מושגים שקשורים ל-Policy API
במאמר הזה מוסברים המושגים והאסטרטגיות של Cloud Identity Policy API.
הוזלה
כדי להציג מדיניות ולקבל אותה, אפשר לעיין במאמרים הגדרת Policy API והצגה וקבלת מדיניות.
הסברים על המונחים
ערך ההגדרה: ערכי ההגדרה שצוינו במדיניות
ערך ההגדרה המצומצם: ערכי ההגדרה הסופיים שחלים על יעד, כמו משתמש, יחידה ארגונית או קבוצה
צמצום: תהליך של צמצום ערכי ההגדרות במדיניות לערך הגדרה יחיד עבור יעד, כמו משתמש, יחידה ארגונית או קבוצה
Reducer: סוג הכללים שקובעים איך ערכי ההגדרות במדיניות מצטמצמים להגדרה אחת עבור משתמש
מדיניות אדמין: מדיניות שנוצרה על ידי אדמינים במסוף Admin
מדיניות מערכת: מדיניות שסופקה על ידי Google Workspace
תהליך ההפחתה
כדי להקטין הגדרה מסוימת עבור משתמש מסוים:
מסננים את כל כללי המדיניות שלא חלים על המשתמש.
סינון מדיניות שלא מכילה את ההגדרה.
מסננים את המדיניות שחלה על היחידה הארגונית שהמשתמש לא נמצא בה.
לסנן את כללי המדיניות שחלים על הקבוצה שהמשתמש לא נכלל בה.
לסנן את כללי המדיניות שחלים על הרישיון שאין למשתמש היעד. מידע נוסף על רישיונות זמין בקטע רישיונות.
החלת ה-Reducer של ההגדרה הנתונה.
Max: לכל שדה בהגדרה המצומצמת, הפונקציה Max בוחרת את הערך מהמדיניות עם sortOrder הגדול ביותר.
מיזוג: לכל שדה בהגדרה המצומצמת, פונקציית המיזוג בוחרת את הערך מהמדיניות עם sortOrder הכי גבוה שיש לו ערך בשדה הזה. אם השדה הוא מערך, הפונקציה Merge reducer (מיזוג) משרשרת את הערכים מכל כללי המדיניות.
MaxMap: רכיב ה-reducer MaxMap משמש להגדרות שבהן לרשומות במערך יש שדה שמתפקד כמפתח ראשי. הפונקציה MaxMap reducer לא משרשרת את רשומות המערך עם אותו מפתח ראשי. במקום זאת, הוא מעדכן את הרשומה באמצעות פונקציית הצמצום Max בשדות האחרים ברשומות המערך שחולקות את אותו מפתח ראשי.
MergeMap: הפונקציה MergeMap reducer משמשת להגדרות שבהן לרשומות במערך יש שדה שמתפקד כמפתח ראשי. הפונקציה MergeMap reducer לא משרשרת את רשומות המערך עם אותו מפתח ראשי. במקום זאת, היא מעדכנת את הרשומה באמצעות פונקציית ה-reducer של מיזוג בשדות האחרים ברשומות המערך שחולקות את אותו מפתח ראשי.
רשימה: ההגדרות האלה לא מצטמצמות להגדרה אחת. במקום זאת, כל רצף ההגדרות נשמר ומוחל כרשימה.
פונקציות לצמצום נתונים להגדרות
| שם ההגדרה | Reducer |
api_controls.custom_user_message
|
מקסימום |
api_controls.google_services
|
MaxMap |
api_controls.internal_apps
|
מקסימום |
api_controls.unconfigured_third_party_apps
|
מזג |
calendar.appointment_schedules
|
מקסימום |
calendar.external_invitations
|
מקסימום |
calendar.interoperability
|
מזג |
calendar.primary_calendar_max_allowed_external_sharing
|
מזג |
calendar.secondary_calendar_max_allowed_external_sharing
|
מזג |
chat.chat_apps_access
|
מקסימום |
chat.chat_file_sharing
|
מקסימום |
chat.chat_history
|
מזג |
chat.external_chat_restriction
|
מזג |
chat.space_history
|
מקסימום |
classroom.api_data_access
|
מקסימום |
classroom.class_membership
|
מקסימום |
classroom.guardian_access
|
מקסימום |
classroom.originality_reports
|
מקסימום |
classroom.roster_import
|
מקסימום |
classroom.student_unenrollment
|
מקסימום |
classroom.teacher_permissions
|
מקסימום |
cloud_sharing_options.cloud_data_sharing
|
מקסימום |
detector.regular_expression
|
רשימה |
detector.word_list
|
רשימה |
drive_and_docs.drive_for_desktop
|
מקסימום |
drive_and_docs.drive_sdk
|
מזג |
drive_and_docs.external_sharing
|
מקסימום |
