A genuine first for me.. gtempaccount

alexgrutza
Contributor III

This is a fascinating thing as I've never experienced this type of notification or issue before.

One of our users was notified by google about confirming a backup email (jdoe%ourdomain.tld@gtempaccount.com).

Digging into it, it seems like this user (and the others listed in the Unmanaged Users section - https://support.google.com/a/answer/6178640) created Google accounts before our organization went to a Google Workspace account (~2009, though there are recent modifications of as recent as 2018). 

I had no idea that you could create a Google account with any email address at some point in history before they started doing @gmail.com for Google accounts..

Fascinating!

 

--
CISSP | LinkedIn | @Phyxiis
1 ACCEPTED SOLUTION

If you go to an outside service like Dropbox, you’d typically set up an account with your existing email address and a password. My point is that it’s possible for people whose institutions don’t offer Google accounts to do exactly the same thing with Google accounts. 

For all of those services, the service provider will typically offer a way to “roll in” any existing consumer accounts if the owner of the domain signs a deal with the company. That roll-in process at Google is exactly what causes the gtempaccount accounts to be created. 

Some vendors even offer you the choice about whether you want to force roll-in all the consumer accounts or not. 

View solution in original post

5 REPLIES 5

icrew
Contributor II

You can still do it today! See the “Use an existing email address“ section of https://support.google.com/accounts/answer/27441?hl=en&co=GENIE.Platform%3DDesktop&oco=0  just like any other online service (like Dropbox, or Slack, or Zoom, or LinkedIn or your bank or whatever), it’s possible to create a Google account with an email address you already own.

Interesting. Any way to disable this for users? Perhaps I don't understand, but by signing up for Dropbox, it's not creating a Google account, you're just signing into Dropbox as your current Workspace account, no?

--
CISSP | LinkedIn | @Phyxiis

If you go to an outside service like Dropbox, you’d typically set up an account with your existing email address and a password. My point is that it’s possible for people whose institutions don’t offer Google accounts to do exactly the same thing with Google accounts. 

For all of those services, the service provider will typically offer a way to “roll in” any existing consumer accounts if the owner of the domain signs a deal with the company. That roll-in process at Google is exactly what causes the gtempaccount accounts to be created. 

Some vendors even offer you the choice about whether you want to force roll-in all the consumer accounts or not. 

I see. I do recall maybe a year ago an external vendor of ours needed to access Google Drive information, and Google changed something to where a Google account was needed in order to be Editor or something, and the vendor used MS365, so they had to create a google account with their own MS365 domain account, so that they could access our Drive data... 

People need to stop clicking things they shouldn't lol

--
CISSP | LinkedIn | @Phyxiis

This is apparently how you deny users within your domain from creating personal unmanaged accounts https://support.google.com/a/answer/16219306?hl=en&ref_topic=7042002&sjid=7532969668592679416-NC&aut...

--
CISSP | LinkedIn | @Phyxiis