2.3.6 Ensure 'Control Manifest v2 extension availability' Is Set to Forced Only

Information

This policy setting controls extension management settings for Google Chrome, specifically v2 extensions. This policy setting is being sunsetted as Google develops the Manifest v3, but that rollout is currently postponed.

The policy can be configured to:

Default (0): Default browser behavior

Disabled (1): Manifest v2 is disabled

Enabled (2): Manifest v2 is enabled

Forced Only (3): Manifest v2 is enabled for forced extensions only

Rationale:

Setting this to Forced Only will not allow users to install any additional v2 extensions, and all existing, non-forced, v2 extensions will be disabled.

Impact:

Users that use extensions regularly will have a set of them blocked, which will change their user experience.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Manifest v2 is enabled for forced extensions only:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Extensions\Control Manifest v2 extension availability

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|9.4

Plugin: Windows

Control ID: e9a3a8a346f9cf654fb91a23a62b6ac7e4c3983757c0042cea68c9f5522483af