jthompson Posted November 29, 2018 Posted November 29, 2018 What are other G Suite admins doing regarding API access? I've been going through all our domain settings and now realising that with all the APIs enabled, users have collectively gathered up rather a large list of Oauth, iOS and Android apps (Admin -> Security -> API Permissions -> Installed Apps). Am I right to now be looking at building up a whitelist of trusted apps but disabling the APIs for everything else (user complaints be damned)? It seems like I'm leaving the doors wide open otherwise, and not protecting users from themselves.
Narwhal Posted December 10, 2018 Posted December 10, 2018 Just bumping this thread as I have just been doing the same as jthompson and have come to the same conclusion. Does anyone have an opinion on this?
jthompson Posted December 12, 2018 Author Posted December 12, 2018 I pulled the trigger on this this afternoon. Whitelisted various obvious things (like our GCDS OAuth, Show My Homework apps, which we use, etc.) after going systematically through the long list of current apps with access, then disabled access to all of the APIs. Also left the "Trust domain owned apps" option ticked. Let's see what people come back with.
jthompson Posted December 13, 2018 Author Posted December 13, 2018 I've been poking around with this a little more and have noticed that there are still a lot of apps listed as being installed (but not trusted), in spite of all of the APIs being disabled. You can't remove anything from that list, seemingly. Apps can still access some core account info (name, for instance) to facilitate logins, signups, etc with those API controls set to disabled. Users are therefore still able to use the "Sign in with Google" option on sites. If an access permission dialogue asks for access to stuff covered by a disabled API scope, however, it results in the error message as configured. I was hoping to be able to prevent use of "Sign in with Google" on untrusted apps. Not sure if that's an option elsewhere or not. I'm guessing that the data available to third-parties in this way is limited enough to not really be of concern anyway.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now