6 ways Google Workspace helps IT admins safely use BYOD

4196
Of your peers have already read this article.
6:30 Minutes
The most insightful time you'll spend today!
Many organizations, including Google, have moved quickly to embrace working from home. With this widespread remote work, it’s never been more important for IT admins to be certain that every device in their organization is secure, even when that device isn’t company-owned.
We pioneered zero-trust security through our BeyondCorp strategy and leverage it to offer advanced security for G Suite* users to protect secure access for all devices. Admins can enforce these controls across G Suite and other corporate applications and data, ensuring consistent security and user experience across your organization.
Today, we’re laying out six key controls that IT admins can use within G Suite to help keep their organizations safe when using the bring your own device approach (BYOD). You can also review our detailed security checklist here, and learn more from our course on Managing G Suite here.
Secure mobile and desktop devices with endpoint management

BYOD devices can differ widely across an organization, with a range of OS versions, hardware modes, patch versions, and more, so it’s impossible to rely on a one-size-fits-all approach to device management. With Google endpoint management, IT admins can easily support a variety of mobile and desktop devices by enforcing measures like minimum software versions and blocking jailbroken or rooted devices, in many cases without requiring full device rights for employee privacy.
When it comes to managing mobile devices, G Suite offers basic and advanced mobile device management:
- With basic mobile device management, BYOD devices are secured with baseline security features with no end user friction. Admins can enforce a passcode, get a device inventory, wipe Google accounts remotely, and even remotely install applications on Android devices.
- With advanced mobile device management, admins can apply more policy controls over BYOD devices, and Android users can keep their personal data private and separate from their work data with Android Work Profiles. You can also allow and manage work apps on iOS and Android devices.


Admins can also manage and secure desktop devices with fundamental device management and enhanced desktop security for Windows. With fundamental device management, when a user logs into G Suite through any browser on a Windows, Mac, Chrome, or Linux device, that device will be automatically enrolled with endpoint management. This provides a base level of security to every desktop device that accesses G Suite data. With enhanced desktop security for Windows, admins can easily manage and secure Windows 10 devices through the admin console.
Enable secure connections without a corporate VPN using context-aware access

Context-aware access offers protection from unwanted access to G Suite services without the need for a VPN, and allows admins to set up different access levels based on a user’s identity and the context of the request, taking into account factors such as the country, device security status, and IP address of the request. For example, you can require BYOD devices accessing G Suite to meet encryption and password requirements, or restrict contractors from accessing G Suite from company managed Chromebooks.
Control data access with app access control

It’s important to protect all devices in your organization—corporate or BYOD—from malicious apps trying to gain access to corporate data. Using app access control, admins can take steps to prevent these apps from tricking users into mistakenly granting access to corporate data. With this feature, admins can choose which third-party apps are allowed to access users’ G Suite data by explicitly trusting, limiting, or blocking access for apps.
Enforce 2-Step Verification

With 2-Step Verification, admins can reduce the risk of unauthorized access by asking users for additional proof of identity when signing in. And you can now use the Advanced Protection Program—our strongest protection for users at risk of targeted attacks. With the Advanced Protection Program for the enterprise, we’ll enforce a specific set of policies for enrolled users including security key enforcement, blocking access to untrusted apps and enhanced scanning for email threats
If you choose not to use security keys for any reason, you have multiple other options to enforce 2-Step Verification on BYOD devices. For Android and iOS, you can use Google prompt, Google Authenticator, text message, or phone call options for a second verification step.
Prevent data loss and leakage with data loss prevention

We know that as an admin, one of your highest priorities is to keep internal information safe and secure. That’s why we developed data loss prevention (DLP) policies to help protect sensitive information in Drive, Docs, Sheets, Slides, and Gmail from loss, misuse, or being accessed by unauthorized users. With G Suite DLP, admins can choose which types of data are sensitive and exactly how to protect them. Our controls enable easy detection of a wide variety of common info types, and administrators can supplement this with custom content detectors to meet their organization’s needs. You can also classify files in Drive automatically using DLP rules (beta) to categorize your data by sensitivity levels. DLP works on all the devices in your organization, including BYOD ones, since the protection is at the data and application level.
In addition to DLP, you can use DXP for iOS devices to restrict the copy/pasting of G Suite data to other accounts, personal or otherwise. DXP for iOS can also restrict users’ ability to drag and drop files from specific apps within their G Suite account. Similarly, you can use Google endpoint management to configure Android devices to prevent data sharing between personal and work profiles.
Make retention and eDiscovery possible on all your devices with Vault

