Control access to apps based on user & device context
Control access to actions in apps
When you assign access levels to apps, you usually give access to everything in the app or nothing at all. Sometimes, however, certain actions in an app are more sensitive than others. In Google Drive, downloading a document might be more sensitive than simply viewing it.
As an administrator, you can enhance security for specific actions by combining Context-Aware Access conditions with data loss prevention (DLP) rules. You can, for example, restrict downloading files in Drive on personal or Bring Your Own Device (BYOD) devices. You can control how your organization’s data is accessed based on the user and their device.
Example: Block download of Drive files on personal devices
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu and thenSecurity > Access and data control > Context-Aware Access.
Requires the Data security access level and rule management privileges and the Admin API groups and users read privileges.
- Click Create Access Level. You might need to click Access levels first.
- Enter a name, such as BYOD devices, and a description for the new access level.
- For Context conditions, click Add Condition.
- Select Doesn't meet 1 or more attributes (OR).
- For Select attribute, select Device.
- For Select condition, select Company-owned.
- Click Create. Now, you can create a DLP rule with this access level.
- Click Create Rule.
- Click Name and enter a name for the rule and, optionally, a description.
- For Scope, choose an option:
- To apply to all users in your organization, select All in your organization.
- To apply to specific organizational units or groups, select Organizational units and/or groups and add or exclude them as needed.
- Click Continue.
- In Apps, for Google Drive, check the Drive files box and click Continue.
- For Content type to scan, choose All content.
- For What to scan for, choose a DLP scan type and select attributes. For more information on available attributes, go to Create a DLP rule.
- In the Context conditions section, select Select an access leveland thenthe access level created earlier, such as BYOD devices.
The rule is applied when the conditions in the access level are met.So, in this example, the access level must be True for BYOD devices. - Click Continue.
- For Google Drive, click Action and select Disable download, print, and copyand thenFor commenters and viewers only.
- (Optional) To set an alert severity level and send alert notifications, choose the options.
- Click Continue.
- Review the rule details and for Rule status, select Active to immediately run the rule or Inactive to activate it later.
- Click Create.
Changes can take up to 24 hours but typically happen more quickly. Learn more