Comments and action items are now available for client-side encrypted Google Sheets and Slides

What’s changing

We’re pleased to announce that the use of comments and action items are now available in client-side encrypted Google Sheets and Slides. This includes the ability to add, edit, reply, filter, or delete comments, as well as assign action items to yourself or others. This is already available for client-side encrypted Google Docs. Expanding this functionality to Sheets and Slides makes it easier to collaborate across encrypted documents.

Using comments in a client-side encrypted sheet

Additional details

Note that when sharing encrypted files, you can only assign “viewer” or “editor” permissions. “Commenter” permission is not supported. Viewers can view comments. Comments are saved each time the document is autosaved. If you restore the document to a previous version, the comments added to the document in that version are also restored.

Getting started

Admins: Client-side encryption can be enabled at the domain, OU, and Group levels (Admin console > Security > Access and data control > Client-side encryption). Visit our Help Center to learn more about client-side encryption.End users: If client-side encryption is enabled by your admin, use our Help Center to learn more about working with encrypted files in Drive, Docs, Sheets & Slides.

Rollout pace

Rapid Release domains: Extended rollout (potentially longer than 15 days for feature visibility) starting on October 2, 2024Scheduled Release domains: Extended rollout (potentially longer than 15 days for feature visibility) starting on October 12, 2024

Beta update: Data Loss Prevention enforcement in Gmail is now instantaneous

What’s changing 

Today, we are announcing enhancements for the Data Loss Prevention for Gmail open beta, which are designed to improve usability without compromising sensitive data protections for Gmail. Once deployed, users will receive instant notifications on risks to applicable DLP policies prior to leaving their inbox, instead of having DLP rules evaluated after the message has already left the inbox. In addition to more timely user feedback, this capability, called synchronous DLP, helps educate users about the potential risk of leaking sensitive information. 
We’re also introducing a new action for DLP rules, “Warn”, which will notify users about potentially sensitive data while providing the option to send the message based on a user’s assessment of a risk. For added safety, the DLP service will scan messages one additional time after they leave the sender’s mailbox.

Who’s impacted

Admins and end users

Why it matters 

Data breaches are one of the most common and costly security issues facing organizations. Often these breaches originate from within an organization by unintentional or intentional actions by their users. Data loss prevention capabilities help prevent this exfiltration of data and helps guide users about what information to share. To help safeguard sensitive information, organizations can create and enforce policies that not only detect and block sensitive information from being shared, but educate users on what information sharing is or is not appropriate and how to be compliant with those guidelines. Specifically, data loss prevention rules can look for sensitive text stings, custom detectors, or predefined detectors in outgoing messages sent internally or externally. 
The latest update for data loss prevention rules in Gmail brings the experience in line with Google Drive and Google Chat, which are already adopted broadly by Google Workspace customers. You can refer to our Help Center for more information about data loss prevention in Gmail.

Additional details

Customizable warning messages
DLP rules can be configured to block the message, warn users about sensitive information, or quarantine the message. When sensitive information is detected, users will be shown a dialog box notifying them of the risk. Admins can now choose to customize the information shown to end users in these dialog boxes, including why their message was flagged, what they can do to unblock themselves, and links to additional resources to educate them further.
Example of a custom warning message
Continued asynchronous scanning of messages
While messages will now be scanned synchronously, messages will go through additional scanning asynchronously (after the message leaves the inbox) for an additional layer of protection. This includes messages that are sent automatically, such as auto-forward or scheduled send, and messages sent from non-Gmail clients.

Getting started

Admins:Data loss prevention in Gmail is available in open beta for select Google Workspace customers. These rules can be configured at the domain, OU, or group level. DLP rules can be enabled in Gmail in the Admin console under Security > Access and data control > Data protection. Note that with the new synchronous scanning, your end users will begin seeing dialog boxes related to these rules before messages leave the inbox. These will be displayed when using Gmail on the web and mobile.

