After reviewing my typical Monday morning report of server activity, I noticed a handful of users installed Google Chrome.
I can’t uninstall this globally as an Administrator so I had to run the following from the command-line as their user. Start -> Run -> “cmd” right-click and “Run As Different User…” and enter the user’s credentials.
C:UsersdoejohnAppDataLocalGoogleChromeApplication21.0.1180.60Installersetup.exe –uninstall –force-uninstall
The Application folder still exists, so the following removes it
rd /S /Q “c:usersdoejohnAppDataLocalGoogleChrome”
Further, I decided to remove the entire “Google” folder
rd /S /Q “c:usersdoejohnAppDataLocalGoogle”
After that, I decided it was time to enforce not allowing Google Chrome to be installed on this terminal server. Sorry Google. =)
- Open the Group Policy Management Console (GPMC).
- Right-click your domain and choose the Create a GPO in this domain, and link it here option.
- Name the Group Policy Object (GPO) Block Google Chrome and click OK.
- Right-click the policy you just created and click Edit.
- Navigate to the User ConfigurationPoliciesWindows SettingsSecurity SettingsSoftware Restriction Policies folder.
- Right-click Software Restriction Policies and select New Software Restriction Policies.
- Right click Additional Rules and choose New Path Rule.
- In the Path field, type chromesetup.exe.
- In the Security level drop-down box, choose Disallowed and click OK.
- Repeat steps 7 through 9 for the chrome.exe and gears-chrome-opt.msi files.
- Repeat steps 7 through 9 for the path C:Users%username%AppDataLocalGoogleChromeApplicationchrome.exe for Vista machines or C:Documents and Settings%username%Local SettingsApplication DataGoogleChromeApplicationchrome.exe for XP machines. You should include this rule in case some of your users have already installed the browser. After you implement the GPO and the Group Policy settings refresh on those users’ local machines, they’ll no longer be able to successfully run Google Chrome.
- Open a command-prompt window and run the command
to apply the new rules.
- Run the command
in Vista SP1 or the command
in XP and Vista (pre-SP1) to verify that the newly created GPO has successfully been applied.
- As a final test, attempt to run the installer from the Google Chrome website. If the policy is successful, you should see the error that shows.