<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic For those that disable third party apps but allow internal apps in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/For-those-that-disable-third-party-apps-but-allow-internal-apps/m-p/180849#M4536</link>
    <description>&lt;P&gt;We identified something that was new to us but maybe others already knew this.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have GCP disabled within our Google Workspace environment for all users except a few that need it&lt;/LI&gt;&lt;LI&gt;We have AppScripts enabled by default - something that may change in the future&lt;/LI&gt;&lt;LI&gt;We have Google Drive service within the API Third Party area to "Restricted" - so only trusted apps can access that service-data&lt;/LI&gt;&lt;LI&gt;We had before yesterday the "internal third party apps are trusted" enabled&lt;/LI&gt;&lt;LI&gt;We noticed that users were still using mail merge applications with access to Drive data in which we did not "trust"&lt;/LI&gt;&lt;LI&gt;Further investigating, came to find out that AppScript has the ability to create hidden Projects within GCP regardless of the GCP Service on/off within Workspace&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;So users had set up an AppScript mail merge third party app (which really was just an user-initiated-internal-app using AppScript) which then provided access to Drive data - reason being that "trust internal apps" was checked&lt;/LI&gt;&lt;LI&gt;We unchecked the "trust internal apps" and then had to "block" then "limit" in bulk the list of "internal" apps&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This may be common sense or already known, but it was new to us since the blocking of third party apps is relatively new. So consider this: google services (AppScript) and other google services (GCP) along with a misunderstanding of "trust internal apps" led to users still having access to drive data.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Oct 2025 14:40:18 GMT</pubDate>
    <dc:creator>alexgrutza</dc:creator>
    <dc:date>2025-10-15T14:40:18Z</dc:date>
    <item>
      <title>For those that disable third party apps but allow internal apps</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/For-those-that-disable-third-party-apps-but-allow-internal-apps/m-p/180849#M4536</link>
      <description>&lt;P&gt;We identified something that was new to us but maybe others already knew this.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have GCP disabled within our Google Workspace environment for all users except a few that need it&lt;/LI&gt;&lt;LI&gt;We have AppScripts enabled by default - something that may change in the future&lt;/LI&gt;&lt;LI&gt;We have Google Drive service within the API Third Party area to "Restricted" - so only trusted apps can access that service-data&lt;/LI&gt;&lt;LI&gt;We had before yesterday the "internal third party apps are trusted" enabled&lt;/LI&gt;&lt;LI&gt;We noticed that users were still using mail merge applications with access to Drive data in which we did not "trust"&lt;/LI&gt;&lt;LI&gt;Further investigating, came to find out that AppScript has the ability to create hidden Projects within GCP regardless of the GCP Service on/off within Workspace&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;So users had set up an AppScript mail merge third party app (which really was just an user-initiated-internal-app using AppScript) which then provided access to Drive data - reason being that "trust internal apps" was checked&lt;/LI&gt;&lt;LI&gt;We unchecked the "trust internal apps" and then had to "block" then "limit" in bulk the list of "internal" apps&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This may be common sense or already known, but it was new to us since the blocking of third party apps is relatively new. So consider this: google services (AppScript) and other google services (GCP) along with a misunderstanding of "trust internal apps" led to users still having access to drive data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 14:40:18 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/For-those-that-disable-third-party-apps-but-allow-internal-apps/m-p/180849#M4536</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2025-10-15T14:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: For those that disable third party apps but allow internal apps</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/For-those-that-disable-third-party-apps-but-allow-internal-apps/m-p/181510#M4588</link>
      <description>&lt;P&gt;Hiya Alex, (yes, this was just something you didn't know&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; and, as always, the tough love is faster to type&lt;span class="lia-unicode-emoji" title=":red_heart:"&gt;❤️&lt;/span&gt;)&lt;/P&gt;&lt;P&gt;I assume that "users having access to drive data" is still true?&lt;/P&gt;&lt;P&gt;It's a fairly safe assumption, unless you have disabled the Drive service.&lt;/P&gt;&lt;P&gt;So, yes, it's good to know what that button does, but &lt;EM&gt;nothing has changed, or wasn't clear&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;It's even written exactly there what the setting does allow.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Trust internal apps" style="width: 999px;"&gt;&lt;img src="https://www.googleforeducommunity.com/t5/image/serverpage/image-id/5501i77ABBDCC30F71E3D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Skärmavbild 2025-11-11 kl. 16.56.46.png" alt="Skärmavbild 2025-11-11 kl. 16.56.46.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Allowing&amp;nbsp;&lt;EM&gt;internal apps&lt;/EM&gt;&amp;nbsp;(there is no such thing as "internal third party apps") lets users develop or use open source scripts (even Google publish such mail merge scripts) to make their life easier. It doesn't change the access those user have to actual content.&lt;/P&gt;&lt;P&gt;The code they create will not suddenly give them access to other things than what they already have access to.&lt;/P&gt;&lt;P&gt;***&lt;/P&gt;&lt;P&gt;Now... if you have a policy that nobody is allowed to send personalised emails with content from their Drive... then you have a case. If not, you just made people's job harder.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 16:07:50 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/For-those-that-disable-third-party-apps-but-allow-internal-apps/m-p/181510#M4588</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2025-11-11T16:07:50Z</dc:date>
    </item>
  </channel>
</rss>