Visit the Help Center to learn more about controlling sensitive data shared in Gmail. Note that you can modify existing DLP rules for Drive and Chat to also apply to Gmail. 

DLP events can be reviewed in the Security Investigation Tool or Security > Alert Center, if alerts are configured in rules.

We recommend selecting “Audit only” when you’re setting up a new rule in order to test and monitor its performance, or to passively monitor the environment without interrupting email flow for your users. There are no changes to the “Audit only” action with this update, they will continue to operate as usual.

End users: Depending on the data loss prevention rules configured by your admin, you may see a dialog letting you know that:

Your message is blocked: Your message contains information that cannot be shared — you’ll need to remove it in order to send your message.

Dialog in case of a blocked message

Your message contains sensitive information: Your message contains information that is sensitive, but can be shared — you can decide whether to send it or edit the message to exclude this information. Note that your admin will be notified about this activity.


Dialog in case of a warning

Your message contains sensitive information that requires review: Your message contains information that will need to be reviewed by an admin. You’ll have the option to submit it for review, and upon review it will be released for delivery or declined. You may receive a notification about the message being declined from delivery.


Example of a quarantine message

Rollout pace

Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on October 7, 2024

Availability

Available for Google Workspace:
Enterprise Standard, Enterprise PlusEducation Fundamentals, Standard, Plus, and the Teaching & Learning UpgradeFrontline StandardCloud Identity Premium customers

Resources

Gmail Q&A now available on iOS devices

What’s changing

Last month, we introduced a new way of searching your inbox with Gemini on Android devices. Starting today, this feature is also available on iOS devices, enabling you to ask Gemini questions about your inbox. Gmail Q&A can help you answer specific questions about your emails, show you unread messages or messages from a specific sender, summarize emails about a topic in your inbox, and even answer general questions from search, all without having to leave your inbox.

Who’s impacted 

End users 

Why it matters

We are excited to help users supercharge their productivity with the help of Gemini in Gmail. Users now have even more capabilities from Gemini to help users get more done during their day at their desks and now, on the go. 

Getting started

Admins: To access Gmail Q&A on Android, users need to have smart features and personalization turned on. Admins can turn on default personalization setting for their users in the Admin console. End users: Open Gemini in the Gmail app via the black Gemini star at the top right of your app or from a “summarize this email” chip. To start, Gmail Q&A can find information from your inbox. In the future, it will be able to find information from your Drive as wellNote: Gmail Q&A is currently available in English only.Visit the Help Center to learn more about Gemini in Gmail.

Rollout pace 

Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on October 3, 2024

Availability 

Available for Google Workspace customers with these add-ons: 
Gemini Business, Enterprise, Education, Education Premium Google One AI Premium 

Resources 

New Watermarking in Google Meet Helps Protect Your Meeting Content

What’s changing 

Google Workspace customers with a Gemini add-on can now watermark presented content and video feeds in Google Meet. Watermarking in Google Meet will appear as a subtle text overlay that displays the meeting code and the email address of the viewer over the shared content and video feeds of participants. Using a watermark can help discourage unauthorized copying and sharing, protecting both users’ video images and content shared during meetings. Hosts and co-hosts can turn on watermarking at any time in the meeting. Once watermarking is turned on, it shows on all participants’ screens.

Additional details

Watermarking is available  to meeting participants signed into a Google account using the latest Chrome browser, Android or iOS apps, or Google Meet hardware devices. Only participants using supported browsers and apps will see video feeds when watermarking is turned on. 
Additionally, watermarking cannot be used when recording a meeting or live streaming a meeting. If you turn on a recording during a meeting, you’ll see a dialog box notifying you that watermarking stops when recording starts.

