Jump to content

GSuite - 3rd party apps - API controls - Apps access control


Recommended Posts

Posted (edited)

After a discussion on another thread about how a certain app is hanging on to my Google account, I've opened (what may be) a can of worms...

 

Our GSuite login should only be used (as far as I'm concerned) for apps in GSuite that have been allowed and Adobe (which I set-up).

 

After trying to work out a sign-on with a newer version of the Smartboard software (signing-on with Gsuite log-in), I have been told it would have put itself without my knowledge into my Google account as a 'sign-on with Google' 3rd party app.

 

By 'without my knowledge' I freely admit that I mean I don't really know how it works...

 

So, with a little more research wondering if I can limit this sort of thing and not let them sign in to just anything with their school GSuite account, I was guided to

 

Google Admin > Security > API controls > App access control > Apps...

 

Not really expecting to find much there (but hoping to just find Smart maybe) I opened the page to find (to my horror) hundreds of apps!

 

From Spotify, NVIDIA, Gemsloot, Converter for Google Drive, Wish, Whatsapp, Zoom, Lucky Day, Project-312722122075, ZombsRoyale, ebay, Intruder Selfie, Prodigy Game, TikTok... honestly the list goes on forever...

 

What 'exactly' have I found...? Have all these been signed into with our school GSuite accounts? And is there some way I can stop it?

Edited by Koldov
Posted

I am no expert but believe if you open the page that lists each of the Google API services (Gmail, Calander etc) you can and should edit each one so it's listed as restricted. For the first two, Drive & Gmail you want restricted but with Auth0 also selected.

 

This lets some 3rd party apps use the account but blocks those 3rd party apps from accessing data, unless you allow it.

 

This is what I have been told recenlty.

  • Thanks 1
Posted

I'm glad I spotted this thread; just looked through mine and 3 people had linked their school accounts to OnlyFans.com :embarassed: :censored:

Shame it doesn't tell me who it was :laugh:

Posted
I am no expert but believe if you open the page that lists each of the Google API services (Gmail, Calander etc) you can and should edit each one so it's listed as restricted. For the first two, Drive & Gmail you want restricted but with Auth0 also selected.

 

This lets some 3rd party apps use the account but blocks those 3rd party apps from accessing data, unless you allow it.

 

This is what I have been told recenlty.

 

Thanks I will look into this, any chance you could share the link with this info? I'm not sure where you mean and I don't want to do anything without knowing what will happen.

 

Shame it doesn't tell me who it was

 

Do you mean which user, or which OnlyFans page...? :p

 

Seriously though why doesn't it tell you...?

 

I'm not getting a lot of feedback from this thread on what is actually going on, so do you mean that this is actually what is happening?

 

Are all these apps are now sitting in the 3rd Party App as 'sign-on with Google' for my users school GSuite accounts?

 

Is it a 'bad' thing?

 

If so is there anyway to stop it?!

Posted
Thanks I will look into this, any chance you could share the link with this info? I'm not sure where you mean and I don't want to do anything without knowing what will happen.

 

 

 

Do you mean which user, or which OnlyFans page...? :p

 

Seriously though why doesn't it tell you...?

 

I'm not getting a lot of feedback from this thread on what is actually going on, so do you mean that this is actually what is happening?

 

Are all these apps are now sitting in the 3rd Party App as 'sign-on with Google' for my users school GSuite accounts?

 

Is it a 'bad' thing?

 

If so is there anyway to stop it?!

 

 

you can block it by getting the clientid and blocking it presumably in the api controlls, anything anyone in your domain has used should popup there

Posted

There are over 150 apps... :mad:

 

OMG! Just checking through the list (which by the way I can't seem to export to csv or actually do anything useful with)...

 

and I have spotted OnlyFans.com too! :(

 

I can't easily tell if some of the others are students or teachers, whether the apps are legitimate or useful or potentially dangerous... :confused:

 

What a mess, surely something like this should be 'off' by default...?

Posted

you should be able to find the users, i know you can see on each users profile what apps they have linked.

 

 

And no oath is too useful to play whitelist only, lets face it - the alternative would be they have put their email address in which is just as likely not explicitly filtered on any of our domains... until youre prompted to

Posted
if you go into google admin, reports and under auduit log in token i think that shows api accesses, if you search the of clientid or name there you should see who and what
  • Thanks 2
Posted (edited)

So, out of over 55,000 entries in the 'Token' log, I've managed to narrow it down to the 150 apps that have been user authorised...

 

Why are they able to do that by default?

