Jump to content

Recommended Posts

Posted

Source: www.blog.google/products/g-suite/manage-access-third-party-apps-new-g-suite-security-controls/

 

Protecting your organization’s most sensitive data and assets is a constant challenge. G Suite helps protect your data in a number of ways: thwarting attackers with advanced phishing detection through machine learning, mandating strong authentication with security key enforcement and preventing data leakage through tools such as DLP.

 

Today, we're adding another security feature that improves data access control and enhances phishing prevention—OAuth apps whitelisting, giving your organization added visibility and control into how third-party applications are using your data.

 

New third-party application access controls

OAuth apps whitelisting helps keep your data safe by letting admins specifically select which third-party apps are allowed to access users’ G Suite data. Once an app is part of a whitelist, users can choose to grant authorized access to their G Suite apps data. This prevents malicious apps from tricking users into accidentally granting access to their corporate data.

 

With these new security controls, an admin can:

 

  1. Get fine-grained visibility into the third-party apps that are accessing G Suite data.
  2. Allow access to only trusted and vetted third-party OAuth apps.
  3. Guard OAuth access to core G Suite apps data by preventing unauthorized app installs, thus limiting the problems caused by shadow IT.

Once the OAuth whitelisting settings are in place, access to third-party apps is enforced based on the policy set by admins, and employees are automatically protected against unauthorized apps.

 

Enable OAuth Apps Whitelisting for your domain

This feature is being rolled out in phases and will be made available within the Admin console in next few days. Check out instructions on how to get started here.

 

GCloud_BeyondcorpGSuiteAppSecurity2%2520%25281%2529.width-1000.png

 

GCloud_BeyondcorpGSuiteAppSecurity1%2520%25281%2529.width-1000.png

  • Thanks 1
  • 8 months later...
Posted

Need to resurrect this one. Has anyone disabled access to apis and which ones? I'm considering enabling this, but its domain wide so i can't test with a few users.

 

I know I can trust apps from the installed apps list, but if that app isn't installed how do I get its App ID to add it?

 

I have several apps that are just the app id for the name, anyway to find out what those are?

 

Some apps say they have access to other, whats that?

 

For gmail and drive, I can disable access to high risk. Google gives an example, but is there a detailed list of what data this is?

 

Thank you

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...