Jump to content

Recommended Posts

Posted

Those using G Suite can you tell me if you enable or disable the setting for "Drive SDK" and "Add-Ons" in Apps>G Suite>Settings for Drive and Docs for Staff and or Students?

 

Admin console.jpg

Posted
@Arthur - In your screenshot it shows against "Drive" 27 Apps and 267 users. Does this mean there are 27 Apps (Add-Ons) that your 267 users have added to Docs?
Posted

When they try to add an app, they get an error 400 admin policy enforced.

Within the block message is a client ID.

Add that client ID to your trusted apps list and they will be able to use it.

Posted
When they try to add an app, they get an error 400 admin policy enforced.

Within the block message is a client ID.

Add that client ID to your trusted apps list and they will be able to use it.

 

Which trusted Apps list? Under extensions I block all extensions except the ones I allow but these are Doc/Sheet Add-Ons. Is there a separate section to allow these?

Posted (edited)
So if students and/or staff want Doc add-ons how do you handle that? Not Chrome Extensions but Doc Add-ons ie Zoho Writer or DocHub?

Google Doc add-ons are trusted under 'Drive'.

 

Is there a separate section to allow these?

In the 'Security' section mentioned above, then API Permissions > Trusted Apps. :)

 

zWhf3G.png

 

Edit. The following video may help?

 

Edited by Arthur
Posted

@Arthur I have checked under Security and I have many Apps installed but none Trusted. What does this mean? Not trusting them hasn't stopped users installing them as Add-Ons to Docs/Sheets.

 

What's the difference between "enable" and "disable" in your first screenshot? You have API access for drive disabled but you have 27 Apps listed against drive. So those 27 Add-Ons dont have API access but users can still use them?

Posted
In your screenshot it shows against "Drive" 27 Apps and 267 users. Does this mean there are 27 Apps (Add-Ons) that your 267 users have added to Docs?

Under 'Drive' I have client IDs for 27 trusted apps, although I am not sure how the user number is calculated since some of the apps have more than 267 users.

 

PcOTSr.png

  • Thanks 1
Posted

Roger's video helped!!

 

My problem now is that everything was originally enabled. Not sure if that was the default as I don't remember setting it to enabled. Now if I disable then users will start losing access to Apps that I haven't whitelisted. I will have to go through each one in the list and trust those that I think users will need before disabling.

Posted

Enabled was the default as it was a new security feature. I trusted all the apps I think we use and set them to disabled over the summer so I didn't break anything mid year.

Since the start of this school year, I've had at least 5 but no more then 10 requests.

The biggest hassle is getting client ID from the user.

If you go through the list of installed apps now, it is a click of a button to trust them. After you change to disabled you need to use the plus button on the trusted apps screen and enter the client id.

Posted
Hope you don't mind me jumping in (it's similar) but I just noticed this while following your post and wondered what you all had it set on.

 

[ATTACH=CONFIG]50989[/ATTACH]

 

Its in Security /Advanced security settings

 

this kills smtp access mind - i found out the hard way when our finance system stopped sending emails...

  • Thanks 1
Posted
We leave it as it is because of all the systems we have that need to send email notifications ie MFDs (scan to email), Papercut, UPS's.
  • Thanks 1
Posted
Enabled was the default as it was a new security feature. I trusted all the apps I think we use and set them to disabled over the summer so I didn't break anything mid year.

Since the start of this school year, I've had at least 5 but no more then 10 requests.

The biggest hassle is getting client ID from the user.

If you go through the list of installed apps now, it is a click of a button to trust them. After you change to disabled you need to use the plus button on the trusted apps screen and enter the client id.

 

i will change mine over Christmas and then add the ones I know about to Trusted. See how many requests I get in the new year.

Posted (edited)
We leave it as it is because of all the systems we have that need to send email notifications ie MFDs (scan to email), Papercut, UPS's.

 

just put all your service accounts into another OU and apply the settings localy for them to allow it and cut access in the rest of the domain.

 

we have disabled pop3/imap and everything. the only way to use our services is through the official google apps, i have disabled high risk API scopes without prior whitelisting so we can still use oauth and the like for logins to services but stop third party apps being used that could be a security issue.

Edited by DGardiner
Posted

We have app whitelisting in place, but have a policy of basically saying no to any requests for third-party apps. We don't want anyone relying on stuff that could change/disappear without notice. There's also a data protection angle to it. The core Google apps are different in that Google do at at least give you some control over how updates to those apps are rolled out to users.

 

Someone more familiar with might be able to tell me: if an approved third-party app changes it's permissions, does it then need reapproval, or can users just okay those new permissions?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...