Skip to main content
This guide walks GoGuardian Super Users through installing the GoGuardian extensions in Google Admin Console, along with the key Google Admin Console settings. The extensions must be installed for any user you intend to filter and review with GoGuardian Admin, Teacher, or Beacon. GoGuardian users (teachers, admins, and staff) only need an account registered at manage.goguardian.com with product access enabled to sign in and use GoGuardian products.
To install the extensions using Active Directory or Microsoft Intune, or to deploy The GoGuardian App to Windows, iPads, or Mac, contact your GoGuardian Account Manager for guidance. If you have already installed the extensions, skip to Verify Extension Deployment.

Locate Your GoGuardian Extensions

Every GoGuardian account has a unique pair of Chrome extensions. To find your organization’s extensions, sign in to GoGuardian with your Super User credentials and open the Org Management Installation page. Keep this window open for the next step. GoGuardian Org Management Chrome/Extension installation page showing the GoGuardian and GoGuardian License extension App IDs and URLs

Force-Install the Extensions

  1. Using your Google Admin credentials, sign in to admin.google.com.
  2. In the left panel, click DevicesChromeApps & extensionsUsers & browsers.
Google Admin Console Apps & Extensions page with the Users & browsers tab and an organizational unit selected in the left panel
  1. Select the organizational unit or units that contain the student accounts you intend to filter and review.
  2. To filter all users in the organization, including teachers and staff, select the domain-level (top-level) OU. Sub-OUs inherit extensions from their parent OU, but double-check each OU and sub-OU you intend to deploy to.
  3. Hover over the plus sign near the bottom corner of the screen.
  4. Click the waffle icon to add a Chrome app or extension by ID.
Google Admin Console Users & browsers panel with the add-extension waffle icon highlighted next to the Chrome Web Store and Play Store icons
  1. Click the drop-down menu and select From a Custom URL.
Google Admin Console Add Chrome app or extension by ID dialog with the From a Custom URL option highlighted
  1. Refer back to the Chrome extension install page in Org Management for the App IDs and URLs.
  2. Copy and paste the first App ID and URL pair into their fields, then click Save. Both extensions have unique installation URLs.
  3. In the following window, open the Installation policy drop-down and select Force install, then select Allow all permissions under Permissions and URL access.
Repeat this process for both the GoGuardian Extension and the GoGuardian License extension. Google Admin Console extension row with Force Install selected as the installation policy and Allow all permissions selected under Permissions and URL access

Configure User and Browser Settings

User and browser settings control Chrome browser behavior and apply to signed-in managed accounts. From the Google Admin home screen, click DevicesChromeSettingsUsers & browsers, select the OU that contains the user accounts you are deploying to, and configure the following policies. Use the Find tool (Command+F on Mac, Ctrl+F on Windows) to locate policies quickly.

Configure Required Policies

Google Admin Console Users & browsers settings showing the User management of installed CA certificates policy set to Disallow users from managing certificates Google Admin Console Users & browsers settings showing the SSL error override policy set to Block users from clicking through SSL warnings Google Admin Console Users & browsers settings showing the URL blocking policy with javascript://* added to Blocked URLs Google Admin Console Users & browsers settings showing the Side panel search history policy set to disable recent Google Search results in the browser side panel

Review Optional Policies

Configure App Settings

From the Google Admin Console home screen, go to DevicesChromeApps & extensionsUser app settings.
  • Allowed types of apps and extensions (Required): the Extension type must be checked. Unchecking a type prevents that type from being installed by admins or users. Google Admin Console Apps & Extensions User app settings tab with the Allowed types of apps and extensions setting highlighted Google Admin Console Allowed types of apps and extensions setting with Extension, Theme, Google Apps Script, Hosted app, Legacy packaged app, and Chrome packaged app all checked
  • Allow/block mode (Recommended): Block all apps; admin manages allowlist for both the Play Store and Chrome Web Store. Some third-party apps and extensions can bypass GoGuardian if they contain a built-in browser that is not Chrome or Edge, or that does not require sign-in. Block all other apps and extensions and manage an approved list on the Apps & ExtensionsOverview page. Google Admin Console User app settings Allow/block mode panel showing Block all apps, admin manages allowlist for both Play Store and Chrome Web Store
  • Permissions and URLs (Required): confirm that these permissions are not blocked:
    • Alarms
    • Detect idle
    • Notifications
    • Memory metadata
    • Identity
    • Storage
    • Web requests
    • Geolocation
    • CPU metadata
    • Native messaging
    • Block web requests
    Google Admin Console Permissions and URLs settings showing the Block extensions by permission checklist

Configure Device Settings

From the Google Admin home screen, click DevicesChromeSettingsDevice settings, select the OU that contains your Chromebooks, and configure the following. For Sign-in Restrictions, add your district’s domain and subdomains preceded by a wildcard, separating multiple entries with commas — for example: *@goguardian.com, *@students.goguardian.com, *@teachers.goguardian.com.
If your campus has a restrictive firewall or additional content filter, you may need to open connections to GoGuardian services. Refer to GoGuardian’s firewall and additional content-filter allowlist guidance.

Import Your OU Structure

Importing organizational units maps students to an assigned OU in GoGuardian. OUs are used for two purposes: Teacher and admin permissions. Super Users can grant all OU access or limit a user’s OU permissions to control which student data that user can access. For GoGuardian Admin, Admin OU access controls which student data an admin can see and which filtering policies an admin can edit. GoGuardian features. For GoGuardian Admin filtering, policies are applied to imported OUs to filter students granularly by org unit. For Smart Alerts, OUs configure Smart Alert Triggers, such as notifying and assigning school admins by the trigger’s OUs. For GoGuardian Beacon, OUs create Beacon Deployments that can be customized with alert settings, school hours, parent notifications, and school counselors.

Import or Sync OUs

Set up the initial OU import and OU source on the Data Sources → OU Settings page in Org Management. Only one OU source can be selected at a time: Google Admin Console, Clever, ClassLink, Active Directory, or OneRoster.
  1. Sign in to Org Management.
  2. Open Data Sources → OU Settings.
  3. Click Configure next to Google Admin Console (GAC).
  4. Authorize the sync, select each OU to import (not just new OUs), and complete the import.
  5. Verify the result: The selected OUs appear in GoGuardian Org Management.

Automatic vs. Force Sync

Once imported, GoGuardian syncs the OU source each night and updates users’ assigned OUs when they move between existing OUs. If new OUs are created, or existing OUs are renamed or reorganized, re-import the OU structure manually to add the new OUs.
A significant OU change can affect features that rely on the OU source. Policies may become unassigned if their OU is removed or changed, and Smart Alert Trigger OU assignments and Beacon Deployments may need updating. After a significant OU change, double-check your GoGuardian Admin policies, Smart Alert Triggers, and Beacon Deployments.

Verify Extension Deployment

For GoGuardian products to work, both the GoGuardian and GoGuardian License extensions must be installed for each user you intend to filter and review. GoGuardian recommends creating a test account, such as teststudent@schooldistrict.org, in the same OU as your students.
  1. Sign in to a test or student account that belongs to the OU the extensions were deployed to. If available, you can also check a student’s device.
  2. In Google Chrome, go to chrome://extensions.
  3. Verify that both the GoGuardian and GoGuardian License extensions are present and enabled.
The extensions only need to be deployed one time. Chrome extensions page showing both the GoGuardian and GoGuardian License extensions installed and enabled on a managed Chromebook
Last modified on August 12, 2026