To support your organization’s retention and eDiscovery needs, Vault enables corporate data that’s stored in G Suite and accessed by BYOD devices to be available for all your information governance needs. No matter the owner of the device, your organization’s data stored in Gmail, Drive, Chat, Groups, Voice, and Meet are accessible to Vault.
Using the zero-trust security model, the G Suite features above work together to keep your data protected and organization secure across all devices, whether they’re corporate-owned or BYOD.
(*Google Workspace was previously G Suite)
Google Workspace Bolsters Data Security by Adding Client-Side Encryption to Gmail and Calendar

1575
Of your peers have already read this article.
4:30 Minutes
The most insightful time you'll spend today!
Editor’s note: This post originally appeared on the Google Workspace blog.
We consistently hear from our customers that the privacy of their data is top of mind, which is why we’ve built state-of-the-art security and privacy-preserving technologies into our products — to keep customer data private and secure. We’ve put Google AI to work on behalf of our customers to automatically stop the majority of online threats before they emerge. Gmail, for example, automatically blocks more than 99.9% of spam, phishing, and malware. These defenses, together with our unique encryption capabilities like client-side encryption (CSE), help our customers such as Groupe Le Monde, PwC, and Verizon, meet their security, privacy, compliance, and digital sovereignty requirements.
Last year, we enabled CSE for Drive, Docs, Slides, Sheets, and Meet, and today we’re excited to share that CSE is generally available for Gmail and Calendar, enabling even more organizations to become arbiters of their own data and the sole party deciding who has access to it. We recognize sovereign controls are important to customers and have accelerated delivery of these encryption capabilities to support our customers in maintaining control over their data and meeting their regulatory compliance needs.
Guarantee complete control of your data for the most challenging regulations
The expansion of CSE capabilities across Google Workspace helps to significantly reduce the burden of compliance for enterprises and public sector organizations. It gives organizations higher confidence that any third party, including Google and foreign governments, cannot access their confidential data. Workspace already encrypts data at rest and in transit by using secure-by-design cryptographic libraries. Client-side encryption takes this encryption capability to the next level by ensuring that customers have sole control over their encryption keys — and thus complete control over all access to their data. Starting today, users can send and receive emails or create meeting events with internal colleagues and external parties, knowing that their sensitive data (including inline images and attachments) has been encrypted before it reaches Google servers.
Users can continue to collaborate across other essential apps in Google Workspace while IT and security teams can ensure that sensitive data stays compliant with regulations. As customers retain control over the encryption keys and the identity management service to access those keys, sensitive data is indecipherable to Google and other external entities.
One key use case for CSE in this context centers on helping organizations subject to regulatory requirements, such as PwC, remain compliant, by meeting the need for the highest levels of encryption for certain types of communication.
“We have been searching for the capability to guarantee that our encrypted communications remain inaccessible to third-parties, including our technology providers, for some time. Google appears to be uniquely positioned with client-side encryption in providing us with complete control over our sensitive data, ensuring that we remain compliant as an organization in the ever changing world of data regulation. These features now being available across Google Workspace represent a pivotal moment for us. We’re enthusiastic about the ability to continue to benefit from the efficiency in working that Workspace provides us with, whilst at the same time maintaining trust with our customers that their confidential data will stay private and compliant,” said Shaun Bookham, UK Operations & Technology Director at PwC.
One of our global telecommunications customers, Verizon, is leveraging CSE to gain complete control over their sensitive data, ensuring that they remain compliant as an organization while supporting customers in highly regulated industries. This opens doors for the company to deliver an exceptional experience for its customers, by extending the level of data protection and privacy to their clients.
“At Verizon, we adhere to governance requirements related to access of our sensitive data while also providing the best experience coupled with deep trust. We have worked alongside Google to develop new encryption solutions and are excited to explore their utilization,” said Russell Leader, Director Collaboration and Mobility at Verizon.

