AWS Bedrock AgentCore adds Chrome enterprise policy support with 450+ browser settings
Amazon Bedrock AgentCore Browser now supports Chrome enterprise policies and custom root CA certificates, giving organizations control over 450+ browser settings for AI agents. The feature enables URL filtering, download restrictions, password manager controls, and connectivity to internal services through custom certificate authorities.
AWS Bedrock AgentCore adds Chrome enterprise policy support with 450+ browser settings
Amazon Bedrock AgentCore Browser now supports Chrome enterprise policies and custom root CA certificates, according to AWS. Organizations can now configure over 450 browser settings for AI agents, including URL filtering, download restrictions, and password manager controls.
Two-tier policy enforcement
The implementation uses two layers of policy enforcement. Managed policies operate at the browser level through Chrome's /etc/chromium/policies/managed/ directory. These policies are provided during browser creation via the control plane API and apply to every session. Recommended policies operate at the session level through Chrome's /etc/chromium/policies/recommended/ directory and can be provided when starting a browser session through the data plane API.
When managed and recommended policies conflict on the same setting, the managed policy takes precedence. This follows standard Chrome enterprise behavior.
Custom root CA certificate support
Organizations can store root CA certificates in AWS Secrets Manager and reference them when creating a browser or AgentCore Code Interpreter. The service imports the certificate into the certificate trust store, enabling connections to internal services and SSL-intercepting proxies without disabling certificate validation.
This addresses a specific barrier for organizations with internal services using private certificate authorities, where HTTPS connections previously failed with certificate validation errors.
Implementation architecture
Chrome policy JSON files are stored in Amazon S3. The control plane fetches these files when CreateBrowser is called and retrieves optional root CA certificates from AWS Secrets Manager. Applications call the CreateBrowser API followed by the StartBrowserSession API. The control plane passes browser configuration metadata to the data plane, which deploys managed policies, recommended policies, and root CA certificates to the isolated browser session.
Use case: domain restriction
The feature addresses three organizational requirements. First, URL allowlists and denylists restrict agent scope to approved domains. An agent processing invoices on a specific portal can be prevented from accessing social media or search engines through browser-level enforcement.
Second, organizations can disable risky browser features including password managers, file downloads, and autofill capabilities. Third, policy management is separated from agent development—security teams define browser configurations while development teams focus on agent logic.
Availability
The feature is available now in AWS Regions where Amazon Bedrock AgentCore is supported. AWS provides a complete sample implementation as a Jupyter notebook in the amazon-bedrock-agentcore-samples repository on GitHub. The sample demonstrates policy enforcement through session recording and custom root CA certificate configuration using a public test site.
Prerequisites include Python 3.10 or later, AWS credentials, and access to an AI model. The sample uses Anthropic Claude through Amazon Bedrock, though AgentCore is model-agnostic.
What this means
This is infrastructure-level security for browser-based AI agents. Organizations running agents that interact with web services can now enforce the same browser restrictions they apply to human users. The separation of managed and recommended policies provides a clear boundary between security team controls and application-level configuration. Custom root CA support removes a significant deployment blocker for enterprises with private certificate authorities, where agent browser sessions previously couldn't connect to internal services without disabling certificate validation entirely.
Related Articles
AWS adds managed Web Search to Claude Desktop via Bedrock AgentCore Gateway in three Regions
AWS published a walkthrough for connecting Claude Desktop on Amazon Bedrock to a managed, MCP-compatible Web Search capability through Amazon Bedrock AgentCore Gateway. According to AWS, the search is backed by an Amazon web index spanning tens of billions of documents, and query traffic stays within AWS infrastructure. Web Search is available in three AWS Regions; pricing is not disclosed in the post.
Amazon open-sources Strands Decider 2B, a small decision model built on a Qwen3.5-2B base
Amazon Web Services has released Strands Decider 2B, an open-source model that chooses among pre-decided options and returns a confidence score instead of generating text. It is inspired by TypeSafe's Jev and is small enough to run locally. Amazon says it briefly topped the Jevbench ranking for models of its size.
Meta launches Muse Gadgets, open-source firmware and Linux SDK for building hardware that connects to its Muse agent
Meta introduced Muse Gadgets on Friday, an open-source project with firmware and a Linux SDK for building hardware that connects to its Muse personal AI agent. Meta also built a first-party device, Muse Home Link, and says it is giving away 5,000 units to Muse subscribers.
Pi 1.0 agent harness goes stable; Pi Durable ports it to TypeScript with crash-resumable state
Pi, the minimalist agent harness now under Earendil, has reached version 1.0. A companion release, Pi Durable, ports it to TypeScript and externalizes all stateful components so agents can resume after crashes. Pricing and licensing were not disclosed in the source.
Comments
Loading...