fiza Posted November 15, 2018 Posted November 15, 2018 Those using G Suite can you tell me if you enable or disable the setting for "Drive SDK" and "Add-Ons" in Apps>G Suite>Settings for Drive and Docs for Staff and or Students?
Arthur Posted November 15, 2018 Posted November 15, 2018 I have those two settings enabled, but control which apps/add-ons are allowed through API Permissions (under Security). 1
fiza Posted November 15, 2018 Author Posted November 15, 2018 @Arthur - So if students and/or staff want Doc add-ons how do you handle that? Not Chrome Extensions but Doc Add-ons ie Zoho Writer or DocHub?
fiza Posted November 15, 2018 Author Posted November 15, 2018 @Arthur - In your screenshot it shows against "Drive" 27 Apps and 267 users. Does this mean there are 27 Apps (Add-Ons) that your 267 users have added to Docs?
ADMaster Posted November 15, 2018 Posted November 15, 2018 When they try to add an app, they get an error 400 admin policy enforced. Within the block message is a client ID. Add that client ID to your trusted apps list and they will be able to use it.
fiza Posted November 15, 2018 Author Posted November 15, 2018 When they try to add an app, they get an error 400 admin policy enforced. Within the block message is a client ID. Add that client ID to your trusted apps list and they will be able to use it. Which trusted Apps list? Under extensions I block all extensions except the ones I allow but these are Doc/Sheet Add-Ons. Is there a separate section to allow these?
Arthur Posted November 15, 2018 Posted November 15, 2018 (edited) So if students and/or staff want Doc add-ons how do you handle that? Not Chrome Extensions but Doc Add-ons ie Zoho Writer or DocHub? Google Doc add-ons are trusted under 'Drive'. Is there a separate section to allow these? In the 'Security' section mentioned above, then API Permissions > Trusted Apps. Edit. The following video may help? Edited November 15, 2018 by Arthur
fiza Posted November 15, 2018 Author Posted November 15, 2018 @Arthur I have checked under Security and I have many Apps installed but none Trusted. What does this mean? Not trusting them hasn't stopped users installing them as Add-Ons to Docs/Sheets. What's the difference between "enable" and "disable" in your first screenshot? You have API access for drive disabled but you have 27 Apps listed against drive. So those 27 Add-Ons dont have API access but users can still use them?
Arthur Posted November 15, 2018 Posted November 15, 2018 In your screenshot it shows against "Drive" 27 Apps and 267 users. Does this mean there are 27 Apps (Add-Ons) that your 267 users have added to Docs? Under 'Drive' I have client IDs for 27 trusted apps, although I am not sure how the user number is calculated since some of the apps have more than 267 users. 1
ADMaster Posted November 15, 2018 Posted November 15, 2018 If you change that setting to disable then users will loose access to them unless you add them to the trusted list. 1
fiza Posted November 15, 2018 Author Posted November 15, 2018 @Arthur - So is there no way of blocking users from adding Add-Ons to Docs/Sheets unless they are approved? Ok so posted before I saw @ADMaster reply.
fiza Posted November 15, 2018 Author Posted November 15, 2018 Roger's video helped!! My problem now is that everything was originally enabled. Not sure if that was the default as I don't remember setting it to enabled. Now if I disable then users will start losing access to Apps that I haven't whitelisted. I will have to go through each one in the list and trust those that I think users will need before disabling.
TwistedHelixis Posted November 15, 2018 Posted November 15, 2018 Hope you don't mind me jumping in (it's similar) but I just noticed this while following your post and wondered what you all had it set on. Its in Security /Advanced security settings
ADMaster Posted November 15, 2018 Posted November 15, 2018 Enabled was the default as it was a new security feature. I trusted all the apps I think we use and set them to disabled over the summer so I didn't break anything mid year. Since the start of this school year, I've had at least 5 but no more then 10 requests. The biggest hassle is getting client ID from the user. If you go through the list of installed apps now, it is a click of a button to trust them. After you change to disabled you need to use the plus button on the trusted apps screen and enter the client id.
DGardiner Posted November 15, 2018 Posted November 15, 2018 Hope you don't mind me jumping in (it's similar) but I just noticed this while following your post and wondered what you all had it set on. [ATTACH=CONFIG]50989[/ATTACH] Its in Security /Advanced security settings this kills smtp access mind - i found out the hard way when our finance system stopped sending emails... 1
fiza Posted November 15, 2018 Author Posted November 15, 2018 We leave it as it is because of all the systems we have that need to send email notifications ie MFDs (scan to email), Papercut, UPS's. 1
fiza Posted November 15, 2018 Author Posted November 15, 2018 Enabled was the default as it was a new security feature. I trusted all the apps I think we use and set them to disabled over the summer so I didn't break anything mid year. Since the start of this school year, I've had at least 5 but no more then 10 requests. The biggest hassle is getting client ID from the user. If you go through the list of installed apps now, it is a click of a button to trust them. After you change to disabled you need to use the plus button on the trusted apps screen and enter the client id. i will change mine over Christmas and then add the ones I know about to Trusted. See how many requests I get in the new year.
DGardiner Posted November 15, 2018 Posted November 15, 2018 (edited) We leave it as it is because of all the systems we have that need to send email notifications ie MFDs (scan to email), Papercut, UPS's. just put all your service accounts into another OU and apply the settings localy for them to allow it and cut access in the rest of the domain. we have disabled pop3/imap and everything. the only way to use our services is through the official google apps, i have disabled high risk API scopes without prior whitelisting so we can still use oauth and the like for logins to services but stop third party apps being used that could be a security issue. Edited November 15, 2018 by DGardiner
jthompson Posted November 15, 2018 Posted November 15, 2018 We have app whitelisting in place, but have a policy of basically saying no to any requests for third-party apps. We don't want anyone relying on stuff that could change/disappear without notice. There's also a data protection angle to it. The core Google apps are different in that Google do at at least give you some control over how updates to those apps are rolled out to users. Someone more familiar with might be able to tell me: if an approved third-party app changes it's permissions, does it then need reapproval, or can users just okay those new permissions?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now