Getting started

Admins: There is no admin control for this feature.End users: To turn watermarking, go to Host controls > Add a watermark. Visit the Help Center to learn more about how to apply watermarks to your meeting.
Host controls > Add a watermark

Rollout pace

Rapid and Scheduled Release domains: Extended rollout (potentially longer than 15 days for feature visibility) starting on October 3, 2024

Availability

Available for Google Workspace customers with these add-ons: 
Gemini Enterprise Gemini Education Premium AI Security AI Meetings & Messaging 

Resources

Additional iOS data exfiltration enhancement: account level data sharing between Google Workspace apps and non-Google Workspace apps on or off

What’s changing 

Admins can now enable content sharing on personal Workspace accounts while preventing data sharing from corporate Workspace accounts on iOS devices.

Additionally, admins can now prevent data sharing from unknown sources (typically non-Google Workspace apps) to personal Workspace accounts on Gmail, Drive, Docs, Sheets, Chat, and more, by setting a managed configuration
The {customer_id} is a unique customer ID that’s assigned to your account. You can find it in your Admin console at Account > Account settings > Profile.

Getting started

Admins: Blocking sending of work data to personal apps, including all non-Google Workspace apps on the iOS share sheet, will be OFF by default and can be enabled at the OU level. These settings can be configured in the Admin console under Devices > Mobile and endpoints > iOS settings > Data Sharing. Visit the Help Center to learn more about data protection on iOS devices. Use this article in our Help Center to learn more about how to set up the managed configuration, go to set up iOS apps with managed configurations.

End users: Sharing of data between Google Workspace apps and non-Google Workspace apps depends on your admin configuration. If you’re unable to share data between apps, you may see a warning message. Visit the Help Center to learn more about how your iOS device is managed.

Rollout pace

Rapid Release and Scheduled Release domains: Full rollout (1–3 days for feature visibility) starting on September 19, 2024

Availability

Available for Google Workspace:
Enterprise Standard and PlusEducation Standard and PlusEnterprise Essentials PlusFrontline StandardCloud Identity Premium

Resources

Create birthdays in Google Calendar

What’s changing 

Currently, Google Calendar automatically pulls in birthday information from Google Contacts. However, it is not currently possible to create birthday events directly in Calendar. 
To ensure a birthday is never missed, we’re introducing the ability to create and modify birthday events in Google Calendar on Android devices. 
For developers, newly created birthday events will be available in the Calendar API with the eventType “birthday.” Both Events.list and Events.watch will support the “birthday” event type filter and return “birthday” events by default. Only a subset of the event properties will be supported for birthday events. To learn more, see our developer guide about working with the birthday event type.

Who’s impacted

End users and developers 

Additional details 

Birthday events do not support all event properties. If you’re using the Calendar API, we recommend reviewing your code so you don’t apply any non-supported properties. 
Creating dedicated birthday events in Google Calendar will also become available on web and iOS devices in the future. 

Getting started 

Admins: There is no admin control for this feature. End users: There is no end user setting for this feature. Visit the Help Center to learn more about managing birthdays on your calendar. Developers: Use our developer guide about working with the birthday event type. 

Rollout pace 

Web: 
Rapid Release domains: Gradual rollout (up to 15 days for feature visibility) starting on September 19, 2024Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on October 9, 2024 
Mobile: 
Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on September 24, 2024 

Availability 

Available to all Google Workspace customers, Workspace Individual Subscribers, and users with personal Google accounts. 

Resources 

Empowering Google Workspace customers to take control of their emissions with Electricity Maps

What’s changing

To help our customers continue to understand and measure the carbon intensity of their cloud computing, we have partnered with Electricity Maps to provide hourly emissions data within the Carbon Footprint report. Since we launched the Google Workspace Carbon Footprint report at Cloud Next 2023, we have continued our collaboration with Electricity Maps to further help users understand their emissions. Directly within the Admin console, admins can track the carbon footprint and emissions of using Google Workspace, down to specific tools such as Google Meet, Gmail, Google Docs, and more. 

