This official feed from the Google Workspace team provides essential information about new features and improvements for Google Workspace customers.


To help organizations elevate their security posture, we are introducing context-aware access (CAA) policies in the Admin console for Gemini Enterprise. Google Workspace administrators can select granular security attributes for Gemini Enterprise access, including device security and location settings that can be applied to personal and managed devices.

For example, an administrator can create a CAA policy that restricts access to Gemini Enterprise from specific geographic regions. Organizations can also reuse their existing policies that apply to Workspace apps by also applying them to Gemini Enterprise.



Context-Aware Access settings for Gemini Enterprise in Admin console

Getting started

  • Admins: Context-Aware Access for Gemini Enterprise can be configured at the organizational unit (OU) or group level. Visit the Help Center to learn more about Context-Aware Access, creating Context-Aware Access levels, and assigning Context-Aware Access levels to apps.
  • End users: If enabled by your admin, you can access Gemini Enterprise when authenticating using your Google sign-in. If your organization’s Context-Aware Access settings are not set to allow access, you may see a message letting you know that you cannot use Google sign-in to authenticate with Gemini Enterprise, or you may see remediation messages which will provide some options on how to unblock Gemini Enterprise.

Rollout pace

Availability

  • Enterprise: Enterprise Standard, and Plus
  • Education: Education Standard, and Plus
  • Other: Frontline Standard and Plus; Enterprise Essentials Plus; Cloud Identity Premium

Note: You will need to have purchased Gemini Enterprise to apply Context-Aware Access policies for your users.

Resources



Google Workspace administrators can now access comprehensive audit logs for Gemini Notebook in the Admin console, providing greater insights into how the application is used across their organizations. This update introduces full visibility into Gemini Notebook actions, allowing administrators to review usage and audit data access in the security investigation tool and audit and investigation tool.



Gemini Notebook log events in the ‘Audit and Investigation’ tool in the Admin console.

Additional details

Administrators can track a wide range of user actions across multiple categories, including notebook visibility, user identity, IP address, and resource context. These audit logs can be exported and reviewed using BigQuery or accessed directly within the Admin console using the security investigation tool. These monitoring capabilities help administrators meet regulatory compliance requirements, understand collaboration patterns, and protect company data within their digital environments.

Note: While audit log storage itself follows standard Workspace regional routing policies, Gemini Notebook user data—such as notebooks, sources, and chat histories—is stored globally and does not currently support data regionalization.

Getting started

Rollout pace

Availability

Resources

We’re excited to introduce the ability to specify Context-Aware Access policies to control access to Google Classroom. This update allows Google Workspace administrators to set granular security parameters for Classroom access directly from the Admin console. For example, an organization can create a policy that permits users to access Classroom only if they are connecting from a specific geographic region.

Expanding Context-Aware Access to Classroom gives administrators deeper control over their digital learning environments. Security policies can be tailored based on specific user attributes, including user identity, geographic location, device security status, and IP address.

By incorporating Classroom into broader organizational security frameworks, administrators can seamlessly manage access permissions across their Workspace apps. This ensures that sensitive school and student data remains protected, while making certain that only authorized users can connect to Classroom under secure, approved conditions.





Getting started

  • Admins: Context-Aware Access for Google Classroom can be configured at the organizational unit (OU) or group level. Visit the Help Center to learn more about Context-Aware Access, creating Context-Aware Access levels, and assigning Context-Aware Access levels to apps.
  • End users:  If enabled by your admin, you can access Google Classroom when authenticating using your Google sign-in. If your organization’s Context-Aware Access settings are not set to allow access, you may see a message letting you know that you cannot use Google sign-in to authenticate with Classroom, or you may see remediation messages which will provide some options on how to unblock Classroom.

Rollout pace

Availability

  • Education: Education Standard and Plus

Resources

For enterprise organizations, migrating files along with their permissions to a new platform can feel daunting and risk interrupting daily business operations. To help simplify this transition, we are excited to announce general availability of Google Workspace data import (advanced mode) to support large-scale file migrations from Microsoft OneDrive. Just like the other features of the data import, this is available at no additional cost.

