Deploying the CAASPP and ELPAC Secure Browser on ChromeOS
Use this 2026–27 overview to prepare managed Chromebooks for California online testing. ChromeOS support and secure-browser configuration can change during the administration year, so confirm the live California requirements before each deployment.
Do not use the former installation procedure
The former procedure used Developer Mode, chrome://extensions, and a legacy Chrome App. That process is obsolete and may erase local data if it includes powerwashing a device.
Do not enable Developer Mode or powerwash a Chromebook solely to install the current secure browser. Current supported ChromeOS devices use the SecureTest progressive web application (PWA) deployed as a kiosk app through the Google Admin console.
Current 2026–27 ChromeOS requirements
Check both the operating-system channel and device-management status before beginning deployment.
| Requirement | Current direction |
|---|---|
| Minimum supported versions | ChromeOS 144 LTS, ChromeOS 144 LTC, or ChromeOS 148 Stable and above. |
| Recommended channel | Long-Term Support Candidate (LTC) or Long-Term Support (LTS). Beta and Dev channels are not supported for student testing. |
| Device management | Supported Chromebooks must be enrolled in a management domain. Chromebooks manufactured in 2017 or later require an Enterprise or Education license. |
| Testing mode | The SecureTest PWA must run in kiosk mode. ChromeOS tablet mode and tablets running ChromeOS are not supported; touchscreen features on supported Chromebooks may be used. |
| ChromeOS Flex | The SecureTest PWA is supported on currently supported ChromeOS versions, including ChromeOS Flex. Confirm the device and version on the live support page. |
Managed deployment workflow
Use the live advanced-installation guide while working in the Google Admin console. Application identifiers, URLs, policies, and screen labels should be copied from that guide rather than from a local article.
- Confirm the supported version and channel. Compare the device fleet with the current Supported Operating Systems and Devices page before changing ChromeOS versions.
- Select the correct organizational unit. In the Google Admin console, identify the organizational unit and any sub-organizations that contain the testing devices.
- Add SecureTest as a kiosk PWA. Follow the current ChromeOS Advanced Secure Browser Installation guide to add the required launchpad URL, application extension, allowed origins, and kiosk settings.
- Configure Verified Mode. Current guidance marks verified-access configuration as required. Apply it to the testing-device organizational unit and add the service account specified in the live guide.
- Enable the Hardware Platform API. Current guidance also requires the Enterprise Hardware Platform API policy for the managed extension. Confirm that applicable sub-organizations inherit the setting.
- Apply policies and restart devices. Allow time for Google Admin policies to reach representative Chromebooks, then restart or sign out as directed.
- Launch from the kiosk screen. Confirm that SecureTest opens from the device’s kiosk application screen and reaches the California student sign-in interface.
- Run a representative practice test. Verify audio, keyboard, mouse or touch input, display resolution, and every accessibility resource students will use. Repeat this check after operating-system updates.
Plan operating-system updates deliberately
A newly released operating-system version may not be supported immediately. California recommends waiting until a version appears on the supported list; support is typically added within 60 days. Review current announcements and known issues before allowing a fleet update during a testing window.
Pretesting checklist
- The ChromeOS version and channel appear on the current supported list.
- Testing devices are enrolled, licensed when required, and assigned to the intended Google Admin organizational unit.
- The SecureTest PWA appears as a kiosk application and launches without an ordinary user session.
- Verified Mode, the required service account, and the Enterprise Hardware Platform API are configured as directed.
- Required California testing URLs and network traffic are allowed.
- Display, headphones, microphones, input devices, and assigned accessibility resources work on representative devices.
- Automatic updates and policy changes are controlled during operational testing.
- A practice test has been completed after deployment and after any material ChromeOS update.
Official resources
- California technology resources and secure browsers
- Supported operating systems and devices
- ChromeOS advanced secure-browser installation
- California Secure Browsers portal
- Known issues
This article intentionally does not reproduce the current application identifier, service account, or vendor screen sequence. Use the live advanced-installation guide when deploying or reconfiguring devices. SDLA content review: September 4, 2026.







































































