Control access to corporate data on Chrome, Mac, and Windows devices with endpoint verification
Thursday, February 28, 2019
- Note that device access to corporate data can be configured at any time by using the Access Context Manager.
- For desktop devices, Admins will have the option to select Approve or Block, which will tag the device accordingly in the Access Context Manager.
- Approve or block actions on devices will generate an audit event within the Admin Console. For more information on audit logs for devices, see here.
- End users: No action needed
Additional details
This launch allows you to control access for devices with endpoint verification installed. This includes Chromebooks and other desktop devices running the Google Chrome browser.Tag newly registered endpoint verification devices as ‘Approved’ or ‘Blocked’ before setting access
When a new device is registered via Endpoint Verification, admins can turn on access restriction in the Access Context Manager. From there, they can govern device access by selecting ‘Approve’ or ‘Block’.
See image below to see how this will look in the Admin console with the feature ON.
If this policy is OFF, devices will be approved by default and can be blocked later on, for example, if a device is lost or a device is compromised.
Turn individual device access on or off
Admins can approve or remove access for devices in the Admin Console. A new view at Admin console > Device Management > Device Approvals will list all devices in a pending approval state. From this list, they can be tagged as Deviced/Approved — once devices are tagged, further access policies can be configured in the Access Context Manager.
Admins can also get email notifications for when a device is registered but needs admin approval. See our Help Center to learn how to configure email notifications.
Helpful links
- Help Center (end users): Allow an Admin to monitor your computer (Endpoint Verification)
- Help Center (Admins): Turn Endpoint Verification on or off
- Help Center (Admins): Control what devices can access your data
- Help Center (Admins): Devices audit log
Availability
Rollout details
- Rapid Release domains: Full rollout (1-3 days for feature visibility) starting on Feb 28, 2019
- Scheduled Release domains: Full rollout (1-3 days for feature visibility) starting on Feb 28, 2019
- Available to all G Suite editions.
On/off by default?
- Manual device verification will be OFF by default and can be enabled at the domain and OU level.
- Individual device access controls will be ON by default.
Stay up to date with G Suite launches