Protecting an organization’s most important assets
The regulatory requirements for separation between an organization’s data and their cloud provider’s environment has resulted in important use cases for client-side encryption — from keeping sensitive R&D data extremely private, even from an organization’s SaaS provider, to scenarios where confidentiality is paramount to the success or failure of a mission-critical operation.
Customers, such as media giant Groupe Le Monde, rely on client-side encryption to protect their most crucial assets. By leveraging client-side encryption across Workspace, Groupe Le Monde can be assured that their communications, appointments, and files will not be subject to leaks, thus helping to keep their journalists safe.
“Client-side encryption gives us the next level of privacy, to ensure integrity within the journalistic process. This allows us to guarantee a higher level of security for our journalists, and to protect our sensitive content,” said Sacha Morard, Chief Technology Officer at Groupe Le Monde.
Another industry-leading Google Workspace enterprise customer uses client-side encryption to protect their most sensitive projects. For these projects, the customer is the sole owner of their encryption keys, thereby protecting their critical intellectual property and maintaining their data sovereignty requirements.

While each customer’s digital transformation journey is different, with all essential Google Workspace apps now being covered by CSE, companies of all sizes in all industries can benefit from these protections.
Starting today, client-side encryption is available globally to customers with Workspace Enterprise Plus, Education Standard, and Education Plus. To learn more about client-side encryption and how to get started today, watch our presentation from Google Cloud Next ’22 and check out the documentation.
A set of new capabilities to build a differentiated data platform: BigLake, now generally available

3584
Of your peers have already read this article.
3:30 Minutes
The most insightful time you'll spend today!
Data continues to grow in volume and is increasingly distributed across lakes, warehouses, clouds, and file formats. As more users demand more use cases, the traditional approach to build data movement infrastructure is proving difficult to scale. Unlocking the full potential of data requires breaking down these silos, and is increasingly a top priority for enterprises.
Earlier this year, we previewed BigLake, a storage engine that extends innovations in BigQuery storage to open file formats running on public cloud object stores. This allows customers to build secure multi-cloud data lakes over open file formats. BigLake provides consistent, fine-grained security controls for Google Cloud and open-source query engines to interact with data. Today, we are excited to announce General Availability for BigLake, and a set of new capabilities to help you build a differentiated data platform.
“We are using GCP to build and extend one of the street’s largest risk systems. During several tests we have seen the great potential and scale of BigLake. It is one of the products that could support our cloud journey and drive application’s future efficiency” – Scott Condit, Director, Risk CTO Deutsche Bank.