This update allows IT teams to execute large migrations efficiently, as you can import multiple concurrent batches at a time. Data import automatically adjusts import speeds to match your Microsoft licensing tier, maximizing throughput without exceeding source quotas.

Data import provides:

  • Ease of use: A turnkey, scalable cloud-native service that can be accessed and used directly from the admin console. 
  • Quicker speeds and accuracy: Finish importing data sooner with faster migration speeds from parallelization and improved algorithms.
  • No additional cost to use: No additional infrastructure costs during migration or licensing costs for third-party data migration tools.


Additionally, customers will be able to use the migration planning utility for file migrations that will help improve their change management and data migration forecasting. The migration planning utility is available to provide source data corpus details and migration timeline estimates. This offers customers no-friction discovery and data-driven planning when undertaking large scale enterprise migrations from Microsoft 365 to Google Workspace.


Getting started

Rollout pace

Availability

  • Business: Business Starter, Standard, and Plus
  • Enterprise: Enterprise Standard and Plus
  • Education: Education Fundamentals, Standard, and Plus
  • Other Editions: Frontline Starter, Standard, and Plus; Essentials Starter, Enterprise Essentials, and Enterprise Essentials Plus; Nonprofit

Resources

For enterprise organizations, migrating communication history and collaboration channels to a new platform can feel daunting and risk interrupting daily business operations. To make this transition smoother, we are excited to announce that migrating chat data from Microsoft Teams to Google Workspace for large scale workloads is now generally available in data import. Just like the other features of the Data Import tool, this is available at  zero tool cost.

This enhancement builds on our existing data import capabilities, allowing admins to easily copy channel messages, group chats, and direct conversations from Teams to Workspace at no additional tool or infrastructure costs.

Data import for Teams offers:

  • Ease of use: A turnkey, scalable cloud-native solution that can be accessed and used directly from the admin console.
  • Quicker speeds and accuracy: Finish importing data sooner with faster migration speeds from parallelization and improved algorithms.
  • No additional cost to use: No additional infrastructure costs during migration or licensing costs for third-party data migration tools.
  • High fidelity: Both Teams channels as well as private chat messages (i.e. 1:1 and group messages) are imported.


Additionally, the migration planning utility now supports Teams to help customers improve their change management and data migration forecasting. The migration planning utility is available to provide migration timeline estimates and organize user data into speed-optimized batches. This offers customers simplified discovery and data-driven planning when undertaking large scale enterprise migrations from Microsoft 365 to Google Workspace.


Getting started

Rollout pace

Availability

  • Business: Business Starter, Standard, and Plus
  • Enterprise: Enterprise Standard and Plus
  • Education: Education Fundamentals, Standard, and Plus
  • Other Editions: Frontline Starter, Standard, and Plus; Essentials Starter, Enterprise Essentials, and Enterprise Essentials Plus; Nonprofit

Resources

The Google Workspace Allowlisted Domains API is now generally available. Previously, administrators had to manage their allowlisted domains list manually through the Google Workspace Admin console. With this release, hosted under the Cloud Identity API suite as a top-level resource, organizations can securely automate and programmatically manage their list of allowlisted domains.

By programmatically managing trusted external sharing boundaries, Workspace administrators can easily automate domain lists. This allows organizations to restrict external collaboration to verified, trusted partners, thereby mitigating data exfiltration risks and strengthening overall security posture without manual administrative overhead.

This launch includes a robust set of core capabilities to support your domain management workflows:

  • Core CRUD operations: Programmatic Create, Delete, List, and Get capabilities to manage your list of allowlisted domains
  • Exact-match filtering: Easily check and verify the presence of specific domains using exact-match filtering within the List API

Note: Reseller-managed workflows are not currently supported.

Getting started

  • Admins: To configure these rules via the API, administrators must have either domain management or domain allowlist management privileges for Google Workspace. See our documentation to learn more.
  • End users: There is no end-user setting or action required for this feature.

Rollout pace

Availability

  • Available to all Google Workspace customers

Resources

We are excited to announce the general availability of Google Workspace inbound SCIM APIs to help IT administrators standardize identity lifecycle management. This new capability allows you to sync your Google Workspace directory in real time with any SCIM-compatible Identity Provider (IdP), HR system (HRIS), or custom application.

