You can deploy Jamf Safe Internet to ChromeOS devices by obtaining a DNS over HTTPS (DoH) server URL and CA Certificate from an activation profile, and then adding them to your organization's Google Admin Console.
Training Video
Watch the Deploy Jamf Safe Internet to Chromebooks video to learn the deployment process.
UEM Connect configured for Google Admin Console.
For more information, see Configuring UEM Connect for Google Admin Console.
Administrator access to your instance of Google Admin Console
Experience with configuring and deploying ChromeOS policies to your organization's devices.
Chrome Enterprise Upgrade
A new or existing organizational unit in Google Admin Console for ChromeOS users to be moved into.
For more information, see Add an organizational unit in the Google Workspace Admin Help.
The required user account that is assigned to the organizational unit in Google Admin Console.
- In Safe Internet, navigate to .
- Select the activation profile you want to deploy.
- In the Managed deployment pane, select Google Admin Console.
- Copy the DoH server URL and click Download CA certificate.
- Add the DoH server URL to your Google Admin Console Users & browsers settings.
- In the Google Admin Console, go to and create a certificate for the applicable organizational unit and confirm the settings are correct.
- Choose or from the DNS-over-HTTPS mode pop-up menu.
- In the DNS over HTTPS field, paste the DoH server URL you copied from Safe Internet.
- Upload the CA Certificate to your Google Admin Console.
To verify the certificate is deployed on a Chromebook, open Google Chrome and go to and locate org-jamf and confirm the root certificate exists.
To verify the DNS settings are applied, and confirm Enabled Verified Access and Use Secure DNS are enforced.