Jump to content

Google Workspace Admin: Ascertaining who has accessed apps


Recommended Posts

Posted

Hi guys, would be keen to get to the bottom of this.

 

I have been working through the list of Apps users have requested to access and was quite surprised (in a primary school) that someone has tried to access Only Fans:doh:

 

If I visit Security>API Controls>App Access Control> Apps Pending Review, I can see 1 user has tried to access it. Is there any way to find out which user? I am expecting this must be a pupil account signed in to a device at home not owned by the school as we use Smoothwall and it has not detectected anything involving the words Only Fans as far as I can see. Very strange.

 

Screenshot 2025-01-30 150951.png

Posted

It could be that they have used a private unit and account and then chose to log in with Google and there selected the school account.

 

It is usually extremely much they want to use the school account instead of their own account.

 

Since it has probably been surfed via a private device, it is also not possible to know who it was that I know of.

  • Thanks 1
Posted
I've been doing this for our trust and ended up adding this as a feature request to Google. Would have been nice, as I had over 2000 apps to go through. If the user hadn't set up the app themselves, there was absolutely no way of seeing who was the actual users.
  • Thanks 1
Posted

Thanks guys. Yeah I am assuming this must be a private home device, but signed in on one of our pupil logins. It is not the sort of thing a primary school aged child would use so guessing an older sibling or adult in the family. Just didn't know if there was a way to narrow down who it was so we could look at reminding them of E-Safety guidance.

 

Thanks again. :o

Posted

Yes, we had OnlyFans, Tinder, etc.

 

Interesting... does anyone know the actual process that makes this happen? Is this a Google thing or a Chrome thing?

 

Private device, phone, tablet or computer... presumably the parents have these tabs open in the browser? Child opens new tab and logs in to school Google Workspace\Classroom, browser tries to log in the other tabs with this user account?

 

Or are we saying the child is trying to log in to OnlyFans with their Google Workspace account... does it have a log-in with Google SSO (honestly never looked... honestly)?

 

Either way, if you could find out who had done this, a phone call from the school to remind them of 'e-safety' may raise questions about how the school can see any information about anything that happens on their private device...

  • Thanks 1
Posted
Yes, we had OnlyFans, Tinder, etc.

 

Interesting... does anyone know the actual process that makes this happen? Is this a Google thing or a Chrome thing?

 

Private device, phone, tablet or computer... presumably the parents have these tabs open in the browser? Child opens new tab and logs in to school Google Workspace\Classroom, browser tries to log in the other tabs with this user account?

 

Or are we saying the child is trying to log in to OnlyFans with their Google Workspace account... does it have a log-in with Google SSO (honestly never looked... honestly)?

 

Either way, if you could find out who had done this, a phone call from the school to remind them of 'e-safety' may raise questions about how the school can see any information about anything that happens on their private device...

 

 

Like you, I would be interested to find out how this happens. If ever I get time, I will try and test it. Maybe on Tinder or similar.

Good point about parents raising concerns about how school can see what they are up to on private device but if they are signing in using a school tenancy, we have a duty of care to re-remind them of cybersecurity concerns. This is how compromises can occur and of all the schools I have worked with, this one in particular has an awfully high number of breached google accounts where pupils are logging in on compromised systems at home, which capture their login details and sell them on presumably on the dark web.

  • Thanks 1
Posted
I will try and test it. Maybe on Tinder or similar.

 

Purely for research purposes... ;) :p

 

 

Good point about parents raising concerns about how school can see what they are up to on private device but if they are signing in using a school tenancy, we have a duty of care to re-remind them of cybersecurity concerns. .

 

Completely agree, although it would obviously be the child signing-in to the device not the parent and I doubt the parents understand (as we don't fully). I also doubt very much anyone has reached out to the parents to advise them or explain that if they let a child sign-in on their device (possibly the only device in the house) it compromises both their device in terms of what we could potentially see and our Google Workspace from (as you say) their possibly compromised devices. I mean (apart from us maybe) who wouldn't let their child sign-in on the household device to let them do their homework?

Posted
... this one in particular has an awfully high number of breached google accounts where pupils are logging in on compromised systems ...

 

how do you identify breached accounts ? e.g. is it an audit process/report you run every week ?

Would be interested to know how you do it :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...