מושגים שקשורים ל-Policy API

במאמר הזה מוסברים המושגים והאסטרטגיות של Cloud Identity Policy API.

הוזלה

כדי להציג מדיניות ולקבל אותה, אפשר לעיין במאמרים הגדרת Policy API והצגה וקבלת מדיניות.

הסברים על המונחים

  • ערך ההגדרה: ערכי ההגדרה שצוינו במדיניות

  • ערך ההגדרה המצומצם: ערכי ההגדרה הסופיים שחלים על יעד, כמו משתמש, יחידה ארגונית או קבוצה

  • צמצום: תהליך של צמצום ערכי ההגדרות במדיניות לערך הגדרה יחיד עבור יעד, כמו משתמש, יחידה ארגונית או קבוצה

  • Reducer: סוג הכללים שקובעים איך ערכי ההגדרות במדיניות מצטמצמים להגדרה אחת עבור משתמש

  • מדיניות אדמין: מדיניות שנוצרה על ידי אדמינים במסוף Admin

  • מדיניות מערכת: מדיניות שסופקה על ידי Google Workspace

תהליך ההפחתה

כדי להקטין הגדרה מסוימת עבור משתמש מסוים:

  1. מסננים את כל כללי המדיניות שלא חלים על המשתמש.

    1. סינון מדיניות שלא מכילה את ההגדרה.

    2. מסננים את המדיניות שחלה על היחידה הארגונית שהמשתמש לא נמצא בה.

    3. לסנן את כללי המדיניות שחלים על הקבוצה שהמשתמש לא נכלל בה.

    4. לסנן את כללי המדיניות שחלים על הרישיון שאין למשתמש היעד. מידע נוסף על רישיונות זמין בקטע רישיונות.

  2. החלת ה-Reducer של ההגדרה הנתונה.

    • Max: לכל שדה בהגדרה המצומצמת, הפונקציה Max בוחרת את הערך מהמדיניות עם sortOrder הגדול ביותר.

    • מיזוג: לכל שדה בהגדרה המצומצמת, פונקציית המיזוג בוחרת את הערך מהמדיניות עם sortOrder הכי גבוה שיש לו ערך בשדה הזה. אם השדה הוא מערך, הפונקציה Merge reducer (מיזוג) משרשרת את הערכים מכל כללי המדיניות.

    • MaxMap: רכיב ה-reducer‏ MaxMap משמש להגדרות שבהן לרשומות במערך יש שדה שמתפקד כמפתח ראשי. הפונקציה MaxMap reducer לא משרשרת את רשומות המערך עם אותו מפתח ראשי. במקום זאת, הוא מעדכן את הרשומה באמצעות פונקציית הצמצום Max בשדות האחרים ברשומות המערך שחולקות את אותו מפתח ראשי.

    • MergeMap: הפונקציה MergeMap reducer משמשת להגדרות שבהן לרשומות במערך יש שדה שמתפקד כמפתח ראשי. הפונקציה MergeMap reducer לא משרשרת את רשומות המערך עם אותו מפתח ראשי. במקום זאת, היא מעדכנת את הרשומה באמצעות פונקציית ה-reducer של מיזוג בשדות האחרים ברשומות המערך שחולקות את אותו מפתח ראשי.

    • רשימה: ההגדרות האלה לא מצטמצמות להגדרה אחת. במקום זאת, כל רצף ההגדרות נשמר ומוחל כרשימה.

