Skip to main content

Google Workspace

Google WorkspaceConditional policies are a feature that allows you to set and manage security policies for documents stored in Google Drive (My Drive, Shared Drives). You can decrypt DRM documents stored in Google Drive and convert them into regular documents.

This guide explains the components and configuration methods of Google Workspace conditional policies.

This menu is only displayed to customers using Google Workspace.Microsoft 365with the policyList of Separate Policiesis operated, and the priorities of the two policies do not affect each other.


Difference with Microsoft 365 Policies

itemMicrosoft 365Google Workspace
Target StorageOneDrive · SharePoint · TeamsMy Drive · Shared Drive
Target Document TypeGeneral Document / DRM Document / MIP DocumentDRM Document
Document Execution PolicyEncryption with MIP / Document Deletion / Document DecryptionDocument Decryption
Document Path SpecificationYou can specify the folder path in the storage.Drive Unit Specification (No Subdirectory Specification)
Document Event SpecificationFile creation/modification/upload, file movementNot applicable

Google Drive conditional policies include**There are no document event specification steps.**The policy registration screen and the policy list do not display any event trigger items.


Conditional Policy Components

SHIELD DRM Admin Page조건부 정책 > Cloud Storage > Google WorkspaceClick the menu to access the screen.

Policy List Table Structure

  • **Priority:**It indicates the order of policy implementation.
  • **Policy Name:**This is the unique name of the policy.
  • **Description:**The purpose of the policy or a brief description.
  • **Members:**Specify the users, groups, or policy groups to which the policy applies.
  • **Target document:**This is the type of document to which the policy applies. If security level (C/S/O) conditions are set, those conditions will also be displayed.
  • **Document path:**Displays the drives where the policy is applied (My Drive / Shared Drive).
  • **Document Encryption Policy:**This is the document encryption method that will be applied to the policy.
  • **Revision date:**This is the date when the policy was last modified.

How to Register Conditional Policies

1. Policy Registration

정책 등록Click the button to enter the policy creation screen.

2. Enter Basic Policy Information

  • Policy Name(Required) : Enter the unique name of the policy.
  • Policy Description: You can enter the purpose of the policy or a brief description.
  • Member Assignment(Required) : Select the user or group to which the policy will be applied.모든 사용자, can be specified for a specific user, group, or policy group.
  • Specify target document(Required) : The document subject to Google Workspace policy isDRM DocumentIt is. Unlike Microsoft 365 policies, general documents and MIP documents are not offered as optional.

(+) Additional settings when selecting the specified DRM document:

  • Check Constructor Information
    • Check if the document creator is the same as the logged-in user
    • Option: Same / Not Same
  • DRM Document Encryption Types
    • Select from DAC(ACL), MAC(Category), GRADE(Rank)
    • You can enter the related ID depending on the selected type.
  • DRM Document Permission Assignment
    • Check document permissions for logged-in users, creators, and added groups
    • Permission types: Read, Edit, Output, Export, Release, Change Permission, Print Marking, Validity Period
  • DRM encryption document release permission verification
    • When applying the document decryption policy, we also check whether the subject has decryption permissions.
  • File Extension Specification
    • Specifies the extension of the target DRM document.
  • Security Level (C/S/O) Conditions
    • You can additionally specify security level (label) conditions for the target document. Multiple selections are possible.
    • If you do not select a grade, all grades will be included.
    • The grade ID and label ID are mapped in pairs and are judged together, and the policy is applied only when the grade and label information of the target document matches completely.
  • Document Path Specification(Required) : Specify the Google Drive to which the enforcement policy will be applied.
    • 내 드라이브
    • 공유 드라이브
    • Both items can be selected multiple times,at least oneYou must select to save.
    • Unlike Microsoft 365 policies, the folder path within the drive is not specified, and the entire path of the selected drive is the target.

3. Setting Conditions

  • time: You can specify the time zone in which the policy will be applied.
    • 시간 제한 없음If you select __PH_0__, the policy will always be applied.
    • 등록된 시간에서 선택You can specify a specific time zone through __PH_0__.
    • You can set exception times so that policies do not apply during specific time zones.

4. Document Execution Policy Settings

The document enforcement policies that can be set in Google Workspace policies are as follows.

  • **Document Decryption:**Decrypting the document and converting it to a regular document.

Provided in Microsoft 365 policiesMIP로 암호화, 문서 삭제is not provided by Google Drive policy.

5. Policy Settings

  • Usage status: You can set the activation or deactivation of the policy through the toggle button.
  • Expiration Date: You can specify a start date and an expiration date, and the expiration date will무기한You can set it to.

6. Save and Complete

When all settings are complete,저장Click the button. It will be registered in the policy list, and you can modify or delete it afterwards.


Conditional Policy Editing

  • You can click on the policy you want to edit from the policy list to change the detailed settings.
  • Changing the order of the policy will reset the priority.
  • The policy copy, delete, and JSON edit functions are provided in the same way as the existing conditional policies.

Caution

  • The policy name must be unique and cannot be duplicated.
  • Required fields must be filled in for the policy to be saved. If no drive is selected in the document path, it cannot be saved.
  • **The installation of a notification channel for changes to the target drive must precede policy application.**Documents on drives where the channel is not installed are not subject to policy. Installation status is연동 관리 > Google Drive 이벤트 채널Check in.
  • If security level (C/S/O) conditions are set for the target document, the document's grade and label information must all match for the policy to be applied. If no conditions are set, the entire grade will be targeted.
  • Items with higher priority in the policy will be executed first.
  • When editing the policy, the changes will be applied only after clicking the save button.
  • Policy creation, modification, and deletion history is in the admin log.Google DriveIt is recorded as a policy type.
  • Use of the menuGoogle WorkspaceYou need role permissions.