TwistedHelixis Posted October 10, 2020 Author Posted October 10, 2020 We have a Google Form where people request access to apps How do they know what apps to request if they can only access whitelisted apps in the Play Store?
DGardiner Posted October 10, 2020 Posted October 10, 2020 They would have browsed the software online and then checked with me, but by default teachers cant even browse the apps in the Play Store. When they open the Play Store they can only see the apps I have whitelisted, so how are they meant to let me know which apps they want, or are you saying they should be able to browse the apps in the Play Store but I have something blocking them in my setup? i dont have one to test but i was sure ours could browse but "this is not approved for your domain" was displayed, i could be wrong though
aicrd Posted October 10, 2020 Posted October 10, 2020 That'll only approve Chrome Web Store apps. You can't allow install of all play store apps on an education account: Allow the installation of any app This feature is not available for education domains. https://support.google.com/chrome/a/answer/7131624?hl=en
TwistedHelixis Posted October 10, 2020 Author Posted October 10, 2020 You can't allow install of all play store apps on an education account: I don't need to allow the teachers to install the apps just view what apps are available. Anyway my workaround is to pin the web version of the play store as a favourite to the teachers chrome browser, this does let them browse the apps and not install. Surely it should be up to the admin to decide who can see all the apps in the app store and who only gets the whitelisted apps.
aicrd Posted October 10, 2020 Posted October 10, 2020 Chromebooks use the managed play store which is curated so you only get to see apps that are approved. Not sure you can disable that on edu accounts.
TwistedHelixis Posted October 10, 2020 Author Posted October 10, 2020 Really sorry for all the dumb questions but just found another issue :-( If I block all other apps and extensions (see pic below) G Suite then uninstalls G Docs, Slides and a load of other apps we need from the Chromebook app draw. Do others have this blocked, and if so how do I add back the missing apps we need or do your users use G Docs through the Chrome browser only.
DGardiner Posted October 10, 2020 Posted October 10, 2020 Really sorry for all the dumb questions but just found another issue :-( If I block all other apps and extensions (see pic below) G Suite then uninstalls G Docs, Slides and a load of other apps we need from the Chromebook app draw. Do others have this blocked, and if so how do I add back the missing apps we need or do your users use G Docs through the Chrome browser only. [ATTACH=CONFIG]59375[/ATTACH] Browser only, theyre better that way anyway imo. The web apps are listed as apps anyway i think in the app drawer - coud set the homepage to https://workspace.google.com/dashboard cant see a search button though so that might upset some! Id also reccomend going to https://admin.google.com/ac/owl/list?tab=services and setting gmail/drive to restricted - high risk access, this will stop staff gfiving random web apps access to your drives/emails etc. this will mean you need to whitelist anything requesting anything in the high risk scopes, but will still functions for things like "login with google" 1
TwistedHelixis Posted October 10, 2020 Author Posted October 10, 2020 (edited) Browser only, theyre better that way anyway imo. Ok Thanks :0) Id also reccomend going to https://admin.google.com/ac/owl/list?tab=services and setting gmail/drive to restricted - high risk access, this will stop staff gfiving random web apps access to your drives/emails etc. this will mean you need to whitelist anything requesting anything in the high risk scopes, but will still functions for things like "login with google" Sounds perfect. If I change these to restrictive do you know if they will effect our Spanning Cloud backup in anyway? EDIT - Spanning Backup is not listed on the other tab marked 'Apps connected', so going to assume it will not effect this. Edited October 10, 2020 by TwistedHelixis
TwistedHelixis Posted October 10, 2020 Author Posted October 10, 2020 Id also reccomend going to https://admin.google.com/ac/owl/list?tab=services and setting gmail/drive to restricted - high risk access, this will stop staff gfiving random web apps access to your drives/emails etc. this will mean you need to whitelist anything requesting anything in the high risk scopes, but will still functions for things like "login with google" Does this also mean I can safely re enable 'apps and extensions' for the Chromebooks as they can only install low risk apps anyway?
