Skip to main content

AD_4nXesG9aPo6tKWWCQ3QwniCdXr9ek28NUQG_nha69aXBobVVhWgZPhcFS3txNvMe3R7gCgUFNNIE8yHZY2qmckPBSPOoSnJ4oH7ZsNTz-yL3Rqus61MataJUne_X5Z5YLwxfEZLGKPA?key=AY9vDVF6RkX2E2rpyQPWCgWr

Netskope Global Technical Success (GTS)

Block Google Drive Personal Instance Access

 

Netskope Cloud Version - 122

 

Objective

Google Drive personal account access should be blocked

 

Prerequisite

Netskope CASB Inline license is required

 

Context

Some customers use Google Suite, with Google Drive as their official Storage application. They might want to allow only their business Google Drive instance and block personal Gdrive accounts. This document will discuss how to achieve this.

 

Do You Know?

  • Netskope acknowledges Google Drive as a Cloud Application and provides a pre-defined cloud app connector.
  • As of Dec 10 2024, Netskope's Google Drive predefined cloud app connector can identify instances.

AD_4nXfCqn6RYlwUGjRWizmLvbhbcFvZVYqgPvlKy1qXk4N-qtCXcu2CuEwOaB6tXG8iFgfvlXhGKVoS3TbTn0dceND5QXhsYzxZmRD0UqkBKD2uhVhgzpbLGjSkb32dPxifNvuPcQNL?key=AY9vDVF6RkX2E2rpyQPWCgWr

Configuration

  • Step 1 - Instance Tagging

Path: Netskope Tenant UI >>> Policies >>> Profiles - - - App Instance >>> New Custom App Instance >>> New App Instance

AD_4nXf0cEx4tlO92yYOnrJnwHdphj23nfBffZKir6v-7RqG9eiQO0neX0qAnVNQTjbOyE783HbAMXwJ06mZgYYaoKYcWA5QnTPFzUQ-C6M2xw8GBsHBLpgY047eH5Mok12z86K7B9sMeg?key=AY9vDVF6RkX2E2rpyQPWCgWr

Note - Netskope enables administrators to name application instances using Application Events.

 

  • Step 2 - Real-time protection policy

Path: Netskope Tenant UI >>> Policies >>> Real-time Protection >>> New Policy

AD_4nXdu351JsGOk_5s1kJS7B_VvNz1VoZKqpK4gj04Eqe54HbcRyb46IDjWzABskRUKbS52gYeLx3m1UrzmAnZXeAr_csgt709ElyvMbYM2TwQ6iCSBs48HIx2lEUqAI_JFTs6MNymQIg?key=AY9vDVF6RkX2E2rpyQPWCgWr

 

Note:
If you want to allow “View” access to personal account but block Upload and Downloads, you can select Upload and Download from the Activities section.
If left blank, the page access will be completely blocked.

 

Verification

  • Step 1 - Try to access Google Gmail via personal account

AD_4nXcFM_GGzE0DdpCsrmXTkRm5E3N0W8TvnY9JBKKEOPKHDpa_7RkzGcxIwlReIgO9lfjDYXBbOpimgyf-Sppi4EUELfLujb0E2i1Z7pdfQn012mBLAhmL1G-bIwct24qaP313Wvyi?key=AY9vDVF6RkX2E2rpyQPWCgWr

 

  • Step 2 - Check policy hits

AD_4nXdD9HLmiw486opisRlfDdPRcmCraSxdcC18x7mPyCd0__tTFGH_MD1cGKtsHDykoEucFY7OCqBNHxPUfZH3rDx1K69Nwp3SjeRSEm28rvEUYDZeM_kleR8iyZErMJt-J2glrZknFw?key=AY9vDVF6RkX2E2rpyQPWCgWr

 

AD_4nXc9Jd6QC-qobQZHR5rKzALEAgItHWjEINOoWK_aNY1cr4NchUkvXQwLcWnFRdAx7AXS7rL7NpU_wzuL7yf0RPKvOMXVPaxv1ey8PjW08T3ugYj64JlOMNFlxUwoWxP2sko4VBSw5Q?key=AY9vDVF6RkX2E2rpyQPWCgWr

AD_4nXemZrgJmhePaJEosn0Cv-7Br9YVknj_-bfHS_gHWHNOgsZ5xQCtIpImTrGkp15kpyIeM_DaA_YEQIbm0RzPa8e_9TjBtlrl0vR5yTKawAYIEm54OPw6K8lxX0YeBhkBZwjDj29D?key=AY9vDVF6RkX2E2rpyQPWCgWr

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.