Skip to content
    Securly Learn DocsSign in
    All documentation

    Classroom › Set up and get started

    Recommended Google Admin settings

    When using Securly Classroom, there are certain Google Admin settings that we recommend in order to prevent students from circumventing the restrictions imposed by the extension.

    Note

    No firewall or port changes are necessary when setting up Securly Classroom.

    For Device OUs

    Adjust these settings in the OU with the student devices.

    Disable Guest Mode

    This setting prevents students from using Guest Mode, then logging in from the browser with a personal Gmail account.

    Navigate to Devices > Chrome > Settings > Device Settings > Sign-in Settings > Guest mode.

    Set “Guest Mode” to "Disable guest mode".

    Sign-in Restriction

    This setting allows login only for domain accounts to prevent students from signing into Chromebooks with personal Gmail accounts.

    Navigate to Devices > Chrome > Settings > Device Settings > Sign-in Settings > Sign-in restriction.

    Set “Sign-in restriction” to "Restrict sign-in to a list of users" and enter *@(your domain) in the list.

    Forced Re-enrollment

    This setting ensures that if a device is reset, it will be forced to enroll back into your domain.

    Navigate to Devices > Chrome > Settings > Device Settings > Enrollment and access > Forced re-enrollment.

    Set “Forced re-enrollment” to "Force device to re-enroll into this domain after wiping". This setting might already be inherited from a higher OU level, such as your organization level.

    For Student User OUs

    Adjust these settings in the OU with the student user accounts.

    Disable Task Manager

    This prevents students from closing the Securly Classroom extension by ending the process in the Task Manager.

    Navigate to Devices > Chrome > Settings > User & Browser Settings > Apps and extensions > Task Manager.

    Set “Task Manager” to "Block users from ending processes with the Chrome task manager”.

    Prevent Incognito mode

    This setting prevents students from opening incognito windows that are not managed by Securly Classroom.

    Navigate to Devices > Chrome > Settings > User & Browser Settings > Security > Incognito.

    Set “Incognito mode” to "Disallow incognito mode".

    Managing browser history

    This setting prevents students from clearing the Chrome browser history.

    Navigate to Devices > Chrome > Settings > User & Browser Settings > Security.

    Select Browser history and set it to "Always save browser history." Select Clear browser history and set it to "Do not allow clearing history in settings menu."

    Disable Developer Tools

    This setting prevents students from opening developer tools.

    Navigate to Devices > Chrome > Settings > User & Browser Settings > User Experience > Developer tools.

    Select Developer tools and set "Developer tools availability" to "Never allow use of built-in developer tools" and "Extensions page developer mode" to "Do not allow use of developer tools on extensions page."

    Set disabled system features

    Specify default apps and system features to disable.

    Navigate to Devices > Chrome > Settings > User & Browser Settings > User Experience > Disabled system features.

    Select "Disabled system features" then put a check in the box for each feature to be disabled.

    At a minimum, we recommend disabling:

    • OS Settings: prevent changing OS settings

    • Crosh: prevent the use of Chrome Shell

    • Gallery: prevent use of the Gallery (Media viewer) app, which can be used for playing videos or viewing photos from local storage

    Others to consider:

    • Browser settings: prevent changing browser settings

    • Terminal: disable terminal unless it's needed for computer science classes where students need access for coding projects.

    • Camera: using this setting to disable the camera only disables the native Chromebook camera app. It does NOT disable the use of the camera from websites that request access to the camera.

    • Web Store: disable this unless students are permitted to browse and install extensions on their Chromebook

    Block JavaScript from running on local files

    This setting will help prevent some games from running from downloaded files.

    Navigate to Devices > Chrome > Settings > User & Browser Settings > Content.

    Select JavaScript. In the configuration box for "Block JavaScript on these sites" enter: file:///*

    Block sensitive internal Chrome URLs

    This setting will block sensitive Chrome URLs that could be used for bypass and circumvention attempts. These URLs typically start with chrome:// or chrome-untrusted:// and include pages and apps such as terminal, bluetooth-internals, certificate-manager, crash dump and many more.

    Navigate to Devices > Chrome > Settings > User & Browser Settings > Content.

    Select URL blocking. Look for the selector under the Blocked URLs box and set it for "Block sensitive internal Chrome URLs". A link is provided to view the full list of URLs.

    You're viewing the text-only version of the Securly Learn help center. Sign in for search, the AI assistant, images, audio, and downloads.