To manage mobile apps for your organization, go here instead.
If your users sign in to apps through their Google accounts, you can control how these apps access your organization's data. Using OAuth 2.0 settings in the Google Admin console, you can manage 3 types of apps:
- Google-owned—Apps developed by Google
- Internal—Apps that your organization develops
- Third-party—Apps not created or owned by Google or your organization
Some apps use OAuth 2.0 scopes—a mechanism to limit access to a user's account. You can also customize the message that users see when they try to install an unauthorized app.
Note: For Google Workspace for Education, additional restrictions might prevent users in primary and secondary institutions from accessing certain apps.
On this page
- Before you begin: Review apps for your organization
- Restrict or unrestrict Google services
- Restrict access to high-risk OAuth scopes
- Manage app access to Google services & add apps
- Choose settings for unconfigured apps
- Known limitations
Before you begin: Review apps for your organization
In App access control, you can review the following apps:
- Configured apps—Apps configured with an access setting (Trusted, Limited, Specific Google data, or Blocked).
- Accessed apps—Apps that have accessed Google data.
- Apps pending review—Apps that users have requested access to.
Details about apps typically appear 24–48 hours after authorization.
-
In the Google Admin console, go to Menu
Security
Access and data control
API controls.
Requires having the Service Settings administrator privilege.
Click Manage App Access to view your configured apps. To filter the app list, click Add a filter and select an option.
The app list shows app name, type, and ID, as well as the following information for each app:
- Verified status—Verified apps have been reviewed by Google to ensure compliance with certain policies. Many well-known apps might not be verified in this way. For more details, go to What is a verified third-party app?
Access—Shows which organizational units have a configured access policy for the app. Point to an app and click View details to see the access levels (Trusted, Limited, Specific Google data, or Blocked).
If you apply an access policy to an organizational unit and then apply a different policy to your entire organization, the first policy remains in effect for the organizational unit.
Ownership—Shows if the app is third party, internal, or Google owned.
Google-verified badge—Shows for internal and third-party apps that have gone through the OAuth app verification process.
To see accessed apps, in the Accessed apps section, click View list.
For