Showing posts with label Security and Compliance. Show all posts
Showing posts with label Security and Compliance. Show all posts
An update on identity verification and login challenges

An update on identity verification and login challenges

Donal Trung 12:58 PM Add Comment
Back in May, we communicated the upcoming launch of login challenges--a new feature aimed at keeping domain accounts safe from hijackers, even if they have attained a user’s username and password. The login challenges feature was rolled out slowly over the past few weeks, and impacted a large number of domains this week. The initial intent was not to expose this feature to users with 2-Step Verification enabled and domains using SSO. While the challenge feature is not enabled for domains using SSO, many users in these domains did see a prompt to enter their phone number as a means of verifying their identity in the future. This understandably caused confusion and led to escalations to admins. Upon hearing of this confusion, the launch of the interstitial prompt was temporarily rolled back for all domains until SSO domains can be fully excluded, at which point it will be relaunched. We are passionate about keeping our users’ information safe and secure, so we do plan to enable login challenges for domains using SSO later this year. Furthermore, enabling 2-Step Verification provides the highest level of protection for users, so we encourage domains to take advantage of this offering to protect their data. For more information:

whatsnew.googleapps.com
Get these product update alerts by email
Subscribe to the RSS feed of these updates
Identity verification to keep your account safe

Identity verification to keep your account safe

Donal Trung 12:42 PM Add Comment
In the coming weeks we’re introducing a feature to keep your account safe from hijackers, even if they have your username and password. Now when we detect a suspicious login, users will be prompted to verify their identity by entering their phone number. Users who have not set up their phone number will see a place to do so in the coming weeks. Note that users can skip entering their phone number but may be asked to add their phone number again at a later date. Google will use that phone number to verify their identity upon the next suspicious login. Once a user verifies their identity the alert is dismissed. Note: the paragraph below was edited on June 12 to clarify impact to users logging in through SSO. Users with 2-Step Verification enabled will not be affected by this launch and will not see the interstitial to set up their phone number. Users logging in through SSO may see the interstitial to set up their phone number, but will not be challenged to verify their identity at this time. This feature will be slowly rolling out to Rapid and Scheduled release domains in the coming weeks. Release Track:Rapid release and Scheduled release. For more information:https://support.google.com/a/answer/6002699


Ability to enforce 2-step verification for users

Ability to enforce 2-step verification for users

Donal Trung 4:36 PM Add Comment
Domain admins now have the ability to enforce 2-step verification for users in their domain through the control panel. This can be enforced for all users in the domain or a subset of users in an organizational unit.

Editions included:
Google Apps, Google Apps for Business, Government and Education

Languages included:
US English only (Next Generation release only)

For more information:

http://support.google.com/a/bin/answer.py?hl=en&answer=2548882
http://googleenterprise.blogspot.com/2012/06/posted-by-rishi-dhand-product-manager.html

whatsnew.googleapps.com
Get these product update alerts by email
Subscribe to the RSS feed of these updates
Message Security for Google Apps launches Message Log Search

Message Security for Google Apps launches Message Log Search

Donal Trung 1:49 AM Add Comment

Message Security for Google Apps, powered by Postini, now provides Message Log Search. This provides administrators with visibility into how messages are processed, filtered and delivered, and insight in the traffic patterns for the domain.

Use Message Log Search to:
- Run searches on message log data using a variety of criteria and queries.
- View search results and details about groups or individual messages.
- Track what happened to an inbound or outbound message -- whether it was delivered, quarantined, archived, encrypted, or other disposition -- and see if the message triggered a specific filter.
- Track all messages for a specific sender, recipient, domain, or IP address.

Editions included:
Premier and qualifying Education Editions

Languages included:
English Only

How to access what's new:
- Log in to the Message Security Administration Console, and click the Log Search tab.
- From the Log Search page, you can run queries and view results.

For more information:
Message Security for Google Apps Administration Guide

Get these product update alerts by email
Subscribe to the RSS feed of these updates
Google Web Security now available

Google Web Security now available

Donal Trung 7:00 PM Add Comment

Google Web Security for Enterprise, powered by Postini, provides real-time malware protection and URL filtering with policy enforcement and reporting. An additional feature extends the same protections to users working remotely on laptops in hotels, cafes, and even guest networks without requiring any action on their part.

Editions impacted:
Google Web Security can be used in conjunction with all editions of Google Apps messaging and collaboration services.

Languages impacted:
US English

How to access what's new:
Visit the link below to learn more.

For more information:
http://www.google.com/a/help/intl/en/security/web.html
Google Message Security and Compliance available

Google Message Security and Compliance available

Donal Trung 6:44 PM Add Comment

Administrators can now add security and compliance services to their existing messaging solutions, even if they don't use Google Apps for Gmail. Inbound message filtering for spam, virus and phishing protection is available, as are outbound message policy controls and long term message archiving for compliance purposes.

Editions impacted:
Message Filtering, Message Security and Message Discovery

Languages impacted:
US English

How to access what's new:
Visit the Google Apps Security and Compliance homepage to learn more. (see link below)

For more information:
http://www.google.com/a/help/intl/en/security/index.html
Postini policy management controls improved for Premier Edition

Postini policy management controls improved for Premier Edition

Donal Trung 5:15 PM Add Comment

Administrators can now set email policy rules using regular expressions, which allows for inbound and outbound filtering on content like social security numbers, phone numbers and other structured information.

Editions impacted:
Premier Edition

Languages impacted:
US English

How to access what's new:
Sign in to the Premier Edition administrative control panel and launch the Postini management interface to configure email policy management rules.

For more information:
http://groups.google.com/group/PostiniSupportForGoogleApps
Postini message security services available in Premier Edition

Postini message security services available in Premier Edition

Donal Trung 12:48 PM Add Comment

Custom message policy management and 90-day message recovery for accidentally deleted messages are now included in Premier Edition at no additional charge.

Editions impacted:
Premier Edition

Languages impacted:
US English

How to access what's new:
In the Premier Edition administrative control panel, click 'Add services' and select 'Policy Management and Message Recovery'.

For more information:
http://www.google.com/support/a/bin/answer.py?hl=en-ie&answer=77041