Skip to content
    Securly Learn DocsSign in
    All documentation

    Filter › Certificates and SSL

    How to Manage User Access to Certificates

    The default values from Google allow users to edit trust settings for all CA certificates, remove user-imported certificates, and import certificates.

    If a user removes CA certificates from their device, there is a possibility it could affect the functionality of our services. It is recommended that you do not allow users to edit certificates installed on their devices.

    To Do This:

    1. Log into your Google Workspace as a Super Admin User (admin.google.com).
    2. Navigate to Devices > Chrome > Settings > Users & Browser Settings.
    3. Select your root directory (if you wish to limit the scope of this best practice, select the container which contains the proper users).
    4. Scroll down to Security and locate the settings:
      • User management of installed CA certificates
      • User management of installed client certificates
    5. Select 'Disallow users from managing certificates' for both fields:

    Full navigation path, applied on root directory, with settings highlighted:

    Close Up of Specific Settings:

    You're viewing the text-only version of the Securly Learn help center. Sign in for search, the AI assistant, images, audio, and downloads.