With inbound SCIM, when a Workspace end user’s account permissions are changed via their organization’s IdP, their access to Workspace data and any downstream apps, such as Gemini Enterprise, will also be updated in real time. Previously, customers would need to build custom integrations using Google directory APIs.

SCIM overview

System for Cross-domain Identity Management (SCIM) is an open protocol that synchronizes directory information between identity systems. With inbound SCIM, Google Workspace acts as a SCIM Service Provider, enabling compatible Identity Providers (IdPs) to automatically provision, update, and deactivate users and groups in real time.

Inbound SCIM offers:

  • Automated lifecycle management: IT teams no longer need to manually create user accounts or update details for Workspace, saving significant time and costs.
  • Seamless onboarding and day-one productivity: New employees have access to all Workspace productivity tools the moment they start, creating a frictionless onboarding experience.
  • Enhanced security with instant deprovisioning: When an employee leaves your organization or changes roles, SCIM instantly pushes an update request to Workspace. This eliminates the security risks associated with orphaned accounts and makes compliance audits significantly easier.
  • Simplified admin experience: Inbound SCIM offers a one-click token generation experience and admin controls to lock synced groups from your external source to prevent manual changes in Workspace that would conflict with your identity provider.

Getting started

  • Admins: This feature will be available by default and can be disabled/enabled at the domain level. Visit the Help Center to learn more.
  • End users: This is an admin-facing feature only.

The Manage external directories page in the Admin console showing Inbound SCIM setup


Configure a new Inbound SCIM connection with external IdP

Rollout pace

Availability

  • Business: Business Starter, Standard, and Plus
  • Enterprise: Enterprise Starter, Standard, and Plus

Resources

Beginning today, the Gemini app adheres to your organization’s data regionalization requirements. As with Google Workspace, admins have the flexibility to configure controls for EU storage and processing, US storage and processing, or both, including granular settings down to the organizational unit (OU) level.


Data regions are critical for ensuring many customers can meet their own internal requirements, as well as other legal, regulatory, and data sovereignty requirements by controlling the geographical location of their data at rest. Expanding these controls to the Gemini app allows our customers to adopt Gemini broadly in their organization with confidence that their data is being processed and stored in the location they require. 

Getting started

Rollout pace

Availability

  • Enterprise: Enterprise Plus (provides in-region processing and storage capabilities)
  • Education: Education Plus and Education Standard (provides in-region storage capabilities only)
  • Other Editions: Frontline Plus (provides in-region processing and storage capabilities)

Resources

We’re giving admins more granular control over how mobile device management privileges are delegated. Specifically, admins can be assigned privileges for specific organizational units (OUs), adding another layer of security by scoping access only to necessary OUs.

Previously available in beta, we’re now making this feature generally available, with improvements to the way devices are displayed to help admins view and manage their devices more efficiently.



Example experience for an admin with OU-level permissions

Getting started

Rollout pace

Availability

  • Available to all Google Workspace customers

Resources

Google Workspace administrators can now utilize incremental exports when backing up organizational data. Instead of re-exporting their entire organization's data, admins can export frequent snapshots of their data into their organization’s own Google Cloud Storage (GCS) bucket.

Key benefits include faster completion times, reduced Google Cloud Storage consumption and costs, and the ability to establish more frequent backup schedules to mitigate the risk of potential data loss. 

Specifically, admins can schedule automated exports for Gmail, Drive, and Chat, with the flexibility to scope data by organizational unit (OU), group, or specific users. They can initiate:

  • Periodic full backups - establishing a baseline snapshot through regular full exports
    • Quarterly (every 3 months)
    • Semi-annually (every 6 months)
    • Annually (every year)
  • Frequent incremental backups - supplementing the baseline with frequent incremental backups, such as backing up data from the "last x days" every "y days"
    • Capture data from the last 5 days, running every 3 days
    • Capture data from the last 7 days, running every 5 days


Getting started

Rollout pace

Availability

Resources

In Alert Center, we are expanding the existing “Super Admin password reset” alert into a broader Admin password reset alert. Previously, this rule only triggered alerts when a super admin’s password was changed. With this update, the alert will now cover password resets for all administrator roles within your organization.

