> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.spacesedu.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Google Workspace for Education and SpacesEDU

Google has enhanced its app access controls to improve student data privacy. Organizations using Google SSO or Google Drive integration must mark SpacesEDU as a trusted app to ensure uninterrupted service.

###### Before You Start

* These configuration steps must be completed by a Google Workspace administrator with **Security privileges**.
* Failure to configure these settings will block access for all users designated as **under 18**.
* Ensure you have access to your Google Workspace Admin Console before beginning.

###### Steps to Confirm Third-Party App Settings

Google provides a guided experience for administrators to manage third-party permissions. Follow these steps to trust the SpacesEDU application:

1. Access the [Google guided experience](https://admin.google.com/ac/owl/guidedexperience).
2. Click **Continue** to begin the setup.
3. Confirm settings for unconfigured third-party apps.
4. Select the option: **Allow users to access third-party apps that only ask for Google sign in info**.
5. Click **Next**.
6. Review the configured apps in the **Access** column for your top-level organizational unit.
7. Click **Add app** > **OAuth App Name or Client ID**.
8. Search for **SpacesEDU**.
9. Set the access level to **Trusted**.
10. Review the confirmation details and click **Confirm**.

###### Impact of Restricted Access

If SpacesEDU is not marked as a trusted app, users under 18 will receive one of the following errors when attempting to sign in via Google:

* **Error 400: access\_not\_configured**: The OAuth connection is rejected because the app has not been configured in the Admin Console.
* **Error 400: admin\_policy\_enforced**: The OAuth connection is rejected because the administrator has explicitly blocked the application.


![Screenshot of the error message](https://storage.crisp.chat/users/helpdesk/website/5dd7b1041aefec00/32806895-b633-45f5-ae7b-4b8d40_txe30f.png)

###### Google Resources

For more detailed information, refer to these resources from the Google Help Center:

* [Confirm your third-party app settings](https://support.google.com/a/answer/13289151)
* [Manage access to unconfigured third-party apps for users under 18](https://support.google.com/a/answer/13288650)
* [Google Workspace for Education Admin Console: Reviewing configured apps](https://support.google.com/a/answer/13289151#review_apps)
* [Third-party app access enhancements for Google Workspace for Education](https://workspaceupdates.googleblog.com/2023/08/third-party-app-access-enhancements-for-google-workspace-for-education.html)

###### Good to Know

* **SSO and Drive Integration:** Marking the app as "Trusted" covers both the Google SSO login process and the ability for students to attach files directly from their Google Drive.
* **Organizational Units:** Ensure these settings are applied to the correct Organizational Unit (OU) containing your student accounts.
* **Propagation Time:** Changes made in the Google Workspace Admin Console may take up to 24 hours to propagate across all users.