Overview
By default, users can grant any third-party app access to their Google account data. Restricting this reduces the risk of unauthorized apps accessing sensitive company data. Depending on your organization's security requirements, you can either limit access to apps that only request basic sign-in information, or block all unconfigured third-party apps entirely.
Prerequisites
Super Admin access to the Google Admin console
Instructions
Sign in to the Google Admin console
Navigate to Security > Access and data control > API controls
Click Settings
Under Unconfigured third-party apps, select one of the following depending on your organization's requirements:
Standard restriction β Select Allow users to access third-party apps that only request basic info needed for Sign in with Google. Users can access apps that only request their name, email, and profile picture, but cannot access apps that request additional Google account data until those apps are explicitly configured.
Strict restriction β Select Don't allow users to access any third-party apps. Users cannot access any third-party apps until access is explicitly configured for each app.
Check Allow users to request access to unconfigured third-party apps so users can submit requests for apps they need access to
Click Save
Note: When users request access to an app, you'll be notified so you can review and configure access as needed.