 

Now I have to work out which ones are harmless or legitimate... Or do I somehow block this sort of thing entirely, whitelist and only allow GSUITE apps to be signed into?

 

How do I even do that?

 

Also, I'm thinking that a couple of these now I know about them, is going to mean a visit to the Safeguarding lead... Anything else in the list jump out to anyone?

 

3P Learning (Mathletics, Spellodrome & IntoScience)

Adobe

Adobe Acrobat Reader

Adobe Identity Management

Adobe Photoshop Express

Agar.io

Amazon

Amazon Influencer Program

Amino Apps

AnimeStar

Answers

ASIA Wargaming.net

Atlassian

Auth

Babbel

Basecamp 3

BeFunky Photo Editor

BIGO LIVE

BlockSite

Boosted

Brainscape App

Brilliant.org

busuu

Call of Duty: Mobile

Call of Duty®: Mobile

ClassDojo

CloudConvert

Code.org

Connekt Earning

Converter for Google Drive Document

Daily Life

Desmos

Discord

DocHub - PDF Sign & Edit

Duolingo

eBay

Edpuzzle

Education.com

EmojiPro

EnhanceTV

Epic Games, Inc.

Episode

Fandom Web Login

FormsApp

Gamekit

Gazzetta Lavoro

Gemsloot

GeniusU

GoDaddy Login

Google Developer Docs

GrabPoints

Grammarly

Hero Wars Web

Honey

Hordes.io

Huawei Email

IMDb

iMovie

Indeed

Intruder selfie1

JusTalk

Kahoot!

Kami

Khan Academy

KineMaster

Loom

LoveCrafts

Lucky Day

Lumin PDF

Magisto

Mathway

MCProHosting Client Area Sign-In

Medium

Memrise

Merc Zone

mote

My Files

MY.GAMES

Nintendo Account

NVIDIA

OfficeSuite

OneVOne

OnlyFans.com

Padlet

PAGO

Paint By Number

Pandai.org

Patreon

paypal.com

PDF Viewer

PicsArt Photo & Video Editor

Pinterest

Pokémon GO

PowerDirector

Prodigy Game

project-312722122075

project-669122138973

project-982260418824

PurpleMash

QR Code Generator PRO

Quizizz

Quizlet

Quora

Record To Slides

Remini

Riot Accounts

Roblominer

SAMSUNG Account

Samsung Email

Sequin Diary with Lock

Shell Shockers

Shimejis.xyz

Showbie

Simkl

Simply Piano

Sing Google

Smallpdf

SportPursuit

Spotify

SS_Android

Stadia

TES

The New York Times

Thunkable

TikTok

Tiya

Trivia Royale

Ubuntu

University of Michigan Center for Digital Curricula

Vimeo

Vimo

VLive

Wattpad

WEBTOON

WeVideo

Wish

wormate.io

Xsolla Login

YouTube Kids

YouTube on TV

YouVersion

Z5 Global

ZEE5

ZIP Extractor

Zoho Accounts

Zoho Show

Zoho Writer

ZombsRoyale

Zoom

Edited by Koldov
Posted

If you go https://admin.google.com/ac/owl and click manage google services, you can set the scopes to be open or restricted(require whitelist) im not sure which is oauth - im presuming gmail.

 

We have it set to Restricted - High-Risk Access, this allows oath logins, but anything that wants to put fingers into your actual account data needs to be on the whitelist.

 

Presumably you could set this to restricted all together and it would stop anything not google or on the whitelist, just be aware if youre using google login on anything not google youre probably in for a few days of hassle

  • Thanks 1
Posted (edited)

Ok, so let me see if I've got this straight...

 

Go to: Google Admin > Security > API Controls > App access control

 

Click on: Manage Google Services

 

Set 'Drive' and 'Gmail' to Restricted (Restrict access to high-risk OAuth scope only for Gmail and Drive)... set everything else to 'Restricted'.

 

Then click on 'Apps'... Is this the 'Whitelist'...? Because it feels more like a Whack-a-Mole Blacklist... I just have to wait for them to pop-up here and block them...?

 

Go through the 150 apps and 'Change access' for each one to 'Trusted', 'Limited' or 'Blocked' (depending if it's legitimate or not)...

 

So, this will stop the 3rd party apps on that list accessing account data... then, how do I stop it happening going forward? :confused:

 

This is a ball-ache! Surely there must be a way to stop little Freddie (name changed to protect the 'not so innocent') being able to sign-in to OnlyFans with his school GSuite account!!! :mad:

Edited by Koldov
Posted (edited)
So, this will stop the 3rd party apps on that list accessing account data... then, how do I stop it happening going forward?

