Deploying Jamf Safe Internet to ChromeOS Devices using Google Admin Console - Jamf Safe Internet Documentation

Jamf Safe Internet Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can deploy Jamf Safe Internet to ChromeOS devices by obtaining a DNS over HTTPS (DoH) server URL and CA Certificate from an activation profile, and then adding them to your organization's Google Admin Console.

Training Video

Watch the Deploy Jamf Safe Internet to Chromebooks video to learn the deployment process.

Requirements
  • UEM Connect configured for Google Admin Console.

    For more information, see Configuring UEM Connect for Google Admin Console.

  • Administrator access to your instance of Google Admin Console

  • Experience with configuring and deploying ChromeOS policies to your organization's devices.

  • Chrome Enterprise Upgrade

  • A new or existing organizational unit in Google Admin Console for ChromeOS users to be moved into.

    For more information, see Add an organizational unit in the Google Workspace Admin Help.

  • The required user account that is assigned to the organizational unit in Google Admin Console.

  1. In Safe Internet, navigate to Devices > Activation profiles.
  2. Select the activation profile you want to deploy.
  3. In the Managed deployment pane, select Google Admin Console.
  4. Copy the DoH server URL and click Download CA certificate.
  5. Add the DoH server URL to your Google Admin Console Users & browsers settings.
    1. In the Google Admin Console, go to Devices > Chrome > Settings > Users & Browsers and create a certificate for the applicable organizational unit and confirm the settings are correct.
    2. Choose "Enable DNS-over-HTTPS with insecure fallback" or "Enable DNS-over-HTTPS without insecure fallback" from the DNS-over-HTTPS mode pop-up menu.
    3. In the DNS over HTTPS field, paste the DoH server URL you copied from Safe Internet.
  6. Upload the CA Certificate to your Google Admin Console.
    1. In Google Admin Console, click Networks.
    2. Click Certificates.

      If you organization has never uploaded a certificate, click Create Certificate to upload your first certificate.

    3. Give your certificate a name and click Upload to choose the certificate file.
    4. Select Enabled for Chromebook, and then click Add.
The settings and certificate are distributed to the target chromeOS devices and Jamf Safe Internet is enabled.

To verify the certificate is deployed on a Chromebook, open Google Chrome and go to Settings > Privacy and Security > Security > Managed certificates > Authorities and locate org-jamf and confirm the root certificate exists.

To verify the DNS settings are applied, Settings > Privacy and Security > Security > Manage secure DNS in ChromeOS settings and confirm Enabled Verified Access and Use Secure DNS are enforced.