Preamble:
This space will be utilized to synthesize my notes and help improve my learning process while I study for the Google Workspace Professional Administrator certification. I will be doing a similar process for other certifications I work on in the future. Please follow along for Google Workspace notes and feel free to ask any questions or, if I get something wrong, offer suggestions to correct any mistakes.
Setup SSO with Google as an identity provider
Google Workspace supports SSO (Single-Sing On) as the Identity Provider (IdP) using SAML. This allows users to use their managed Google account to sign into enterprise cloud applications. You can configure SSO with Google Workspace either using over 200 third-party pre-integrated cloud applications as your service provider or you can set up your own custom SAML with enterprise cloud services with Google as the IdP.
If you are setting up SSO for SAML applications please note the settings in the following section:
Security> Overview> Set up Sign sign-on (SSO) fo SAML Applications:
You will see an SSO URL and Entity ID. These will be needed by the Service Provider (SP) as well as the Google Certificate that is found on this page. The certificate is used to establish trust between Google and the SP.
which allows the service to sync with your Google Workspace Directory.
.
NOTE:
You can add Network Masks to determine which addresses will be affected by SSO. This can be useful when you are testing your SSO integration. If no Netmask is configured, SSO will be applied to the entire network.
When using a third-party IdP the “Require password change” option for your users in the Admin Panel will be disabled
Only Chrome can verify that the certificate you upload is valid. Other browsers will not work.
Administrators signing into
When configuring Secure LDAP for an application, you can choose to allow access to the entire Organization or specific OUs to verify user credentials, read user information etc.
Please note that Secure LDAP is available to Enterprise and Cloud Identity Premium subscribers.
Admin . This will allow developers to interact with the Admin console to access objects like Users, groups, OUs etc.
It is recommended to restrict access to this API if you do not have any applications using it. To disable the API follow the steps below:
- Go to Security> Access and Data Control> API controls> Manage Google Services
- Find the Google Workspace Admin service and click Change Access
- Select Restricted
Before an application can gain access to a managed Google Workspace account the application must request access to the data it requires and the user must grant this access. This is completed during the application install and the flow of this access granting is known as the .
As a Google Workspace Administrator you are able to restrict access to specific API access. You can also create a trusted list of applications that can access disabled APIs. You can do the following steps in order to block API access to all applications except for a single application that you trust or apps that are made internally by your organization.
- Go to Security> Access and data controls> API Controls
- In the Settings section, make sure “Trust Internal Apps” is selected
- Select Trusted and click continue and then finish.
NOTE You can also choose to install to specific OUs or groups.
An alternative solution instead of installing apps for your users directly would be to utilize the Allowlist of apps for Marketplace applications. This can be done by
- Go to Apps> Marketplace Apps> Click on Allowlist App
- Search for your app and click select
- Click the option to either allow users to install the app or block users.
- Select the from the following options for allowing/blocking app installs:
- Everyone
- Specific Groups
- Specific OUs
- Click finish
Google Workspace has a robust Alert Center to help you navigate any potential issues with your domain. To access the Alert Center simply go to Security> Alert Center. You can alter Alert notifications here by going to Manager Alerts and Email Notifications. This will open up the Rules section of the Admin Panel like we explored previously. You can then change how/what you will want to be alerted about.
And with that this concludes Part 2 of the Google Workspace Security portion of the Workspace Professional Administrator exam. Thanks for coming on the journey with me. As mentioned above, if you have any questions for me or if I made a mistake, please leave me a comment and I would love to correct it or answer your question.
SOCIAL SHARE CARD GENERATOR