52 Offline & desktop-sync data minimization
draft
Offline Docs, offline Gmail and Drive for desktop each mirror tenant data onto the local disk, where a lost, stolen or seized laptop yields it with no Workspace authentication in the way. This control turns those caches off, or restricts Drive for desktop to authorized devices — listed in the company-owned device inventory with a matching serial number — so the data stays server-side where the access controls actually are.
Caveats
- Turning offline access off does not purge caches that already exist — local data on user machines survives the policy change, and clearing it needs an endpoint wipe or a profile reset.
- The local copy only stays gone if users cannot simply re-enable it — pair this with device-trust CAA (№29) and the Chrome managed-profile baseline (№10).
- Real usability cost: mobile, airport and field workflows genuinely break — scope it to the high-risk OU rather than tenant-wide unless the friction is acceptable everywhere.
- The device-policy variant is available on every edition, but requires installing the managed device policy on each computer and does not apply to ChromeOS or mobile.
Setup steps
- open ↗
https://admin.google.com/ac/managedsettings/55656082996 · captured 2026-07-15
Apps › Google Workspace › Drive and Docs › Features and Applications- Offline access
Use policies to control offline access from computers (not 'Allow users to turn on offline access')
-
Apps › Google Workspace › Drive and Docs › Features and Applications › Google Drive for desktopAllow Google Drive for desktop in your organization = off for high-risk OU; otherwise 'Only allow Google Drive for desktop on authorized devices' = checked
- open ↗
https://admin.google.com/ac/apps/gmail/enduseraccess · captured 2026-07-15
Apps › Google Workspace › Gmail › User settingsEnable Gmail web offline = unchecked for the OU; optionally check 'Force deletion of offline data on log out of Google account'
How to verify
-
On a covered machine, confirm Drive offline availability and desktop-sync are refused for the restricted OU (the Drive settings toggle should be absent/greyed for a test user).
draft v0.0.3 Prevent policy #25 · #15, #7 ↗