Articles on: Technical Support
This article is also available in:

Google Workspace for Education and SpacesEDU

Google has enhanced its app access controls to improve student data privacy. Organizations using Google SSO or Google Drive integration must mark SpacesEDU as a trusted app to ensure uninterrupted service.


Before You Start


  • These configuration steps must be completed by a Google Workspace administrator with Security privileges.
  • Failure to configure these settings will block access for all users designated as under 18.
  • Ensure you have access to your Google Workspace Admin Console before beginning.


Steps to Confirm Third-Party App Settings


Google provides a guided experience for administrators to manage third-party permissions. Follow these steps to trust the SpacesEDU application:


  1. Access the Google guided experience.
  2. Click Continue to begin the setup.
  3. Confirm settings for unconfigured third-party apps.
  4. Select the option: Allow users to access third-party apps that only ask for Google sign in info.
  5. Click Next.
  6. Review the configured apps in the Access column for your top-level organizational unit.
  7. Click Add app > OAuth App Name or Client ID.
  8. Search for SpacesEDU.
  9. Set the access level to Trusted.
  10. Review the confirmation details and click Confirm.


Impact of Restricted Access


If SpacesEDU is not marked as a trusted app, users under 18 will receive one of the following errors when attempting to sign in via Google:


  • Error 400: access_not_configured: The OAuth connection is rejected because the app has not been configured in the Admin Console.
  • Error 400: admin_policy_enforced: The OAuth connection is rejected because the administrator has explicitly blocked the application.



Screenshot of the error message


Google Resources


For more detailed information, refer to these resources from the Google Help Center:



Good to Know


  • SSO and Drive Integration: Marking the app as "Trusted" covers both the Google SSO login process and the ability for students to attach files directly from their Google Drive.
  • Organizational Units: Ensure these settings are applied to the correct Organizational Unit (OU) containing your student accounts.
  • Propagation Time: Changes made in the Google Workspace Admin Console may take up to 24 hours to propagate across all users.

Updated on: 17/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!