# Installing Browser Extensions for Windows via Group Policy

If your organization controls Browser Extensions via Group Policy, ThousandEyes recommends you to deploy and manage the Browser Extensions via the Group policy instructions explained below and do not install the extension via the MSI installer. For organizations not controlling browser extensions via GPO, you can use these instructions to force the enablement of a Browser Extension that was installed via the MSI.

## Microsoft Edge via GPO

{% hint style="info" %}
These instructions guide you on the settings to force the enablement of the browser extensions. You must install the base [MSI](https://docs.thousandeyes.com/product-documentation/global-vantage-points/endpoint-agents/installing/install-endpoint-agent-for-windows-via-group-policy#msi-installer-via-gpo) in addition to these instructions.
{% endhint %}

To Control the Microsoft Edge Browser Extension you must have the Microsoft Edge GPO Policy Templates installed. You can download them from the [Edge Business Page](https://www.microsoft.com/en-us/edge/business/download?form=MA13FJ) and subsequently follow the instructions outlined [here](https://learn.microsoft.com/en-us/DeployEdge/configure-microsoft-edge).

1. Open up Group Policy Management.
2. Create a group policy with the appropriate name. In this example, we will name it **TE-Endpoint-Agent\_Edge**.

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-6cb0dc7e5f86c70a0fef1da736bb16f2098dc97f%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-16.png?alt=media\&token=e59c2bdd-f521-4267-bc63-911a3bca7902)
3. Right click the newly created GPO and select **Edit**
4. With the object open, navigate to the following: `Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Extensions`
5. Right click, and choose **Edit** on the **Control which extensions are installed silently**.

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-5e8cedb2e4170d29692b9beae638f86d4af45ded%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-17.png?alt=media\&token=1ca79079-dad9-4340-8508-e552da1c5e39)
6. Enable this setting.
7. In the options section, choose the **Show** button.

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-a4065e64bf46f2d39c8b9c4d3f2aaf39d6c7a9e7%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-18.png?alt=media\&token=cae8f4ed-0d0a-49fb-a00a-c6a4eab144c5)
8. In the **Value** field, add the following CSLID: `obdencanbejmhpbikpcgkdflkffifoof`
9. Click **OK** to close the Add-On List window.
10. Click **Ok** again to close the Configuration for Add-On List window
11. Assign the group policy to a specific Organizational Unit (OU).
12. Right click the group policy under the OU you have assigned it - Click Enabled
13. Right click the group policy again, and click enforced.

## Google Chrome via GPO

1. Download the ADM/ADMX templates from Google using this link: <https://dl.google.com/dl/edgedl/chrome/policy/policy_templates.zip>
2. Open Group Policy Management
3. Expand Group Policy Objects
4. Right-click Group Policy Objects and select New
5. Provide a name for your new Group Policy Object (GPO)
6. Right-click your newly created GPO and select Edit
7. Expand Computer Configuration, expand Policies, right-click Administrative Templates and click Add/Remove Templates

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-bbc7da023488e28bcc17f677963d5cb1cf805b04%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-8.png?alt=media\&token=4326f5a0-8c3d-4dab-809e-c236bdca4439)
8. Select Add in the new dialog window

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-a37ee36018b57fbbc19261629dd82cb11de4a588%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-9.png?alt=media\&token=ade316b2-9656-42f0-ad5e-532729858544)
9. Navigate to a network share where the policy template resides, and select the **chrome.adm** file listed here **policy\_templates/windows/adm/en-US/chrome.adm1**

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-66fa1e01a0b6d1d23371d0b57f1f23e31df20e24%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-10.png?alt=media\&token=ab5ff25d-eac2-4796-b77a-d890e3a315ac)
10. Click Close
11. Expand Classic Administrative Templates (ADM), select Google Chrome and subsequently Extensions

    ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-816b1a940581e8cc3e8ffea91015365f6202a4da%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-11.png?alt=media\&token=fd78d788-8067-4024-b3de-86bfd6524bd2)
12. Open the Configure the list of force-installed extensions policy and select Enabled
13. Click Show
14. Paste the following into value: ddnennmeinlkhkmajmmfaojcnpddnpgb;<http://clients2.google.com/service/update2/crx>

    ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-c6ed8f0530bef4156dc3eb58b2ecfe864df3e698%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-12.png?alt=media\&token=148caea0-1dfe-4fdd-988c-4a08650e4202)
15. Select Ok and close the Group Policy Management Editor
16. Select the organizational unit that you would like to apply the GPO to. Right-click the OU and select Link an Existing GPO

    ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-7f8067b67c3378295d5fe944142ff36843a58923%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-13.png?alt=media\&token=919a2c71-71f5-4cb7-a4ea-ff293d2e8f8b) ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-36f6e512b5adca6713b7f8ac10cda94a089a624c%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-14.png?alt=media\&token=3420aa18-de56-4401-9d61-b53d63424103)
17. Right-click the newly created linked GPO and select Enforced

    ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-0608670283c25e31a53df709390d012eed0d7c14%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-15.png?alt=media\&token=05227a69-4e41-4dc5-bf7c-8081ef549e27)
18. Wait 15 minutes for the group policy objects to sync across servers, or manually sync the Active Directory Servers through Sites and Services
19. Test end-user machine by running gpupdate.exe

## IE Add-on via GPO

{% hint style="info" %}
With the Internet Explorer in end-of-life phase, the IE Browser Extension can only be used in a limited capacity in Edge browser in the IE Edge Mode.
{% endhint %}

1. Open up Group Policy Management
2. Create a group policy with the appropriate name. In this example, we will use “TE-Endpoint-Agent\_IE”

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-4d41950e177488f7ff47886b2a9b1809ccd516b0%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-4.png?alt=media\&token=6f0d2203-a750-4dc2-95c8-42b54704aef5)
3. Right click the newly created GPO and select Edit
4. With the object open, navigate to the following: Computer Configuration\Policies\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management
5. Double-click “Add-On List”
6. Click Enable

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-f2c9bc77e73d668f182cd9e2d243d21648260cbd%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-5.png?alt=media\&token=c55c015e-21be-4c79-b085-93fe3767fdf7)
7. Click Show

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-dc276f7d4883a603066e11dd98b8399eee3d25cf%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-6.png?alt=media\&token=b65ef33f-adbe-4539-a234-53c5e0aa5c14)
8. In the new window, under “Value Name” add the CLSID for the ThousandEyes Endpoint Agent for IE. The current CSLID is: E1F5283B-B591-412E-8E2F-4C65A9C94AF1
9. The Value number is dependant on how you would like users to be able to interact with the Add-On. The current value options are:\
   0 - The add-on is disabled and your employees can’t change it.\
   1 - The add-on is enabled and your employees can’t change it.\
   2 - The add-on is enabled and your employees can change it.

   ![](https://1112912342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M4QARF6s57qxMrOHDTZ%2Fuploads%2Fgit-blob-760b699feec649f010eb7fcedc0eacd9f4b671a4%2Fproduct-documentation_endpoint-agent-installation_installing-endpoint-agent-for-windows-via-group-policy-7.png?alt=media\&token=41013594-7a7f-4337-a33f-263e370919c0)
10. Click Ok to close the Add-On List window
11. Click Ok again to close the Configuration for Add-On List window
12. Assign the GP to a specific OU
13. Right click the GP under the OU you have assigned it - Click Enabled
14. Right click the GP again, and click enforced.
