Classroom GuardianDeployment Center

Google Admin installation guide

Deploy Classroom Guardian to managed Chrome users.

Create the school release, add it by ID and custom update URL, force-install it for the correct organizational unit, and verify one managed device.

About 10 minutes Google administrator required ChromeOS, Windows, macOS + Linux
The tutorial images are redacted.

Organization names, account markers, extension IDs, and school-specific identifiers have been removed. Always copy the values from your own school’s Release panel.

1

Classroom Guardian

Create the school release

In the school dashboard, open Extension deployment. Optionally enable the custom blocked page, then select Create release.

Copy Extension IDCopy Update URLKeep this tab open
2

Google Admin

Open Apps & extensions and select the correct users

Sign in to the Google Admin console with an administrator account. Go to Devices → Chrome → Apps & extensions → Users & browsers. If your organization uses Chrome Enterprise Core, the starting menu may be Chrome browser.

Select the organizational unit that contains the students who should receive Classroom Guardian. Start with a limited school-approved group when validating a new deployment.

Google Admin Apps and Extensions page with the organizational unit name and account marker redacted
Select Users & browsers, then choose the intended student organizational unit.
3

Add the extension

Open the yellow Add menu

Select the yellow + button in the lower-right corner, then choose Add Chrome app or extension by ID.

Google Admin yellow add menu expanded
The available icons can vary as Google updates the Admin console.
4

Release values

Add it from a custom URL

Choose From a custom URL. Paste the 32-character Extension ID and the HTTPS Update URL from your school’s Classroom Guardian Release panel. Then select Save.

Do not copy values from a screenshot.Every school release has its own ID and fixed update URL.
Google Admin Add Chrome app or extension by ID dialog with From a custom URL selected
Select From a custom URL before entering the school’s release values.
5

Installation policy

Set the extension to Force install

Open the newly added extension. Under Installation policy, choose Force install. This installs Classroom Guardian for users in the selected organizational unit and prevents them from removing it.

Google Admin extension settings with extension IDs and organization name redacted and Force install selected
The screenshot’s extension identifiers are intentionally covered.
6

Required setting

Enable Allow access to file URLs

In the extension settings, scroll to File URLs and turn on Allow access to file URLs. This is required for supported local-file navigation and the managed blocked-page workflow.

Google Admin Allow access to file URLs toggle switched on
The switch should be on and locally applied for the selected organizational unit.
7

Recommended security setting

Restrict developer tools for force-installed extensions

Go to Devices → Chrome → Settings → Users & browsers, select the same student organizational unit, and search for Developer tools.

Set Developer tools availability to Allow use of built-in developer tools except for force-installed extensions and component extensions. Set Extensions page developer mode to Do not allow use of developer tools on extensions page, then save.

To block Chrome’s offline dinosaur game, search for Allow Dinosaur Easter Egg, set it to Do not allow users to play the dinosaur easter egg game, and save. Classroom Guardian blocks supported Google Search and Google Doodle games when the school Games category is blocked; the managed Chrome policy covers the protected chrome:// offline page that extensions cannot access.

Apply this to student users, not school developers.This keeps ordinary webpage developer tools available while protecting enterprise-installed extensions. Schools may choose a stricter policy for younger students.
Google Admin Developer tools policy with organization name and account marker redacted
The organization name and administrator account marker are intentionally covered.
8

Validation

Save, reload policy, and verify one device

Select Save in Google Admin. On one managed test device, open chrome://policy, choose Reload policies, and confirm that the extension appears in chrome://extensions as managed by the organization.

If Extension Install Policies says “No policies set,” the Google policy has not reached that Chrome profile.Confirm the test user is signed into Chrome with the managed school account, the account belongs to the organizational unit selected in Apps & extensions, and chrome://management says the browser or profile is managed. Then reload policies and restart Chrome. A personal Gmail profile or an unmanaged browser will not receive the force-install rule.
Windows: “Current user / OK” confirms delivery, but not machine enrollment.For the self-hosted Classroom Guardian CRX, deploy the generated Windows Chrome policy from the school Release panel as an administrator, or enroll the browser/device through the school’s supported Windows management system. Afterward, ExtensionInstallForcelist should also be present as a machine/platform policy. A user-only cloud policy can appear valid while Chrome still declines the off-store package.

The message Version pinning is not supported for this Chrome app or extension is expected for this self-hosted release. It does not prevent Force install or Force install + pin from installing the extension.

  • The Classroom Guardian extension is installed and cannot be removed by the student.
  • The extension version matches the current Release version.
  • The device appears in Classroom Guardian and reports a recent heartbeat.
  • A school-approved test rule reaches the device and behaves as expected.
Deployment completeAfter the validation device succeeds, expand the policy to the approved student organizational units.

Google documentation

Review the platform owner’s instructions.

Google’s interface and labels can change. These official pages explain force installation, organizational-unit scope, and self-hosted extension update locations.