{"id":987517306,"date":"2024-12-10T17:11:40","date_gmt":"2024-12-10T17:11:40","guid":{"rendered":"https:\/\/workspace.trace.pt\/available-in-open-beta-prevent-sensitive-changes-by-locking-groups\/"},"modified":"2024-12-10T17:11:40","modified_gmt":"2024-12-10T17:11:40","slug":"available-in-open-beta-prevent-sensitive-changes-by-locking-groups","status":"publish","type":"post","link":"https:\/\/workspace.trace.pt\/es\/available-in-open-beta-prevent-sensitive-changes-by-locking-groups\/","title":{"rendered":"Available in open beta: prevent sensitive changes by locking Groups"},"content":{"rendered":"<h3>Qu\u00e9 est\u00e1 cambiando<\/h3>\n<p>Admins can now label a <a href=\"https:\/\/support.google.com\/a\/answer\/33329?hl=en\">Google Group<\/a> as \u201cLocked,\u201d which will heavily restrict changes to group attributes (such as group name &amp; email address) and memberships. This will help admins who sync their groups from an external source and want to prevent getting out of sync, or who want to restrict changes to sensitive groups. This feature will be available in open beta, which means no additional sign-up is required.\u00a0<\/p>\n<div class=\"separator\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgVa-BTi_wl2NaFzDKhXMC0fCi8iaj_1dXKphC96GfKvDfTARlyjaD8_XMjuVDVyDcrTZzWEg1n_bQ9DdPZiyc5okMkK0temUlDmgU_jhR16hix-UGEIdG7ghZkNbuOCBeB7XOe6KXK59-s4hjx5s__TPhcnnKdbKtr4r-rayHyCVP6y_ciTBWl9R-jw5Q\/s1057\/lckgr1.png\"><img decoding=\"async\" border=\"0\" data-original-height=\"828\" data-original-width=\"1057\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgVa-BTi_wl2NaFzDKhXMC0fCi8iaj_1dXKphC96GfKvDfTARlyjaD8_XMjuVDVyDcrTZzWEg1n_bQ9DdPZiyc5okMkK0temUlDmgU_jhR16hix-UGEIdG7ghZkNbuOCBeB7XOe6KXK59-s4hjx5s__TPhcnnKdbKtr4r-rayHyCVP6y_ciTBWl9R-jw5Q\/s16000\/lckgr1.png\"><\/a><\/div>\n<div class=\"separator\"><i><span>The Group Details page in the Admin console shows a \u201cLocked\u201d label on the group, with the message\u00a0<\/span><\/i><i><span>\u201cYou can\u2019t update this group &#8211; it might be managed by an external identity system.\u201d<\/span><\/i><\/div>\n<div class=\"separator\">\n<div><\/div>\n<\/div>\n<p><\/p>\n<h3>A qui\u00e9n afecta<\/h3>\n<p>Admins<\/p>\n<h3>Por qu\u00e9 es importante<\/h3>\n<p>If you use third-party tools, like Entra ID, to manage group synchronization, you may encounter inconsistencies when modifications are made to these groups, like adding or removing members, for example. To help address this, we\u2019re introducing the option to \u201clock\u201d a group, which will prevent modifications within Google Workspace and help maintain synchronization with the external source.\u00a0<\/p>\n<p>When a group is locked, only certain admins* can modify:<\/p>\n<\/p>\n<ul>\n<li>The group name, description, email, and alias(es)<\/li>\n<li>Group labels<\/li>\n<li>Memberships (adding or removing members) and member restrictions<\/li>\n<li>Membership roles<\/li>\n<li>Delete the group<\/li>\n<li>Set up a new membership expiry<\/li>\n<\/ul>\n<p>When a group is locked, access and content moderation settings are not affected, this includes:<\/p>\n<\/p>\n<ul>\n<li>Who can post<\/li>\n<li>Who can view members<\/li>\n<li>Who can contact members<\/li>\n<li>Membership removals due to an existing membership expiry<\/li>\n<li>Access or content moderation settings<\/li>\n<\/ul>\n<p><i><span>*Super Admins, Group Admins, and Group Editors with a condition that includes \u201cLocked Groups\u201d<br \/><\/span><\/i><\/p>\n<div>\n<h3>M\u00e1s informaci\u00f3n<\/h3>\n<div>By default, the changes listed above will be restricted from end users, including group owners and managers of a locked group. If you want to also restrict some admins from making these changes in the Admin Console or APIs, you can assign them the Group Editor role with a condition that excludes locked groups.