Overview
One of the most common misconceptions during offboarding is that disabling a Google Workspace account automatically revokes access to files the user previously shared. Unfortunately, that is not how Google Drive works.
The Scenario
During a security investigation, an alert indicated that a document’s visibility had changed from people within the organization to people with the link.
The user account had already been disabled, which led to the assumption that the shared link would no longer function.
The Reality
Disabling or suspending a Google Workspace account prevents the user from signing in and stops access to Google Workspace services. However, it does not automatically remove sharing permissions from files the user owns.
If a file was shared externally before the account was disabled, the link can remain accessible until those permissions are explicitly removed.
Why This Matters
This creates a potential security risk during employee offboarding.
- Sensitive documents may remain accessible externally.
- Anyone-with-the-link or external sharing permissions may continue to exist.
- Ownership remains with the suspended account until transferred.
Simply disabling the account is not sufficient to secure the user’s Google Drive data.
What Administrators Should Do
As part of the offboarding process, administrators should:
- Review Google Drive sharing for the departing user.
- Remove external sharing where appropriate.
- Transfer ownership of important files to another employee or service account.
- Verify that no sensitive documents remain publicly accessible.
Investigating Shared Files
Google Workspace administrators can use several sources to investigate shared files:
- Audit and Investigation: Drive Log Events
- Drive sharing reports
- Google Workspace APIs
- GAM, also known as Google Apps Manager
These tools can help administrators identify externally shared files and revoke access when necessary.
Best Practices
A secure Google Workspace offboarding checklist should include:
- Disable the user account.
- Reset sessions and revoke tokens.
- Transfer Drive ownership.
- Review and remove external sharing.
- Remove delegated mailbox access.
- Archive data according to retention requirements.
Final Thoughts
Suspending a user protects the account, but it does not protect the data they have already shared.
If an organization relies on Google Workspace, reviewing Drive permissions should be a standard part of every offboarding process. It is a simple step that can prevent accidental data exposure long after an employee has left the organization.
HTMLcat > /tmp/google-workspace-offboarding.html <<'HTML'
Overview
One of the most common misconceptions during offboarding is that disabling a Google Workspace account automatically revokes access to files the user previously shared. Unfortunately, that is not how Google Drive works.
The Scenario
During a security investigation, an alert indicated that a document’s visibility had changed from people within the organization to people with the link.
The user account had already been disabled, which led to the assumption that the shared link would no longer function.
The Reality
Disabling or suspending a Google Workspace account prevents the user from signing in and stops access to Google Workspace services. However, it does not automatically remove sharing permissions from files the user owns.
If a file was shared externally before the account was disabled, the link can remain accessible until those permissions are explicitly removed.
Why This Matters
This creates a potential security risk during employee offboarding.
- Sensitive documents may remain accessible externally.
- Anyone-with-the-link or external sharing permissions may continue to exist.
- Ownership remains with the suspended account until transferred.
Simply disabling the account is not sufficient to secure the user’s Google Drive data.
What Administrators Should Do
As part of the offboarding process, administrators should:
- Review Google Drive sharing for the departing user.
- Remove external sharing where appropriate.
- Transfer ownership of important files to another employee or service account.
- Verify that no sensitive documents remain publicly accessible.
Investigating Shared Files
Google Workspace administrators can use several sources to investigate shared files:
- Audit and Investigation: Drive Log Events
- Drive sharing reports
- Google Workspace APIs
- GAM, also known as Google Apps Manager
These tools can help administrators identify externally shared files and revoke access when necessary.
Best Practices
A secure Google Workspace offboarding checklist should include:
- Disable the user account.
- Reset sessions and revoke tokens.
- Transfer Drive ownership.
- Review and remove external sharing.
- Remove delegated mailbox access.
- Archive data according to retention requirements.
Final Thoughts
Suspending a user protects the account, but it does not protect the data they have already shared.
If an organization relies on Google Workspace, reviewing Drive permissions should be a standard part of every offboarding process. It is a simple step that can prevent accidental data exposure long after an employee has left the organization.