drive_and_docs.file_security_update
|
מקסימום |
drive_and_docs.general_access_default
|
מקסימום |
drive_and_docs.shared_drive_creation
|
מקסימום |
gmail.attachment_compliance
|
MaxMap |
gmail.auto_forwarding
|
מקסימום |
gmail.blocked_sender_lists
|
MaxMap |
gmail.comprehensive_mail_storage
|
מקסימום |
gmail.confidential_mode
|
מקסימום |
gmail.content_compliance
|
MaxMap |
gmail.email_address_lists
|
MaxMap |
gmail.email_attachment_safety
|
מקסימום |
gmail.email_image_proxy_bypass
|
מזג |
gmail.email_spam_filter_ip_allowlist
|
מקסימום |
gmail.enhanced_pre_delivery_message_scanning
|
מקסימום |
gmail.enhanced_smime_encryption
|
מקסימום |
gmail.imap_access
|
מזג |
gmail.links_and_external_images
|
מקסימום |
gmail.mail_delegation
|
מזג |
gmail.name_format
|
מזג |
gmail.objectionable_content
|
MaxMap |
gmail.per_user_outbound_gateway
|
מקסימום |
gmail.pop_access
|
מקסימום |
gmail.rule_states
|
MaxMap |
gmail.spam_override_lists
|
MaxMap |
gmail.spoofing_and_authentication
|
מקסימום |
gmail.user_email_uploads
|
מקסימום |
gmail.workspace_sync_for_outlook
|
מקסימום |
groups_for_business.groups_sharing
|
מזג |
meet.safety_access
|
מקסימום |
meet.safety_domain
|
מקסימום |
meet.safety_external_participants
|
מקסימום |
meet.safety_host_management
|
מקסימום |
meet.video_recording
|
מקסימום |
rule.dlp
|
רשימה |
rule.system_defined_alerts
|
רשימה |
security.advanced_protection_program
|
מקסימום |
security.less_secure_apps
|
מזג |
security.login_challenges
|
מקסימום |
security.password
|
מקסימום |
security.session_controls
|
מקסימום |
security.super_admin_account_recovery
|
מזג |
security.two_step_verification_device_trust
|
מקסימום |
security.two_step_verification_enforcement
|
מקסימום |
security.two_step_verification_enforcement_factor
|
מקסימום |
security.two_step_verification_enrollment
|
מקסימום |
security.two_step_verification_grace_period
|
מקסימום |
security.two_step_verification_sign_in_code
|
מקסימום |
security.user_account_recovery
|
מזג |
SERVICE_STATUS_APP_NAME.service_status
|
מקסימום |
sites.sites_creation_and_modification
|
מקסימום |
user_takeout
|
מקסימום |
workspace_marketplace.apps_access_options
|
מזג |
workspace_marketplace.apps_allowlist
|
MergeMap (המפתח הראשי הוא: application_id) |
רישיונות
כללי המדיניות חלים על המשתמשים בהתאם לרישיונות Workspace שלהם. תנאי הרישיון מפורט ב-PolicyQuery.
רשימה מלאה של מזהי המק"טים ומזהי המוצרים של Workspace
בדוגמאות הבאות אפשר לראות איך אפשר להחיל מדיניות על קבוצות מסוימות של משתמשים על סמך הרישיונות שלהם.
דוגמה 1: סעיף רגיל בלבד
entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010020027'])
המדיניות חלה על משתמש אם יש לו רשיון לפחות לאחד מהמק"טים ברשימה.
דוגמה 2: סעיף רגיל וסעיף הפוך
entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010020027']) && !entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010060005'])
המדיניות חלה על משתמש אם יש לו רישיון לפחות לאחד מהמק"טים בסעיף הראשון. עם זאת, אם למשתמש יש רישיון לאחד מהמק"טים בסעיף השני, המדיניות לא חלה על המשתמש הזה בכלל.
דוגמה 3: רק סעיף הפוך
!entity.licenses.exists(license, license in ['/product/Google-Apps/sku/1010060005'])
המדיניות חלה על משתמשים שאין להם רישיון לאף אחד מהמק"טים ברשימה.
