Introduction
In today’s mobile-centric world, ensuring that only secure devices can access your organization’s data is critical. Google Workspace provides a powerful tool to achieve this: Security Advisor’s app access protection. This feature allows administrators to control which mobile devices can access core Workspace applications, adding an extra layer of security to your organization’s data.
What is Security Advisor for app access protection?
App access protection enables administrators to warn or block users on unsafe mobile devices from accessing essential Workspace apps like Drive or Gmail. The definition of an “unsafe” device varies depending on whether it’s an Android or iOS device.
For Android devices, unsafe devices include those:
- Running an operating system at or below Android 10.
- Missing security updates (if a device hasn’t had a security patch applied within the last 3 years, it’s considered unsafe).
- With potentially harmful apps installed.
- That are compromised (e.g., rooted or jailbroken).
For iOS devices, unsafe devices are those:
- With an outdated OS (any OS more than a year old).
When users attempt to access Google apps on a risky device, they’ll receive a message explaining the device risk and how to resolve it.
Which apps are protected?
Security Advisor can protect access to these core Google Workspace apps:
- Gmail
- Drive
- Calendar
- Hangouts
- Chat
- Keep
- Tasks
Admin privileges needed
To configure app access protection, you’ll need administrator privileges. Ensure you have a super administrator account or a delegated admin account with these privileges:
- Data Security > Access level management
- Data Security > Rule management
It’s recommended to create a custom role that includes both of these permissions.
Default settings and potential conflicts
- Default settings: App access protection is off by default for existing customers. For upgraded and new customers, it’s on by default, with all settings in “Warn” mode.
- Potential conflicts: If you’re using Context-Aware Access, be aware that actions assigned to access levels using Device OS attributes might conflict with your app access protection settings (Enterprise editions only). Generally, a “Block” setting will override a “Warn” setting in case of conflict.
Editing app access protection settings
You can easily adjust app access protection settings in the Google Admin console. Options include:
- Warn users: Users receive a warning but can still access apps.
- Block users: Users are blocked from accessing apps.
- Off: Disables the protection.
For both “Warn” and “Block,” the message displayed to the user will explain why their device is considered risky and provide guidance on how to address the issue (e.g., upgrading their OS).
Viewing logs
To monitor app access from unsafe mobile devices, you can view detailed information in the Device log events directly from Security Advisor. This log includes device information like the owner, model, and OS version.
By leveraging Security Advisor’s app access protection, organizations can enforce stricter security measures, ensuring that only safe and compliant mobile devices can access sensitive Google Workspace data.
Available for Google Workspace Business Plus and above


