Deployment for G-suit
Introduction
This document provides step-by-step instructions for installing HawkShield Email Protection as a centralized Chrome extension within the Google Workspace Admin Console. This setup ensures consistent deployment and enforcement of HawkShield's email protection features across all user devices in the organization.
Step 1: Access the Google Admin Console
Open your web browser and navigate to admin.google.com.
Sign in using your Google Workspace administrator credentials.
From the Google Apps menu (grid icon in the top-right corner), select Admin to open the Admin Console.

Step 2: Navigate to Apps & Extensions
In the Admin Console, go to the left-hand menu and click:
Devices => Chrome => Apps & Extensions.
Select Users & browsers from the top menu to configure the extension for users.

Step 3: Add HawkShield from the Chrome Webstore
Click the “+” (plus sign) at the bottom right of the Apps & Extensions panel.
Select “Add from Chrome Web Store.”

Step 4: Locate the HawkShield Extension
In the Chrome Web Store dialog, choose the Search by ID option.
Enter “HawkShield” in the search bar.

Step 5: Select the HawkShield Extension
From the search results, locate and select “HawkShield Email Protection.”
Click on the extension preview to proceed.

Step 6: Configure Extension Installation
Click on the Select button in the top right corner.

Step 7: Modify Installation Policy
Confirm that HawkShield Email Protection now appears in the Users & browsers section.
In the extension settings panel, go to the right-side panel under Installation Policy.
Click the drop-down next to Allow install.

Step 8: Enforce Extension Deployment
From the drop-down menu, select Force install + pin to browser toolbar / Force Install.

Step 9: Enable Incognito Enforcement
Toggle on the setting for Extension is mandatory in incognito to enforce protection in incognito mode.

Step 10: Configure User Profile Restrictions
In the left menu, go to Settings, then select Users & browsers.
Scroll to the Separate profile for managed Google Identity.
Click the drop-down beside Locally applied and choose:
Force separate profile and forbid secondary managed accounts.

Step 11: Enable Sign-in Interception
Navigate to the Sign-in interception tab.
Click on Inheritance, then select Enable sign-in interception.

Step 12: Enforce Browser Sign-In
Go to the Browser sign-in settings tab.
Click Inheritance and choose Force users to sign in to use the browser.

Step 13: Disable Incognito Mode
Navigate to the Incognito mode tab.
Under Configuration, select Disallow incognito mode.
Click Save at the bottom of the page to apply all settings.

After completing the above steps, HawkShield Email Protection will be enforced across all designated Chrome browsers in your organization. This ensures consistent security and compliance for email communications within Google Workspace.
Last updated