TwistedHelixis Posted October 10, 2020 Author Posted October 10, 2020 Almost there, got 99% of my settings down now :0) When I go to API > App access control, and restrict Drive or Gmail, I have a couple of options. Restricted: Only trusted apps can access a service or the above + Restrict access to high-risk OAuth scopes only for Gmail and Drive Which should I select so things like "login with google" will still work?
DGardiner Posted October 10, 2020 Posted October 10, 2020 Almost there, got 99% of my settings down now :0) When I go to API > App access control, and restrict Drive or Gmail, I have a couple of options. Restricted: Only trusted apps can access a service or the above + Restrict access to high-risk OAuth scopes only for Gmail and Drive [ATTACH=CONFIG]59376[/ATTACH] Which should I select so things like "login with google" will still work? Restricted and tick the box 1
jthompson Posted October 10, 2020 Posted October 10, 2020 Which should I select so things like "login with google" will still work? IIRC, you can't stop "login with Google" from working, even if you wanted to. 1
TwistedHelixis Posted October 11, 2020 Author Posted October 11, 2020 @DGardiner - Just had a look at the Web Painter app in one of your screen shots. Now this might be a very handy little app, gives everyone the ability to draw or add text to any webpage. Cheers Think I might start a new post tomorrow - Must have Chrome / Android apps for school use.
TwistedHelixis Posted October 12, 2020 Author Posted October 12, 2020 Just double checking the device settings before handing all these Chromebooks out, and wanted to make sure I have 'Auto enrolment' setup properly and that I understand how it works. So I think it works like this for 'Forced re enrolment with user credentials. Provided I (the admin) have initially logged into the Chromebook and provisioned them, if a pupil then wipes their Chromebook the auto enrolment will kick in and re enrol it, but also leave the device in my 'Devices' OU I have crated. I think one of the other options moves the device to the users OU, which I really don't want.
DGardiner Posted October 12, 2020 Posted October 12, 2020 Just double checking the device settings before handing all these Chromebooks out, and wanted to make sure I have 'Auto enrolment' setup properly and that I understand how it works. [ATTACH=CONFIG]59382[/ATTACH] So I think it works like this for 'Forced re enrolment with user credentials. Provided I (the admin) have initially logged into the Chromebook and provisioned them, if a pupil then wipes their Chromebook the auto enrolment will kick in and re enrol it, but also leave the device in my 'Devices' OU I have crated. I think one of the other options moves the device to the users OU, which I really don't want. you want the top one, im not sure how they all behave in regards to placing the deivice. The one you have selected will require someone with permissions to re-enroll it. the top one just puts it straight back into google without any user intervention. Just power wash one after updating the policy and see what happens 2
TwistedHelixis Posted October 12, 2020 Author Posted October 12, 2020 you want the top one, im not sure how they all behave in regards to placing the deivice. The one you have selected will require someone with permissions to re-enroll it. the top one just puts it straight back into google without any user intervention. Just power wash one after updating the policy and see what happens I have just found a user setting that controls how the device is put back :0)
paulkerton Posted October 12, 2020 Posted October 12, 2020 Provided I (the admin) have initially logged into the Chromebook and provisioned them, if a pupil then wipes their Chromebook the auto enrolment will kick in and re enrol it, but also leave the device in my 'Devices' OU I have crated. I think one of the other options moves the device to the users OU, which I really don't want. Yes. You don't want it to move OUs. I would only use this for loan devices for users across multi-site settings, where they can work at multiple sites but do the same work at both.
TwistedHelixis Posted October 12, 2020 Author Posted October 12, 2020 Think I'm now ready to deploy all these Chromebooks. I am very grateful to everyone that has taken their time to help:0)
paulkerton Posted October 12, 2020 Posted October 12, 2020 The beauty of Chromebooks is that once they're setup, the general settings only really need to be altered if there are new settings available. It's very hard to break them or have an issue that requires the equivalent of gpupdate /force Hope it all goes well for you 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now