This official feed from the Google Workspace team provides essential information about new features and improvements for Google Workspace customers.


We are updating the administrative privileges setting for Windows device management to give administrators more control over how local administrative access is handled on Windows 10 and Windows 11 devices, managed by Google Endpoint Management.

This update simplifies settings and provides greater flexibility for organizations that need to preserve local admin access while managing specific users via Google Workspace. Previously, managing local administrative access used a "Replace" behavior, which removed any existing members from the local administrators group before adding the newly requested ones.

Getting started

Rollout pace

Availability

  • Business Plus
  • Enterprise Standard and Plus
  • Enterprise Essentials and Enterprise Essentials Plus
  • Frontline Starter, Standard, and Plus
  • Cloud Identity Premium
  • Education Standard and Plus
  • Endpoint Education add-on

Resources


What’s changing 

The Shared Signals Framework (SSF) is a community supported initiative of the OpenID Foundation, focused on developing and maintaining a standardized protocol for cross-system communication between security platforms to share security insights and events. To support the SSF initiative, Google Workspace is implementing a SSF Receiver to ingest Continuous Access Evaluation Profile (CAEP) signals. This feature is available in closed beta for Google Workspace customers and interested partners. Eligible customers and security platform providers can use this form to express interest in the closed beta

Who’s impacted 

Admins 

Why it matters 

Our closed beta of the Shared Signals Framework (SSF) offers an example use case: session revocation. When Google Workspace gets a signal to revoke a session, the user's session is automatically invalidated, which cuts down the time a potentially compromised user has system access. This highlights SSF's strength: enhancing security by improving cross-system communication and speeding up responses to security events. 

Getting started 

  • Admins: If you are a security platform interested in transmitting CAEP signals to Google Workspace, or a Google Workspace customer interested in testing the Shared Signals integration in your domain, please express your interest by filling out this form
    • Please note: While we are in a Closed Beta development phase, we intend to gradually onboard both security platforms and customers. Submission of the form does not guarantee acceptance to the Closed Beta. We will reach out to those who’ve submitted the form if there is availability. 
  • End users: There is no end user setting for this feature. 

Availability 

Available for Google Workspace: 
  • Enterprise Plus



What’s changing 

Admins can now apply Context-Aware Access (CAA) policies to apps which use OpenID Connect (OIDC), which are a subset of OAuth apps that are authenticated using Google sign-in. Admins can use a single setting to apply CAA policies to all OIDC apps by default. We are not providing per app access control for individual apps at this moment. The new OIDC setting can also be applied in monitor mode for admins to gauge potential end user impact before applying in active mode. 

CAA creates granular access control security policies for apps based on attributes, such as user identity, location, device security status, and IP address, and they can be applied to users on personal and managed devices. Expanding CAA to encompass OIDC apps means admins can ensure their users are able to access or are blocked from accessing these apps according to the broader security parameters of their organizations. 

Admins can configure CAA policies for OIDC apps in the Admin console under Security > Context-Aware Access > General settings 

Getting started 

  • Admins: CAA for OIDC apps can be configured at the OU level. Visit the Help Center to learn more about context-aware access, creating context-aware access levels, and assigning access levels to third-party apps
  • End users: If enabled by your admin, you can access certain apps when authenticating using your Google sign-in. Or you may see a message letting you know that you cannot use Google sign-in to authenticate with certain apps or you may see remediation messages which will provide some options on how to unblock apps. 

Rollout pace 


Availability 

Available for Google Workspace: 
  • Frontline Standard and Plus 
  • Enterprise Standard and Plus 
  • Education Standard and Plus 
  • Enterprise Essentials Plus 
  • Also available for Cloud Identity Premium 

Resources 

What’s changing 

Admins can now select “Warn” as an action when deploying context-aware access (CAA) levels. When applied, end users will see a warning message if they do not meet their admin defined conditions for accessing Google Workspace applications. They can click “See details” to see more information about why they received the warning – for example, they may be notified that their operating system is outdated and requires an update. The warning provides a useful reminder for the user to take action otherwise access could be blocked in the future. 

It’s important to note that “Warn” mode will not block users from accessing a particular app or service and they will have the option to proceed despite the warning. “Warn” mode helps educate users if they’re trying to access apps in a less secure situation and how to remediate this risk, while reducing the workload required by admins to socialize best practices. 
Example of a warning notification 


Example of what a user might see when they click “See details” 

Additional details 

  • Warning messages will be shown to users once every 48 hours if their device and session continues to not meet access levels to ensure minimizing end user friction. 
  • "Access Warning Sent” and “Access Warning Viewed by User” events can be reviewed in the CAA audit logs and in the security investigation tool for select Google Workspace customers. 

Getting started 


Admin app access level assignment flow

Rollout pace 


Availability 

Available for Google Workspace: 
  • Frontline Standard and Frontline Plus 
  • Enterprise Standard and Enterprise Plus 
  • Education Standard and Education Plus 
  • Enterprise Essentials Plus 
  • Cloud Identity Premium 

Resources 

What’s changing 

In 2019, we announced that a new Android management client, Android Device Policy, would replace the legacy Google Apps Device Policy client. We’re now in the final stages of this upgrade. 


All devices with the Google Apps Device Policy will lose access during March 2023 if they have not already upgraded. Existing Google Apps Device Policy app users must switch to Android Device Policy before then to continue syncing work data. Note that, per our last update, the new user registration flow on the legacy Google Apps Device Policy will be blocked and users may see errors during the registration process as of January 2022. Admins can act directly from the alert in the Admin console to identify users who need to upgrade.