Google Workspace Enhanced Desktop Management

A handful of community members came together today (by initiative of @ayates) to discuss how an midsized to large company that is primarily NOT on Windows can use Google Workspace's Enhanced Desktop Management to either start managing Windows machines or replace (Azure) Active Directory. 

We decided to open this thread to gather use cases, feedback, and best practices around that! 

Here are a couple of useful links to start: Common custom settings for Windows 10 devices - Google Workspace Admin Help  Device management security checklist - Google Workspace Admin Help NFTF: Google Workspace | GCPW / EDSW Enhanced desktop security for Windows [WIP]
13 7 1,938

Thanks for sharing.  Common custom settings for Windows 10 help article includes 30+ settings. I encourage community members to share any other custom settings and values (if possible) used in your environment. We will keep an eye on this thread to identify popular settings and will update the article to help other Workspace users.


Great discussion this morning and definitely going to follow this thread so I can keep up with popular settings shared by others.

I've done a write up before on using Enhanced Desktop Security for Windows (EDSW) for Chrome Browser Cloud Management (CBCM).

And it looks like my issue with software discovery has been solved by a Windows update and removing and re-enrolling a test device.

That said - a big part of device management for us is software auditing. It's great I can see installed software via Enhanced Desktop Security... but it's less great there's not an API (at least that I can find...) to query this information. Or is there a page of documentation I've missed ๐Ÿ˜›

Just to recap the story - and highlight what weโ€™re trying to achieveโ€ฆ

Thoughtworks is a Mac-centric company with a relatively small number of Windows devices. We generally operate using a โ€œtrust but verifyโ€ approach - and have rolled out a lightweight Mac-specific management solution, which has been incredibly useful as part of this. Now we would like to do the same thing for our Windows fleet - and have been enrolling our Windows devices into Google Enhanced Desktop Management, to see if that will work for us in a similar fashion.

Weโ€™re a data-driven organisation - thereโ€™s a few basic security posture settings we control, but the majority of the value we get from management is providing software discovery and patch status events to downstream systems.

APIs that will let us do this are critical - as the ultimate goal is to pull the information together, and allow stakeholders to get a complete picture of all devices, as well as drill down to the places where we need to take action. 

This is a core requirement for us - and there are some gaps in the APIs that are quite important. Iโ€™ve put each one of these in as a feature request - as I thought it would be helpful to gauge broader interest - but I also wanted to post here to connect things all together for the folks who were part of this discussion:

An API for exporting software discovery information from managed Windows devices

More detailed OS information in the Device API (especially for Windows 10)

Improved ability to filter Device API queries

But it's not just APIs - there are a few other places where Enhanced Desktop Security could be more helpful or more user friendly. These feature requests revolve around the lack of an API - and could be potential (short term!) workarounds. What do you all think?

More granular device management permissions in the admin console

Better csv export options for managed device information

And finally - the bigger asks, namely:

Device Management by Group (not OU)

Ability to self-host custom software packages for Windows

Neither of these are show stoppers for our current rollout - but both could cause pain in the medium to long term.

Thanks ๐Ÿ™‚


a common ask from r/gsuite and some of our customers is the ability to escrow bitlocker keys. any update you can share on this @rkkumar ?

another common ask is the ability to sign automatically into Drive for Desktop app. it automatically signs into Chrome browser, but still requires user interaction to complete sign in to Drive for Desktop. If we can do this either as a Chrome policy/Windows Policy or tighter product integration, I think we could possibly see a higher adoption.

On somewhat related note, I just recorded a quick video on associating existing Windows profile with GCPW.