SecureMyEmail logoSecureMyEmail

Google Workspace security guide

Review third-party apps in Google Workspace

A practical, step-by-step guide for Australian businesses. Find, classify and restrict unnecessary or over-privileged app access to Gmail, Drive, calendars and contacts.

Reviewing third-party app permissions connected to Google Workspace services

Recommended method: review, classify and restrict third-party app access every three months

Third-party applications may have ongoing access to Gmail, Google Drive, calendars, contacts and other organisational information. Apps that are no longer required—or have more access than necessary—should be restricted or blocked.

Before you begin

  • A Google Workspace administrator account.
  • The Service Settings administrator privilege, or an appropriate Super Admin account.
  • A list of approved business applications and their owners.
  • A maintenance window for changes that could disrupt services.
  • Use a separate administrator account and document the current settings before making changes.
1

Open API Controls

  • Sign in to the Google Admin console.
  • Open the main menu.
  • Go to Security.
  • Select Access and data control.
  • Select API controls.

If Security is not visible, select Show more or use the Admin console search box to find API controls.

2

Review applications that have accessed company data

  • Under App access control, select Manage Third-Party App Access.
  • Locate the Accessed apps section.
  • Select View list.
  • Review the following for each application: Application name, Application type, OAuth client ID, whether Google has verified the application, number of users, requested Google services, individual OAuth permissions or scopes, and current access status.
  • If required, select Download list to export the information to a CSV file for documentation.

An application may take approximately 24–48 hours to appear after it is authorised.

3

Identify applications requiring investigation

Look for applications that are:

  • Unknown to the business or IT administrator.
  • No longer used.
  • Authorised by former employees.
  • Duplicated or replaced.
  • From an unknown or unverified publisher.
  • Used by only one or two people without an identified business need.
  • Requesting Gmail or Drive access unrelated to their purpose.
  • Requesting permission to read, modify, send or delete information.
  • Unsupported by a current supplier.
  • Connected to a free trial that has ended.

Do not block an app solely because its name is unfamiliar. Backup, email-security, CRM, accounting, migration and document-management services may legitimately require extensive access.

4

Examine an application’s permissions

  • Select the application from the Accessed apps list.
  • Review its full OAuth client ID, publisher or developer, verification status, privacy policy, support information, number of users and requested Google services.
  • Expand the requested services to display the individual OAuth scopes.
  • Confirm that every requested scope is necessary for the application’s documented purpose.

Pay particular attention to access allowing an app to:

  • Read all Gmail messages.
  • Modify or delete email.
  • Send email as a user.
  • Change Gmail settings or forwarding.
  • Read all Google Drive files.
  • Create, modify or delete Drive files.
  • Access Google Docs content.
  • Access contacts or calendars.
  • Continue accessing data when a user is not actively using the app.

High-risk Gmail scopes include access to read, modify, compose or send email. High-risk Drive scopes include access to all files, file metadata, documents or scripts.

5

Confirm the business requirement

Before changing access, establish:

  • Who authorised or installed the application?
  • Who currently uses it?
  • What business process depends on it?
  • Is the publisher reputable and contactable?
  • Does the app have a suitable privacy and security policy?
  • Are all requested permissions necessary?
  • Can the application operate using less access?
  • Would blocking it affect backups, email delivery, workflows or authentication?

Classify each application as:

ClassificationMeaning
ApprovedRecognised and appropriately permissioned.
RestrictRequired, but should have access only to specified data.
BlockObsolete, unauthorised, excessive or suspicious.
InvestigateBusiness purpose or ownership has not yet been confirmed.
6

Change an application’s access

  • Return to Security → Access and data control → API controls.
  • Under App access control, select Manage Third-Party App Access.
  • Open the Configured apps or Accessed apps list.
  • Point to the application and select Change access.
  • If available, select the organisational units that the change should apply to.
  • Choose the appropriate access level: Trusted, Limited, Specific Google data, or Blocked.
  • Select Change, Configure access or Save, depending on the page displayed.
  • Record the decision and test any affected business process.
Access levelEffect
TrustedThe app may request access to all Google Workspace services, including restricted services.
LimitedThe app can access only Google services classified as unrestricted.
Specific Google dataThe app can access only the OAuth scopes explicitly selected by the administrator.
BlockedThe app cannot access Google services or request Google Workspace data.

Where available, Specific Google data is generally preferable to Trusted because it supports least-privilege access.

