Google Workspace
Google WorkspaceConditional policies are a feature that allows you to set and manage security policies for documents stored in Google Drive (My Drive, Shared Drives). You can decrypt DRM documents stored in Google Drive and convert them into regular documents.
This guide explains the components and configuration methods of Google Workspace conditional policies.
This menu is only displayed to customers using Google Workspace.
Microsoft 365with the policyList of Separate Policiesis operated, and the priorities of the two policies do not affect each other.
Prerequisites
Registering a policy and the policyActually executed thingis different. If the conditions below are not met, the policy will be saved, but nothing will happen.
| # | condition | Check Location |
|---|---|---|
| 1 | Google WorkspaceYou must have role permissions. | Admin Permission Settings |
| 2 | The target drive must have a change notification channel installed. | 연동 관리 > Google Drive 이벤트 채널 |
| 3 | If you are targeting a shared drive, the service account must be added as a member of that shared drive and have write permissions. | Google Workspace Administration |
Channel installation for condition 2 includes**Each user's SHIELD ID account must be linked to a Google Workspace account.**does. For more details, refer to "Google Drive Event Channel"Document's
선행 조건Please refer to.
If this menu is visible, it means that the client's contract includes Google Workspace. The scope of cloud service usage isIt is not an item set directly by the administrator., There is no corresponding settings screen in the admin console.
Order of Policy Implementation
Google Drive policy includes**There are no steps to select document events.**The point at which notifications of changes in Drive are received is the same as the policy evaluation point.
Difference with Microsoft 365 Policies
| item | Microsoft 365 | Google Workspace |
|---|---|---|
| Target Storage | OneDrive · SharePoint · Teams | My Drive · Shared Drive |
| Target Document Type | General Document / DRM Document / MIP Document | DRM Document |
| Document Execution Policy | Encryption with MIP / Document Deletion / Document Decryption | Document Decryption |
| Document Path Specification | You can specify the folder path in the storage. | Drive Unit Specification (No Subdirectory Specification) |
| Document Event Specification | File creation/modification/upload, file movement | Not applicable |
**Google Drive conditional policies do not have a document event specification stage.**Google Drive's change notifications do not distinguish whether a file has been newly created or an existing file has been modified. Neither the policy registration screen nor the policy list displays event trigger items.
Conditional Policy Components
SHIELD DRM Admin Page조건부 정책 > Cloud Storage > Google WorkspaceClick the menu to access the screen.
Policy List Table Structure
- **Priority:**Indicates the order of policy implementation.
- **Policy Name:**This is the unique name of the policy.
- **Description:**The purpose of the policy or a brief description.
- **Members:**Specify the users, groups, or policy groups to which the policy applies.
- **Target document:**This is the type of document to which the policy applies. If security level (C/S/O) conditions are set, those conditions will also be displayed.
- **Document Path:**Displays the drives to which the policy applies (My Drive / Shared Drive).
- **Document Encryption Policy:**This is the document encryption method to which the policy will be applied.
- **Revision Date:**This is the date when the policy was last modified.
How to Register Conditional Policies
1. Policy Registration
정책 등록Click the button to enter the policy creation screen.
2. Enter Basic Policy Information
- Policy Name(Required) : Enter the unique name of the policy.
- Policy Description: You can enter the purpose of the policy or a brief description.
- Designating Members(Required) : Select the user or group to which the policy will be applied.
모든 사용자, can be specified for a specific user, group, or policy group. - Specify target document(Required) : The document subject to Google Workspace policy isDRM DocumentIt is. Unlike Microsoft 365 policies, general documents and MIP documents are not offered as optional.
(+) Additional settings when selecting the specified DRM document:
- Check Constructor Information
- Check if the document creator is the same as the logged-in user
- Option: Same / Not the same
- DRM Document Encryption Types
- Select from DAC(ACL), MAC(Category), GRADE(Rank)
- You can enter the related ID depending on the selected type.
- DRM Document Permission Assignment
- Check document permissions for logged-in users, creators, and added groups
- Permission types: Read, Edit, Output, Export, Release, Change Permission, Print Marking, Validity Period
- DRM Encryption Document Release Permission Check
- When applying the document decryption policy, we also check whether the subject has decryption rights.
