resources:courses:gws_c3
差别
这里会显示出您选择的修订版和当前版本之间的差别。
后一修订版 | 前一修订版 | ||
resources:courses:gws_c3 [2025/01/20 23:00] – 创建 jackiez | resources:courses:gws_c3 [2025/01/23 18:06] (当前版本) – jackiez | ||
---|---|---|---|
行 1: | 行 1: | ||
# 第3章 GWS安全 | # 第3章 GWS安全 | ||
+ | ## 练习1 | ||
+ | 准备GWS域名,已经完成,略 | ||
+ | ## 配置通用安全设定 | ||
+ | {{: | ||
+ | 默认2FA是打开的,用户可以自行设定,但不是必须的。 | ||
+ | {{: | ||
+ | 如果要变更PW方针,可以勾选下次登录时执行,这个方针适用单位是OU或以上。 | ||
+ | {{: | ||
+ | 这里刚好有一个更新,2025年1月之后,所有第三方APP | ||
+ | [[https:// | ||
+ | 还有一个设置是恢复账户,Console里设置了权限,默认只有超级管理员可以恢复用户账号密码 | ||
+ | {{: | ||
+ | 这里把Allow users and non-super admins to recover their account设为ON,保存。 | ||
+ | ## 练习2 | ||
+ | 查看用户安全设置 | ||
+ | {{: | ||
+ | {{: | ||
+ | 作为管理员,可以强制用户重置密码,也可以为他添加恢复用邮箱和电话号码。另外,当用户登录活动可疑时,如果不能正确验明身份,则账户会被锁,这时管理员可以暂时关闭验证,以让用户本人可以正常登录,修改密码。 | ||
+ | 还可以查看该账号连携了哪些APP | ||
+ | 100名以上用户的IT管理员检查清单:[[https:// | ||
+ | ## 练习3 | ||
+ | 强制2FA | ||
+ | {{: | ||
+ | 然后找一个高管的邮箱,比如Alex登录后,会出现提示 | ||
+ | {{: | ||
+ | < | ||
+ | 有4种方式 | ||
+ | - 通行密钥和安全密钥 | ||
+ | - Google提示(如手机端的Gmail) | ||
+ | - 身份验证器(二维码或是OTP等) | ||
+ | - 电话号码(验证码或语音电话) | ||
+ | 参考链接[[https:// | ||
+ | 我们可以单独建立一个Group,对OU关闭2FA,但对Group是打开。 | ||
+ | ## 练习4 | ||
+ | 我们可以控制用户访问谷歌服务的会话时长,从1小时到默认的14天。 | ||
+ | {{: | ||
+ | 只对外包人员设置更短的会话时长。 | ||
+ | ## 测试1 | ||
+ | < | ||
+ | - **It' | ||
+ | - We wouldn' | ||
+ | - It would be a great opportunity to make sure everyone is the organization has a security key | ||
+ | - **It' | ||
+ | |||
+ | < | ||
+ | - **All the options** | ||
+ | - Disable access to less secure apps | ||
+ | - Set up 2-step verification | ||
+ | - View and manage your users' security settings | ||
+ | |||
+ | < | ||
+ | - **Security > Password management** | ||
+ | - Reports > Security | ||
+ | - Users > Account | ||
+ | - Security > Password monitoring | ||
+ | |||
+ | < | ||
+ | - Review a user's administrative access | ||
+ | - **Require a password change** | ||
+ | - **Temporarily disable the user's login challenge for 10 minutes** | ||
+ | - **Determine if the user is enrolled in 2-step verification** | ||
+ | |||
+ | < | ||
+ | - **You' | ||
+ | - Enforcing 2-step verification will not affect your users as they can still opt-out. | ||
+ | - **When you create new user accounts after enforcement, | ||
+ | - **You' | ||
+ | |||
+ | ## SSO介绍 | ||
+ | ## 练习1 | ||
+ | {{: | ||
+ | 如果要使用SAML来实现SSO,则需要同第三方服务商确认SSO的URL和EntityID信息。 | ||
+ | App> | ||
+ | {{: | ||
+ | 下载Metadata | ||
+ | {{: | ||
+ | 详细设定指导的URL [[https:// | ||
+ | {{: | ||
+ | 把域名补全,然后ID格式选择Email,继续 | ||
+ | {{: | ||
+ | 完成后,按照指导URL一步步操作才能用。因为公司用的HenngeOne,所以GWS上的操作也可以免了。。 | ||
+ | ## 练习2 | ||
+ | {{: | ||
+ | 这里要上传证书,需要OpenSSL,而且只能在Chrome浏览器,不能用其他的。 | ||
+ | 没有证书,所以练习略过。 | ||
+ | ## Secure LDAP | ||
+ | 同时管理SaaS和传统程序,需要LDAP服务,除了微软的AD外,还有谷歌的Secure LDAP。 | ||
+ | < | ||
+ | 步骤 | ||
+ | * Create LDAP client in the Admin console | ||
+ | * Configure your LDAP client to connect to the secure LDAP service | ||