פונקציות לצמצום נתונים להגדרות

שם ההגדרה Reducer
api_controls.custom_user_message מקסימום
api_controls.google_services MaxMap
api_controls.internal_apps מקסימום
api_controls.unconfigured_third_party_apps מזג
calendar.appointment_schedules מקסימום
calendar.external_invitations מקסימום
calendar.interoperability מזג
calendar.primary_calendar_max_allowed_external_sharing מזג
calendar.secondary_calendar_max_allowed_external_sharing מזג
chat.chat_apps_access מקסימום
chat.chat_file_sharing מקסימום
chat.chat_history מזג
chat.external_chat_restriction מזג
chat.space_history מקסימום
classroom.api_data_access מקסימום
classroom.class_membership מקסימום
classroom.guardian_access מקסימום
classroom.originality_reports מקסימום
classroom.roster_import מקסימום
classroom.student_unenrollment מקסימום
classroom.teacher_permissions מקסימום
cloud_sharing_options.cloud_data_sharing מקסימום
detector.regular_expression רשימה
detector.word_list רשימה
drive_and_docs.drive_for_desktop מקסימום
drive_and_docs.drive_sdk מזג
drive_and_docs.external_sharing מקסימום
drive_and_docs.file_security_update מקסימום
drive_and_docs.general_access_default מקסימום
drive_and_docs.shared_drive_creation מקסימום
gmail.attachment_compliance MaxMap
gmail.auto_forwarding מקסימום
gmail.blocked_sender_lists MaxMap
gmail.comprehensive_mail_storage מקסימום
gmail.confidential_mode מקסימום
gmail.content_compliance MaxMap
gmail.email_address_lists MaxMap
gmail.email_attachment_safety מקסימום
gmail.email_image_proxy_bypass מזג
gmail.email_spam_filter_ip_allowlist מקסימום
gmail.enhanced_pre_delivery_message_scanning מקסימום
gmail.enhanced_smime_encryption מקסימום
gmail.imap_access מזג
gmail.links_and_external_images מקסימום
gmail.mail_delegation מזג
gmail.name_format מזג
gmail.objectionable_content MaxMap
gmail.per_user_outbound_gateway מקסימום
gmail.pop_access מקסימום
gmail.rule_states MaxMap
gmail.spam_override_lists MaxMap
gmail.spoofing_and_authentication מקסימום
gmail.user_email_uploads מקסימום
gmail.workspace_sync_for_outlook מקסימום
groups_for_business.groups_sharing מזג
meet.safety_access מקסימום
meet.safety_domain מקסימום
meet.safety_external_participants מקסימום
meet.safety_host_management מקסימום
meet.video_recording מקסימום
rule.dlp רשימה
rule.system_defined_alerts רשימה
security.advanced_protection_program מקסימום
security.less_secure_apps מזג
security.login_challenges מקסימום
security.password מקסימום
security.session_controls מקסימום
security.super_admin_account_recovery מזג
security.two_step_verification_device_trust מקסימום
security.two_step_verification_enforcement מקסימום
security.two_step_verification_enforcement_factor מקסימום
security.two_step_verification_enrollment מקסימום
security.two_step_verification_grace_period מקסימום
security.two_step_verification_sign_in_code מקסימום
security.user_account_recovery מזג
SERVICE_STATUS_APP_NAME.service_status מקסימום
sites.sites_creation_and_modification מקסימום
user_takeout מקסימום
workspace_marketplace.apps_access_options מזג
workspace_marketplace.apps_allowlist ‫MergeMap (המפתח הראשי הוא: application_id)

רישיונות

כללי המדיניות חלים על המשתמשים בהתאם לרישיונות Workspace שלהם. תנאי הרישיון מפורט ב-PolicyQuery.

רשימה מלאה של מזהי המק"טים ומזהי המוצרים של Workspace

בדוגמאות הבאות אפשר לראות איך אפשר להחיל מדיניות על קבוצות מסוימות של משתמשים על סמך הרישיונות שלהם.

דוגמה 1: סעיף רגיל בלבד

entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010020027'])

המדיניות חלה על משתמש אם יש לו רשיון לפחות לאחד מהמק"טים ברשימה.

דוגמה 2: סעיף רגיל וסעיף הפוך

entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010020027']) && !entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010060005'])

המדיניות חלה על משתמש אם יש לו רישיון לפחות לאחד מהמק"טים בסעיף הראשון. עם זאת, אם למשתמש יש רישיון לאחד מהמק"טים בסעיף השני, המדיניות לא חלה על המשתמש הזה בכלל.

דוגמה 3: רק סעיף הפוך

!entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010060005'])

המדיניות חלה על משתמשים שאין להם רישיון לאף אחד מהמק"טים ברשימה.

ערכי ברירת המחדל שבשדות

אם שדה מסוים לא מופיע בהגדרה המצומצמת, ערך ברירת המחדל שלו הוא:

