{"id":987517306,"date":"2024-12-10T17:11:40","date_gmt":"2024-12-10T17:11:40","guid":{"rendered":"https:\/\/workspace.trace.pt\/available-in-open-beta-prevent-sensitive-changes-by-locking-groups\/"},"modified":"2024-12-10T17:11:40","modified_gmt":"2024-12-10T17:11:40","slug":"available-in-open-beta-prevent-sensitive-changes-by-locking-groups","status":"publish","type":"post","link":"https:\/\/workspace.trace.pt\/fr\/available-in-open-beta-prevent-sensitive-changes-by-locking-groups\/","title":{"rendered":"Available in open beta: prevent sensitive changes by locking Groups"},"content":{"rendered":"<h3>What\u2019s changing<\/h3>\n<p>Admins can now label a <a href=\"https:\/\/support.google.com\/a\/answer\/33329?hl=en\">Google Group<\/a> as \u201cLocked,\u201d which will heavily restrict changes to group attributes (such as group name &amp; email address) and memberships. This will help admins who sync their groups from an external source and want to prevent getting out of sync, or who want to restrict changes to sensitive groups. This feature will be available in open beta, which means no additional sign-up is required.\u00a0<\/p>\n<div class=\"separator\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgVa-BTi_wl2NaFzDKhXMC0fCi8iaj_1dXKphC96GfKvDfTARlyjaD8_XMjuVDVyDcrTZzWEg1n_bQ9DdPZiyc5okMkK0temUlDmgU_jhR16hix-UGEIdG7ghZkNbuOCBeB7XOe6KXK59-s4hjx5s__TPhcnnKdbKtr4r-rayHyCVP6y_ciTBWl9R-jw5Q\/s1057\/lckgr1.png\"><img decoding=\"async\" border=\"0\" data-original-height=\"828\" data-original-width=\"1057\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgVa-BTi_wl2NaFzDKhXMC0fCi8iaj_1dXKphC96GfKvDfTARlyjaD8_XMjuVDVyDcrTZzWEg1n_bQ9DdPZiyc5okMkK0temUlDmgU_jhR16hix-UGEIdG7ghZkNbuOCBeB7XOe6KXK59-s4hjx5s__TPhcnnKdbKtr4r-rayHyCVP6y_ciTBWl9R-jw5Q\/s16000\/lckgr1.png\"><\/a><\/div>\n<div class=\"separator\"><i><span>The Group Details page in the Admin console shows a \u201cLocked\u201d label on the group, with the message\u00a0<\/span><\/i><i><span>\u201cYou can\u2019t update this group &#8211; it might be managed by an external identity system.\u201d<\/span><\/i><\/div>\n<div class=\"separator\">\n<div><\/div>\n<\/div>\n<p><\/p>\n<h3>Who\u2019s impacted<\/h3>\n<p>Admins<\/p>\n<h3>Why it\u2019s important<\/h3>\n<p>If you use third-party tools, like Entra ID, to manage group synchronization, you may encounter inconsistencies when modifications are made to these groups, like adding or removing members, for example. To help address this, we\u2019re introducing the option to \u201clock\u201d a group, which will prevent modifications within Google Workspace and help maintain synchronization with the external source.\u00a0<\/p>\n<p>When a group is locked, only certain admins* can modify:<\/p>\n<\/p>\n<ul>\n<li>The group name, description, email, and alias(es)<\/li>\n<li>Group labels<\/li>\n<li>Memberships (adding or removing members) and member restrictions<\/li>\n<li>Membership roles<\/li>\n<li>Delete the group<\/li>\n<li>Set up a new membership expiry<\/li>\n<\/ul>\n<p>When a group is locked, access and content moderation settings are not affected, this includes:<\/p>\n<\/p>\n<ul>\n<li>Who can post<\/li>\n<li>Who can view members<\/li>\n<li>Who can contact members<\/li>\n<li>Membership removals due to an existing membership expiry<\/li>\n<li>Access or content moderation settings<\/li>\n<\/ul>\n<p><i><span>*Super Admins, Group Admins, and Group Editors with a condition that includes \u201cLocked Groups\u201d<br \/><\/span><\/i><\/p>\n<div>\n<h3>Additional details<\/h3>\n<div>By default, the changes listed above will be restricted from end users, including group owners and managers of a locked group. If you want to also restrict some admins from making these changes in the Admin Console or APIs, you can assign them the Group Editor role with a condition that excludes locked groups.