Easier Sharing of Google Docs; Watch Your Permissions

google drive
Google is making it easier to share Google Docs, Drawings, and Slides (not Sheets) with people outside your Google Apps for Business domain.

  • Files shared outside your domain to an email address not linked to an existing Google Account can be viewed without having to sign in or create a new Google Account.
  • If a file is shared with edit or comment permissions, the recieving user must still sign in with a Google Account in order to edit or comment on that file.

This change actually reflects a new “invitation” model.  When a user directly shares with individuals who do not have Google Accounts, those recipients will be able to view the file without signing in. Because no sign in is required, anyone may view the file with this sharing link until the person who the file was explicitly shared with creates a Google Account and expends the invitation.

Once the person creates a Google Account two things happen: (1) the sharing link will no longer work for new users to access the file and the sharing dialog will indicate that the invitation has been used; (2) any user who accessed the file using the sharing link while it was open and signed in using their Google Account will be added to the sharing access list for that file and will continue to have access. Users with permissions to change sharing settings can revoke this access if desired.

While you can prevent this behavior by disabling sharing outside the domain to people who are not using a Google Account via settings in the Admin console, the change makes monitoring of Google Drive permissions more important to maintaining a secure ecosystem.

Tools, such as CloudLock, provide a means for monitoring and managing permissions, helping ensure that sensitive data remains secure.  Contact us if you would like more information.