We’ve also added a new admin role for accessing Carbon Footprint reports. Previously, only Workspace admins with reporting privileges had access to the carbon footprint dashboard. However, we know our customers have specialists, such as a dedicated Sustainability team, who rely on this information to inform their work. Now, admins can grant access to the Workspace Carbon Footprint report to select users by creating a custom role

Who’s impacted

Admins

Why it’s important

Cloud computing has immense significance for powering global business operations and innovation. But, in a world facing the accelerating impacts of climate change, it is increasingly important to keep an eye on its environmental impact. The dynamic and global nature of cloud computing creates challenges for precisely measuring its emissions and requires granular data that captures the carbon emissions of electricity at every hour in locations around the world. Partnering with Electricity Maps gives our customers a way to monitor their cloud emissions over time by product — giving IT teams and developers the high quality metrics they need to monitor, improve, and reduce their carbon emissions.

Electricity Maps gathers real-time and historical power generation and power exchange data from multiple sources around the globe, calculating the hourly consumption mix available on the grid and its carbon intensity. Electricity Maps follows a highly granular approach, combined with a transparent and scientific methodology and a strict collective vetting process of their open-source community. This guarantees high-quality and trustworthy data that aligns with Google’s ambition for a realistic and science-backed perspective on climate impact. For maximum transparency, emissions can be viewed on either location-based or market-based Scope 2 accounting standards. Location-based emissions show the emissions linked to the actual electricity used for the operations, whereas the market-based emissions represent emissions from the purchased electricity, including Google’s annual renewable energy purchases.  More information about the methodology behind Google’s Workspace and Cloud Carbon Footprints can be found here

Additional details

More about Google’s sustainability commitments
In 2020, we set a goal to run on 24/7 carbon-free energy—every hour of every day on every grid where we operate—by 2030. We continue to make product and operational improvements to reduce environmental impact and we’re sharing technology, methods, and funding to enable organizations around the world to transition to more carbon-free and sustainable systems — see here for more information about our sustainability commitments.
Google uses the Greenhouse Gas Protocol, the global standard for carbon accounting to generate the Workspace Carbon Footprint reports. We recommend that admins familiarize themselves with the GHG terminology — you can find more information in our Help Center or the video below.

Getting started

Admins: You can find your Carbon Footprint report in the Admin console under Reporting > Carbon footprint. Visit the Help Center to learn more about the Workspace Carbon Footprint.

Rollout pace

Availability

Available to all domain verified Google Workspace customers

Google Workspace Updates Weekly Recap – September 6, 2024

1 New update

Unless otherwise indicated, the features below are available to all Google Workspace customers, and are fully launched or in the process of rolling out. Rollouts should take no more than 15 business days to complete if launching to both Rapid and Scheduled Release at the same time. If not, each stage of rollout should take no more than 15 business days to complete.

Improved user experience for Google Meet on Android devices
If you’re joining a Google Meet call from Android phone, tablets or large screen devices, you’ll now see a more streamlined, space-efficient experience with edge-to-edge video. We’ve expanded the video feed to encompass spaces where there were previously margins around the video feed. This helps provide a richer, more immersive viewing experience. You’ll also notice a sleeker user interface for meeting controls, and clearer indicators for information such as the meeting title. | Rollout to Rapid Release and Scheduled Release domains is complete. | Available now for all Google Workspace customers, Workspace Individual Subscribers, and users with personal Google accounts. | Visit the Help Center to learn more about joining a meeting.