ערכי ברירת המחדל שבשדות
אם שדה מסוים לא מופיע בהגדרה המצומצמת, ערך ברירת המחדל שלו הוא:
| שם ההגדרה | שדה | ערך ברירת המחדל של השדה |
api_controls.google_services
|
services | [] (רשימה ריקה)
|
calendar.external_invitations
|
warn_on_invite | true
|
calendar.interoperability
|
enable_interoperability | false
|
calendar.primary_calendar_max_allowed_external_sharing
|
max_allowed_external_sharing | EXTERNAL_FREE_BUSY_ONLY
|
calendar.secondary_calendar_max_allowed_external_sharing
|
max_allowed_external_sharing | EXTERNAL_ALL_INFO_READ_ONLY
|
chat.chat_apps_access
|
enable_apps | true במהדורות EDU, false במהדורות שאינן EDU. מהדורות EDU:
|
| enable_webhooks | true במהדורות EDU, false במהדורות שאינן EDU. מהדורות EDU:
|
|
chat.chat_history
|
enable_chat_history | false
|
| history_on_by_default | false
|
|
| allow_user_modification | true
|
|
chat.external_chat_restriction
|
allow_external_chat | false
|
| external_chat_restriction | NO_RESTRICTION
|
|
directory.external_directory_setting
|
sharing_option | ORGANIZATION_DIRECTORY_DATA
|
drive_and_docs.drive_sdk
|
enable_drive_sdk_api_access | true
|
drive_and_docs.external_sharing
|
external_sharing_mode | ALLOWED
|
| allow_receiving_external_files | true
|
|
| warn_for_sharing_outside_allowlisted_domains | true
|
|
| allow_non_google_invites_in_allowlisted_domains | false
|
|
| allow_receiving_files_outside_allowlisted_domains | true
|
|
| warn_for_external_sharing | true
|
|
| allow_non_google_invites | true
|
|
| allow_publishing_files | true
|
|
| access_checker_suggestions | RECIPIENTS_OR_AUDIENCE_OR_PUBLIC
|
|
| allowed_parties_for_distributing_content | ALL_ELIGIBLE_USERS
|
|
drive_and_docs.general_access_default
|
default_file_access | LINK_SHARING_PRIVATE
|
gmail.auto_forwarding
|
enable_auto_forwarding | true
|
gmail.email_image_proxy_bypass
|
image_proxy_bypass_pattern | [] (רשימה ריקה)
|
| enable_image_proxy | true
|
|
gmail.email_spam_filter_ip_allowlist
|
allowed_ip_addresses | [] (רשימה ריקה)
|
gmail.links_and_external_images
|
apply_future_settings_automatically | true
|
| enable_aggressive_warnings_on_untrusted_links | false
|
|
gmail.mail_delegation
|
enable_mail_delegation | false
|
gmail.smime_encryption
|
enable_smime_encryption | STATUS_DISABLED
|
| allow_sha1_globally_in_smime_signature | false
|
|
gmail.spoofing_and_authentication
|
apply_future_settings_automatically | true
|
gmail.user_email_uploads
|
enable_mail_and_contacts_import | false
|
gmail.workspace_sync_for_outlook
|
enable_google_workspace_sync_for_microsoft_outlook | true
|
groups_for_business.groups_sharing
|
collaboration_capability | DOMAIN_USERS_ONLY
|
| create_groups_access_level | USERS_IN_DOMAIN
|
|
| view_topics_default_access_level | DOMAIN_USERS
|
|
| owners_can_allow_external_members | false
|
|
| owners_can_allow_incoming_mail_from_public | true
|
|
| owners_can_hide_groups | false
|
|
| new_groups_are_hidden | false
|
|
security.less_secure_apps
|
allow_less_secure_apps | false
|
security.super_admin_account_recovery
|
enable_account_recovery | false
|
security.two_step_verification_device_trust
|
allow_trusting_device | true
|
security.two_step_verification_enforcement
|
enforced_from | ביטול הגדרות |
security.two_step_verification_enforcement_factor
|
allowed_sign_in_factor_set | ALL
|
security.two_step_verification_enrollment
|
allow_enrollment | true
|
security.two_step_verification_grace_period
|
enrollment_grace_period | 0s
|
security.user_account_recovery
|
enable_account_recovery | false
|
workspace_marketplace.apps_access_options
|
access_level | ללקוחות K12: ALLOW_NONE
אחרת: ALLOW_ALL
|
| allow_all_internal_apps | false
|
|
workspace_marketplace.apps_allowlist
|
אפליקציות | [] (רשימה ריקה)
|
קבוצות מערכת
קבוצות מערכת של Google הן קבוצות שלא מופיעות ב-Groups API ומקושרות למדיניות המערכת. מזהי הקבוצות שלהם לא מתחילים בקידומת groups/, בניגוד למזהי קבוצות אחרים. בטבלה הבאה מפורטות הקבוצות האלה והמשתמשים שמשויכים אליהן.
| GroupId | משתמשים שמשויכים לקבוצה הזו |
WORKSPACE_ALL_ADMIN_GROUP
|
כל האדמינים. |
UNCONSENTED_CHILD_GROUP
|
משתמשי EDU שסווגו כמשתמשים מתחת לגיל 18 ולא אישרו את הסכמת ההורה לגבי שירות נוסף אחד או יותר. |