Mass Deployment of SmartCloud Connect Chrome Extension for Gmail¶
SCC Chrome Extension for Gmail unfolds most of the SCC Add-In’s and Synchronization features for Gmail / GSuite. The Extension can be installed individually or mass-deployed for all end users by the local system Admin.
This article describes the mass deployment scenario where the local system Admin installs the SCC for Gmail and Salesforce Chrome Extension for all SCC end users in an Org. It is a standard secure Chrome browser extension reviewed by Google, and in the enterprise environment it can be mass-deployed for multiple end users using Microsoft Group Policy mechanisms.
SmartCloud Connect Extension deployment string to be used (fast prod build installation):
The described method to mass-deploy Chrome extensions is through Microsoft Group Policy. As per Google: “For Windows, it is recommended to use Group Policy vs. preferences files because only Group Policy can be enforced”. An identical statement is made in the Chrome Deployment Guide: “Use Windows Group Policies (GPO policies) and cloud policy over preferences when possible. Unlike policies, preferences do not apply to previous installations of Chrome and are only applied to a single profile. Policies also override any preferences settings for a feature. Also note that the master_preferences file can be changed and not enforced like group policies can”.
Google provides official ADM and ADMX files which enable the end users to manage its products. For SCC Extension mass deployment, we recommend you to use the ADMX files only and not the ADM files. Before you can use Microsoft Group Policies to mass-deploy the Extension, you first need to import the Google Chrome ADMX files in your Group Policy Central Store. The ADMX files, as well as the ADM language files, (.ADML) can be found in the directory Configuration\admx* of the extracted Chrome Enterprise Bundle archive.
If you are not familiar with the Central Store for Group Policies and require more detailed information, refer to the official Microsoft article How to create and manage the Central Store for Group Policy Administrative Templates in Windows.
Chrome Enterprise Bundle includes the following six ADMX files:
The purposes of most of these ADMX files are self-explanatory, except for the ADMX file google.admx. This file only has one purpose, which is to set the shared “Google” folder in the Group Policy editor. This folder ensures that all Google policy settings (for the Chrome browser or other Google products) are grouped under one folder.
The Group Policy Central Store is located on your domain controllers.
- The Central Store root path (containing the ADMX files): \\%LogonServer%\sysvol\#DomainName#\Policies\PolicyDefinitions
The ADMX files are put in the root of the Store; the language files (*.ADML), are put in the language-specific subdirectories.
- Central Store subdirectories for the language files: \\%LogonServer%\sysvol\#DomainName#\Policies\PolicyDefinitions\#languagecode-countrycode#
Copy the Chrome ADMX files into this folder:
Copy the English language .ADML files into the en-US folder:
The 2020 updates of SmartCloud Connect also include support for several more languages; make sure to copy non-English ADML files for the supported language(s) you will use into their corresponding directories. The correct directory name for your language can be found in Configuration\admx of the unarchived Chrome Enterprise Bundle.
Now that you have copied all required files, you can start configuring your settings using a Group Policy editor (such as Group Policy Management Console).
In case you do not want to update your Central Store right away, you can first perform some tests by using the local ADMX repository on a server. The local repository of a Windows server is located here: C:\Windows\PolicyDefinitions. Apply the same procedure for copying the ADMX and ADML files as for the Central Store. Use the local Group Policy editor to configure your settings (gpedit.msc).
The future versions of Chrome will feature updated .ADMX and .ADML files included into Chrome Enterprise Bundle. Please remember that your Group Policy settings are not affected when you update the .ADMX files. Your settings are kept in different files within each individual Group Policy itself: Registry.pol contains the Group Policy settings; .xml (e.g. Files.xml*) contains your Group Policy preferences settings.
The path to an individual group policy is as follows: \\%LogonServer%\sysvol\#DomainName#\Policies\#PolicyGUID#
After configuring your Chrome settings you can check if your Chrome policies are applied by entering chrome://policy in Chrome address bar. This will show you all Chrome settings applied for your PC and user.
User settings can be either mandatory or recommended. Mandatory user settings are configured here:
User Configuration \ Administrative Templates \ Google \ Google Chrome
Recommended user settings are configured here:
User Configuration \ Administrative Templates \ Google \ Google Chrome - Default Settings (users can override)
On the local server or client, Chrome’s computer and user policies are stored in the following registry keys:
- HKEY_CURRENT_USER \ SOFTWARE \ Policies \ Google \ Chrome
- HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Google \ Chrome
2. To force-install SCC for Salesforce and Gmail Chrome Extension, open your Group Policy Management Console (dsa.msc) and go to User Configuration > Administrative Templates > Google > Google Chrome > Extensions. Fine the setting Configure the list of force-installed apps and extensions and enable it.
Click Show and enter the string we provided at the beginning of the article into the Value field:
Now the policy setting is configured. On the next Group Policy refresh the users will automatically get the required extension. To summarize, this policy update will mass-deploy the Extension for all users to whom the Group Policy applies. Extension installation is performed silently, without user interaction.
As mentioned above, after the Extension has been mass-deployed, you can see it in the directory on the users’ PCs C:\Users\%UserName%\AppData\Local\Google\Chrome\User Data\Default\Extensions
!!! note “Note” Make sure that Developer mode is disabled on the Extensions tab of users’ Chrome browsers. During the tests, Extensions were not automatically installed with Developer mode enabled.
If you delete the Extension from the Configure the list of force-installed apps and extensions policy setting, the extension is automatically removed from Chrome browser for all users to whom the Group Policy applies.
Future updates of the SCC for Salesforce and Gmail Extension are automatically installed through the update URL specified in the Extension’s manifest file (https://clients2.google.com/service/update2/crx).