Tag Archives: Security and Compliance

Google Workspace Updates Weekly Recap – June 13, 2025

New update

Unless otherwise indicated, the features below are available to all Google Workspace customers, and are fully launched or in the process of rolling out. Rollouts should take no more than 15 business days to complete if launching to both Rapid and Scheduled Release at the same time. If not, each stage of rollout should take no more than 15 business days to complete.

Mitigating prompt injection attacks with a layered defense strategy
This week, we shared more details on how we protect Gemini and mitigate threats from malicious actors utilizing indirect prompt injection attacks to exfiltrate user data or execute other rogue actions. Google takes a layered security approach, with security measures designed for each stage of the prompt lifecycle. From Gemini 2.5 model hardening, to purpose-built machine learning (ML) models detecting malicious instructions, to system-level safeguards, we are meaningfully elevating the difficulty, expense, and complexity faced by an attacker. 

Our model training with adversarial data significantly enhanced our defenses against indirect prompt injection attacks in Gemini 2.5 models. This inherent model resilience is augmented with additional defenses that we built directly into Gemini, including: 
  • Prompt injection content classifiers 
  • Security thought reinforcement 
  • Markdown sanitization and suspicious 
  • URL redaction User confirmation framework 
  • End-user security mitigation notifications 
This layered approach to our security strategy strengthens the overall security framework for Gemini – throughout the prompt lifecycle and across diverse attack techniques. 

You can read the full blog post, “Mitigating prompt injection attacks with a layered defense strategy,” on the Google Online Security Blog.| Rolling out now to Rapid Release and Scheduled Release domains. | Available to all Google Workspace customers, Workspace Individual Subscribers, and users with personal Google accounts. | Visit the Help Center to learn: 

Previous announcements

The announcements below were published on the Workspace Updates blog earlier this week. Please refer to the original blog posts for complete details.
New class analytics and insights for educators in Google Classroom
Teachers can view data via an “Analytics” tab on their class pages. In addition, teachers will be able to see relevant insights on the class analytics page that alert them on how students are progressing and where they may need additional support. | Learn more about class analytics in Classroom.

Use Gemini in Google Docs on Android devices in 20+ languages
We’re excited to bring the power of Gemini in Docs to your Android devices so that you can understand, summarize, and ask questions about documents on mobile. As a result, you can use Gemini to surface insights and key points on-the-go. Plus, Gemini in Docs on Android is available in 20+ languages. | Learn more about Gemini in Docs on mobile.

Audit reports for data regions are now available in the Admin console
Using the security investigation tool, admins can now access a new data set: policy compliance log events. Admins can use these logs to view a list of their Assured Controls users, their assigned data regions, and any advanced data region settings. | Learn more about audit reports.

Data regions support for Gemini features in Google Workspace is now available
Beginning this week, Gemini features in Google Workspace apps, like Gemini in the side panel of Workspace apps or “Help me write” in Google Docs, for example, will now adhere to your organization’s data regionalization requirements. | Learn more about data regions support.

Generate fully editable charts using Gemini in Google Sheets 
Earlier this year, we introduced the ability for Gemini to provide insights and generate charts based on your data in Google Sheets. At that time, the generated charts could only be inserted as static images over cells in a spreadsheet. Starting this week, Gemini can produce fully editable charts that regenerate if the spreadsheet data changes. | Learn more about editable charts in Sheets.

Generate video clips with sound using Veo 3 in Google Vids
We're introducing our newest model, Veo 3, that enables users to generate 8-second videos with higher quality and realistic sound. | Learn more about Veo 3 in Vids.

Migrate email and calendar content from Microsoft Exchange Online to Google Workspace
The ability to migrate email from Microsoft Exchange Online to Google Workspace, part of our new Data migration service, is now generally available. | Learn more about email migration.

Use Gemini in Google Forms to summarize form responses 
To help you quickly gain insights from responses to Google Form short-answer or paragraph questions, we’re introducing AI-generated text summarizations. | Learn more about Forms summaries. 

Use Gemini in Google Forms to quickly create a new form
With Help me create in Forms, users can craft a form by entering a prompt that describes the form they want to create or a prompt that references supporting Docs, Sheets, Slides or PDFs. Gemini will then generate a draft form, incorporating details from any files you reference, that can be used instantly or further customized. | Learn more about Help me create in Forms.

Introducing PDF summary cards in Google Drive
We’re excited to expand the capabilities of Gemini in Drive files by introducing PDF summary cards. | Learn more about PDF summary cards.

New host management control for who can ask to join a meeting
Meeting hosts can now control who can request to join a meeting (also known as “knocking”). | Learn more about host controls.

Join a meeting using “companion mode” from Android and iOS tablets
You can use companion mode on Apple iPads & Android tablets and foldable devices. | Learn more about companion mode in Meet.

Introducing the Comeen Workplace AI Agent for the Comeen Google Chat app
We’re excited to announce the next evolution of the Comeen app: the Workplace AI Agent. This powerful assistant uses generative AI to help users complete key workplace actions using natural language. From bookings to workplace knowledge, everything happens in seconds through simple prompts. | Learn more about the Comeen Google Chat app.

