Chrome Enterprise Premium POV — DLP rule validation

One test page per DLP rule from the CEP POV guide (Citrix DLP track). Each page shows the rule's configuration as built in the Google Admin Console, an interactive test target, and the expected result — so testers can validate every rule end-to-end and record pass/fail.

Prerequisites (per POV guide)

Before testing, the following must be in place — see the POV guide for setup steps:

Console & licenses

Chrome Enterprise Core active, domain verified, CEP trial license assigned via GCP (BeyondCorp roles + CEP project). OUs created: Managed Browsers and Users.

Extensions & connectors

Endpoint Verification and Secure Enterprise Browser extensions force-installed. All five CEP connectors enabled: real-time URL check, upload, download, bulk text and print content analysis — each set to delay until analysis is complete.

Detectors & context

Detectors All URLs = (.*) and Internal URLs word list created. Sensitive content storage and OCR analysis toggled on. Access level CEP-Unmanaged Profiles created (management_state != BROWSER_MANAGED).

The eight sample rules + optional policy

rule 01 · block

URL Filtering

Block Generative AI URL category, except Google Gemini. Test navigation to ChatGPT vs. Gemini.

Run test →
rule 02 · audit

Watermarking

Translucent watermark with user/device ID over matching pages. Verify rendering and ID differences.

Run test →
rule 03 · audit

Screenshot & Screen Sharing

Page content blacked out in screenshots and screen shares on matching URLs.

Run test →
rule 04 · audit

URL Audit

Audit event for every visited URL except the Internal URLs word list. Verify Chrome log events.

Run test →
rule 05 · block

PII DLP

Block upload, download, paste and print of credit card data — except on Internal URLs.

Run test →
rule 06 · block

Paste Source Control

Block pasting from incognito, other profiles or external applications into Chrome.

Run test →
rule 07 · audit

Data Masking

SSNs masked on the page with hover-to-reveal on matching URLs.

Run test →
rule 08 · block

Unmanaged Profile Downloads

Block all downloads on non-corporate (unmanaged) profiles via context-aware access level.

Run test →
rule 09 · policy

Copy/Paste Policies

Optional Chrome policy: block copying from managed profile into other profiles, incognito, or other apps.

Run test →

Test checklist

Record the result per rule and device class as you test. Results live in this browser tab only — export to CSV before closing to add to the pilot KPI log.

RuleManaged browserManaged profile (BYOD)Unmanaged profile