1 of 35

Workspace Security Policies

Chrome Device Management Security Configurations

Google Workspace

Proprietary + Confidential

2 of 35

Overview

Implementing security best practices for Google Workspace is crucial for protecting sensitive information, complying with regulations, maintaining a good reputation, ensuring school continuity, and saving costs.

The following slides outline the recommended Google Workspace for Education settings to configure within your kura or school. ��We recognise some kura and schools may have particular configurations in place to suit the needs of their particular learning environment. In such cases, we respect that kura and schools may choose not to follow a specific recommendation.��

We’re so glad you’re joining us in updating your

Google Workspace policies.

Proprietary + Confidential

3 of 35

Need Help?

Use the direct link to the Admin Console page to jump straight to the setting.��Refer to the Help Centre Guide for further information

Select the video & join our Google experts who provide a short overview of the setting and answer common questions

Look out for Tips along the way

Tip!

Proprietary + Confidential

4 of 35

Settings

01

02

03

04

Chrome Devices

Apps & Extensions

Chrome Device settings

Chrome User Settings

Proprietary + Confidential

5 of 35

Chrome Devices

Proprietary + Confidential

6 of 35

End of Life Devices

  • Avoid having Auto update expiration (AUE) devices in use

Regularly check your school Chrome devices to ensure your aware of when they will reach the auto update expiration date. Have a plan in place for replacing expired devices.

Proprietary + Confidential

Proprietary + Confidential

7 of 35

Outdated versions of Chrome OS

  • Ensure devices are up to date

Regularly check your devices ChromeOS version, and avoid having devices on old versions of ChromeOS to provide most up to date security, protection and features to your users.

Proprietary + Confidential

Proprietary + Confidential

8 of 35

Apps & Extensions Settings

Proprietary + Confidential

9 of 35

Apps & Extensions Allowlist

School Administrators should block all apps and only allow installation of applications they have approved via the application allowlist.

  • Admin control Chrome apps and extensions

Tip! Enable the ability for users to request extensions

Proprietary + Confidential

Proprietary + Confidential

10 of 35

Android reporting for users and devices

Enable Android app reporting in the Google Admin console, to see if a force-installed app installed correctly on user devices, and which Android apps have been installed.

  • Enable Android reporting

Proprietary + Confidential

Proprietary + Confidential

11 of 35

Chrome Devices Settings

Proprietary + Confidential

12 of 35

Force re-enrolment

Enable device force re-enrolment for school owned devices to ensure when a device is wiped, the device is automatically re-enrolled to the school domain.

  • Enable for school owned devices to force device re-enrolment

Proprietary + Confidential

Proprietary + Confidential

13 of 35

Enable verified access

Enable additional protection of School Data by enforcing devices to require to be run in verified boot mode.

  • Enable for content protection

Proprietary + Confidential

Proprietary + Confidential

14 of 35

Restrict sign-in to domain managed users

For all School owned devices only allow sign in to devices for school users by restricting sign to your School's domain managed users

  • Enable

Tip! User *@yourdomain.org to restrict to domain users only

Proprietary + Confidential

Proprietary + Confidential

15 of 35

Enable automatic updates and Chrome variations

Enable automatic updates for chrome to ensure devices are kept up to date to the latest version of Chrome.

  • Enable

Proprietary + Confidential

Proprietary + Confidential

16 of 35

ChromeOS Updates - Allow reboots and enforce updates

Enable devices to automatically reboot to enforce ChromeOS updates to keep devices up to date automatically.

  • Enable

Proprietary + Confidential

Proprietary + Confidential

17 of 35

Report device OS information

By enabling OS reporting devices send their current OS state information such as OS version, boot mode, and update status.

  • Enable

Proprietary + Confidential

Proprietary + Confidential

18 of 35

Report device user tracking

Track recent users of your School devices by enabling tracking.

  • Enable

Proprietary + Confidential

Proprietary + Confidential

19 of 35

Prevent virtual machines and ADB sideloading

Prevent use of virtual machines to support Linux apps and ADB Sideloading.

  • Block and Prevent

Proprietary + Confidential

Proprietary + Confidential

20 of 35

Chrome User Settings

Proprietary + Confidential

21 of 35

Configure appropriate idle settings

Set idle settings to automatically logout the users or put the device to sleep after 10 minutes of inactivity.

  • Recommended to set to 10 minutes

Proprietary + Confidential

Proprietary + Confidential

22 of 35

Incognito Mode

Disable incognito mode to prevent users from using Chrome Browser in incognito mode.

  • Disallow incognito mode

Proprietary + Confidential

Proprietary + Confidential

23 of 35

SafeSearch and YouTube Restricted Mode

Apply the use of Google SafeSearch and restrict access to restricted Youtube content to protect students

  • Enforce SafeSearch for Google Search and Youtube content access

Proprietary + Confidential

Proprietary + Confidential

24 of 35

Strict treatment for mixed content & control use of insecure content exceptions

Use strict treatment for Chrome browser and ChromeOS devices to treat insecure HTTP audio, video, and image mixed content.

  • Use strict treatment, and do not allow sites to load blockable mixed content

Proprietary + Confidential

Proprietary + Confidential

25 of 35

Signing into secondary accounts

Disable school users from signing into secondary accounts allowing them to switch windows in the browser or Google Play store once they have logged into their device.

  • Block users from signing into secondary accounts

Proprietary + Confidential

Proprietary + Confidential

26 of 35

External storage devices

Disable school users from using external storage devices on School owned Chrome Devices.

  • Prevent use of external storage devices

Proprietary + Confidential

Proprietary + Confidential

27 of 35

Managed browser cloud reporting

Enable managed browser cloud reporting to get automatic browser profile and system information sent to the Google Admin console.

  • Enable

Tip! Force install the Endpoint Verification extension to complete reporting setup

Proprietary + Confidential

Proprietary + Confidential

28 of 35

Safe browsing protection level

Enable Safe Browsing in Chrome to help protect your School users from websites that may contain malware or phishing content.

  • Enable safe browsing

Proprietary + Confidential

Proprietary + Confidential

29 of 35

Download restrictions

Prevents users from downloading dangerous files, such as malware or infected files by blocking all malicious downloads.

  • Block all malicious downloads as minimum

Proprietary + Confidential

Proprietary + Confidential

30 of 35

Password alert for re-use

If School users reuse their password on a website that you didn’t authorize, Chrome sends the URL to Google Safe Browsing to determine its reputation. If the website contains phishing content, users are prompted to change their password.

  • Configure password alert for re-use (on any site, or just identified phishing sites)

Proprietary + Confidential

Proprietary + Confidential

31 of 35

Sites with intrusive ads

Block ads on websites with intrusive ads to provide School users with a better browsing experience.

  • Block ads on sites with intrusive ads

Proprietary + Confidential

Proprietary + Confidential

32 of 35

Relaunch Notification

Force Chrome Browser to relaunch after a specific time when an update has been installed to apply the update.

  • Configure ‘Force relaunch after a period’

Proprietary + Confidential

Proprietary + Confidential

33 of 35

Linux virtual machines

Block School users from Linux virtual machine access.

  • Block Linux VM access unless required

Proprietary + Confidential

Proprietary + Confidential

34 of 35

Need Support?

Feedback

We would love to hear your feedback to hear how you went, and what improvements you would like to see.

Please send any feedback to digital.services@education.govt.nz

  • Contact your managed IT service provider�
  • Reach out to googlesupport@fronde.com (Trusted Google Partner)�
  • Subscribe to The Digital Download newsletter for updates

Proprietary + Confidential

35 of 35

You have completed one module!

Congratulations!

Proprietary + Confidential