Google Workspace API controls: Restrict third-party app access in Australia

▶ Watch the short explainer for this tip
Third-party apps often request broad permissions to access your Google Workspace data. While some are essential for business operations, others can pose significant security risks if not properly managed. Controlling which apps can access your organisation's data is a critical step in protecting against unauthorised access and potential data breaches. This TECH TIP guides Australian small and medium businesses through securing their Google Workspace environment.
What is restricting third-party app access?
Restricting third-party app access with Google Workspace API (Application Programming Interface) controls means you decide which external applications can connect to and interact with your organisation's Google Workspace data. This setting allows you to approve or block specific apps, preventing unapproved software from accessing sensitive information.
Why should you restrict third-party app access?
You should restrict third-party app access to prevent unauthorised applications from gaining access to your organisation's emails, documents, and other sensitive data. Many apps, even seemingly benign ones, can request extensive permissions that could be exploited in a security incident or a business email compromise (BEC) attack. Implementing these controls is a crucial step in maintaining good cyber hygiene and reducing your attack surface.
What happens if you don't restrict third-party apps?
If you don't restrict third-party app access, you leave your Google Workspace data vulnerable to potential breaches, ransomware, or data exfiltration. An unvetted app could be compromised, or a malicious app could be installed, leading to financial loss, operational downtime, and reputational damage. Such incidents could also trigger a notifiable data breach (NDB) under Australian privacy law, incurring significant costs and legal obligations. This risk is highlighted by the Australian Signals Directorate's Australian Cyber Security Centre (ACSC) in their guidance on cyber security risks for small businesses.
How to restrict third-party app access in Google Workspace
Here are the steps to restrict third-party app access in your Google Workspace environment: 1. Sign in to admin.google.com and go to Security > Access and data control > API controls. 2. Open Manage third-party app access and review the apps already connected. 3. Select Configure new app to allowlist the apps your business genuinely uses, marking them Trusted. 4. Back on API controls, set unconfigured third-party apps to Blocked (or Limited to Google services that do not contain sensitive data), and Save.
How to check it worked and what to warn staff about
To check it worked, go to Manage third-party app access; it will list your approved apps as Trusted and everything else as Blocked. Staff will lose access to unapproved add-ons immediately, which might cause disruption. It's vital to publish your request process for new app approvals before you 'flip the switch' on this setting to minimise impact. Neil offers a complimentary 15-minute chat to discuss your Google Workspace security posture – book yours at https://calendly.com/netlogyx/m365audit.
Important disclaimer about settings
These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Restricting third-party app access in Google Workspace is a simple yet powerful security measure to protect your business data from unauthorised access and cyber threats. Don't leave your organisation vulnerable.
Disclaimer: These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Frequently asked questions
- What are Google Workspace API controls?
- Google Workspace API (Application Programming Interface) controls are settings that let you manage how third-party applications can interact with your organisation's Google Workspace data. They enable you to specify which apps are permitted to connect and access information.
- Why should Australian small businesses care about third-party app access?
- Australian small businesses should care because uncontrolled third-party apps can create significant security vulnerabilities, potentially leading to data breaches or compliance issues under Australian privacy laws. It's a key part of protecting sensitive customer and business information.
- Can I block all third-party apps in Google Workspace?
- Yes, you can set unconfigured third-party apps to 'Blocked' within Google Workspace API controls. This means only apps you have explicitly marked as 'Trusted' will be allowed to access your organisation's data.
- What if a staff member needs a blocked app for their work?
- If a staff member needs a blocked app, they will need to follow your internal approval process for new applications. Once approved, you can add it to your allowlist and mark it as 'Trusted' in the Google Admin console.
Sources
Every reference below was link-checked when this article was published.
- 1.Best practices for administrator accountsGoogle Workspace Admin Help
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


