Jump to content

Recommended Posts

Posted

Hi all,

 

Just wondering how everyone else is managing 3rd party API access for their google domain/users. Are people just monitoring the "unconfigured" section and blocking access to that particular website/software.

 

Are you giving 3rd party apps trusted access, or limited access? I feel like it is a bit of a rabbit hole. I do not want to limit access if staff/students are using that particular website.

 

The only reason I am asking is mainly due to change google are implementing regarding 3rd party app access. If you have any OUs with an age label of < 18 they will not be able to access any of the "unconfigured" 3rd party apps (unless you configure the access e.g. trusted, limited, or restricted)

 

TIA - I hope everyone has a lovely weekend.

  • 3 weeks later...
Posted

I am setting it to (Default) Don't allow users to access any third-part apps.

In that way I will get informed of any sites that users are connecting to using their Google IDs. Approving them is a simple process so I am happy to stick to that for now.

  • Thanks 1
Posted

This is a major issue for some schools who have never looked at it before, and it is something to take to your DPO.

By using the school credentials to sign in to non-school related services, you are passing on school data to 3rd parties ... i.e. other data controllers. You might think that is ok for some sites, but what about all the chat sites that let you use Google accounts to sign in/create accounts?

The only '3rd parties' who should be able to do this, are your Data Processors ... companies you have signed up with and have agreements in place where you are in control.

Most GWfE are set up this way out of the box, but not all have been over the years. Google have provided guidance previously and there is a change coming up to force some of it too.

Posted
This is a major issue for some schools who have never looked at it before, and it is something to take to your DPO.

By using the school credentials to sign in to non-school related services, you are passing on school data to 3rd parties ... i.e. other data controllers. You might think that is ok for some sites, but what about all the chat sites that let you use Google accounts to sign in/create accounts?

The only '3rd parties' who should be able to do this, are your Data Processors ... companies you have signed up with and have agreements in place where you are in control.

Most GWfE are set up this way out of the box, but not all have been over the years. Google have provided guidance previously and there is a change coming up to force some of it too.

 

I have decided to block all access to 3rd party apps with Google accounts. Even for OU's labelled as over 18... this way I can just approve any manually if needed.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...