Classroom › Set up and get started
Recommended Google Admin settings
When using Securly Classroom, there are certain Google Admin settings that we recommend in order to prevent students from circumventing the restrictions imposed by the extension.
Note
No firewall or port changes are necessary when setting up Securly Classroom.
For Device OUs
Adjust these settings in the OU with the student devices.
Disable Guest Mode
This setting prevents students from using Guest Mode, then logging in from the browser with a personal Gmail account.
Navigate to Devices > Chrome > Settings > Device Settings > Sign-in Settings > Guest mode.
Set “Guest Mode” to "Disable guest mode"
Sign-in Restriction
This setting allows login only for domain accounts to prevent students from signing into Chromebooks with personal Gmail accounts.
Navigate to Devices > Chrome > Settings > Device Settings > Sign-in Settings > Sign-in restriction.
Set “Sign-in restriction” to "Restrict sign-in to a list of users" and enter *@(your domain) in the list.
Forced Re-enrollment
This setting ensures that if a device is reset, it will be forced to enroll back into your domain.
Navigate to Devices > Chrome > Settings > Device Settings > Enrollment and access > Forced re-enrollment.
Set “Forced re-enrollment” to "Force device to re-enroll into this domain after wiping". This setting might already be inherited from a higher OU level, such as your organization level.
For Student User OUs
Adjust these settings in the OU with the student user accounts.
Disable Task Manager
This prevents students from closing the Securly Classroom extension by ending the process in the Task Manager.
Navigate to Devices > Chrome > Settings > User & Browser Settings > Apps and extensions > Task Manager.
Set “Task Manager” to "Block users from ending processes with the Chrome task manager”.
Prevent Incognito mode
This setting prevents students from opening incognito windows that are not managed by Securly Classroom.
Navigate to Devices > Chrome > Settings > User & Browser Settings > Security > Incognito.
Set “Incognito mode” to "Disallow incognito mode".
Managing browser history
This setting prevents students from clearing the Chrome browser history.
Navigate to Devices > Chrome > Settings > User & Browser Settings > Security .
Select Browser history and it to "Always save browser history." Select Clear browser history and set it to "Do not allow clearing history in settings menu."
Disable Developer Tools
This setting prevents students from opening developer tools.
Navigate to Devices > Chrome > Settings > User & Browser Settings > User Experience > Developer tools .
Select Developer tools and set "Developer tools availability" to "Never allow use of built-in developer tools" and "Extensions page developer mode" to "Do not allow use of developer tools on extensions page."
Set disabled system features
Specify default apps and system features to disable.
Navigate to Devices > Chrome > Settings > User & Browser Settings > User Experience > Disabled system features.
Select "Disabled system features" then put a check in the box for each feature to be disabled.
At a minimum, we recommend disabling:
OS Settings: prevent changing OS settings
Crosh: prevent the use of Chrome Shell
Gallery: prevent use of the Gallery (Media viewer) app, which can be used for playing videos or viewing photos from local storage
Others to consider:
Browser settings: prevent changing browser settings
Terminal: disable terminal unless it's needed for computer science classes where students need acceess for coding projects.
Camera: using this setting to disable the camera only disables the native Chromebook camera app. It does NOT disable the use of the camera from web sites that request access to the camera.
Web Store: disable this unless students are permitted to browse and install extensions on their Chromebook
Block JavaScript from running on local files
This setting will help prevent some games from running from downloaded files.
Navigate to Devices > Chrome > Settings > User & Browser Settings > Content.
Select JavaScript. In the configuration box for "Block JavaScript on these sites" enter: file:///*
Block sensitive internal Chrome URLs
This setting will block sensitive Chrome URLs that could be used for bypass and circumvention atempts. These URLs typicall start wtih chrome:// or chrome-untrusted:// and include pages and apps such as terminal, bluetooth-internals, certificate-manager, crash dump and many more.
Navigate to Devices > Chrome > Settings > User & Browser Settings > Content.
Select URL blocking. Look for the selector under the Blocked URLs box and set it for "Block sensitive internal Chrome URLs" A link is provided to view the full list of URLs.