Skip to main content

Enterprise deployment (managed Chrome)

This guide is for Google Workspace administrators who want to roll PhishNet out to their organization centrally, instead of asking each employee to install it from the Chrome Web Store.

With this setup, Chrome silently pushes the extension to every user in the organizational unit (OU) you choose. Employees don't install anything — the PhishNet shield simply appears in their toolbar and starts protecting Gmail.

Everything below is done in the Google Workspace Admin console. You need Workspace super-admin (or a role with the Chrome and API-controls privileges). These settings don't exist for personal @gmail.com accounts — only for Workspace organizations.

Start with a pilot OU

Apply both steps to a small pilot OU first (for example, a single team), confirm the extension installs and reads Gmail as expected, then widen the rollout to the rest of the organization.

What you'll need

ValueUse it in
Extension IDephmdgmkompjhhpgcpnfdhpaioeggpgbStep 1 (force-install)
OAuth client ID794782735284-5ajq4cnpd7o4a9d7urlkd1cdoe4bvnss.apps.googleusercontent.comStep 2 (trust the app)

Step 1 — Force-install the extension

  1. In the Admin console, go to Devices → Chrome → Apps & extensions → Users & browsers.
  2. Select the OU you're deploying to (start with your pilot OU).
  3. Click the button → Add Chrome app or extension by ID.
  4. Paste the Extension ID (ephmdgmkompjhhpgcpnfdhpaioeggpgb).
  5. Set Installation policy to Force install — or Force install + pin to keep the shield icon visible in the toolbar.
  6. Click Save.

Step 2 — Trust the OAuth client

This tells Workspace to allow PhishNet's Google sign-in, so users aren't blocked by third-party app restrictions and don't see an "unverified app" warning.

  1. Go to Security → Access and data control → API controls.
  2. Under App access control, click Manage Third-Party App Access.
  3. Click Add app → OAuth Client ID.
  4. Paste the OAuth client ID (794782735284-5ajq4cnpd7o4a9d7urlkd1cdoe4bvnss.apps.googleusercontent.com).
  5. Set the app to Trusted.
  6. Click Save.

What happens next

Chrome pushes the extension to every user in the selected OU on their next sync (usually within minutes). Users don't take any action — the PhishNet shield appears in their toolbar. The first time they open Gmail, they complete the standard Google sign-in consent once, and scanning begins automatically.

Scope and limitations

Force-install reaches managed Chrome only — that is, Chrome profiles signed in to a Workspace account governed by these policies. It does not cover:

  • users on other browsers (Safari, Firefox, Edge without the equivalent policy);
  • unmanaged or personal Chrome profiles.

For those users, the manual Chrome Web Store install still works. Broader, browser-independent coverage (for example, a Gmail Add-on) is on the roadmap but is not required for a managed-Chrome rollout.