+ | ## 练习3 | ||
+ | {{: | ||
+ | 设置最高权限 | ||
+ | {{: | ||
+ | {{: | ||
+ | 相关资料: | ||
+ | [[https:// | ||
+ | [[https:// | ||
+ | 类似于加入AD域的操作。 | ||
+ | ## 测试2 | ||
+ | < | ||
+ | - User's authenticate against a local directory to gain access to Google Workspace services | ||
+ | - **It reduces maintenance as directory information is consolidated into one directory** | ||
+ | - **It allows you to connect your LDAP-based applications and services to Google Workspace** | ||
+ | - **Users authenticate against the Google Workspace directory to gain access to LDAP compliant applications and services** | ||
+ | |||
+ | < | ||
+ | - Change Password URL | ||
+ | - **Google Certificate** | ||
+ | - **Entity ID URL** | ||
+ | - **SSO URL** | ||
+ | |||
+ | < | ||
+ | - Password reuse policy | ||
+ | - Password recovery | ||
+ | - **Require password change** | ||
+ | - Password monitoring | ||
+ | |||
+ | < | ||
+ | - **Apps > Web and mobile apps > Add App > Search for apps. Then search for Asana from the list of predefined applications** | ||
+ | - Security > Set up single sign-on (SSO) for SAML applications and provide the necessary information | ||
+ | - Apps > Web and mobile apps > plus sign (+) > SETUP MY OWN CUSTOM APP from the Enable SSO for SAML Application window | ||
+ | - Apps > Settings > Third-party integrations. Then search for Asana. | ||
+ | |||
+ | ## App安全 | ||
+ | - Control access from the Admin SDK API | ||
+ | - Block access to a specific service | ||
+ | - Create a trusted application list | ||
+ | - Explore the GWS Marketplace | ||
+ | ## 练习1 | ||
+ | {{: | ||
+ | {{: | ||
+ | ## 练习2 | ||
+ | 有许多第三方APP会连到GWS上,作为管理员要进行控制。 | ||
+ | {{: | ||
+ | {{: | ||
+ | {{: | ||
+ | 最后点FINISH,然后再把它限制 | ||
+ | {{: | ||
+ | < | ||
+ | 2.当用户想安装被禁用的APP,会收到错误信息</ | ||
+ | 参考链接:[[https:// | ||
+ | ## 练习3 | ||
+ | {{: | ||
+ | {{: | ||
+ | 安装GA4 | ||
+ | {{: | ||
+ | {{: | ||
+ | 查看结果 | ||
+ | {{: | ||
+ | 然后设置,只允许用户安装白名单的APP | ||
+ | {{: | ||
+ | 再添加白名单APP,练习中要求添加Google Apps Script, | ||
+ | 换成某一个用户的账号登录,查看URL apps.google.com/ | ||
+ | {{: | ||
+ | 再打开Market,任意安装一个APP,会跳出提示 | ||
+ | {{: | ||
+ | ## 测试3 | ||
+ | < | ||
+ | - Already installed applications that use the blocked API will continue to work until the application needs a new OAuth token | ||
+ | - **Already installed applications will stop working and OAuth tokens will be revoked** | ||
+ | - Already installed applications that use the blocked API will continue to work indefinitely | ||
+ | - Already installed applications that use the blocked API will continue to work until the user next signs in to Google Workspace | ||
+ | |||
+ | < | ||
+ | - **Users can not attempt to install an application that is not on the allowlist because they only see allowed apps in the Marketplace** | ||
+ | - When the user attempts to install the app they will see a message advising that the app cannot be installed because it has not been allowed | ||