\u00a0<\/div>\n<div><\/div>\n<div>The ability to lock or unlock a group using the \u201cLocked\u201d label is available to Super Admins, Group Admins, or a custom role with the \u201cManage Locked Label\u201d privilege. Lock a group using the \u201cLocked\u201d group label in the Admin Console, or the <a href=\"https:\/\/cloud.google.com\/identity\/docs\/how-to\/setup\">API de grupos de identidad en la nube<\/a>.<\/div>\n<\/div>\n<div>\n<\/div>\n<div>\n<h3>Para empezar<\/h3>\n<div>\n<ul>\n<li><b>Admins:<\/b> Visite el Centro de ayuda para obtener m\u00e1s informaci\u00f3n sobre <a href=\"https:\/\/support.google.com\/a\/answer\/15634160\">locking groups<\/a> y <a href=\"https:\/\/support.google.com\/a\/answer\/9807615#zippy=%2Cassign-roles-to-one-user%2Cassign-a-role-to-several-users-at-once%2Cassign-a-role-to-a-group%2Cassign-a-role-to-a-service-account\">assigning the Group Editor role with conditions<\/a>. Use our developer documentation to learn more about managing locked groups with the <a href=\"https:\/\/cloud.google.com\/identity\/docs\/how-to\/setup\">API de grupos de identidad en la nube<\/a> (beta version).<\/li>\n<li><b>Usuarios finales: <\/b>There is no end user action required.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div>\n<h3><span>Ritmo de implantaci\u00f3n<\/span><\/h3>\n<div>\n<ul>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/172177\">\u00c1mbitos de liberaci\u00f3n r\u00e1pida y liberaci\u00f3n programada<\/a>: Gradual rollout (up to 15 days for feature visibility) starting on December 10, 2024<\/li>\n<\/ul>\n<\/div>\n<h3>Disponibilidad<\/h3>\n<div>Disponible para Google Workspace:<\/div>\n<div>\n<ul>\n<li>Enterprise Standard and Plus<\/li>\n<li>Enterprise Essentials Plus<\/li>\n<li>Educaci\u00f3n Est\u00e1ndar y Plus<\/li>\n<li>Also available to Cloud Identity Premium customers<\/li>\n<\/ul>\n<\/div>\n<h3>Recursos<\/h3>\n<div>\n<ul>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/15634160\">Google Workspace Admin Help: Lock groups to keep data in sync<\/a><\/li>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/2405986?hl=en\">Google Workspace Admin Help: Prebuilt Administrator Roles<\/a><\/li>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/9807615#zippy=%2Cassign-roles-to-one-user%2Cassign-a-role-to-several-users-at-once%2Cassign-a-role-to-a-group%2Cassign-a-role-to-a-service-account\">Google Workspace Admin Help: Asignaci\u00f3n de funciones de administraci\u00f3n espec\u00edficas<\/a><\/li>\n<li><a href=\"https:\/\/cloud.google.com\/identity\/docs\/reference\/rest\/v1\/groups\">API Documentation: Group Labels<\/a><\/li>\n<li><a href=\"https:\/\/developers.google.com\/admin-sdk\/directory\/reference\/rest\/v1\/roleAssignments\">API Documentation: Role Assignment<\/a><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div><\/div>","protected":false},"excerpt":{"rendered":"<p>What\u2019s changing Admins can now label a Google Group as \u201cLocked,\u201d which will heavily restrict changes to group attributes (such as group name &amp; email address) and memberships. This will help admins who sync their groups from an external source and want to prevent getting out of sync, or who want to restrict changes to [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-987517306","post","type-post","status-publish","format-standard","hentry","category-noticias"],"acf":[],"_links":{"self":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/posts\/987517306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/comments?post=987517306"}],"version-history":[{"count":0,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/posts\/987517306\/revisions"}],"wp:attachment":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/media?parent=987517306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/categories?post=987517306"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/tags?post=987517306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}