5 ms·
This article puts consumer accounts, enterprise accounts and what we call robot accounts in the same bag, but the reality is that the three classes of accounts
by m3drano 4y ago
This article puts consumer accounts, enterprise accounts and what we call robot accounts in the same bag, but the reality is that the three classes of accounts have different authentication and authorisation processes and the risk evaluation is quite different.
- usr1106 4y agoQuite different? Maybe. But undocumented and untestable, until that first and last test case that fails.
- hlandau 4y agoAuthor here. A bit confused by this comment since I make this exact point in the article. The requirements for 'consumer' and 'enterprise' authentication aren't the same, yet they're forced to use the same system in Google's case.
- wodenokoto 4y agoParent is saying that those 3 are not the same for google and that you are mixing them together. My employee account used to access workspace and GCP was quite different from my personal account.
- michaelt 4y agoEnterprises using Google can use any oauth2 provider they like, AFAIK.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- rippercushions 4y agoNo. You can use Google's consumer systems if you want to, and will do so if you log on with your Gmail (consumer) account, but GCP will happily talk with "enterprise" Workspace orgs, Active Directory, Okta, etc.
- getoffmyyawn 4y agoAs a business user of Google Workspace, it is a very different situation. Any one of our Super Admins (we have 3) can quickly unlock an account of any employee that has been locked out. We can also adjust the sensitivity of the auto lockout. For example, we currently get notifications of "suspicious" logins but do not auto lockout the user.
- NoZebra120vClip 4y agoThat seems great for expediency, but it also seems to place the exposure to social engineering back on the org, who might not have the best tools to authenticate someone whose account is already in lockdown. For example, I'm a remote user, and if I got logged out of all company systems, I could phone my supervisor or send email from my personal account. Is that enough to assure the Super Admins that I am who I say I am?
- getoffmyyawn 4y agoNo, that wouldn't be enough. Our employees can only access the Google Workspace from managed devices and everyone is required to use 2fa. If your account is flagged for a suspicious login, we call you. Unlocking your account only allows access from your assigned managed devices. If you have forgotten your password or lost your 2fa token and/or managed device, you have to come to the office in person.
- deleted 4y ago[deleted]