ΊΪΑΟΊ£½Η91ΘλΏΪ

Get Started: ΊΪΑΟΊ£½Η91ΘλΏΪ Goβ„’

ΊΪΑΟΊ£½Η91ΘλΏΪ Goβ„’ provides the most secure and convenient way for users to access their ΊΪΑΟΊ£½Η91ΘλΏΪ-protected resources the moment they unlock their managed device. After initial registration with their password, users verify their identity seamlessly during device login, unlock, or in the browser using device authenticators with biometrics (Apple Touch ID and Windows Hello). ΊΪΑΟΊ£½Η91ΘλΏΪ Go improves security for organizations by simplifying the user login flow, reducing authentication fatigue, and minimizing password use. ΊΪΑΟΊ£½Η91ΘλΏΪ Go authentication also satisfies any User Portal MFA requirements.Β 

Important:

Features:

  • Phishing-resistant: After registering their device, users don't enter their credentials in a browser session. Instead, users verify their identity using either their local device password or biometric device authenticator.
  • Device-bound and hardware-protected: ΊΪΑΟΊ£½Η91ΘλΏΪ Go leverages device authenticators and hardware secure stores to protect and secure user credentials.
  • Passwordless: Faster, safer, and simpler user verification saves time for users and admins.

Prerequisites:

  • ΊΪΑΟΊ£½Η91ΘλΏΪ Go supports the following device types that meet these hardware requirements:
    • macOS devices with a .
    • Windows devices with a .
    • Linux devices (GNOME-based distros) with a Trusted Platform Module (TPM) 2.0.
  • The ΊΪΑΟΊ£½Η91ΘλΏΪ agent has to be installed and running on macOS, Windows, and Linux devices. See Install the ΊΪΑΟΊ£½Η91ΘλΏΪ Agent.
  • The ΊΪΑΟΊ£½Η91ΘλΏΪ Go browser extension has to be installed on a supported web browser:
    • Chromium-based browsers (Google Chrome, Microsoft Edge, and Brave only) with the .
    • Firefox with the .
      • Note: Firefox is only supported on macOS and Windows devices.
    • If the browser extension isn't installed, see Installing Browser Extensions Manually.

Considerations:

  • Users need to work from their ΊΪΑΟΊ£½Η91ΘλΏΪ-managed device and be logged in to their managed device account. ΊΪΑΟΊ£½Η91ΘλΏΪ Go doesn't support local device accounts.
  • Biometrics are only supported on macOS and Windows devices. Users need to configure biometrics on their device to use them with ΊΪΑΟΊ£½Η91ΘλΏΪ Go:
    • For macOS devices, see Apple’s .
    • For Windows devices, see Microsoft’s .
  • For Linux devices:
    • Self-contained browsers installed using Snap or Flatpack (including the built-in Firefox browser in some distros) aren't supported. Only browsers installed using standalone methods are supported.
    • Only Chromium-based browsers (Chrome, Edge, and Brave) with the Chrome extension are supported on Linux. 
    • After enabling ΊΪΑΟΊ£½Η91ΘλΏΪ Go, users on CentOS 7/RHEL 7 devices need to log out and log back in.
  • The ΊΪΑΟΊ£½Η91ΘλΏΪ agent will install ΊΪΑΟΊ£½Η91ΘλΏΪ Go components regardless of whether the setting is enabled or disabled in the Admin Portal. See Agent Compatibility, System Requirements, and Impacts.

Understanding Authentication Factors 

When you enable ΊΪΑΟΊ£½Η91ΘλΏΪ Go, it serves as an MFA factor for User Portal and SSO authentication. End users confirm their identity using their device authenticator. See MFA for Admins.

Tip:

ΊΪΑΟΊ£½Η91ΘλΏΪ Go serves as an MFA factor when accessing SSO apps in addition to the User Portal.

If you also enable MFA for User Portal authentication, ΊΪΑΟΊ£½Η91ΘλΏΪ Go uses 3 authentication factors to confirm a user’s identity during registration. For subsequent verifications, users can manually configure biometrics on their device for ΊΪΑΟΊ£½Η91ΘλΏΪ Go. ΊΪΑΟΊ£½Η91ΘλΏΪ Go also provides two factor authentication when biometrics aren’t configured, but uses alternative factors (local device password):

ΊΪΑΟΊ£½Η91ΘλΏΪ Go Authentication Factors

Factor Type Registration without MFA Registration with MFA Verification with biometrics Verification without biometrics
Something you have (managed device) βœ… βœ… βœ… βœ…
Something you are (biometrics) ❌ βœ… βœ… ❌
Something you know (password) βœ… βœ… ❌ βœ…

Installing the ΊΪΑΟΊ£½Η91ΘλΏΪ Go Browser Extension

The ΊΪΑΟΊ£½Η91ΘλΏΪ Go browser extension is required to use ΊΪΑΟΊ£½Η91ΘλΏΪ Go. You can install it on your devices in the following ways:

Chrome: Using ΊΪΑΟΊ£½Η91ΘλΏΪ Policy to Deploy the Extension

If your organization is not using Google Workspace and CBCM, you can deploy the browser extension to macOS and Windows devices using a ΊΪΑΟΊ£½Η91ΘλΏΪ policy. For instructions on using a policy to deploy the browser extension, see Create a Mac or Windows Chrome Force-Installed Extension List Policy.

Chrome: Using CBCM to Deploy the Extension

If your organization is already using Google Workspace, you can deploy the ΊΪΑΟΊ£½Η91ΘλΏΪ Browser Extension with CBCM. See .