Completed rollouts

The features below completed their rollouts to Rapid Release domains, Scheduled Release domains, or both. Please refer to the original blog posts for additional details.

Scheduled Release Domains: 
Rapid and Scheduled Release Domains: 
For a recap of announcements in the past six months, check out What’s new in Google Workspace (recent releases).

Data regions support for Gemini features in Google Workspace is now available

What’s changing

Beginning today, Gemini features in Google Workspace apps, like Gemini in the side panel of Workspace apps or “Help me write” in Google Docs, for example, will now adhere to your organization’s data regionalization requirements. As with other data, Admins have the flexibility to configure controls for EU processing, US processing, or both, including granular settings down to the organizational unit (OU) level.


Who’s impacted

Admins

Why it matters 

Data regions are critical for ensuring many customers can meet their own internal requirements, as well as other legal, regulatory, and data sovereignty requirements by controlling the geographical location of their data at rest. Expanding these controls to Gemini features in Google Workspace allows our customers to adopt Gemini features broadly in their organization with confidence  that their data is being processed and stored in the location they require.

Getting started

Data regions support for Gemini features in Google Workspace is now available

What’s changing

Beginning today, Gemini features in Google Workspace apps, like Gemini in the side panel of Workspace apps or “Help me write” in Google Docs, for example, will now adhere to your organization’s data regionalization requirements. As with other data, Admins have the flexibility to configure controls for EU processing, US processing, or both, including granular settings down to the organizational unit (OU) level.


Who’s impacted

Admins

Why it matters 

Data regions are critical for ensuring many customers can meet their own internal requirements, as well as other legal, regulatory, and data sovereignty requirements by controlling the geographical location of their data at rest. Expanding these controls to Gemini features in Google Workspace allows our customers to adopt Gemini features broadly in their organization with confidence  that their data is being processed and stored in the location they require.

Getting started

Audit reports for data regions are now available in the Admin console

What’s changing 

Using the security investigation tool, admins can now access a new data set: policy compliance log events. Admins can use these logs to view a list of their Assured Controls users, their assigned data regions, and any advanced data region settings.

Policy compliance log events in the security investigation tool

Who’s impacted

Admins

Why it’s important

Policy compliance log events help admins quickly generate detailed reports of users assigned to specific data regions, which are critical for ensuring and providing data region settings are in line with internal policies and external regulatory guidelines. Querying these logs in the security investigation tool streamlines the auditing process, saving time and effort.

Getting started

Rollout pace

Availability

Available for Google Workspace:

Resources


Audit reports for data regions are now available in the Admin console

What’s changing 

Using the security investigation tool, admins can now access a new data set: policy compliance log events. Admins can use these logs to view a list of their Assured Controls users, their assigned data regions, and any advanced data region settings.

Policy compliance log events in the security investigation tool

Who’s impacted

Admins

Why it’s important

Policy compliance log events help admins quickly generate detailed reports of users assigned to specific data regions, which are critical for ensuring and providing data region settings are in line with internal policies and external regulatory guidelines. Querying these logs in the security investigation tool streamlines the auditing process, saving time and effort.

Getting started

Rollout pace

Availability

Available for Google Workspace:

Resources


Available in beta: Edit client-side encrypted Microsoft Word files with Google Docs

What’s changing 

Launching in beta, you can now view and edit client-side encrypted Microsoft Word files in Google Docs. Any changes made are saved in the original Word format. This update makes it easy for you to leverage Google Workspace with the tools and formats you already use while preserving confidentiality of your sensitive data with client-side encryption. 


Eligible Google Workspace admins can use this form to request access to the beta. We’ll share more specific instructions once you’re accepted into the beta.

In Google Docs, navigate to File > Open.



Additional details

Note that with this release:
  • You can only view and edit .docx Word file types. Additional Word file types are not supported.
  • The maximum file size is 20MB.
  • As we continue to improve Office editing in encrypted Google Docs, you may encounter incompatibilities for certain features. Some features may not be displayed and may not be editable, but will be preserved in the document and viewable in Microsoft Office.
  • Other features may be lost or altered in the latest version of the file when it is edited in Google Docs. You will see a notification within the document if editing will cause any features to be lost.


Getting started

Rollout pace

  • The feature will be available immediately once you're accepted into the beta.

Availability

Available to Google Workspace 
  • Enterprise Plus
  • Education Standard and Plus
  • Frontline Plus


Available in beta: Edit client-side encrypted Microsoft Word files with Google Docs

What’s changing 

Launching in beta, you can now view and edit client-side encrypted Microsoft Word files in Google Docs. Any changes made are saved in the original Word format. This update makes it easy for you to leverage Google Workspace with the tools and formats you already use while preserving confidentiality of your sensitive data with client-side encryption. 


Eligible Google Workspace admins can use this form to request access to the beta. We’ll share more specific instructions once you’re accepted into the beta.

In Google Docs, navigate to File > Open.



