The Google Workspace Admin gives IT/Security teams three options when it comes to governing 3rd party OAuth Tokens:
1. Block of any installations of OAuth Apps. This can clearly slow down business enablement as modern workforce teams are used to sign up with their Google account to 3rd party services required to get things done.
2. Allow any installations of OAuth Apps. While this is great from a business enablement standpoint, it is a disaster for security teams since employees can accidentally install overprivileged, malicious, and risky OAuth tokens. Higher likelihood of API access by unwanted 3rd party services without any security review/governance.
3. Maintain a list of Trusted/Limited OAuth Apps. On paper this sounds like the most balanced option, but it comes with an insane cost. Employees install thousands of OAuth Apps across literally every single department and job. It's very hard to expect from a small security team to now manually maintain a list of trusted OAuth Apps, as this is highly time consuming as well as error-prone.
The solution? DoControl.
1. Full discovery of all of your user and admin based OAuth Apps installations.
2. Real-time risk profiling of OAuth Apps based on threat intelligence, SaaS databases, permission scopes, usage, etc.
3. Security workflows breaking down and segmenting OAuth Apps across risk-level, employment status, IDP groups, HRIS department, permission scopes, etc. to streamline various actions, such as approval processes via Slack/ServiceNow, time-bounded installation, or immediate removal of the OAuth app.
Try our Free Risk Assessment to quantify your Google Workspace data exposure, insider threats, misconfigurations, and risky OAuth apps:
https://lnkd.in/dK3PPVbw
???? #GoogleWorkspace admins can block, trust, or limit app access with the Google Admin console. Trusted apps access all services, while limited apps access only unrestricted services. Learn more in this tutorial ↓ https://goo.gle/3SmWDnI
7x Certified Professional Google Workspace Administrator
7 个月One of the best feature in terms of safety