7

Block an unnecessary application

  • Open the application’s access settings.
  • Select the appropriate organisational units.
  • Choose Blocked.
  • Review the change.
  • Select Configure access or Change.
  • Notify affected users if prompted.
  • Monitor for business-system failures.

Blocking an app prevents users from signing in to it with their managed Google account and prevents it from requesting Google Workspace data. Changes can take up to 24 hours, although they usually apply sooner.

8

Review administrator-installed Marketplace apps

  • In the Admin console, go to Apps.
  • Select Google Workspace Marketplace apps.
  • Select Apps list.
  • Review both Domain Installed Apps and Allowlisted Apps.
  • Select an application.
  • Open the Data Access section.
  • Review its OAuth clients and requested scopes.
  • If it is no longer approved, select Revoke access.
  • If the application is no longer required, uninstall it and remove it from the allowlist.

Google notes that access cannot be revoked for individual scopes on this particular Marketplace-app page—Revoke access revokes all access. Users may subsequently be prompted to authorise the app again unless API Controls or Marketplace installation restrictions also block it.

9

Review domain-wide delegation

  • Go to Security → Access and data control → API controls.
  • Select Manage Domain Wide Delegation.
  • Review every listed client ID and its OAuth scopes.
  • Confirm the owning application or supplier, the responsible internal person, the business purpose, the required scopes, and whether the integration is still active.
  • Remove any delegation that is obsolete or unauthorised.
  • If an application requires only some of its existing scopes, consult its supplier before replacing the authorisation with a reduced scope list.

Treat unfamiliar domain-wide delegation as a potentially serious security concern.

10

Restrict high-risk Gmail and Drive access

  • Go to Security → Access and data control → API controls.
  • Select Manage Google Services.
  • Locate Gmail and Google Drive.
  • Review their current access settings.
  • Select the services you want to manage.
  • Select Change access.
  • Choose Restricted.
  • If appropriate, allow untrusted apps to request only scopes that Google does not classify as high risk.
  • Confirm the change.

When a service is changed to Restricted, previously installed apps that are not trusted or specifically allowed may stop working and their tokens may be revoked. Test this change carefully.

11

Control unconfigured third-party apps

  • Open API controls.
  • Select the Settings card.
  • Select Unconfigured third-party apps.
  • Choose one of the following options.

Choose one of the following:

  • Allow users to access third-party apps that only ask for Google sign-in information; or
  • Don’t allow users to access any third-party apps.
  • Select Save.
  • Configure legitimate business applications individually as Limited, Specific Google data or Trusted.

Blocking all unconfigured apps is more secure but can create additional administrative work and interrupt apps that have not yet been documented.

12

Review new application requests

  • Go to Security → Access and data control → API controls.
  • Under App access control, select Apps pending review.
  • Review who requested the application, number of requests, organisational units involved, Google services requested, OAuth permissions, publisher and business purpose.
  • Approve only the necessary data access.
  • Select Block for rejected or suspicious applications.
  • Notify the requesting users where appropriate.

Recommended review frequency

  • Review third-party applications at least every three months.
  • Review Gmail, Drive and domain-wide delegation monthly.
  • Review access immediately after a security incident.
  • Remove access when an employee leaves or a supplier relationship ends.
  • Require documented approval before trusting a new application.
  • Maintain an application register with owner, purpose, scopes and review date.

Warnings

  • Blocking an application can immediately interrupt backups, email filtering, CRM synchronisation, calendar booking, document signing or other business services.
  • Restricting Gmail or Drive may revoke tokens for applications that have not been explicitly approved.
  • Marking an application Trusted can override restrictions and allow it to request broad access.
  • Google verification does not mean an application is appropriate for your business or should receive unrestricted access.
  • Revoking a Marketplace app’s access might not prevent users from authorising it again. Block it through API Controls and adjust Marketplace installation settings where necessary.
  • A malicious app might already have copied or exported information. Revoking access prevents future access but cannot retrieve data already obtained.
  • Changes can take up to 24 hours, and reporting lists may take 24–48 hours to update.
  • Do not remove a domain-wide delegation entry until its owner, purpose and dependencies have been checked.

Google Workspace disclaimer

These instructions provide general security guidance and may not account for your Google Workspace edition, organisational structure, third-party integrations, regulatory obligations or business requirements. Google may change Admin console menu names and options without notice.

Incorrectly blocking an application or changing API restrictions may interrupt critical services. Before making changes, document the existing configuration, identify affected users, confirm application dependencies and prepare a rollback plan. If an application’s purpose or permissions are unclear, engage a qualified Google Workspace security engineer rather than removing it without investigation.