שם ההגדרה שדה ערך ברירת המחדל של השדה
api_controls.google_services services [] (רשימה ריקה)
calendar.external_invitations warn_on_invite true
calendar.interoperability enable_interoperability false
calendar.primary_calendar_max_allowed_external_sharing max_allowed_external_sharing EXTERNAL_FREE_BUSY_ONLY
calendar.secondary_calendar_max_allowed_external_sharing max_allowed_external_sharing EXTERNAL_ALL_INFO_READ_ONLY
chat.chat_apps_access enable_apps true במהדורות EDU, ‏ false במהדורות שאינן EDU. מהדורות EDU:
  • /product/Google-Apps/sku/Google-Apps-For-Education
  • /product/Google-Apps/sku/1010310002
  • /product/Google-Apps/sku/1010310003
  • /product/Google-Apps/sku/1010310005
  • /product/Google-Apps/sku/1010310006
  • /product/Google-Apps/sku/1010310007
  • /product/Google-Apps/sku/1010310008
  • /product/Google-Apps/sku/1010310009
  • /product/Google-Apps/sku/1010310010
  • /product/Google-Apps/sku/1010460001
  • /product/Google-Apps/sku/1010460002
enable_webhooks true במהדורות EDU, ‏ false במהדורות שאינן EDU. מהדורות EDU:
  • /product/Google-Apps/sku/Google-Apps-For-Education
  • /product/Google-Apps/sku/1010310002
  • /product/Google-Apps/sku/1010310003
  • /product/Google-Apps/sku/1010310005
  • /product/Google-Apps/sku/1010310006
  • /product/Google-Apps/sku/1010310007
  • /product/Google-Apps/sku/1010310008
  • /product/Google-Apps/sku/1010310009
  • /product/Google-Apps/sku/1010310010
  • /product/Google-Apps/sku/1010460001
  • /product/Google-Apps/sku/1010460002
chat.chat_history enable_chat_history false
history_on_by_default false
allow_user_modification true
chat.external_chat_restriction allow_external_chat false
external_chat_restriction NO_RESTRICTION
directory.external_directory_setting sharing_option ORGANIZATION_DIRECTORY_DATA
drive_and_docs.drive_sdk enable_drive_sdk_api_access true
drive_and_docs.external_sharing external_sharing_mode ALLOWED
allow_receiving_external_files true
warn_for_sharing_outside_allowlisted_domains true
allow_non_google_invites_in_allowlisted_domains false
allow_receiving_files_outside_allowlisted_domains true
warn_for_external_sharing true
allow_non_google_invites true
allow_publishing_files true
access_checker_suggestions RECIPIENTS_OR_AUDIENCE_OR_PUBLIC
allowed_parties_for_distributing_content ALL_ELIGIBLE_USERS
drive_and_docs.general_access_default default_file_access LINK_SHARING_PRIVATE
gmail.auto_forwarding enable_auto_forwarding true
gmail.email_image_proxy_bypass image_proxy_bypass_pattern [] (רשימה ריקה)
enable_image_proxy true
gmail.email_spam_filter_ip_allowlist allowed_ip_addresses [] (רשימה ריקה)
gmail.links_and_external_images apply_future_settings_automatically true
enable_aggressive_warnings_on_untrusted_links false
gmail.mail_delegation enable_mail_delegation false
gmail.smime_encryption enable_smime_encryption STATUS_DISABLED
allow_sha1_globally_in_smime_signature false
gmail.spoofing_and_authentication apply_future_settings_automatically true
gmail.user_email_uploads enable_mail_and_contacts_import false
gmail.workspace_sync_for_outlook enable_google_workspace_sync_for_microsoft_outlook true
groups_for_business.groups_sharing collaboration_capability DOMAIN_USERS_ONLY
create_groups_access_level USERS_IN_DOMAIN
view_topics_default_access_level DOMAIN_USERS
owners_can_allow_external_members false
owners_can_allow_incoming_mail_from_public true
owners_can_hide_groups false
new_groups_are_hidden false
security.less_secure_apps allow_less_secure_apps false
security.super_admin_account_recovery enable_account_recovery false
security.two_step_verification_device_trust allow_trusting_device true
security.two_step_verification_enforcement enforced_from ביטול הגדרות
security.two_step_verification_enforcement_factor allowed_sign_in_factor_set ALL
security.two_step_verification_enrollment allow_enrollment true
security.two_step_verification_grace_period enrollment_grace_period 0s
security.user_account_recovery enable_account_recovery false
workspace_marketplace.apps_access_options access_level ללקוחות K12: ALLOW_NONE אחרת: ALLOW_ALL
allow_all_internal_apps false
workspace_marketplace.apps_allowlist אפליקציות [] (רשימה ריקה)

קבוצות מערכת

קבוצות מערכת של Google הן קבוצות שלא מופיעות ב-Groups API ומקושרות למדיניות המערכת. מזהי הקבוצות שלהם לא מתחילים בקידומת groups/, בניגוד למזהי קבוצות אחרים. בטבלה הבאה מפורטות הקבוצות האלה והמשתמשים שמשויכים אליהן.

GroupId משתמשים שמשויכים לקבוצה הזו
WORKSPACE_ALL_ADMIN_GROUP כל האדמינים.
UNCONSENTED_CHILD_GROUP משתמשי EDU שסווגו כמשתמשים מתחת לגיל 18 ולא אישרו את הסכמת ההורה לגבי שירות נוסף אחד או יותר.