Build a distributed data lake that spans across warehouses, object stores & clouds with BigLake
Customers can create BigLake tables on Google Cloud Storage (GCS), Amazon S3 and ADLS Gen 2 over supported open file formats, such as Parquet, ORC and Avro. BigLake tables are a new type of external table that can be managed similar to data warehouse tables. Administrators do not need to grant end users access to files in object stores, but instead manage access at a table, row or a column level. These tables can be created from a query engine of your choice, such as BigQuery or open-source engines using the BigLake connector. Once these tables are created, BigLake and BigQuery tables can be centrally discovered in the data catalog and managed at scale using Dataplex.
BigLake extends the BigQuery storage API to object stores to help you build a multi-compute architecture. BigLake connectors are built on the BigQuery storage API and enable Google Cloud DataFlow and open-source query engines (such as Spark, Trino, Presto, Hive) to query BigLake tables by enforcing security. This eliminates the need to move the data to a query engine specific use case and security only needs to be configured at one place and is enforced everywhere.
“We are using GCP to design datalake solutions for our customers and transform their digital strategy to create a data-driven enterprise. Biglake has been critical for our customers to quickly realize the value of analytical solutions by reducing the need to build ETL pipelines and cutting-down time-to-market. The performance & governance features of BigLake enabled a variety of data lake use cases for our customers.” – Sureet Bhurat, Founding Board member – Synapse LLC
BigLake unlocks new use cases using Google Cloud and OSS Query engines
During the preview, we saw a large number of customers use BigLake in various ways. Some of the top use cases include:
Building secure and governed data lakes for open-source workloads – Workloads migrating from Hadoop, Spark first customers, or those using Presto/Trino, can now use BigLake to build secure, governed and performant data lakes on GCS. BigLake tables on GCS provide fine-grained security, table management (vs giving access to files), better query performance and integrated governance with Dataplex. These characteristics are accessible across multiple OSS query engines when using the BigLake connectors.
“To support our data driven organization, Wizard needs a data lake solution that leverages open file formats and can grow to meet our needs. BigLake allows us to build and query on open file formats, scales to meet our needs, and accelerates our insight discovery. We look forward to expanding our use cases with future BigLake features” – Rich Archer, Senior Data Engineer – Wizard
Eliminate or reduce data duplication across data warehouses and lakes – Customers who use GCS, and BigQuery managed storage had to previously create two copies of data to support users using BigQuery and OSS engines. BigLake makes the GCS tables more consistent with BigQuery tables, reducing the need to duplicate data. Instead, customers can now keep a single copy of data split across BigQuery storage and GCS, and data can be accessed by BigQuery or OSS engines in either places in a consistent, secure manner.
Fine-grained security for multi-cloud use cases – BigQuery Omni customers can now use BigLake tables on Amazon S3, and ADLS Gen 2 to configure fine grained security access control, and take advantage of localized data processing, and cross cloud transfer capabilities to do multi-cloud analytics. Tables created on other clouds are centrally discoverable on Data catalog for ease of management & governance
Interoperability between analytics and data science workloads – Data science workloads, using either Spark or Vertex AI notebooks can now directly access data in BigQuery or GCS through the API connector, enforcing security & eliminating the need to import data for training models. For BigQuery customers, these models can be imported back into BigQuery ML to produce inferences.
Build a differentiated data platform with new BigLake capabilities
We are also excited to announce new capabilities as part of this General Availability launch. These include:
- Analytics Hub support: Customers can now share BigLake tables on GCS with partners, vendors or suppliers as linked data sets. Consumers can access this data in place through the preferred query engine of their choice (BigQuery, Spark, Presto, Trino, Tensorflow).
- BigLake tables is now the default table type BigQuery Omni, and has been upgraded from the previous default of external tables.
- BigQuery ML support: BigQuery customers can now train their models on GCS BigLake tables using BigQuery ML, without needing to import data, and accessing the data in accordance to the access policies on the table.
- Performance acceleration (preview): Queries for GCS BigLake tables can now be accelerated using the underlying BigQuery infrastructure. If you would like to use this feature please get in touch with your account team or fill out this form.
- Cloud Data Loss Prevention (DLP) profiling support (coming soon): Cloud DLP can soon scan BigLake tables to identify and protect sensitive data at scale. If you would like to use this feature please get in touch with your account team.
- Data masking and audit logging (Coming soon): BigLake tables now support dynamic data masking, enabling you to mask sensitive data elements to meet compliance needs. End user query requests to GCS for BigLake tables are now audit logged and are available to query via logs.
Next steps
Refer to BigLake documentation to learn more, or get started with this quick start tutorial. If you are already using external tables today, consider upgrading them to BigLake tables to take advantage of above mentioned new features. For more information, reach out to the Google cloud account team to see how BigLake can add value to your data platform.
100 Stores. 5 States. How Schnucks Pulled Off a Mammoth Collaboration Feat

