GWS-K12-008: Managed Student Chromebook Posture
- Platform
- Google Workspace
- Category
- K12 Baseline
- Severity
- Medium
- Zero Trust pillar
- Devices (weight 2)
- Golden fixtures
- 6
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- original
- Scope
- OU-scoped: requires the -StudentOU input (or the Student OUs field in Show-Guerrilla). Without it, this check reports Not Assessed.
Guerrilla K12 Baseline (candidate)
This check assesses control K12-DEVICE-001 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.
What it checks
Student Chromebooks are the district's largest fleet and its most boundary-tested. The posture that keeps the fleet managed: wiped devices re-enroll automatically (students cannot escape management by wiping), extensions install from a district allowlist rather than an open store with a blocklist, and sideloaded extensions from outside the Web Store are blocked.
Recommended value
Forced re-enrollment automatic after wipe; extension installs allowlist-only; external (sideloaded) extensions blocked on student OUs
Remediation
Devices > Chrome > Settings. Select the student organizational unit. Under Device settings > Enrollment and access, set Forced re-enrollment to 'Force device to automatically re-enroll after wiping'. Under Users and browsers > Apps and extensions, set the Chrome Web Store install policy to block all apps with an admin-managed allowlist, and block external extensions.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| blocklist-warn | WARN |
| clean | PASS |
| known-bad | FAIL |
| no-scope | Not Assessed |
| not-assessed | Not Assessed |
| ou-absent | Not Assessed |
Framework mappings
- NIST SP 800-53
- CM-7, CM-2
- MITRE ATT&CK
- T1176