Getting Started with Google Devices in SchoolProtect
Introduction
Chromebooks can be set up to seamlessly send the logged-in username to SchoolProtect to associate users with the correct filtering group and allow all traffic to be logged under the correct username.
The set up is done in two parts:
- In the SchoolProtect admin portal
- In your Google admin console
For each group of users, a policy group is set up in SchoolProtect which generates a unique configuration file for the extension deployed through the Google admin console.
Please note that due to the sequence in which Google Workspace processes extensions, which cannot be altered, there can be a brief delay (mostly a couple of seconds) each time a user logs in before the Chrome extension will become active.
Prerequisites
- School must be on the SchoolProtect filtering platform.
- Chromebooks must be enrolled into the school’s Google Workspace Admin Console.
- You must be a Superadmin account within your Google Workspace.
- Each device must have a unique LGfL IP address (10.x.x.x), not behind a school NAT or proxy.
Instructions
Setup in SchoolProtect
- Sign into the SchoolProtect admin console.
- Browse to Policies - Policy Configuration.
- Create a new policy, choose what to base it on (system default or copy existing policy) and give it a name. The new policy will show under the Inactive Policies section at the bottom of the page.
- Click Edit to enter the Policy Group page (this is where you can configure time schedules and edit the policy allowed/blocked URLs, categories and Bundles).
- You should not enter anything into the Priority box.
- Under Target Group click Chromebook Users (if this button is not showing, check the policy is not targeted to any other user type, i.e. IP addresses, AD groups or USO groups).
- Click the Download Chromebook Config button and save the file ready to upload to the Google admin console in the next section.

Repeat this process for each different filtering policy you need to set up.
Testing & Troubleshooting
To test the extension is working, sign into a Chromebook with a user account that has the extension deployed. After a minute or two, visit http://wsblock.co.uk. You should see a block page which will show the Policy Group. You can see the user name by clicking Display additional information.
If users are not getting the correct filtering policy after waiting a few minutes, check the extension is installed by opening the extensions menu and looking for Netsweeper Workstation Agent. If this is not showing, review the Google Admin Console Support Guide: Automatically install apps and extensions - Google Chrome Enterprise Help.
If the extension is listed but the user is not placed in the correct group, check the correct config file has been uploaded to the Google admin console. Hoving over the Netsweeper Workstation Agent icon in Chrome will give details of whether the user was added to a filtering group or if there was an error.