4408
Of your peers have already read this article.
4:30 Minutes
The most insightful time you'll spend today!
As a family supermarket chain since 1939, Schnuck Markets Inc. depends on driving efficiency and volume sales to achieve its mission, identifying customer service and community partnerships among its key differentiators.
In order to commit its maximum resources for success, Schnucks continues to focus on streamlining operations and achieving greater efficiency. Management and administrative staff throughout the company’s 100 stores in five states need to be able to collaborate effortlessly while enjoying an accurate, centralized information exchange platform. These efficiencies have the potential to impact productivity, customer service, and employee engagement.
Fast-tracking data sharing
Before adopting G Suite, Schnucks found collaborative workflows to be a challenge. Managers from different stores, often in different states, had to provide data that could be compiled and shared. Collaborative documents on traditional platforms faced challenges at Schnucks, where limits of simultaneous users would result in user lockouts. Schnucks managers often exchanged many different versions of the same documents and spreadsheets. However, reconciling all those versions was time-consuming and limited real-time collaboration.
“When we share a Google sheet and request data, 200 people can add their responses immediately at the same time from any device. They don’t walk away and forget and need a reminder. The result is near-effortless compliance,” says Kim Anderson, Director of Procurement and Replenishment at Schnucks.
Schnucks has been successful using the entire range of G Suite tools, with Drive, Docs, Slides, Sheets, and Forms contributing to enhanced collaboration. Google Keep is a popular productivity tool for meeting notes and tasks and creating reminders. Schnucks also uses Hangouts Meet and Hangouts Chat to reduce time and costs spent in face-to-face meetings, and Calendar as the central source for scheduling company events and meetings.
The partnership between Schnucks and Agosto helped with a successful G Suite deployment for the retailer. Agosto helped coordinate the logistics of the move and tackled the G Suite migration with a three-part strategy: IT staffers would move to Google first before employee “Google Guide” experts came in who could help answer teammate G Suite questions.
“Agosto’s deployment plan helped our G Suite deployment run smoothly,” says Dave Steck, Schnucks Vice President of Development and IT Infrastructure. “Their thorough planning helped mitigate the inevitable disruption a change of this size would make.”
Enhanced security and reliability
Previously, Schnucks relied on email to exchange information and any outages added even more lag time to its operations. With Gmail and the entire G Suite, Schnucks now experiences virtually no downtime, allowing for effective communication with enhanced levels of reliability and security.
“We were able to take advantage of the security benefits of G Suite right away,” says Joey Smith, Vice President and Chief Information Security Officer at Schnucks. “Our administrators are able to quickly configure, test, and manage our G Suite security settings to fit the security needs of our business while maintaining compliance with all regulatory obligations.”
On top of the CapEx and OpEx savings with Google providing infrastructure for its office productivity software, Schnucks has gained increased security and high availability, as well as robust disaster recovery. These features are included in G Suite, without any need for IT intervention.
“G Suite automatically encrypts our data with a unique encryption key for each piece and distributes it across multiple data centers for performance, security, and reliability,” says Joey. “This saves us a significant amount of time and money while achieving top notch security.”
Another way Schnucks benefits from Google security is the availability of data loss protection (DLP) features native to Gmail. With DLP, Schnucks can automatically audit outgoing emails for Personal Identifiable Information (PII), Protected Health Information (PHI), and other information the store requires.
“DLP is very powerful because it provides detailed visibility,” says Joey. “We can isolate emails, analyze patterns of false positives, and follow up with education or enhanced restrictions to increase security.”
Spam reduction
An unexpected advantage of adopting G Suite was an instantaneous reduction in spam emails. That’s more administrative time saved for employees. In fact, Gmail native spam prevention is so effective that Schnucks was able to replace its third-party spam filter with a simpler technology that costs 80% less.
Savings on hardware and software
Converting to G Suite saves Schnucks the operational costs of an infrastructure for office and communications solutions, but its web interface also provides substantial savings on application maintenance, anti-virus software, and hardware.
With G Suite files and applications residing in the cloud, the need for employees to use heavyweight installable applications is increasingly rare. As laptops age, Schnucks is replacing them with Chromebooks, saving approximately $1,250 per computer. Because Chromebooks don’t require additional anti-virus software or many other endpoint security measures, the need for software licenses and other security and maintenance costs are simultaneously reduced.