This update provides admins with better visibility and control over the security of their organization's privileged accounts. Monitoring password changes for all admin roles provide a higher level of oversight to respond more quickly to potential account compromises or unauthorized changes.

This change aligns with security best practices by treating all administrative access with increased vigilance.

Getting started

  • Admins: This feature will be ON by default and automatically replaces the previous "Super Admin password reset" rule. No action is required to enable the new alert. If you had modified the recipient list for the previous rule, those settings will automatically carry over to the new rule.
  • End users: There is no end user setting or impact for this feature.

Rollout pace

Availability

  • Available to all Google Workspace customers

Resources

The Workspace Policy API provides a centralized, comprehensive view of your security settings, eliminating the need to navigate to numerous pages in the Admin console.

With our latest update, we are introducing mutate endpoints (Create, Update, Delete) alongside existing read-only capabilities (Get, List) for data loss prevention (DLP) rules and detectors. This allows super admins to programmatically manage and fully automate the entire lifecycle of their DLP policies, from initial creation to real-time activation and deactivation.

Note this is an API-only launch for capabilities currently supported in the Admin console.

About DLP

DLP lets Workspace admins control external file sharing to prevent sensitive information leaks. It scans files for violations, triggering incidents and protective actions like content blocking.

How DLP works:

  • Admins define rules for sensitive content across Drive, Gmail, Chat, and Chrome.
  • DLP scans content for DLP rule violations that trigger DLP incidents.
  • DLP enforces the rules you defined and violations trigger actions, such as alerts.
  • Admins are alerted for DLP rule violations.
Summary of capabilities supported by mutate endpoints for DLP

Getting started

  • Admins: You must be a super admin to use the Policy API. See our developer documentation to learn more about the Policy API. You can also use GAM, an open source tool for managing Workspace, which now supports the Policy API.
  • End users: This is an admin-only capability.

Rollout pace

Availability

  • Available to all Google Workspace customers and Workspace Individual subscribers

Resources

We’re introducing an expanded set of native Apple Mobile Device Management (MDM) settings to Google Endpoint Management, providing administrators with more granular control over how iOS devices are configured and secured. These new settings—spanning categories such as Apps and Services, Device Features, Data Sharing, and Backup & iCloud Sync, etc—allow admins to manage critical device behaviors directly from the Google Workspace Admin console. This update allows organizations to efficiently harden their security posture for both corporate-owned and BYOD iOS devices. With this launch, these settings will become generally available.

See below for a detailed list of the new settings by category.

Apps and Services - Writing tools, App clips, App installation from web, App installation from alternative marketplaces, Apps to be hidden, Locking apps, In app purchases


Safari - Safari history clearing, Safari private browsing

Device Features - Auto unlock, Call recording, Auto dim, Default browser modification, Personalized advertising, eSIM outgoing transfers, OTA PKI updates, iPhone mirroring, Satellite connection, RCS messaging, Unpaired external boot to recovery, Untrusted TLS prompt, Limit ad tracking, AirPlay outgoing requests pairing password, Preserve eSIM on erase

Backup and iCloud Sync - Enterprise book backup

Authentication - Fingerprint for unlock

Data Sharing - Managed pasteboard

Getting started

Rollout pace

Availability

  • Available to all Google Workspace customers with Google Endpoint Management

Resources

Data loss prevention (DLP) for Google Calendar is now generally available to protect sensitive information shared within event details. Previously available in beta, this feature allows you to create and apply data protection rules that scan calendar event titles, descriptions, and locations for sensitive content, such as credit card numbers or national identification numbers.

Key functionalities include:

  • Choice of actions: Admins can choose to audit when an event is saved with sensitive content, warn users about sensitive content in their event, or block event creation or updates if a DLP policy is violated.
  • Event details: DLP rules scan free-text fields in the event, including the event’s title, description, and location fields.
  • Owner-based policies: Rules are applied based on the organizational unit (OU) of the owner (event organizer on primary calendars or calendar owner on secondary calendars), consistent with other Workspace DLP configurations.
  • User notifications: With DLP policies for Calendar, users receive immediate feedback when sensitive data is detected. On the web, users see a pop-up notification explaining the issue. Admins can also customize this message with more specific details. If a meeting update is blocked on Android, iOS, or via the Calendar API, the user will receive an automated email notification explaining the policy violation and why changes to the meeting invite were not successful.

