{"id":987517001,"date":"2024-08-05T20:10:55","date_gmt":"2024-08-05T20:10:55","guid":{"rendered":"https:\/\/workspace.trace.pt\/available-in-open-beta-configure-third-party-apps-by-select-api-scopes\/"},"modified":"2024-08-05T20:10:55","modified_gmt":"2024-08-05T20:10:55","slug":"available-in-open-beta-configure-third-party-apps-by-select-api-scopes","status":"publish","type":"post","link":"https:\/\/workspace.trace.pt\/en\/available-in-open-beta-configure-third-party-apps-by-select-api-scopes\/","title":{"rendered":"Available in open beta: configure third-party apps by selecting API scopes"},"content":{"rendered":"<h3>What's changing\u00a0<\/h3>\n<div>When your users sign in to third-party apps using the \"Sign in with Google\" option (single sign-on) or use OAuth to share their data with those apps, you can control what access those apps have to your organisation's Google data using <a href=\"https:\/\/support.google.com\/a\/answer\/7281227\">app access controls<\/a>.\u00a0<\/div>\n<div><\/div>\n<div><\/div>\n<div>Admins currently can configure the third-party apps as \"Trusted\", giving them access to all OAuth scopes or as \"Limited\", giving them access to scopes only from Google services which are not restricted. Beginning today, we're giving admins another layer of granular control for third-party apps. Specifically, you can now configure apps to be limited by selected<a href=\"https:\/\/developers.google.com\/identity\/protocols\/oauth2\/scopes\"> OAuth 2.0 Scopes for Google APIs<\/a>such as <a href=\"https:\/\/developers.google.com\/identity\/protocols\/oauth2\/scopes#drive\">Drive<\/a> or <a href=\"https:\/\/developers.google.com\/identity\/protocols\/oauth2\/scopes#gmail\">Gmail<\/a> scopes. This helps ensure that these apps do not gain additional access without admin consent based on new API scopes that they might request in the future, keeping data access limited to only what is deemed absolutely necessary by admins.<\/div>\n<div><\/div>\n<div class=\"separator\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh45tQRhNId5F_s2QQLIrzQwUsqPfK_UvXkHe83Yq16G0N2QPt-Ne7F6it63NYXg4A8MaecYaBVLVdaV8-eKdhQ00LnVEGc5Juws8vzcfL3C6KbgTcMjyVB9fid1xn_MsqZdvd1s-jroXTourVeP06NDSC0k6GOi-rdxYyDsl7mtTo2WFeU7C2VcGhpR-E\/s1600\/unnamed.png\"><\/a><\/div>\n<p><\/p>\n<div><\/div>\n<div><\/div>\n<div>\n<h3>Getting started<\/h3>\n<div>Admins: To manage app access, in the Admin console navigate to Security &gt; API Controls &gt; App Access Controls. Visit the Help Centre to learn more about <a href=\"https:\/\/support.google.com\/a\/answer\/7281227\">controlling which third-party &amp; internal apps access Google Workspace data<\/a>.<\/p>\n<div>\n<h3>Rollout pace<\/h3>\n<div><a href=\"https:\/\/support.google.com\/a\/answer\/172177\">Rapid and Scheduled Release domains<\/a>: Available now.<\/div>\n<div><\/div>\n<h3>Availability<\/h3>\n<div>Available to all Google Workspace customers, as well as Cloud Identity Free and Premium customers<\/div>\n<div><\/div>\n<div><\/div>\n<h3>Resources<\/h3>\n<div><a href=\"https:\/\/support.google.com\/a\/answer\/7281227?hl=en&amp;sjid=18331255848683477463-NA\">Google Workspace Admin Help: Control which third-party &amp; internal apps access Google Workspace data<\/a><a href=\"https:\/\/support.google.com\/a\/answer\/6124308\">Google Workspace Admin Help: OAuth log events<\/a><\/div>\n<div><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>What\u2019s changing\u00a0 When your users sign in to third-party apps using the &#8220;Sign in with Google&#8221; option (single sign-on) or use OAuth to share their data with those apps, you can control what access those apps have to your organization\u2019s Google data using app access controls.\u00a0 Admins currently can configure the third-party apps as \u201cTrusted\u201d, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-987517001","post","type-post","status-publish","format-standard","hentry","category-noticias"],"acf":[],"_links":{"self":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts\/987517001","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/comments?post=987517001"}],"version-history":[{"count":0,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts\/987517001\/revisions"}],"wp:attachment":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/media?parent=987517001"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/categories?post=987517001"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/tags?post=987517001"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}