Schnucks also finds that Chromebooks instantly increase productivity. “What’s great about the Chromebook is the productivity savings we get from the speed and ease of use and management,” says Dave Steck, Vice President of Development and IT Infrastructure at Schnucks. “You’re not waiting for applications to start up. As a result, Chromebooks are the only laptops we need for the majority of our teammates.”
Aligning the company across sites
More than just providing a common set of office tools, intuitive collaboration in G Suite enables the grocery chain to provide consistent messaging and a central information hub across all store locations. With posters, presentations, and communications, Schnucks worked hard to help ensure that the entire company understood the value of the tools. The Operations and IT teams rolled out the changeover in three phases, using Google Guides to show the benefits of adoption and then rolling out to larger groups over time.
“Adopting G Suite as a collaborative platform helped us to integrate individual store activities and increase operational efficiency,” says Dave.
Investing in the future
Employees who were already familiar with G Suite because they used it in school or in their personal lives have found the move eases communications company-wide, and Schnucks believes that the move will also help attract prospective employees who already use G Suite.
“Knowing that more and more prospective employees are already familiar with G Suite is a big win for us,” says Joey. “To them, it helps demonstrate our commitment to innovation.”
4686
Of your peers have already watched this video.
2:04 Minutes
The most insightful time you'll spend today!
Video: How Google App Maker Helps Businesses Build Mobile Apps in No Time
Analysts estimate that the right custom mobile app can save each employee 7.5 hours per week (that’s a week’s worth of lunch breaks!). Yet, too few businesses have the means, let alone the resources, to invest time and effort in building customized mobile apps. Why?
That’s because their budgets center on big enterprise apps like CRM, ERP, and SCM and beyond those priorities.
App Maker was created to enable your line-of-business teams to build apps for the jobs these bigger apps don’t tackle. With App Maker, you can revamp company processes like requesting purchase orders or filing and resolving help desk tickets, create quick marketing assets, and generate sales enablement apps, for example, as if you designed and built the processes yourself.
This low-code, simple, easy-to-use, drag and drop mobile app creator doesn’t need extensive coding knowledge and can build apps in a jiffy. Anyone can make it: As simple as that.
3920
Of your peers have already watched this video.
18:52 Minutes
The most insightful time you'll spend today!
Deep-dive into modern OS architecture built for the cloud
Cloud-based technology–and we all know this–has changed how we work. It has meant that we can work securely from any device, any location, anytime. You can be on a tablet, a phone, a laptop, a desktop, and you get to your work. You can collaborate with others in a really seamless way.
This is something, for those of you that will remember, you know, there was version 12 of the document and you’d send it out to eight people and they’d all give you different revisions and you’d have to somehow merge them together. But now, because it’s in the cloud, and there’s a central place, you can all be collaborating at the same time.
This has really fundamentally changed how fast we work and what happens in challenging times like we’ve been facing for the last several months were working from home didn’t all of a sudden mean you couldn’t do anything. An enormous number of people could continue working if the applications were built for the cloud from the very beginning.
Cloud-native endpoints such as Chrome OS provide the speed, ease of management, and security required as more workloads move to the cloud. This video includes a deep dive into Chrome OS’s multi-layered approach to computing and explores key features that provide differentiated benefits from legacy systems.
More Relevant Stories for Your Company

Streamlining Your Experience: Enhanced Search and Navigation in Google Cloud Console
The Google Cloud console is a powerful platform that lets users manage their cloud projects end-to-end with an intuitive web-based UI. With over 120 Google Cloud products across thousands of pages, it can be challenging to navigate through the console quickly, and many users don’t like to use the command

Google Workspace Now has Adobe Add-on!
Every day, individual people and creative teams combine Google Workspace with Adobe Creative Cloud to bring their best ideas to life and delight their customers or friends, across photography, design, video, 3D design, and more. In fact, Adobe’s add-on for Google Workspace has had over a million installs and counting. By partnering

Google Workspace Now Available to Over 3 Billion Users!
Over the past year, Google Workspace rapidly evolved to meet the needs of users as we collectively grappled with remote and hybrid work. First, we launched Google Workspace to commercial customers, which brought together the powerful individual apps people know and love into a single, integrated solution. Then we made Google Workspace

The Future of Cloud Computing: Choose Your Own Services and Payment Options
As the saying goes, “it’s hard to make predictions, especially about the future.” Some organizations find it challenging to predict what cloud resources they’ll need in months or years ahead. Every organization is on its own unique cloud journey. To help, we’re developing new ways for customers to consume and






