Google Workspace mobile app whitelisted
Description
AlphaSOC detected that a mobile application was added to the whitelist in Google Workspace. Whitelisted applications bypass standard mobile device management (MDM) restrictions and allow access to organizational data on mobile devices.
Impact
Whitelisting mobile applications grants them permission to access Google Workspace data, potentially including email, calendar, contacts, and documents. Malicious or compromised devices can exfiltrate organizational data from mobile devices. Overly permissive whitelisting weakens the organization's mobile security posture.
Severity
| Severity | Condition |
|---|---|
Low | Mobile app added to whitelist |
Investigation and Remediation
Review Google Workspace Admin audit logs to identify which application was whitelisted and who made the change. Research the application to verify it is a legitimate business tool from a trusted developer.
If the application is unauthorized or suspicious, remove it from the whitelist immediately. Review the list of all whitelisted applications to ensure they align with security policies.