Getting started

  • Admins: The feature will be OFF by default and can be enabled at the organizational unit (OU) or group level. Visit the Help Center to learn more about DLP for Calendar.
  • End users: There is no end user setting for this feature.
DLP settings in the admin console to configure policies for sensitive data, including actions and alerts when creating Calendar events
An end user is prompted with a message asking them to remove sensitive information

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Fundamentals, Standard, and Plus
  • Other Editions: Enterprise Essentials; Frontline Standard and Plus

Resources

Data loss prevention (DLP) rules for non-Workspace file attachments and associated proximity conditions are now generally available. These new capabilities enable organizations to target files with specific parameters, such as blocking the sharing of sensitive file formats or identifying files that contain specific strings in their titles.

Using these new content conditions, admins can set up various DLP rules for added protection, such as:

  • File names: Block files containing text string “funkyword”
  • File extensions: Block .java files
  • File types: Block custom mime type such as application/custom_app
  • Proximity matching: Detect “routing number” in proximity of 100 characters of “account number”

Additional details

In addition to file-based conditions, administrators can utilize associated proximity conditions to identify sensitive information in the file. This feature allows for the detection of sensitive data that appears within a specified distance of other predefined data types, regular expressions, or word lists.

For example, a rule can be configured to trigger when a bank account number is found within 100 characters of a routing number. By identifying data in context, proximity matching helps administrators reduce false positives and more accurately secure financial information or proprietary content.

Key functionality in DLP rules for file attachments and associated proximity conditions include:

  • Ability to match against common or custom MIME types and system file categories
  • Support for scanning attachments in Gmail, Drive, and Chat to set rules across communication channels 
  • Granular distance settings for proximity matching, allowing admins to define a range of up to 1,000 characters between matched conditions

Getting started

  • Admins: When configuring DLP rules in the admin console, admins can locate the new content conditions of file extension, file name, and file type under content conditions. Admins can also select the option of proximity matching to set a maximum distance between two pieces of matched texts. Visit the Help Center to learn more.
  • End users: There is no end user setting for this feature.
Content conditions for DLP in the Admin console to configure policies for sensitive file attachments

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Fundamentals, Standard, and Plus
  • Other Editions: Enterprise Essentials; Frontline Standard and Plus

Resources

Previously, data transfers from corporate Google Workspace accounts to third-party apps were restricted. We’re now recalibrating these restrictions to allow for a "trusted ecosystem" between managed apps.

With this release, users are now able to maintain efficient workflows and securely move data between corporate Workspace accounts and other authorized, managed third-party applications without being blocked. For added data protection, this capability strictly prevents the transfer of that data to personal accounts within the same managed Google application or to unmanaged personal apps.

For example, a user is able to copy a client's email address from their corporate Gmail account and successfully paste it into a managed third-party CRM application. When they try to paste that same email address into their personal Gmail account, they are blocked and receive the following message: "This information can only be shared within your organization's Google Workspace apps.”

Getting started

  • End users: There is no end-user setting for this feature.

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Standard and Plus
  • Other Editions: Frontline Standard; Enterprise Essentials Plus; Cloud Identity Premium

Resources

Previously available in beta, Device Bound Session Credentials (DBSC) in the Chrome browser on Windows is now generally available and enabled by default for Google Workspace users.

DBSC strengthens account security after users are logged in and helps bind a session cookie — small files used by websites to remember user information — to the device a user authenticated from. Even if malware was present on the user’s device, DBSC reduces the risk of session theft and makes it meaningfully more difficult for malicious actors to exploit stolen session cookies.

With this change to general availability, Workspace admins no longer need to take action to enable DBSC in the Admin console. Organizations can also bolster protections with more granular account attributes when using DBSC together with context-aware access (CAA). To monitor DBSC binding events, admins can view the audit logs available in the security investigation tool.

An example of the audit log and log details for a DBSC event in the admin console

Getting started

  • Admins: This feature is ON by default for all Google Workspace customers, and there is no administrator control to disable it.
  • End users: There is no end user setting for this feature.

