{"id":987516997,"date":"2024-07-31T17:09:55","date_gmt":"2024-07-31T17:09:55","guid":{"rendered":"https:\/\/workspace.trace.pt\/prevent-downloading-printing-or-copying-files-by-combining-data-loss-prevention-rules-with-context-aware-access-conditions\/"},"modified":"2024-07-31T17:09:55","modified_gmt":"2024-07-31T17:09:55","slug":"prevent-downloading-printing-or-copying-files-by-combining-data-loss-prevention-rules-with-context-aware-access-conditions","status":"publish","type":"post","link":"https:\/\/workspace.trace.pt\/en\/prevent-downloading-printing-or-copying-files-by-combining-data-loss-prevention-rules-with-context-aware-access-conditions\/","title":{"rendered":"Prevent downloading, printing, or copying files by combining Data Loss Prevention rules with Context-Aware Access conditions"},"content":{"rendered":"<h3>What's changing<\/h3>\n<p>Controlling access to sensitive content stored in Google Drive is a critical component for any company's security posture. One way admins can do this is with <a href=\"https:\/\/support.google.com\/a\/answer\/9656855\">Data Loss Prevention (DLP) rules<\/a> that enable <a href=\"https:\/\/support.google.com\/a\/answer\/9656855?#irmfaq\">Information Rights Management (IRM)<\/a> on specific files. This allows admins to disable actions that can lead to accidental or deliberate data exfiltration, such as downloading, copying, and printing.\u00a0<\/p>\n<div><\/div>\n<div><\/div>\n<div>Today, we're expanding on these protections by enabling admins to combine DLP rules with <a href=\"https:\/\/support.google.com\/a\/answer\/12645308?sjid=12873822272074096537-NC\">Context-Aware Access conditions<\/a>. When combined, admins can configure if IRM should be enforced based on context conditions, like a user's location or IP address, are met. This gives admins the ability to configure context-aware-access conditions in a more granular fashion - previously, context-aware-access could only be used to restrict full access to an entire application. This is an important step forward in applying administrator controls at the document level.\n<\/div>\n<div><\/div>\n<div class=\"separator\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiEr5MbaB-T8YG3ASxPNaOC7yaNQ_mx1WqHO8_5hFIzQnQajFJ5dcsXZ-L3xOccBVS_nKIaCjvQM9An39Enfley7du82mrdnN44YH7F6WWlsjBwx9rOoO7RMBzK5WEq84E9IlGEH0SkxpffiBJyphxbWjOU-Bp80nwtsdiaJErlsoCowOa5w1uVa4fLD68\/s1600\/unnamed.gif\"><\/a><\/div>\n<p><\/p>\n<div><\/div>\n<div>\n<h3>Getting started<\/h3>\n<div>Admins: This feature will be OFF by default and can be enabled per-file by creating DLP rules with a CAA access level attached. See this help centre article for more information on <a href=\"https:\/\/support.google.com\/a\/answer\/13447476#zippy=%2Cexample-block-download-of-sensitive-content-on-a-device-which-is-not-admin-approved-drive-beta\">how to configure these rules<\/a>.<\/p>\n<p>End users: Depending on your admin configuration, you may be restricted from taking certain actions on Drive files.<\/p><\/div>\n<\/div>\n<div>\n<h3>Rollout pace<\/h3>\n<div><a href=\"https:\/\/support.google.com\/a\/answer\/172177\">Rapid and Scheduled Release domains<\/a>: Full rollout (1-3 days for feature visibility) beginning on July 31, 2024<\/p>\n<div>\n<h3>Availability<\/h3>\n<div>Available for Google Workspace:<\/div>\n<div><\/div>\n<div>Enterprise Standard and PlusEducation Fundamentals, Standard, Plus, and the Teaching and Learning upgradeFrontline StandardEssentials: Enterprise, Enterprise Plus<\/p>\n<div>\n<h3>Resources<\/h3>\n<div><a href=\"https:\/\/support.google.com\/a\/answer\/13447476#zippy=%2Cexample-block-download-of-sensitive-content-on-a-device-which-is-not-admin-approved-drive-beta\">Google Workspace Admin Help: Combine DLP rules with Context-Aware Access conditions<\/a><a href=\"https:\/\/support.google.com\/a\/answer\/9656855?#irmfaq\">Google Workspace Admin Help: Prevent commenters and viewers from downloading, printing, or copying files FAQ<\/a><a href=\"https:\/\/support.google.com\/a\/answer\/12645308?sjid=12873822272074096537-NC\">Google Workspace Admin Help: Control access to apps based on user &amp; device context<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div><\/div>","protected":false},"excerpt":{"rendered":"<p>What&#8217;s changing Controlling access to sensitive content stored in Google Drive is a critical component for any company&#8217;s security posture. One way admins can do this is with Data Loss Prevention (DLP) rules that enable Information Rights Management (IRM) on specific files. This allows admins to disable actions that can lead to accidental or deliberate [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-987516997","post","type-post","status-publish","format-standard","hentry","category-noticias"],"acf":[],"_links":{"self":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts\/987516997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/comments?post=987516997"}],"version-history":[{"count":0,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts\/987516997\/revisions"}],"wp:attachment":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/media?parent=987516997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/categories?post=987516997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/tags?post=987516997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}