Extension policies allow administrators to control which browser extensions users can install and run in the NordLayer Browser. By creating centralized rules, administrators can allow or block specific Chrome Web Store extensions (or all of them) for designated teams. This reduces extension-related risks and minimizes the organization's attack surface.
How to set up NordLayer Browser extension policies
Before getting started, you'll need to enable NordLayer Browser under the Platform Solutions tab as a prerequisite.
- Click the NordLayer Browser tab and select the Extension Policies section.
- Click Create policy (you can create up to 200 rules).
- In the window that opens, you'll need to:
- Enter a rule name
- Select which teams the policy applies to (you may select multiple teams)
- Choose an action: Allow or Block
- Define the extensions the rule applies to by selecting one of the following:
- Any: applies to all extensions
- Specified extensions: enter specific Chrome extension IDs (up to 100 IDs per policy)
- When you're finished configuring the policy, click Create policy to save your changes.
Rules can be created or reordered even if NordLayer Browser is currently disabled.
Extension IDs
Each Chrome Web Store extension has a unique 32-character lowercase alphanumeric ID. You can find an extension's ID in its Chrome Web Store URL. When entering extension IDs, the system validates that each value matches the expected format and rejects invalid entries with a descriptive error message.
While editing a rule, you can view each extension ID along with a direct link to its Chrome Web Store listing. This helps you verify exactly which extension is associated with a given ID and confirm that it exists in the store.
When you configure Allow or Block policies using specific extension IDs, the rules only apply to extensions hosted in the Chrome Web Store. However, a Block: Any policy restricts all extensions, including both Chrome Web Store extensions and locally unpacked ones.
Rule prioritization
Rules are evaluated in top-to-bottom order — the first matching rule applies. Every newly created rule appears at the top of the rule list.
Administrators can reorder rules via drag and drop to adjust priority. Each row in the list displays the priority position, rule name, action (Allow/Block), extensions, and row-level actions for editing and deleting.
While the browser functionality operates independently once activated, accessing Browser Extension features requires appropriate licensing. The system automatically verifies extension permissions before granting access to extension policy configurations.
Note: In case you have any questions or are experiencing any issues, please feel free to contact our 24/7 customer support team.