- File Extension Specification
- Specifies the extension of the target DRM document.
- Security Level (C/S/O) Conditions
- You can additionally specify security levels (labels) for the target document. Multiple selections are possible.
- If you do not select a grade, all grades will be included.
- The grade ID and label ID are mapped in pairs and are judged together, and the policy will be applied only if the grade and label information of the target document match completely.
- Document Path Specification(Required) : Specify the Google Drive to which the enforcement policy will be applied.
내 드라이브공유 드라이브- Both items can be selected multiple times,at least oneYou must select to save.
- Unlike Microsoft 365 policies, the folder path inside the drive is not specified, and the entire path of the selected drive is the target.
3. Setting Conditions
- time: You can specify the time zone in which the policy will be applied.
시간 제한 없음If you select __PH_0__, the policy will always be applied.등록된 시간에서 선택You can specify a specific time zone through __PH_0__.- You can set exception times so that the policy does not apply during specific time zones.
4. Document Execution Policy Settings
The document enforcement policies that can be set in Google Workspace policies are as follows.
- **Document Decryption:**Decrypting the document and converting it to a regular document.
Provided in Microsoft 365 policies
MIP로 암호화,문서 삭제is not provided by Google Drive policy.
5. Policy Settings
- Usage Status: You can set the activation or deactivation of the policy through the toggle button.
- Expiration Date: You can specify a start date and an expiration date, and the expiration date will
무기한You can set it to.
6. Save and Complete
When all settings are complete,저장Click the button. It will be registered in the policy list, and you can modify or delete it afterwards.
Conditional Policy Editing
- You can click on the policy to edit in the policy list to change the detailed settings.
- Changing the order of the policy will reset the priority.
- The policy copy, delete, and JSON edit functions are provided in the same way as the existing conditional policies.
Order of Confirmation When Policy Is Not Enforced
If you have registered a policy but the document is not being converted, please check the following steps.The most common reason is that the event channel is not installed on the target drive.
Constraints
This is an item that is not supported due to product structure or cannot be bypassed.
| item | content |
|---|---|
| Document Event Specification | **Not provided.**Google Drive change notifications do not distinguish between creation, modification, and upload, so the timing of the change notification is the same as the policy evaluation timing. |
| Target Document | **Only DRM documents are subject to this.**General documents are treated as having no matching policy and are not counted as errors. |
| Execution Policy | This is document decryption. MIP로 암호화·문서 삭제·DRM encryption at the time of upload is not provided. |
| Document Path | **Only specified by drive unit.**The folder path inside the drive cannot be specified. |
| Event Channel | **Policies do not apply to drives where the channel is not installed.**The policy is saved but not enforced. |
| Shared Drive | The service account for the corresponding driveadded as a member and has write permissionIt must be executed. If there is no permission, the event will be received but the execution will fail. |
| Google Chat | **Not supported in this scope.**Files shared via chat are not subject to policy. |
| Synchronization Client | Changes to the Drive for desktop sync folder are also received as Drive change notifications. Sync can generate a continuous stream of change notifications, so the changes may not be reflected immediately. |
| Download Direction | This screen isOnly the direction going up to Driveis responsible. The re-protection of documents downloaded to the PC is조건부 정책 > Endpointis responsible for, and must develop the two policies together. |
| Scope of Cloud Service | This is not an item set directly by the administrator. There is no corresponding settings screen in the admin console. |
| Permission | Use of the menuGoogle WorkspaceYou need role permissions. |
Caution
- The policy name must be unique and cannot be duplicated.
- Required fields must be filled in for the policy to be saved. If no drives are selected in the document path, it cannot be saved.
- **Before registering the policy, please check the channel installation status of the target drive.**Installation status is
연동 관리 > Google Drive 이벤트 채널Check in. - If security level (C/S/O) conditions are set for the target document, the document's grade and label information must all match for the policy to be applied. If no conditions are set, the entire grade will be targeted.
- Items with higher priority in the policy will be executed first.
- When editing the policy, the changes will be applied only after clicking the save button.
- Policy creation, modification, and deletion history is in the admin log.
Google DriveIt is recorded as a policy type. - Execution result is
로그 > 문서 변환 로그You can check it at.