WhitelistVideo on Chromebook
Only the YouTube channels you approve play, on the device your child uses most. Pick the level of protection that fits your family, from a 10-minute setup to an extension that cannot be removed.
Last updated: September 2026
How does WhitelistVideo work on a Chromebook?
WhitelistVideo is a Chrome extension. Once it is installed on your child's Chromebook, every YouTube video is blocked by default and only the channels you approve from the parent dashboard will play. Shorts are off. The whitelist syncs with every other device your child uses. Because ChromeOS is built around Chrome, the same extension covers the whole device.
Can my child remove it?
That depends on who controls the Chromebook, not on the extension. ChromeOS lets any user remove any extension, and Google states that removing one on a Family Link Chromebook needs no parent permission (re-adding does). WhitelistVideo is designed to run on top of the control you already have: with Family Link, removal shows on your dashboard within minutes and re-installing needs your approval; with a managed device (your school's Google Admin console, or your own ChromeOS Enterprise Upgrade), the extension is force-installed and cannot be removed or disabled.
Three levels of protection
Start at level 1. Move up only if your child needs it.
WhitelistVideo + Family Link
The extension does the filtering; Family Link makes every install a parent decision and keeps Guest mode off.
- Installing any extension or Android app needs your approval, so re-adding WhitelistVideo after a removal goes through you
- Your dashboard shows the device as inactive within minutes if the extension is removed or disabled
- Guest mode and new users are blocked when you are the Chromebook's owner account
- Keep the Family Link "Extensions" toggle off so installs always need approval
Most families. Younger children who respond to "I'll know if you turn it off."
Family Link step-by-step guideWhitelistVideo + school Admin console
The school's IT admin force-installs the extension through the Google Admin console it already runs. Your child cannot remove or disable it.
- Send your school IT the extension ID and the deployment guide below
- The extension is pinned by device policy; the Remove button disappears
- Your child signs in with the school account; you still manage the whitelist from your dashboard
- Extension ID: mapkkanjgaongckjkhklbhekefemookh
Children on a school-issued Chromebook.
Deployment guide for school ITWhitelistVideo + ChromeOS Enterprise Upgrade
You enroll the Chromebook in your own Google Admin console, the same tool schools use, and force-install the extension yourself. The child cannot remove it, disable it, or escape by factory resetting.
- Extension force-installed; no Remove button on the child's account
- Factory reset re-enrolls the device automatically
- Incognito, Guest mode, developer tools and the Play Store can all be turned off
- Full walkthrough below
Tech-savvy older children on a personal Chromebook.
Jump to the setup walkthroughWhich level do you need?
What each pairing gives you on a Chromebook
Scroll horizontally to see all columns.
| WhitelistVideo + Family Link | WhitelistVideo + Enterprise Upgrade | WhitelistVideo + School Admin console | |
|---|---|---|---|
| Only approved channels play | Yes | Yes | Yes |
| Installing extensions | Needs your approval | Admin force-installs | IT admin force-installs |
| If your child removes the extension | Dashboard shows it within minutes; re-adding needs your approval | Cannot be removed or disabled | Cannot be removed or disabled |
| Factory reset | Re-setup with your account | Device re-enrolls automatically | Device re-enrolls automatically |
| Incognito | Blocked by Family Link | Blocked by policy | Blocked by policy |
| Guest mode | Off when you own the device | Blocked by policy | Blocked by policy |
| Other browsers (Android apps) | Each install needs your approval | Play Store can be turned off | Play Store can be turned off |
| Setup | 10 minutes | 30 to 60 minutes, once | 5 minutes (ask school IT) |
| Cost | Free | About $12 a month | Free |
Locking the extension on a personal Chromebook
ChromeOS only lets a device administrator force-install an extension. A ChromeOS Enterprise Upgrade makes you that administrator for your child's Chromebook. It is a one-time setup, and afterwards the whitelist runs exactly as before; the only change is that the extension can no longer be removed.
What you need
A domain name
Google Workspace requires one. Google can sell you one during signup, about $12 a year.
