Manage app permissions and sources
Other Settings applies broad controls to apps and extensions in an organisational unit. A restrictive value can block installation or break already deployed extensions, so test changes separately from app deployment.
Open Other Settings
- Open Business+ → Apps & Extensions.
- Select Users & Browsers.
- Select a pilot organisational unit.
- Click Other Settings.
- Review inheritance and Updated setting entries before saving.
Configure allow/block mode
The console provides separate modes for Chromium extensions and Android apps. Common models are:
- Block all apps and manage an allowlist.
- Allow all apps and manage a blocklist.
Choose allowlist-first for tightly controlled devices. Before switching an existing unit, inventory required apps, background extensions, identity providers, VPN extensions, certificate providers, and support tools.
Restrict app types and sources
Allowed types of apps and extensions includes types such as extensions, themes, user scripts, hosted apps, legacy packaged apps, and Chrome packaged apps.
App and extension install sources accepts source URL patterns, one per line. Add only trusted distribution origins. The page also controls insecurely packaged and external extensions.
Restrict permissions
The permission list includes sensitive capabilities such as:
- Audio, video, desktop, and document capture.
- Clipboard read and write.
- Native messaging.
- File system, USB, HID, serial, and storage.
- Proxy and VPN provider.
- Geolocation, identity, notifications, and web request access.
- Enterprise device attributes and platform keys.
Blocking a permission can disable an extension that already depends on it. Record the app owner and business reason for every exception.
Protect runtime hosts
- Runtime blocked hosts prevents extensions from interacting with matching hosts, including script injection, cookies, and web request modification.
- Runtime allowed hosts creates explicit exceptions.
- The current console accepts up to 100 URL patterns in each runtime host list.
Use runtime host blocking to protect identity, payroll, finance, and admin sites from broad extension access. Test every required extension on protected sites.
Verify and roll back
- Save one related group of changes.
- Sign in on a pilot device.
- Verify installation, launch, sign-in, updates, background operation, and protected-site behaviour.
- Review the app list for unexpected Block or force-install results.
- If an app breaks, use Revert before saving or restore the previous local values after saving.
- Expand only after the pilot completes normal work.
What's next
- Manage apps and extensions, choose the target and installation mode.
- Configure user policies, apply related browser settings.