the root cause. It is not an Admin Policy issue, nor a user error.The issue is a missing dependency in the Google Package Repository for Debian 13 (Trixie), which prevents the installation of cros-guest-tools.Without cros-guest-tools, the Chrome OS Host cannot verify the container's integrity or establish the necessary bridges, leading the OS to lock developer features (ADB) as a security fallback.Here is the technical breakdown and the required fix.1. The EnvironmentHost: Chrome OS (Version 131+)Guest: Debian 13 (Trixie) - Current Stable.Repository Config: /etc/apt/sources.list.d/cros.listdeb https://storage.googleapis.com/cros-packages/142 trixie main2. The ErrorWhen attempting to install or update the integration tools via sudo apt install cros-guest-tools, the package manager fails with a
Hello Chrome OS Enterprise Community and Google Product Team, I am an administrator and developer using a managed Chromebook for Android development. For over a month, I have been unable to toggle "Enable ADB debugging" in the Linux (Crostini) settings because it remains grayed out, despite my having full admin access. After weeks of back-and-forth with Google Workspace Support, it has become clear that this is not just a bug, but a profound architectural issue regarding how managed Chrome OS handles policy dependencies and how we navigate the Admin Console. Technical Environment & Stability ContextIt is important to note that my development environment is not a fresh install, but a long-running, stable workspace. I have been using the same Crostini container for over a year, and recently performed a successful dist-upgrade from Debian 12 (Bookworm) to Debian 13 (Trixie), which is the current Stable release.The fact that Crostini handled this major OS upgrade without
Anyone here using Entra ID for IDP and Chrome Password Notifier for local password sync on ChromeOS? There are some known issues and if anyone is experiencing this issue please let us know. Thanks!
Morning all, I'm a bit stuck with a policy configuration issue - I have a managed device/user where access to websites is strictly controlled and so i have blocked access to URL's unless whitelisted, but its painful keep adding variations of these websites....I have played with the wild card option to allow full access to a URL but cannot get it to work for me. Has anyone successfully used this policy before in the way I have described? Any pointers/tips would be gratefully received.
Hello,There is a distinct difference in how Google manages Android versus Chrome OS, and as a developer, I think it is important to recognize why the Chrome OS strategy is superior for productivity.The Android Approach: Android is a commercial product first. It focuses on features, consumer appeal, and running on everything. The priority is "It works now."The Chrome OS Approach: Chrome OS started small and humble. It has grown slowly, not by chasing trends, but by building a foundation of trust and robustness.I see this robustness daily in the Crostini environment. Recently, upgrading my VM from Debian 12 (Bookworm) to Debian 13 (Trixie) was a pleasure—a real upgrade requiring no reinstallation. This level of stability is rare in the OS world. It proves that Chrome OS is engineered with a long-term vision of quality.The RiskThe current rumors about new operating systems or "Android on PC" threaten to undermine this stability. If Google tries to make Chrome OS behave
Our organization uses PaperCut MF and PaperCut Mobility Print as our Print to MFP solution (with a virtual hold / release queue) for all of our end users. While a small number of Staff still use a Windows PC, a vast majority of Teachers and Students have been migrated over to managed Chromebooks as their daily driver device. While Mobility Print does well to support simple print jobs from a Chromebook, our users are frustrated with their inability to select / adjust more advanced finishing Settings, such as staple and hole punch. As I understand it, the lack of MFP-specific (non-generic) print driver support on Chrome OS compared to Windows or Mac is to blame for the lack of additional print / finishing functionality, and there isn't currently much of anything our organization can do to make the Chromebook print experience better for our users at this time. With that being said, as part of the IT Team for our organization, I wanted to reach out here to Google Suppor
Hi folks, This post relates to a recent change in the DnsOverHttpsTemplatesWithIdentifiers setting, which appears to no longer allow for plaintext variables to be passed to the DNS-over-HTTPS resolver, and everything is now forcibly hashed, with no ability to turn this off and restore original behavior. While I understand the reason for this, when it comes to public DNS resolvers, this change now poses a major hindrance to end users who use private DNS resolvers, and WANT to pass plaintext identifying information (USER_EMAIL specifically) to the DNS-over-HTTPS resolver, so they can see who is responsible for the DNS traffic on the other end, in the Analytics and DNS logs that are streamed into the SIEM. Considering DNS payload is already encrypted (DOH is used) and the org admin wants to see the plaintext identifiers, this poses a major UX issue since now they cannot correlate activity easily, and requires creation of mapping files, and constant need to sync
Hi all, In talks with a customer recently about cost-effective, Chromebook-compatible, web-based PDF solutions and they mentioned www.foxit.com Just wondered if any other customers had experience with this solution and could share their experience? Thanks!
Calling all IT Admins! Your voice is our most powerful tool for improvement. We are currently running our bi-annual ChromeOS Admin Survey, and we need your insights to help us prioritize the features and fixes that matter most to your organization. This is your direct line to our Product Managers to tell us what’s working and where we can do better. How to Participate It’s easy! The next time you log in to manage your fleet, look for the survey announcement banner within the ChromeOS section of the Google Admin Console. Global Access: The survey is available in 6 languages. Quick Impact: It only takes a few minutes to complete. Proven Results: Previous feedback from this community has directly influenced our product roadmap and helped us double our engagement efforts. Why Your Input Matters We want to ensure we are hearing from a diverse range of global perspectives. Whether you manage 10 devices or 10,000, your experience is vital to making
I'm really interested in adopting this for our business but am wondering how many businesses in this group have already adopted it but more importantly what are the top two/three security benefits or productivity gains being realised that justify the monthly cost.
At some point of the company, i may plan to have my own cloud, is that something I can negotiate with google? I don't intend to take all cloud, but at least for the clients that utilizes my X8 Synergy System.
We are testing the ephemeral mode functionality on Chromebooks and have observed an unexpected behavior. On devices with ephemeral mode enabled, the Chrome browser automatically launches immediately after the desktop loads. This auto-launch then initiates the extension installation process for the user profile. This automatic launch does not occur on a standard Chromebook (not in ephemeral mode), where Chrome remains closed upon login. The current behavior on ephemeral devices is problematic because the spontaneous Chrome launch creates a race condition that disrupts some of our device automation processes. Trying to see if there is a policy that can be set to explicitly prevent Chrome from auto-launching upon login in ephemeral mode. Thanks
I didn't mind when Chrome added archived tabs. I had recipes and things I was going to buy in there. suddenly they've all disappeared without warning. Google did not announce that it would be deleting tabs after 3 months or else I would have took action.Please give me my tabs back....
This issue was documented in 2021 but with no solution.My Chromebook is managed by my company and I am the manager.But Google tries to find the managed option to unlock for this to work in the administration interface for more than 15 days without success.By the way there are thousands of options in the admin interface it could be a clever feature to number them.If you are in front of the same issue please add your comments to this post.I hope that Google support will succeed to solve the issue soon because I developed my first app for Android on my Chromebook with Android Studio and I was able to download it to my phone before these 15 days.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.