https://www.theregister.com/2024/09/03/google_workspace_third_party_apps/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features VMware Explore Blackhat and DEF CON Cloud Infrastructure Month Malware Month The Reg in Space Spotlight on RSA Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Amazon Web Services (AWS) New Horizon in Cloud Computing Google Gemini Hewlett Packard Enterprise: Edge-to-Cloud Platform Intel vPro VMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [devops] Devops 7 comment bubble on white Deadline looms: Google Workspace mandates OAuth by September 30 7 comment bubble on white 27 days to get your users' third-party apps on Google's sign-in icon Brandon Vigliarolo Tue 3 Sep 2024 // 16:45 UTC # Google Workspace administrators, consider yourselves on notice: In less than a month, many third-party apps (mail, calendar, etc.) will stop connecting to Workspace accounts. The change, effective September 30, will see Google disable access to "less secure apps," or LSAs, for all Google Workspace accounts. Those who haven't checked their Workspace Admin consoles recently will notice that LSA settings have already been removed, so there's no avoiding this change. LSAs, as far as Google is concerned, are anything that doesn't use OAuth by way of Sign-In with Google, the Chocolate Factory's authentication-as-a-service offering. In other words, no more signing into Google Workspace with just a password, so get ready to apologize to some executives. Hi, Helpdesk - yes, we know it's not working This isn't a surprise announcement - Google's Workspace team published a blog post about it last year to announce the transition away from LSAs. Sign-In with Google isn't exactly a new product either, so consider the next few weeks an opportunity to prevent a sudden surge in tickets at the end of the month. Thunderbird, iOS/macOS Mail, and Outlook for Mac users can all simply re-add their Google accounts using the Google account option in setup, and the same goes for users of modern Outlook products. Anyone still sticking to Outlook 2016 will be out of luck, though, so this is your chance to finally force an upgrade. * Google gamed into advertising a malicious version of Authenticator * Microsoft gives Windows admins a break and MFA a hard push * Google will make you use two-step verification to login * Multi-factor auth fatigue is real - and it's why you may be in the headlines next The same goes for calendar and contacts applications that connect to Google Workspace accounts, so be prepared to get those updated as well. Personal Google accounts won't be affected by the change. Mobile Device Management platforms that configure IMAP, CalDAV, CardDAV, POP or Exchange ActiveSync (Google Sync) are being phased out as well. Support for most of those protocols already phased out in June, and ActiveSync will be disabled at the end of September. [devops] "Admins will need to push a Google Account using their MDM provider, which will re-add their Google accounts to iOS devices using OAuth," Google noted. [devops] Finally, the tech giant said that Workspace-account connected scanners and other devices that use email to send documents will have to be reconfigured to use OAuth or some other alternative method as well, because they won't connect after the end of September, either. The countdown is on: 27 days. Of course, we're just yelling into the void, here: El Reg readers definitely know better than to allow users to sign in without any additional authentication factors, right? (r) Get our Tech Resources # Share More about * Authentication * Cybersecurity * Google More like these x More about * Authentication * Cybersecurity * Google * G Suite * Multifactor authentication Narrower topics * Android * App stores * Biometrics * Chrome * Chromium * Gemini * Google AI * Google Cloud Platform * Google I/O * Google Nest * Kubernetes * Pixel * Privacy Sandbox * RSA Conference * Tavis Ormandy * Zero trust Broader topics * 2FA * Alphabet * Cloud Computing * Search Engine * Security More about # Share 7 comment bubble on white COMMENTS More about * Authentication * Cybersecurity * Google More like these x More about * Authentication * Cybersecurity * Google * G Suite * Multifactor authentication Narrower topics * Android * App stores * Biometrics * Chrome * Chromium * Gemini * Google AI * Google Cloud Platform * Google I/O * Google Nest * Kubernetes * Pixel * Privacy Sandbox * RSA Conference * Tavis Ormandy * Zero trust Broader topics * 2FA * Alphabet * Cloud Computing * Search Engine * Security TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Yelp accuses Google of being a local search bully in antitrust lawsuit Chocolate Factory claims rival is trying to revive cases it's already lost Legal29 Aug 2024 | 8 Competition watchdog accuses Google of abusing ad dominance Provisional findings echo worries in the US and EC about the search giant's dominance Personal Tech6 Sep 2024 | 7 Google's Irish bit barn plans denied over eco shortfall DCs on the Emerald Isle better be green, says Dublin council - unless your name is Microsoft Systems27 Aug 2024 | 13 The ultimate dual-use tool for cybersecurity Sword or plowshare? That depends on whether you're an attacker or a defender Sponsored Feature [devops] Google says replacing C/C++ in firmware with Rust is easy Not so much when trying to convert coding veterans Software6 Sep 2024 | 130 White House's new fix for cyber job gaps: Serve the nation in infosec Now do your patriotic duty and fill one of those 500k open roles, please? Security5 Sep 2024 | 17 Rock Chrome hard enough and get paid half a million Google revises Chrome Vulnerability Rewards Program with higher payouts for bug hunters Security29 Aug 2024 | The future of AI/ML depends on the reality of today - and it's not pretty Opinion The return of Windows Recall is more than a bad flashback AI + ML27 Aug 2024 | 112 Check your IP cameras: There's a new Mirai botnet on the rise Infosec in brief Also, US offering $2.5M for Belarusian hacker, Backpage kingpins jailed, additional MOVEit victims, and more Security31 Aug 2024 | 22 What is missing from the web? We're asking for Google Besides sanity, of course Offbeat30 Aug 2024 | 37 Homeland security hopes to scuttle maritime cyber-threats with port infosec testbed Supply chains, 13M jobs and $649B a year at risk, so Uncle Sam is fighting back - with a request for info Public Sector5 Sep 2024 | 6 Brain Cipher claims attack on Olympic venue, promises 300 GB data leak French police reckon financial system targeted during Summer Games Cyber-crime29 Aug 2024 | 4 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2024 no-js