Pastebreak

Admin install guide (one page)

You need: your organization key (vk_…, from the welcome email) and the extension ID (…). The dashboard's Install tab generates every file below with your key filled in.

Google Workspace

  1. Admin console → Devices → Chrome → Apps & extensions → Users & browsers.
  2. Pick the org unit, click + → Add Chrome app or extension by ID, paste the extension ID, from the Chrome Web Store.
  3. Set Installation policy to Force install.
  4. Under "Policy for extensions", paste the contents of pastebreak-workspace-policy.json and save.
  5. Optional: Chrome → Settings → Users & browsers → Incognito mode = Disallow, and restrict sign-in to your domain.

Microsoft Intune (Edge and Chrome on Windows)

  1. Devices → Scripts and remediations → Platform scripts → Add → Windows 10 and later.
  2. Upload pastebreak-windows.ps1 (run as system, 64-bit). It writes the force-install entry and the managed settings to the Chrome and Edge policy registry keys.
  3. Assign to your device group. Alternatively import pastebreak-windows.reg with GPO/Preferences.

macOS (Jamf/Kandji/Intune)

Deploy pastebreak-chrome.mobileconfig (or pastebreak-chrome.plist to /Library/Managed Preferences/com.google.Chrome.plist). Edge uses the same keys under com.microsoft.Edge; replace the domain.

Check it worked

Open chrome://policy (or edge://policy) and click Reload policies. You should see ExtensionInstallForcelist and, under the extension's ID, your orgKey. Open ChatGPT: a small on badge appears top right and the toolbar icon shows on. Paste AKIAIOSFODNN7EXAMPLE (Amazon's published fake key): it should be blocked.

Roll out safely

Set mode to monitor for the first week (nobody is blocked; the dashboard shows what would have been). Then switch the Policy tab to enforce.

Remove

Delete the force-install entry and the policy values; the extension is removed at the next policy refresh. Cancel billing from the dashboard.

The generated files have been built to Chrome's documented policy formats but have not yet been verified on a live Workspace/Intune tenant by the vendor. Test on one pilot group first.