 

Doesn't the fact all the apps (Gmail, Drive etc) are now set to restricted mean any new 3rd party apps are blocked from the data automatically.

 

EDITED to make sense

Edited by TwistedHelixis
Posted
Ok, so let me see if I've got this straight...

 

Go to: Google Admin > Security > API Controls > App access control

 

Click on: Manage Google Services

 

Set 'Drive' and 'Gmail' to Restricted (Restrict access to high-risk OAuth scope only for Gmail and Drive)... set everything else to 'Restricted'.

 

Then click on 'Apps'... Is this the 'Whitelist'...? Because it feels more like a Whack-a-Mole Blacklist... I just have to wait for them to pop-up here and block them...?

 

Go through the 150 apps and 'Change access' for each one to 'Trusted', 'Limited' or 'Blocked' (depending if it's legitimate or not)...

 

So, this will stop the 3rd party apps on that list accessing account data... then, how do I stop it happening going forward? :confused:

 

This is a ball-ache! Surely there must be a way to stop little Freddie (name changed to protect the 'not so innocent') being able to sign-in to OnlyFans with his school GSuite account!!! :mad:

Youre over complicating it.

 

Access

Trusted: Can access all Google services

Limited: Can only access unrestricted Google services

Blocked: Can't access any Google services

 

 

So if you flick the restricted buttons on the services.

 

the apps should be limited by default so they will now be blocked(on the restricted services), anything you want to work you need to set to Trusted.

 

 

If you need to enable anything going forward, when they try to login it will present an error report. saying what scopes the app is requesting and a client id - you can use the client id to manually add them to the list

  • Thanks 1
Posted (edited)
Doesn't the fact all the apps (Gmail, Drive etc) are now set to restricted mean any new 3rd party apps are blocked from the data automatically.

 

I was just hoping to find a way to just stop them signing-in to random apps.

 

But I think you're right, I was just questioning the way it works as I wasn't really understanding the 'data' part.

 

I'm hoping if it works the way @DGardiner is explaining it, the 'data' part means the 'account' and not just the 'data' in it... just me getting confused about the terminololgy I guess (hope)?

 

Youre over complicating it.

 

Story of my life...

 

OK, think I've got it!

 

Apps that appear in the '3rd party' list because they have been signed into by a user only ever appear as 'Limited' by default...

 

Setting all the 'Google Services' to 'Restricted' means users will not be able to 'Sign-in with Google' to any other random 3rd party apps?

 

Because the apps will not get permission to access the 'data/account' and will error.

 

Nothing else will now appear in the list, but I can add them manually.

 

Can I presume all 'Google Workspace apps' (assignments, docs, sheets, slides, meet, etc.) will automatically be trusted?

Edited by Koldov
Posted (edited)
I was just hoping to find a way to just stop them signing-in to random apps.

 

But I think you're right, I was just questioning the way it works as I wasn't really understanding the 'data' part.

 

I'm hoping if it works the way @DGardiner is explaining it, the 'data' part means the 'account' and not just the 'data' in it... just me getting confused about the terminololgy I guess (hope)?

 

 

 

Story of my life...

 

OK, think I've got it!

 

Apps that appear in the '3rd party' list because they have been signed into by a user only ever appear as 'Limited' by default...

 

Setting all the 'Google Services' to 'Restricted' means users will not be able to 'Sign-in with Google' to any other random 3rd party apps?

 

Because the apps will not get permission to access the 'data/account' and will error.

 

Nothing else will now appear in the list, but I can add them manually.

 

Can I presume all 'Google Workspace apps' (assignments, docs, sheets, slides, meet, etc.) will automatically be trusted?

 

Ive never added any workspace apps and had no issues - though i have gmail/drive set to restricted on high risk scopes which just stops apps reading emails/drive files etc but still allows oauth

 

 

i think "data" in this context is connecting to the api scopes,

 

https://developers.google.com/apps-script/api/reference/rest

Edited by DGardiner
Posted
Well this is a fun topic, glad I stopped by as I also found onlyfans! To confirm you can easily find who has given access by going; Reports > Audit > Token > Search by Application Name
Posted

OK, so three further things...

 

Firstly, please shout if you think this is a safeguarding subject...?

 

I have reported, but I'm wondering if I'm being a little OTT...

 

Secondly... I am well aware (before the trolls arrive), the little darlings are more than capable of creating their own email account and signing up to whatever site/app they choose... but there is no way in hell I'm allowing them to do it with their school associated account...ok?

 

Thirdly, can this be anymore fine-grained? As in allow the app, but only for teacher accounts...?

