<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practices for Securing User Ghost Accounts After Ending Employment in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74280#M2894</link>
    <description>&lt;P&gt;"App Access Control setup so users can create accounts using oAuth ONLY for services we have approved"&lt;/P&gt;&lt;P&gt;That is actually the most important step anyone can take.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Sign up/in with email&lt;/EM&gt; - is completely out of your control, since most organisations don't block incoming email for staff, which is usually necessary to verify the email and activate the third-party account.&lt;/P&gt;&lt;P&gt;On the part of accounts costing someone something, as soon as you are made aware, it is possible to do a&amp;nbsp;&lt;EM&gt;password reset&lt;/EM&gt; of the third-party account, sign in and cancel it. Since it's just an email address, you don't even have to create an account. You can just add it as an alias or group, and receive the emailed reset-link to your own inbox.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;EM&gt;prevent&lt;/EM&gt; action is to, of course, educate your users&amp;nbsp;&lt;EM&gt;before&lt;/EM&gt; they make such mistakes, and also&amp;nbsp;&lt;EM&gt;very clearly&lt;/EM&gt; state in the offboarding instructions that such accounts must be cancelled by the user themselves, preferable well in advance of their last day at work.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2024 17:24:17 GMT</pubDate>
    <dc:creator>Kim_Nilsson</dc:creator>
    <dc:date>2024-07-05T17:24:17Z</dc:date>
    <item>
      <title>Best Practices for Securing User Ghost Accounts After Ending Employment</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/73457#M2872</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my protocols for securing employee user accounts after their employment ends, there is a gap for a best practice on securing any ghost accounts users have created.&amp;nbsp; By that, I mean any accounts for third party services they have used their Google Workspace account to create in which they have no record of, nor have they disclosed to me.&lt;/P&gt;&lt;P&gt;We have all our App Access Control setup so users can create accounts using oAuth ONLY for services we have approved, so that's a great start.&amp;nbsp; We also have 2FA enforced.&amp;nbsp; But I'm concerned about any other accounts they have used the "Sign up with Email" option and use a password to login.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any tools in the Admin Console to track or checkup on logins such as these?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 16:33:59 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/73457#M2872</guid>
      <dc:creator>jpark</dc:creator>
      <dc:date>2024-07-01T16:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Securing User Ghost Accounts After Ending Employment</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74145#M2884</link>
      <description>&lt;P&gt;I believe you're referencing unmanaged accounts.&lt;/P&gt;&lt;P&gt;If so, this should help you get started&lt;BR /&gt;&lt;A href="https://support.google.com/a/answer/11112794?hl=en" target="_blank"&gt;https://support.google.com/a/answer/11112794?hl=en&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 19:01:59 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74145#M2884</guid>
      <dc:creator>Bill_Gibson</dc:creator>
      <dc:date>2024-07-03T19:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Securing User Ghost Accounts After Ending Employment</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74275#M2893</link>
      <description>&lt;P&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;But I'm concerned about any other accounts they have used the "Sign up with Email" option and use a password to login.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There isn't going to be anything you can do about 3rd-party, un-manged accounts a user may have created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree that I wish there was another step/switch for what are essentially deprecated accounts.&amp;nbsp; I suspect one could take the time to go after each account and turn off all unneeded services, revoke all permissions, transfer all ownership of files,sites, etc.&amp;nbsp; But I don't like the the account still sits there and can be used.&amp;nbsp; If nothing else,&amp;nbsp; it stinks that it adds a "users" to our account and may cost us money for services that we use that charge "per user" for our Workspace.&amp;nbsp; And for us, these accounts almost always just exist for the sake of email delegation.&amp;nbsp; &amp;nbsp;In the old days, it was a lot easier to manage that because you'd just export their mailbox, and put it in a shared location for those that needed it.&amp;nbsp; But since we're not using an email client anymore (and the process would still be time consuming and impractical even if we were) that's not an option. I wish Google would just allow a way to host a mailbox strictly for delegation purposes. Like a Shared Drive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyhow, it sounds like you've done the primary steps.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dealing with random accounts users may or may not have signed up for using their work email isn't something tech is really going to solve.&lt;/P&gt;&lt;P&gt;There are some services that attempt to track/monitor such things, but it's still not stopping it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 14:05:30 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74275#M2893</guid>
      <dc:creator>Justin_W</dc:creator>
      <dc:date>2024-07-05T14:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Securing User Ghost Accounts After Ending Employment</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74280#M2894</link>
      <description>&lt;P&gt;"App Access Control setup so users can create accounts using oAuth ONLY for services we have approved"&lt;/P&gt;&lt;P&gt;That is actually the most important step anyone can take.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Sign up/in with email&lt;/EM&gt; - is completely out of your control, since most organisations don't block incoming email for staff, which is usually necessary to verify the email and activate the third-party account.&lt;/P&gt;&lt;P&gt;On the part of accounts costing someone something, as soon as you are made aware, it is possible to do a&amp;nbsp;&lt;EM&gt;password reset&lt;/EM&gt; of the third-party account, sign in and cancel it. Since it's just an email address, you don't even have to create an account. You can just add it as an alias or group, and receive the emailed reset-link to your own inbox.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;EM&gt;prevent&lt;/EM&gt; action is to, of course, educate your users&amp;nbsp;&lt;EM&gt;before&lt;/EM&gt; they make such mistakes, and also&amp;nbsp;&lt;EM&gt;very clearly&lt;/EM&gt; state in the offboarding instructions that such accounts must be cancelled by the user themselves, preferable well in advance of their last day at work.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 17:24:17 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74280#M2894</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2024-07-05T17:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Securing User Ghost Accounts After Ending Employment</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74564#M2896</link>
      <description>&lt;P&gt;Thanks, all.&amp;nbsp; &amp;nbsp;That is very sound advice on all fronts.&amp;nbsp; This job would be so much easier without users, right?!?!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 15:02:51 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Best-Practices-for-Securing-User-Ghost-Accounts-After-Ending/m-p/74564#M2896</guid>
      <dc:creator>jpark</dc:creator>
      <dc:date>2024-07-08T15:02:51Z</dc:date>
    </item>
  </channel>
</rss>

