Supported Rules

The tables below lists the supported rules that can be added to policies.

User Drive Rules

Rule NameDescriptionApplicable to Automatic PoliciesApplicable to On-Demand Policies
Drive user / group permission anomaly detectionRestrict user / group drive access and detect excessive or insufficient permission levels to enforce proper access controls.YesNo
Drive user permission replacementTransfer all drive permissions of a user to another user and remove the original user's access for secure transitions during role changes or departures.YesNo
Edit permission restriction for sharing linksRestrict sharing links with edit permission that are shared with "Anyone" or specific target audience.YesNo
External sharing expiration enforcementRestrict long access periods for externally shared files / folders or extend expiring shares as needed.YesYes
File permission inheritance protectionRestrict file-level permission inheritance breaks that cause drive permission inconsistencies.YesYes
Gemini accessed sensitive files detectionDetect and report high-frequency or abnormal Gemini AI access to sensitive files to prevent and investigate potential data scraping or mass extraction incidents via AI usage.YesNo
Orphaned users drive permission restrictionRestrict deleted, archived, and suspended users with drive permissions.YesYes
Permission restriction for groups with external usersRestrict groups containing external users from accessing drives.YesYes
Shared permission expiration enforcementRestrict long access periods for internally shared files / folders or extend expiring shares as needed.YesYes

Shared Drive Rules

Rule NameDescriptionApplicable to Automatic PoliciesApplicable to On-Demand Policies
Drive user / group permission anomaly detectionRestrict user / group drive access and detect excessive or insufficient permission levels to enforce proper access controls.YesNo
Drive user permission replacementTransfer all drive permissions of a user to another user and remove the original user's access for secure transitions during role changes or departures.YesNo
Edit permission restriction for sharing linksRestrict sharing links with edit permission that are shared with "Anyone" or specific target audience.YesNo
External sharing expiration enforcementRestrict long access periods for externally shared files / folders or extend expiring shares as needed.YesYes
External user manager / content manager permission restrictionRestrict external users with manager or content manager permissions on shared drives.YesYes
External user restrictionRestrict external users in shared drives with external sharing disabled.YesYes
File permission inheritance protectionRestrict file-level permission inheritance breaks that cause drive permission inconsistencies.YesYes
Gemini accessed sensitive files detectionDetect and report high-frequency or abnormal Gemini AI access to sensitive files to prevent and investigate potential data scraping or mass extraction incidents via AI usage.YesNo
Manager / Content manager restrictionRestrict users and groups ineligible as shared drive managers.YesNo
Manager count restrictionRestrict the number of managers in a shared drive.YesYes
Manager enforcementEnforce specific users and groups to be managers of a shared drive.YesNo
Member invitation restrictionRestrict designated users from adding members to shared drives during specific periods.YesNo
Membership restrictionRestrict specified users or groups from joining shared drives as members.YesNo
Orphaned users drive permission restrictionRestrict deleted, archived, and suspended users with drive permissions.YesYes
Permission restriction for groups with external usersRestrict groups containing external users from accessing drives.YesYes
Shadow user restrictionRestrict users with file / folder access in shared drives who are not members.YesYes
Shared drive access permission settings restrictionRestrict shared drive settings (manager permissions, external access, sharing, downloads) to maintain compliance and data protection.YesYes
Shared drive creation restrictionRestrict specified users from creating shared drives.YesNo
Shared permission expiration enforcementRestrict long access periods for internally shared files / folders or extend expiring shares as needed.YesYes
Sharing link restrictionRestrict sharing links that are shared with specific target audience.YesYes

Group Rules

Rule NameDescriptionApplicable to Automatic PoliciesApplicable to On-Demand Policies
Admin role assignment restrictionRestrict certain users from being given administrative roles.YesNo
External group member detectionDetect Google groups that contain members from outside of your organization.YesYes
Group external access settings restrictionRestrict external users' access to groups by enforcing group access settings.YesYes

User Rules

Rule NameDescriptionApplicable to Automatic PoliciesApplicable to On-Demand Policies
2-step verification enforcementDetect user accounts that have disabled 2-step verification.YesYes
Inactive user account restrictionRestrict inactive users (not signed in for more than a specified period).YesNo

Gmail Rule

Rule NameDescriptionApplicable to Automatic PoliciesApplicable to On-Demand Policies
External email forwarding settings detectionDetect users who have enabled automatic email forwarding settings and are forwarding to external addresses.YesNo