This article covers filtering through The GoGuardian App on Windows. For DNS-based filtering issues on school networks, see A Device Is Not Filtering on the School Network.
- The GoGuardian App Is Not Installed on the Device
- An Installed GoGuardian Extension Hasn’t Disabled Itself
- The Device Isn’t Correctly Identifying the Signed-In Student
- The Student Is Not in a Filtered Organizational Unit
- The App Is Installed but Filtering Is Still Not Active
The GoGuardian App Is Not Installed on the Device
Cause: The GoGuardian App must be deployed to Windows devices through your MDM solution (SCCM, Intune, or GPO). If the app was never deployed, or if the device was not enrolled in MDM at the time of deployment, no filtering is active.- On the Windows device, open Settings, then go to Apps and search for “GoGuardian.” Confirm The GoGuardian App appears in the list.
- If the app is absent, verify that the device is enrolled in your MDM (SCCM, Intune, or GPO) and that the GoGuardian deployment target includes this device or its device group.
- In your MDM console, check the deployment status for The GoGuardian App. Confirm the deployment succeeded and that no errors are reported for this device.
- If the device was recently enrolled, allow up to 30 minutes for the MDM policy to apply, then recheck the app list.
- Verify the result: The GoGuardian App appears under Apps on the Windows device and no MDM deployment errors are reported.
An Installed GoGuardian Extension Hasn’t Disabled Itself
Cause: The GoGuardian App filters all browsers on Windows at the system level and does not require the GoGuardian browser extension. Any GoGuardian extension installed in Chrome or Edge is designed to disable itself when it detects The GoGuardian App running on the device. If the extension stays active instead of disabling itself, it can conflict with system-level filtering.-
Open Chrome or Edge on the Windows device and go to the extensions page (
chrome://extensionsin Chrome oredge://extensionsin Edge). - If the GoGuardian Extension is listed and still enabled, confirm The GoGuardian App is running on the device (see The GoGuardian App Is Not Installed on the Device to check installation status).
- If The GoGuardian App is confirmed running but the extension remains enabled, remove the extension through your MDM or browser management policy — it is not required alongside The GoGuardian App.
- Verify the result: The GoGuardian Extension is either absent or disabled in the browser’s extension list, and filtering runs through The GoGuardian App.
The Device Isn’t Correctly Identifying the Signed-In Student
Cause: The GoGuardian App does not use browser sign-in to identify students. Most Windows deployments use user injection, where The GoGuardian App reads the currently signed-in operating system user to determine which student is on the device. Filtering policies apply to whichever account the device identifies through this method.- On the Windows device, confirm the student is signed in to the operating system with their assigned school account. Browser sign-in status does not affect filtering.
- Confirm your organization’s user injection configuration is correctly mapping OS accounts to student accounts in GoGuardian Admin. See your MDM or identity provider’s user injection setup for The GoGuardian App.
- If the device is shared or uses a generic or shared OS login rather than an individual student account, user injection cannot identify the correct student, and filtering may apply the wrong policy or none. Confirm each student signs in to Windows with their own account.
- Verify the result: The correct student account appears as identified in The GoGuardian App, and the expected filtering policy applies.
The Student Is Not in a Filtered Organizational Unit
Cause: GoGuardian Admin applies filtering policies through organizational units (OUs). A student whose account is not in any OU configured in GoGuardian Admin receives no filtering policy, even if The GoGuardian App is installed and the student is signed in.- Go to admin.goguardian.com and find the student’s account.
- Confirm the student’s account belongs to an OU that has a filtering policy assigned.
- If your organization uses Active Directory or Clever as the OU source (rather than Google Admin Console), confirm the student’s account was synced from that source and appears in the expected OU in GoGuardian Admin. For Active Directory environments, see Understand Active Directory OU Sync.
- If the student is in the correct OU but no filtering policy is assigned to it, assign one from the Filtering Policies page in GoGuardian Admin.
- Verify the result: The student’s account appears in an OU with an assigned filtering policy in GoGuardian Admin.
The App Is Installed but Filtering Is Still Not Active
Cause: If The GoGuardian App is installed, no conflicting extension is active, and the correct student is identified and assigned to the right OU, a configuration or version issue may be preventing the app from communicating with GoGuardian Admin.- On the Windows device, open The GoGuardian App (if it has a system tray icon or status indicator) and confirm it shows a connected or active state. If it shows an error, note the error message.
- Confirm the device has network access and can reach GoGuardian service endpoints. If a firewall or proxy is in place, confirm that GoGuardian domains and IP addresses are permitted.
- Check the app version. If an older version of The GoGuardian App is installed, update it through your MDM to the current release.
- Restart The GoGuardian App service on the device through your MDM or directly on the device, then retest filtering with a known blocked URL.
- Verify the result: Filtering blocks the expected URL, and the app shows a connected state.
Identify Common Causes
Theft Recovery is not available on Windows devices. If Theft Recovery is listed as a requirement in your deployment plan, it applies only to Chromebook devices.
Know When to Escalate
- The GoGuardian App reports an error state and the error does not resolve after reinstalling
- The device passes all diagnostic checks but filtering is still not applied
- Filtering works for some students on the same device but not others, and OU assignments appear correct
- You need help confirming which filtering path (app-based vs. DNS) is active for a specific device
Resources
Understand Active Directory OU Sync
Review how GoGuardian Admin uses Active Directory as the OU source for Windows environments.
Understand Filtering Policies
Review how filtering policies are created and assigned to OUs.
Configure At-Home Filtering
Set up filtering for students using school devices off campus.
A Device Is Not Filtering on the School Network
Troubleshoot DNS filtering issues on school networks.