Previous announcements

The announcements below were published on the Workspace Updates blog earlier this week. Please refer to the original blog posts for complete details.
Gemini (gemini.google.com) now shows related content links in its responses 
You can now access additional information on topics directly in Gemini’s (gemini.google.com) responses to your prompts. Specifically, you’ll see links to related content in responses to fact-seeking prompts — you can click the arrow chips to dive deeper into the topic. If you have a Gemini for Workspace license and Google Workspace extensions in Gemini are enabled, Gemini will also now include inline links to relevant emails referenced in responses where the Gmail extension is used. | Learn more about related content links shown in Gemini.
View your most relevant Google Drive folders and files on a single page 
You will now see a combined, unified view for file and folder suggestions on the Drive homepage that leverages machine learning to help you find and organize your most relevant content faster and intuitively. | Learn more about the view in Drive.
Empowering Google Workspace customers to take control of their emissions with Electricity Maps
To help our customers continue to understand and measure the carbon intensity of their cloud computing, we have partnered with Electricity Maps to provide hourly emissions data within the Carbon Footprint report. | Learn more about Electricity Maps. 

Completed rollouts

The features below completed their rollouts to Rapid Release domains, Scheduled Release domains, or both. Please refer to the original blog posts for additional details.

Scheduled Release Domains: 
Rapid and Scheduled Release Domains: 

For a recap of announcements in the past six months, check out What’s new in Google Workspace (recent releases).  

Gemini reports now include user-level usage, including app usage insights

What’s changing 

We’re incorporating additional data in Gemini reports to help our customers gain a deeper understanding of Gemini usage and adoption across their organizations. 
Gemini reports now include user and app level Gemini usage and adoption data based on the last 28 days of usage. These insights can help admins identify power users in their organization, whom they can tap into for practical use cases and best practices, which can then be shared broadly with other users to drive adoption. Identifying users with lower adoption rates is equally important and can provide helpful context for creating training, change management programs and materials, and more. 

From Menu > Generative AI > Gemini Reports > User-led usage you can track active Gemini usage days and how that usage is spread across various apps. You can also export this information for further analysis.

As of August 22, usage of gemini.google.com is now captured in the org-level usage portion of the report under the “Chat with Gemini” label, as well as in the new user-level usage reports. Including gemini.google.com usage and adoption information provides a more complete picture of how users are interacting with all Gemini tools across Workspace.

Gemini.google.com adoption data can be found under the “Chat with Gemini” label. Data reported as of August 9, 2024
Note: Gemini reports are denoted as ‘beta’ as we continue to optimize reporting functionality based on customer feedback. These are subject to the “Pre-General Availability Offerings Terms” section of the Google Workspace Service Specific Terms”

Getting started 

Admins: Visit the Help Center to learn more about reviewing Gemini usage in your organization.End users: There is no end user impact or action required. 

Rollout pace 

Rapid Release and Scheduled Release domains: Full rollout (1–3 days for feature visibility) starting on September 9, 2024 

Availability 

Available for Google Workspace customers with these add-ons: 
Gemini Business, Enterprise, Education, Education Premium 

Resources 

Google Cloud Directory Sync now complies with your conflicting accounts management settings

What’s changing 

When Google Cloud Directory Sync (GCDS) attempts to create new users, it may encounter unmanaged accounts that conflict with the accounts it’s attempting to create. In these instances, GCDS will now comply with the conflicting accounts management settings specified in the Admin console. This update helps reduce the time spent migrating user accounts to business accounts, helping to accelerate the adoption of Google Workspace and Google Cloud. Visit the Help Center for specific information on how GCDS will handle conflicting accounts based on your configured settings

Getting started 

Admins:
Google Cloud Directory Sync will automatically respect your existing Admin console settings for handling conflicting unmanaged accounts. We do not recommend turning this feature off in GCDS, rather you should configure these settings as you see fit in the Admin console. Visit the Help Center to learn more about handling conflicting unmanaged accounts with Google Cloud Directory Sync, as well as unmanaged accounts in general. End users: Depending on your admin configuration: You’ll be invited to transfer your account — if accepted, your admin will have the ability to manage your account. If you do not accept the request, your admin may replace your unmanaged account with a managed one. In that case, you’ll receive a new @gmail.com address and retain your content in this unmanaged, personal Google account. 

Rollout pace

Availability

Available for all Google Workspace customers 

 Resources