Google Workspace
The cheapest plan, Business Starter, is enough: from about $7 per user per month. It gives you the Google Admin console.
ChromeOS Enterprise Upgrade
About $4.17 per device per month, billed as roughly $50 a year. A free 30-day trial is available in the Admin console.
The Chromebook, backed up
Enrollment requires a factory reset (Powerwash). Anything stored only on the device is erased.
Cost for one Chromebook
| Item | Monthly | Annual |
|---|---|---|
| Google Workspace Business Starter (1 user) | ~$7 | ~$84 |
| Domain (if you buy a new one) | ~$1 | ~$12 |
| ChromeOS Enterprise Upgrade (per device) | ~$4.17 | ~$50 |
| Total | ~$12 | ~$146 |
Each additional child Chromebook adds about $50 a year; the Workspace account and domain are shared.
Setup walkthrough
- 1
Create a Google Workspace account
Go to workspace.google.com, choose Business Starter, and enter or buy a domain. Think of it as your family's control centre: you will create accounts like parent@yourfamily.com and child@yourfamily.com. The child's account is the one that gets the restrictions. You now have the Google Admin console at admin.google.com.
- 2
Add the ChromeOS Enterprise Upgrade
In the Admin console go to Billing, then Get more services, then ChromeOS Enterprise Upgrade, and start the free trial. Buy one upgrade per Chromebook. The upgrade belongs to the device, not the user. Chrome Enterprise Core, the free browser-management tool, does not manage Chromebooks; you need this paid upgrade.
- 3
Factory reset (Powerwash) the Chromebook
Back up anything stored on the device. Sign out, press Ctrl + Alt + Shift + R at the sign-in screen, click Restart, then Powerwash and Continue. The device must be enrolled before anyone signs in; if someone signs in first, Powerwash again.
- 4
Enroll the device
After the reset, connect to Wi-Fi. On the setup screen choose Enroll the device (or press Ctrl + Alt + E), sign in with your Workspace admin account, skip asset ID and location, and choose Enroll enterprise device. Check Devices, Chrome, Devices in the Admin console: the Chromebook should be listed.
- 5
Create a unit for your child
In the Admin console go to Directory, then Organizational units, and create one called Kids (or your child's name). Move your child's Workspace account into it. Policies apply per unit, so you stay unrestricted at the top level and the lockdown applies only to your child.
- 6
Force-install WhitelistVideo
Go to Devices, Chrome, Apps & extensions, and open the Users & browsers tab. Select the Kids unit, click the yellow plus button, choose Add from Chrome Web Store, and paste the extension ID mapkkanjgaongckjkhklbhekefemookh. Under Installation policy choose Force install (or Force install + pin to ChromeOS taskbar) and save. On the child's Chromebook, chrome://extensions now shows WhitelistVideo with no Remove button.
- 7
Confirm forced re-enrollment
Go to Devices, Chrome, Settings, Device settings and find Forced re-enrollment under Enrollment and Access. It should read Force device to automatically re-enroll after wiping; that is Google's default. With it on, a factory reset brings the device straight back under your management and developer mode is disabled. Only you can release the device, by deprovisioning it in the Admin console.
- 8
Add the protective policies
Still under Devices, Chrome, Settings, for the Kids unit: disallow Incognito mode, disable Guest mode, never allow developer tools, block ending processes in Task manager, restrict sign-in to your domain, block secondary accounts, and turn off the Google Play Store and Linux so no other browser can be installed. Then sign your child in with their child@yourfamily.com account and pair the extension with your WhitelistVideo dashboard as usual.
Extension details for the Admin console
- Extension ID
mapkkanjgaongckjkhklbhekefemookh- Force-install policy string
mapkkanjgaongckjkhklbhekefemookh;https://clients2.google.com/service/update2/crx
Chromebook questions
Start with the extension. Lock it later if you need to.
Install WhitelistVideo on your child's Chromebook, approve a few channels, and see how the whitelist works during the free test period. Levels 2 and 3 add on to the same setup.