\u00a0<\/div>\n<div><\/div>\n<div>The ability to lock or unlock a group using the \u201cLocked\u201d label is available to Super Admins, Group Admins, or a custom role with the \u201cManage Locked Label\u201d privilege. Lock a group using the \u201cLocked\u201d group label in the Admin Console, or the <a href=\"https:\/\/cloud.google.com\/identity\/docs\/how-to\/setup\">Cloud Identity Groups API<\/a>.<\/div>\n<\/div>\n<div>\n<\/div>\n<div>\n<h3>Getting started<\/h3>\n<div>\n<ul>\n<li><b>Admins:<\/b> Visit the Help Center to learn more about <a href=\"https:\/\/support.google.com\/a\/answer\/15634160\">locking groups<\/a> and <a href=\"https:\/\/support.google.com\/a\/answer\/9807615#zippy=%2Cassign-roles-to-one-user%2Cassign-a-role-to-several-users-at-once%2Cassign-a-role-to-a-group%2Cassign-a-role-to-a-service-account\">assigning the Group Editor role with conditions<\/a>. Use our developer documentation to learn more about managing locked groups with the <a href=\"https:\/\/cloud.google.com\/identity\/docs\/how-to\/setup\">Cloud Identity Groups API<\/a> (beta version).<\/li>\n<li><b>End users: <\/b>There is no end user action required.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div>\n<h3><span>Rollout pace<\/span><\/h3>\n<div>\n<ul>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/172177\">Rapid Release and Scheduled Release domains<\/a>: Gradual rollout (up to 15 days for feature visibility) starting on December 10, 2024<\/li>\n<\/ul>\n<\/div>\n<h3>Availability<\/h3>\n<div>Available for Google Workspace:<\/div>\n<div>\n<ul>\n<li>Enterprise Standard and Plus<\/li>\n<li>Enterprise Essentials Plus<\/li>\n<li>Education Standard and Plus<\/li>\n<li>Also available to Cloud Identity Premium customers<\/li>\n<\/ul>\n<\/div>\n<h3>Resources<\/h3>\n<div>\n<ul>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/15634160\">Google Workspace Admin Help: Lock groups to keep data in sync<\/a><\/li>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/2405986?hl=en\">Google Workspace Admin Help: Prebuilt Administrator Roles<\/a><\/li>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/9807615#zippy=%2Cassign-roles-to-one-user%2Cassign-a-role-to-several-users-at-once%2Cassign-a-role-to-a-group%2Cassign-a-role-to-a-service-account\">Google Workspace Admin Help: Assign specific admin roles<\/a><\/li>\n<li><a href=\"https:\/\/cloud.google.com\/identity\/docs\/reference\/rest\/v1\/groups\">API Documentation: Group Labels<\/a><\/li>\n<li><a href=\"https:\/\/developers.google.com\/admin-sdk\/directory\/reference\/rest\/v1\/roleAssignments\">API Documentation: Role Assignment<\/a><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div><\/div>","protected":false},"excerpt":{"rendered":"<p>What\u2019s changing Admins can now label a Google Group as \u201cLocked,\u201d which will heavily restrict changes to group attributes (such as group name &amp; email address) and memberships. This will help admins who sync their groups from an external source and want to prevent getting out of sync, or who want to restrict changes to [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-987517306","post","type-post","status-publish","format-standard","hentry","category-noticias"],"acf":[],"_links":{"self":[{"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/posts\/987517306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/comments?post=987517306"}],"version-history":[{"count":0,"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/posts\/987517306\/revisions"}],"wp:attachment":[{"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/media?parent=987517306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/categories?post=987517306"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workspace.trace.pt\/fr\/wp-json\/wp\/v2\/tags?post=987517306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}