To install the ΊΪΑΟΊ£½Η91ΘλΏΪ Go Browser Extension via CBCM:

  1. Go to the and log in as a Google Administrator.
  2. Go to Devices > Chrome > Apps & Extensions > Users & browsers.
  3. Click ( + ) at the bottom of the screen, then select the Chrome icon to add a new extension from the Chrome Web Store.
  4. Search for the ΊΪΑΟΊ£½Η91ΘλΏΪ Go Browser Extension and click Select to add it.
  5. Click ΊΪΑΟΊ£½Η91ΘλΏΪ Go Browser Extension in the list to expand the menu, and in the right aside under Installation Policy, select Force Install.
    • Selecting Force Install in the Google Admin Portal will force the browser extension to install on managed Chrome browsers. See .

Tip:

You can use ΊΪΑΟΊ£½Η91ΘλΏΪ Browser Patch Management to enroll your devices in Google Chrome Browser Cloud Management and enforce the managed browser extensions. See Chrome Browser Cloud Management Settings

Enabling ΊΪΑΟΊ£½Η91ΘλΏΪ Go

After adding the ΊΪΑΟΊ£½Η91ΘλΏΪ Go browser extension to your browsers on your devices, enable the feature in the Admin Portal.

Note:
  • ΊΪΑΟΊ£½Η91ΘλΏΪ Go is enabled for new organizations by default. If it is not enabled in your org, see the following steps to enable it in the Admin Portal.
  • Enabling ΊΪΑΟΊ£½Η91ΘλΏΪ Go in Features will automatically enable it as an MFA factor in SECURITY MANAGEMENT > MFA Configuration for your users.

To enable ΊΪΑΟΊ£½Η91ΘλΏΪ Go for your org: 

  1. Log in to the .
  2. Go to Settings > Features > ΊΪΑΟΊ£½Η91ΘλΏΪ Go.
  3. Click to toggle ΊΪΑΟΊ£½Η91ΘλΏΪ Go to On.
  4. Click Save.


Using ΊΪΑΟΊ£½Η91ΘλΏΪ Go for Step Up MFA

ΊΪΑΟΊ£½Η91ΘλΏΪ Go SSO requests have additional security with user and device verification occurring during every new application session established using Go. Users that authenticate to the User Portal with ΊΪΑΟΊ£½Η91ΘλΏΪ Go will see the Go loader while accessing their SSO applications.

In addition, ΊΪΑΟΊ£½Η91ΘλΏΪ Go is the default MFA method for SSO Conditional Access Policies (CAPs). When a user accesses an application protected by a CAP, they'll be prompted to "step up" and verify their identity using ΊΪΑΟΊ£½Η91ΘλΏΪ Go. See Get Started: Conditional Access Policies.

Disabling ΊΪΑΟΊ£½Η91ΘλΏΪ Go

To disable ΊΪΑΟΊ£½Η91ΘλΏΪ Go for your organization: 

  1. Log in to the .
  2. Go to Settings > Features > ΊΪΑΟΊ£½Η91ΘλΏΪ Go.
  3. Click to toggle ΊΪΑΟΊ£½Η91ΘλΏΪ Go to Off.
  4. Click Save.

Important:

If you disable ΊΪΑΟΊ£½Η91ΘλΏΪ Go, the ΊΪΑΟΊ£½Η91ΘλΏΪ Go browser extension is not automatically removed from the associated devices. See the following section for steps to uninstall the browser extension.

Uninstalling the ΊΪΑΟΊ£½Η91ΘλΏΪ Go Browser Extension

The process to uninstall the ΊΪΑΟΊ£½Η91ΘλΏΪ Go browser extension varies depending on how it was deployed on your devices.

If users manually installed the extension, they can remove it directly from their browser. See Uninstalling the Browser Extension. Otherwise, see the following section if you deployed the Chrome browser extension to your devices.

Chrome: Using ΊΪΑΟΊ£½Η91ΘλΏΪ Policy to Remove the Extension

If you used a ΊΪΑΟΊ£½Η91ΘλΏΪ policy to install the browser extension, you will need to remove the devices from the associated policies created in the Admin Portal. See Create a Mac or Windows Chrome Force-Installed Extension List Policy for steps to remove managed devices from the associated policies.

Chrome: Using CBCM to remove the extension

If you used CBCM to deploy the browser extension, you will need to remove the ΊΪΑΟΊ£½Η91ΘλΏΪ Go browser extension in the Google Admin Portal, or set the extension to Not Installed. See .

FAQ

Can users still authenticate to ΊΪΑΟΊ£½Η91ΘλΏΪ with traditional authentication (email and password)?

Yes. A company email and password is required to register ΊΪΑΟΊ£½Η91ΘλΏΪ Go. Users can still authenticate with traditional methods after ΊΪΑΟΊ£½Η91ΘλΏΪ Go is enabled.  

Can ΊΪΑΟΊ£½Η91ΘλΏΪ Go be used for device authentication?

No. Only ΊΪΑΟΊ£½Η91ΘλΏΪ User Portal and SSO app authentication are supported.

Are device biometrics required to use ΊΪΑΟΊ£½Η91ΘλΏΪ Go?

No. ΊΪΑΟΊ£½Η91ΘλΏΪ Go works with biometrics when users have configured them on their device. When biometrics aren't configured, ΊΪΑΟΊ£½Η91ΘλΏΪ Go requires the user’s local device password for verification.  

How do Conditional Access Policies (CAPs) work with ΊΪΑΟΊ£½Η91ΘλΏΪ Go?

ΊΪΑΟΊ£½Η91ΘλΏΪ Go is supported as an MFA method for conditional access policies protecting the User Portal and SSO apps. See Using ΊΪΑΟΊ£½Η91ΘλΏΪ Go for Step Up MFA and Get Started: Conditional Access Policies for more information.

Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case