<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Okta Classic Engine

avshch (BCRC) asked a question.

Chrome Enterprise Universal Enrollment with Okta

Has anyone implemented Chrome Enterprise Universal Enrollment as per the following article:

https://www.okta.com/blog/customers-and-partners/bridging-the-gap-in-browser-security-with-google-and-okta/ We are trying to see if this could be a right fit for us as we use Chrome browser running on Citrix. Periodically, Citrix profiles get corrupted or had to be blown away due to sync issues. It appears to be self-enrollment from end-user perspective.

What is the end-user experience? Does a user need to re-enroll into Chrome browser profile if a browser is upgraded to the latest?

Thanks,

 


OktaPreviewA.24420 likes this.
  • Mihai N. (Okta, Inc.)

    Hi @avshch (BCRC)​ , Thank you for reaching out to the Okta Community! 

     

    The blog post is a bit older but I managed to confirm that we currently have an "Okta Verified" dedicated Okta Integrations Network app for Chrome Enterprise Universal Enrollment. 

    You can check the OIN catalog by going to your Okta Admin Dashboard > Applications > Browse App Catalog > Search for "Chrome Enterprise Universal Enrollment" and follow the set up steps from there.  

     The configuration doc can be found here (link also available in the Okta under the app's Sign on > View Setup Instructions ;  so it's "built-in integration" vs "custom integration" mentioned in the blog post). 

     

    To answer your questions based on what I was able to find:

     

    End-User Experience (Initial Enrollment)

    The process is designed as a self-enrollment experience.

    1. The user navigates to a specific Enrollment URL provided by the IT administrator. (Often, administrators embed this link in an Okta "Access Denied" custom error message if a user tries to access a protected app from an unmanaged browser).
    2. The user is redirected to the Okta sign-in page to authenticate.
    3. Once authenticated via Okta, Chrome prompts the user for consent to create a managed profile.
    4. After accepting, the enterprise-grade managed Chrome profile is created on the device, pulling down the organization's browser policies.

     

    Browser Upgrades

    A user does not need to re-enroll or recreate their managed Chrome browser profile simply because the browser application updates to the latest version.

    The managed profile configuration and enrollment tokens are persistent. Much like standard Chrome profiles, the profile data, sync settings, and enterprise policies remain intact across standard browser version upgrades.

     

    I haven't seen reports of issues with it yet, but I would recommend testing in a preview environment first. If you encounter issues with the implementation, please open a case to review the configuration together with our colleagues from the Okta Support team. 

     

    That being said, we'll leave this question open for input from the community if anyone has implemented this and has additional insight to share. 

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Securing AI agents across your org? Join our upcoming Ask Me Anything on 8/5 about Okta for AI Agents. Ask our expert questions.

    Expand Post
    Selected as Best
  • Mihai N. (Okta, Inc.)

    Hi @avshch (BCRC)​ , Thank you for reaching out to the Okta Community! 

     

    The blog post is a bit older but I managed to confirm that we currently have an "Okta Verified" dedicated Okta Integrations Network app for Chrome Enterprise Universal Enrollment. 

    You can check the OIN catalog by going to your Okta Admin Dashboard > Applications > Browse App Catalog > Search for "Chrome Enterprise Universal Enrollment" and follow the set up steps from there.  

     The configuration doc can be found here (link also available in the Okta under the app's Sign on > View Setup Instructions ;  so it's "built-in integration" vs "custom integration" mentioned in the blog post). 

     

    To answer your questions based on what I was able to find:

     

    End-User Experience (Initial Enrollment)

    The process is designed as a self-enrollment experience.

    1. The user navigates to a specific Enrollment URL provided by the IT administrator. (Often, administrators embed this link in an Okta "Access Denied" custom error message if a user tries to access a protected app from an unmanaged browser).
    2. The user is redirected to the Okta sign-in page to authenticate.
    3. Once authenticated via Okta, Chrome prompts the user for consent to create a managed profile.
    4. After accepting, the enterprise-grade managed Chrome profile is created on the device, pulling down the organization's browser policies.

     

    Browser Upgrades

    A user does not need to re-enroll or recreate their managed Chrome browser profile simply because the browser application updates to the latest version.

    The managed profile configuration and enrollment tokens are persistent. Much like standard Chrome profiles, the profile data, sync settings, and enterprise policies remain intact across standard browser version upgrades.

     

    I haven't seen reports of issues with it yet, but I would recommend testing in a preview environment first. If you encounter issues with the implementation, please open a case to review the configuration together with our colleagues from the Okta Support team. 

     

    That being said, we'll leave this question open for input from the community if anyone has implemented this and has additional insight to share. 

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Securing AI agents across your org? Join our upcoming Ask Me Anything on 8/5 about Okta for AI Agents. Ask our expert questions.

    Expand Post
    Selected as Best
  • avshch (BCRC)

    How would admin define "Enrollment URL"?

    Is that actually Okta's "Chrome Enterprise Universal Enrollment" app?

  • avshch (BCRC)

    Is there a way to force automatic enrollment for the users?

    • Mihai N. (Okta, Inc.)

      None that I could find. It is based on the user consent interaction with the prompt for enrollment.

      They will have to accept the profile creation after you share the Enrollment URL.   

      Perhaps you can submit a Feature Request for automation in future iterations of the implementation by going to the Community→ Ideas tab. 

       

      Regards.

      --

      Help others in the community by liking or hitting Select as Best if this response helped you.

      Collect them all. Learn a new skill and earn a new Okta Learning badge.

      Just released: More Okta Community badges just added

      Expand Post
      • avshch (BCRC)

        @Mihai N. (Okta, Inc.)​ is this something could be handled with Workflows?

      • Mihai N. (Okta, Inc.)

        Hi @avshch (BCRC)​ Okta Workflows is not an option to fully automate or force a user's enrollment into Chrome Enterprise Universal Enrollment.

        Universal Enrollment fundamentally requires explicit user consent within the local Chrome browser interface on the endpoint device nad Okta Workflows operates entirely on the backend via APIs and cannot interact with a client-side browser to accept the managed profile consent prompt.

        At best, Workflows can only be used to automate the backend prerequisites surrounding the enrollment process, such as:

        • Automatically assigning the Chrome Enterprise Universal Enrollment OIDC app to users during lifecycle onboarding.
        • Sending automated onboarding communications (via Slack or Email connectors) that contain the Google-hosted Enrollment URL, instructing the user to initiate the self-enrollment process.

         

         

        Regards.

        --

        Help others in the community by liking or hitting Select as Best if this response helped you.

        Collect them all. Learn a new skill and earn a new Okta Learning badge.

        Just released: More Okta Community badges just added

        Expand Post
      • avshch (BCRC)

        @Mihai N. (Okta, Inc.)​ The issue is when there is no option for enforced enrollment is that a user has to complete Chrome Enterprise Universal Enrollment every single time when Citrix profile is deleted or new OS image is redeployed (for non-persistent VDIs).

Loading
Chrome Enterprise Universal Enrollment with Okta