Rollout pace

Availability

  • Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts

Resources

Today, we’re announcing improvements to our Out-of-Domain file-level warnings. First launched in April 2025, these badges alert users to documents and users outside of their Workspace organization, helping to prevent accidental data exfiltration and potential phishing attacks that spoof internal content. We’ve expanded support across devices and sharing types in the following ways:

  • Files in the Android and iOS apps for Drive, Docs, Sheets, and Slides now include external indicators
  • Chat Spaces and Google Groups can be configured to allow external users; if they’re given access to a document, that document now shows the external badge
  • If a service account has access to a document, and that service account is owned by an external Google Cloud organization, it now triggers the external badge in documents
  • Comment email notifications now include badges for external documents and users
  • File sharing email notifications now include badges for external documents and users

How Out-of-Domain warnings work

This feature helps users identify potentially risky files and avoid phishing scams when working with files shared from outside your organization.

Notification in comments

Notification in file sharing email

An image showing a Google Doc with the word "External" displayed in a small yellow badge next to the document title. The badge has been clicked, and a pop-up window appears with more information stating that “This document is owned by someone outside your organization. Be cautious about sharing sensitive information.
Image of "External" badge displayed in Google Docs

Getting started

Screenshot of the Google Workspace Admin console, navigated to Sharing settings. At the bottom of the page, a new section labeled "Highlight external files" is highlighted. The checkbox is checked, and the description reads: "Mark external files shared or owned externally as “external” to flag that content may be viewable outside your organization.
Image of the Google Workspace Admin console, Sharing settings, showing the "Highlight external files" option enabled

Rollout pace

Availability

  • Available to all Google Workspace customers

Resources

Administrators can now apply a global context-aware access (CAA) policy to all SAML applications within their organization. This update introduces a default assignment that serves as a universal security baseline, automatically protecting any SAML-based app that does not have a specific policy already assigned. By establishing this "secure-by-default" posture, IT teams can help protect internal data and third-party SaaS tools as new applications are integrated into their ecosystem.

This global control significantly reduces the administrative burden of managing security for applications at scale. Instead of manually configuring rules for every individual SAML app, administrators can set a single policy to cover their entire environment. Specific application-level policies will still take precedence, allowing for granular control where needed while the global policy acts as a reliable safety net.

These default policies support both Monitor and Active modes, providing flexibility in how security requirements are phased in. Detailed audit logs will capture these enforcement events, and remediation messages help end users understand how to resolve access issues independently.

Admins can configure CAA policies for all SAML apps in the Admin console under Security > Context-aware Access > General settings

Admins can configure CAA policies for all SAML apps in the Admin console under Security > Context-aware Access > General settings.

Getting started

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Standard and Plus
  • Other Editions: Frontline Standard and Plus; Enterprise Essentials Plus; Cloud Identity Premium

Resources

We’re excited to announce the beta release of a new, simplified way for very small and small-sized businesses to import their users from Microsoft to Google Workspace when setting up their Workspace account for the first time.

This new feature allows these businesses and educational institutions to automatically copy their existing Microsoft users into Google Workspace. Once you connect to Microsoft, the system automatically identifies users in your Microsoft account and prepares to add them in your new Google Workspace account. This feature significantly reduces the time and effort of switching from Microsoft and helps you get your organization up and running in no time.

You can complete the import in a single click after connecting to your Microsoft business account.




Additional details

Getting started

  • Admins: This feature will be available in the setup process for Google Workspace. Once you’ve verified your domain and activated your email records, you will find an option to import your users from Microsoft to Google Workspace before completing the setup. Visit the Help Center to learn more about importing business data during setup.
  • End users: This feature is for admins only.

Rollout pace

Availability

  • Business: Business Starter, Standard, and Plus
  • Enterprise: Enterprise Starter, Standard, and Plus 
  • Education: Education Fundamentals, Standard, and Plus
  • Other Editions: Frontline Starter, Standard, and Plus; Essentials Starter, Enterprise Essentials, and Enterprise Essentials Plus; Individual; Nonprofits; Cloud Identity Free and Premium
  • Education Add-ons: Google AI Pro for Education; Teaching and Learning; Endpoint Education

Resources