DLP Agent Chrome and Edge browser extension management
search cancel

DLP Agent Chrome and Edge browser extension management

book

Article ID: 204478

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent Data Loss Prevention

Issue/Introduction

Google Chrome and Microsoft Edge Chromium utilize a browser extension to report the current tab's URL to the DLP Agent (via the Native Messaging Host - brkrprcs64.exe to edpa.exe). The URL is needed when processing policies to understand the destination and to report the URL on incidents. The extension is not installed until after the respective browser has been launched with the extension reference in place.

Important: Chrome extension for DLP Agents 15.8 and newer also actively takes part in detection process (as the detection capabilities were moved there), that's why "Chrome extension not deployed" appears as Agent critical state where "Edge extension not deployed" appears as Agent warning state.

For Chrome extension on Mac search, please refer to the TechDoc Enable Monitoring in Google Chrome on macOS Endpoints

For Edge extension on Mac in DLP 26.1, please see Deploy the Symantec extension to monitor Edge

The Symantec Extension registry value/data information is as follows:

Chrome for Windows

Symantec Extension - DLP 15.8 and above

(https://chrome.google.com/webstore/detail/symantec-extension/dehobbhellcfbmcaeppgfjhnldeimdph)

Registry Type/Data/Value (the value could change, depending on whether there are already any other local extension policies in place):

 

Type: REG_SZ

Value: 1

Data: dehobbhellcfbmcaeppgfjhnldeimdph;https://clients2.google.com/service/update2/crx

 

Edge for Windows

Symantec Extension - All DLP Versions

(https://microsoftedge.microsoft.com/addons/detail/symantec-extension/lgliocaeggimgcpgbbejhdnbmajgaiii)

Registry Type/Data/Value (the value could change, depending on whether there are already any other local extension policies in place):


Type: REG_SZ

Value: 1

Data: lgliocaeggimgcpgbbejhdnbmajgaiii

 

These are added into the Registry at the following keys for the respective browsers:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist

 

Edge for Mac OSX

The Edge extension for Mac OSX has a different ID than the windows extension. This is the proper Mac extension https://microsoftedge.microsoft.com/addons/detail/ifcoeclffkpmgoodbmpmfmcpleljpkfl

Chrome for Mac OSX

The Chrome extension for Mac OSX has a different ID than the windows extension. This is the proper Mac extension  https://chromewebstore.google.com/detail/symantec-extension/egaejpfbkjamgheoingidhokbfnidlpi

Also note that the extension should be install via MDM. See here for details.

 

Environment

DLP 25.1

DLP 26.1

 

Resolution

We recommend that customers who are enforcing Chrome or Edge ExtensionInstallForcelist policies at the Domain GPO level also add the Extension for each browser to the Domain policy and that they be managed at the "Computer (Machine Hive)" level (not at the User level).

This is due to the policy processing order of Windows GPOs combined with Chromium policy behavior. During GPO processing Domain policies are processed last and any key defined in a Domain GPO takes full precedence over the Local GPOs, which means that Registry keys defined in the same hive in competing GPOs do not merge values. Chromium browser policy processing stops at the first defined policy location in this order (1) Device / Machine policy -> (2) Machine-level cloud policy -> (3) OS User policy -> (4) Chrome profile as outlined in the following article:

Understand Chrome policy management

Examples

  • Extension policies defined at LGPO - Computer (Machine) and in Domain GPO - Computer (Machine).
    • The Domain - Computer (Machine) policies win because they are the last to process, fully overwriting the ExtensionInstallForcelist key with the Domain policies.
  • Extension policies defined at LGPO - Computer (Machine) and in Domain GPO - User.
    • The LGPO policies win, because they remain after GPO processing, and Chromium favors Machine policies over User policies.

 

To view an endpoint's Resultant Set of Policy to see where browsers' extension policies are loading from you can run rsop.msc, which will give you a view similar to the following for domain policies:

And when coming from the local group policy, it would appear similar to the following:

You can view the currently installed extensions in each browser by navigating to their respective extensions URLs. To view the current browser policy information, navigate to the browser's policy URL, e.g.:

Chrome

chrome://extensions

chrome://policy

Edge

edge://extensions

edge://policy

 

Additional Information

See also: Incidents generated by Endpoint Prevent Chrome / Edge HTTPS monitor display the URL as 'Unknown'

 

Please note, as of DLP 16.0 it will be expected behavior to see duplicate registry entries