Posted
Thirdly, can this be anymore fine-grained? As in allow the app, but only for teacher accounts...?

 

You want the teachers to have onlyfans accounts? ;)

 

From what I can tell it's domain wide only.

Before you restrict access to the Google Workspace Admin section btw check what's using it. GAM appears there so you'll need to trust it so you don't break anything you might be customizing.

  • Thanks 1
Posted
Well this is a fun topic, glad I stopped by as I also found onlyfans!

 

Yes, unfortunately the thread title isn't very attention grabbing and I'm sure it will soon be lost under the weight of other more important issues (SIMS or MS updates probably)... :p

 

Maybe I should create a thread with the title 'OnlyFans' and see how many views it gets...? ;)

 

Interesting to see how many others didn't know about this, I was feeling a little down about being unaware (#imposter syndrome, #don't know what I don't know,# how many systems do I have to know inside out etc, etc.)... :(

Posted

So I've set all Google Services to restricted and gave trust to those apps that I deemed appropriate. By default the setting for all the currently listed apps is set to "limited".

 

I tested logging into onlyfans with the restrictions set and the access to limited and it didn't perform an API request however it still created an account and let me login using a Google account.

So I believe the apps in that list need to be set to blocked to disable the creation of an account using their Google login.

Posted
So I've set all Google Services to restricted and gave trust to those apps that I deemed appropriate. By default the setting for all the currently listed apps is set to "limited".

 

I tested logging into onlyfans with the restrictions set and the access to limited and it didn't perform an API request however it still created an account and let me login using a Google account.

So I believe the apps in that list need to be set to blocked to disable the creation of an account using their Google login.

 

Not sure how it all works, it may be the case for oath login things that its the act of extracing data that requires permission is if its done its done so logins will continue to work?

 

Wonder if theres a delay from changin settings to it affecting

Posted
Well this is a fun topic, glad I stopped by as I also found onlyfans! To confirm you can easily find who has given access by going; Reports > Audit > Token > Search by Application Name

 

So I've set all Google Services to restricted and gave trust to those apps that I deemed appropriate. By default the setting for all the currently listed apps is set to "limited".

 

I tested logging into onlyfans with the restrictions set and the access to limited and it didn't perform an API request however it still created an account and let me login using a Google account.

So I believe the apps in that list need to be set to blocked to disable the creation of an account using their Google login.

 

Not sure how it all works, it may be the case for oath login things that its the act of extracing data that requires permission is if its done its done so logins will continue to work?

 

Wonder if theres a delay from changin settings to it affecting

 

Can confirm that changing 'all the things' had no effect...

 

From what I can see, the third party app that is 'Limited: Can only access unrestricted Google services' and depending on what the app is requesting will depend on if it is blocked or not...

 

Take 'SMART' for instance, it is requesting 3 'scopes':

 

View your email address

 

See your personal info, including any personal info you've made publicly available

 

Associate you with your personal info on Google

 

Maybe there is another way to block this info being seen/requested, but I guess none of it is in the Google Services that have been restricted, so it won't be blocked from creating an account/'Signing in with Google'...?

 

However, I think(?) if it requested access to Drive, Calendar, Contacts, etc.

 

Then it will get stopped (or as you say - wait until it appears and block it - so I was right with Whack-a-Mole)...

Posted (edited)
Not sure how it all works, it may be the case for oath login things that its the act of extracing data that requires permission is if its done its done so logins will continue to work?

 

Wonder if theres a delay from changin settings to it affecting

 

You may be right...

 

So forget my answer above!

 

Disappointingly, I have also just managed to sign-up to something called 'Lumin PDF' (didn't want to try OnlyFans) which requires 'Drive' access.

 

It is already on the list of 3rd Party apps, but I've set it to 'Limited' and the 'Google Service' for 'Drive' is set to 'Restricted - High-Risk Access'.

 

Created a document and uploaded it to my Google Drive...

 

Audit log for Token:

 

*USER* authorized access to Lumin PDF for

openid, ht tps://www.googleapis.com/auth/userinfo

profile, ht tps://www.googleapis.com/auth/userinfo

email, ht tps://www.googleapis.com/auth/drive.appdata

ht tps://www.googleapis.com/auth/drive.file scopes

 

In the Google Services tab it also still says 15 allowed apps for Drive.

Edited by Koldov
Posted
Checked my sites and nothing beyond some EDU apps (phew!). If the bold apps are "worrisome", I'd argue that many legit artists use Patreon (Professor Elemental and Abney Park often push it).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...