Skip to main content

Restrict App Access in Google Workspace

How to control which third-party apps users can access with their Google Workspace account.

Written by Kavi Harshawat
Updated over 2 weeks ago

Overview

By default, users can grant any third-party app access to their Google account data. Restricting this reduces the risk of unauthorized apps accessing sensitive company data. Depending on your organization's security requirements, you can either limit access to apps that only request basic sign-in information, or block all unconfigured third-party apps entirely.

Prerequisites

  • Super Admin access to the Google Admin console

Instructions

  1. Sign in to the Google Admin console

  2. Navigate to Security > Access and data control > API controls

  3. Click Settings

  4. Under Unconfigured third-party apps, select one of the following depending on your organization's requirements:

Standard restriction β€” Select Allow users to access third-party apps that only request basic info needed for Sign in with Google. Users can access apps that only request their name, email, and profile picture, but cannot access apps that request additional Google account data until those apps are explicitly configured.

Strict restriction β€” Select Don't allow users to access any third-party apps. Users cannot access any third-party apps until access is explicitly configured for each app.

  1. Check Allow users to request access to unconfigured third-party apps so users can submit requests for apps they need access to

  2. Click Save

Note: When users request access to an app, you'll be notified so you can review and configure access as needed.

Did this answer your question?