+ | - Users can install an app that is not in the allowlist but they cannot grant it access to their data so it will not work | ||
+ | - The app will appear to install, but it will not function correctly. | ||
+ | |||
+ | < | ||
+ | - **Change the Marketplace settings to allow users to install only allowed applications from Google Workspace Marketplace** | ||
+ | - Complete a Domain install for each application that you want to allow | ||
+ | - Get your users to Install the Marketplace allowlist app onto each device | ||
+ | - Add the names of all the trusted applications to each user's device policy | ||
+ | |||
+ | < | ||
+ | - Disable API access from the Gmail and Drive service settings | ||
+ | - **From Security > Access and Data Control > API Controls, ensure Trust domain owned apps is enabled. From Security > Access and Data Control > API Controls > MANAGE GOOGLE SERVICES, restrict access to the Gmail and Drive services.** | ||
+ | - From Security > API Permissions, | ||
+ | - Disable Gmail and Drive API access from the top level organization settings | ||
+ | |||
+ | ## 练习1 | ||
+ | Security> | ||
+ | {{: | ||
+ | 发现有一个高危警报,User suspended | ||
+ | {{: | ||
+ | {{: | ||
+ | 找到TLS Failure | ||
+ | {{: | ||
+ | {{: | ||
+ | {{: | ||
+ | 系统预设的Rule只能设置Email通知(被触发时) | ||
+ | ## 练习2 | ||
+ | Reporting> | ||
+ | ## Security Center | ||
+ | - Security best practice | ||
+ | - Analytics | ||
+ | - Actionable insights | ||
+ | |||
+ | 还可以查看各类设置的状态,比如 | ||
+ | - Automatic email forwarding | ||
+ | - Device encryption | ||
+ | - Drive sharing settings | ||
+ | |||
+ | 查看各类报警,比如 | ||
+ | - External file share activity | ||
+ | - Authenticated messages | ||
+ | - Suspicious device activities | ||
+ | - Failed password attempts | ||
+ | |||
+ | Dashboard里则有各种图表,另外,还可以查看Log | ||
+ | - Access device-log data | ||
+ | - Access data about Gmail messages | ||
+ | - Access Gmail log data | ||
+ | - Access Drive log data | ||
+ | 举例来说,我们可以通过Query来确认,是否有如下行为 | ||
+ | - Delete specific messages | ||
+ | - Mark messages as spam or phishing | ||
+ | - Send message to quarantine | ||
+ | - Send message to users' inboxes | ||
+ | |||
+ | < | ||
+ | ## 测试4 | ||
+ | < | ||
+ | - **The alert center consolidates all admin created email alerts into one place** | ||
+ | - The alert center enables you to view alerts and alert details directly in the admin console | ||
+ | - The alert center includes additional in-depth details that enable you to take action to resolve numerous issues that might affect your organization | ||
+ | |||
+ | < | ||
+ | - **Delete message** | ||
+ | - **Mark message as spam** | ||
+ | - Forward tot self | ||
+ | - **View header** | ||
+ | |||
+ | < | ||
+ | - Access Transparency Audit log | ||
+ | - Users Security log | ||
+ | - The Admin Audit log | ||
+ | - **Users Account Activity Report** | ||
+ |
resources/courses/gws_c3.1737381653.txt.gz · 最后更改: 2025/01/20 23:00 由 jackiez