A Google Workspace service was configured as unrestricted
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Domain or Tenant Policy Modification (T1484)
Severity
Informational
Description
An identity configured a Google Workspace service as unrestricted
Apps configured with a trusted or limited access setting can access data for unrestricted services.
Attacker's Goals
Malicious apps can be used to access the organization's Google data.
Investigative actions
Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Check if the new settings look suspicious.
Follow further actions done by the account.
Variations
Was this helpful?