Additional details

Note that with this release:
  • You can only view and edit .docx Word file types. Additional Word file types are not supported.
  • The maximum file size is 20MB.
  • As we continue to improve Office editing in encrypted Google Docs, you may encounter incompatibilities for certain features. Some features may not be displayed and may not be editable, but will be preserved in the document and viewable in Microsoft Office.
  • Other features may be lost or altered in the latest version of the file when it is edited in Google Docs. You will see a notification within the document if editing will cause any features to be lost.


Getting started

Rollout pace

  • The feature will be available immediately once you're accepted into the beta.

Availability

Available to Google Workspace 
  • Enterprise Plus
  • Education Standard and Plus
  • Frontline Plus


Available in beta: Edit client-side encrypted Microsoft Word files with Google Docs

What’s changing 

Launching in beta, you can now view and edit client-side encrypted Microsoft Word files in Google Docs. Any changes made are saved in the original Word format. This update makes it easy for you to leverage Google Workspace with the tools and formats you already use while preserving confidentiality of your sensitive data with client-side encryption. 


Eligible Google Workspace admins can use this form to request access to the beta. We’ll share more specific instructions once you’re accepted into the beta.

In Google Docs, navigate to File > Open.



Additional details

Note that with this release:
  • You can only view and edit .docx Word file types. Additional Word file types are not supported.
  • The maximum file size is 20MB.
  • As we continue to improve Office editing in encrypted Google Docs, you may encounter incompatibilities for certain features. Some features may not be displayed and may not be editable, but will be preserved in the document and viewable in Microsoft Office.
  • Other features may be lost or altered in the latest version of the file when it is edited in Google Docs. You will see a notification within the document if editing will cause any features to be lost.


Getting started

Rollout pace

  • The feature will be available immediately once you're accepted into the beta.

Availability

Available to Google Workspace 
  • Enterprise Plus
  • Education Standard and Plus
  • Frontline Plus


Granular OAuth consent in HTTP Google Workspace add-ons

What’s changing

Granular OAuth consent is rolling out over the next few weeks for Google Workspace add-ons built using HTTP endpoints. Granular consent gives users clear choices about the data they share with third-party applications.

This update is similar to an update made earlier this year with the introduction of granular OAuth consent in the Google Apps Script IDE: when someone installs or runs an HTTP Workspace add-on that supports granular consent, they will see a redesigned consent screen. Instead of being asked to authorize all requested permissions at once, users can selectively grant access to individual OAuth scopes.

For example, Google Workspace add-ons can extend to multiple Workspace apps, but users might only use an add-on for some of the apps it extends. With granular consent, users can choose to grant all permissions to an add-on or grant permissions as needed when they use the add-on in each app.

This screenshot shows the new OAuth consent screen, which lets the user provide consent for a subset of the requested OAuth scopes.


Additional details

Following is the timeline for developers supporting granular consent in HTTP Google Workspace add-ons:

  • New HTTP Google Workspace add-ons built after May 27, 2025 must support granular consent. 
  • Existing add-ons have until December 1, 2025 to add support for granular consent. 
  • After December 1, 2025, all HTTP Google Workspace add-ons must support granular consent.


After a user grants permission to a Google Workspace add-on that supports granular consent, the add-on might request OAuth consent again in the following cases:

  • The user, who has granted consent to a subset of the requested OAuth scopes, tries to run a part of the add-on that requires scopes that were not previously authorized.
  • The add–on is updated in such a way that it requires permission for additional scopes.
  • The user revoked access to the add-on from their Google Account settings.


This update does not apply to the following scenarios, for which granular consent may become available in the future:

  • When an admin initially installs an add-on
  • When an admin updates the permissions granted to an add-on from the Admin console
  • If a Google Workspace add-on is built in Apps Script

Getting Started

  • Admins: There are no changes to the admin controls for this feature.
  • Developers: For information about how to add support for granular consent to HTTP Workspace add-ons, refer to the developer documentation.
  • End users: This new consent screen will only be used for new OAuth scope grants. Pre-existing scope grants will not be affected, so no action is required by users on add-ons they’ve already authorized. 

Rollout pace


Availability


Pre-configure Gemini app conversation history admin settings before they take effect

What’s changing

Starting today, Workspace admins can pre-configure the new Gemini conversation history admin settings before they take effect for their Gemini app users (expected by the end of May 2025). By default, “Gemini conversation history” will be ON and ”Conversation retention” will be set to 18 months (inline with current behavior). 

Generative AI > Settings > Gemini app > Gemini conversation history


Who’s impacted

Admins and end users

Additional details

  • If "Gemini conversation history" is OFF, chats are saved in user accounts for up to 72 hours. This lets Google provide the service and process any feedback. This chat activity won’t appear in a user’s Gemini Apps Activity.
    • Regardless of whether the Gemini app history is on or off, content in chats adheres to enterprise privacy and security protections as described in the Google Workspace Terms of Service. You can also learn more in the Privacy Hub
    • If you turn the setting from ON to OFF, existing user conversation history from before the setting is turned OFF is stored for the length of time specified by the "Conversation retention" setting.
  • This update will not impact your current Gemini app service setting.
  • This update will not impact Gemini in Workspace apps (e.g., Gemini in Gmail).

Getting started

  • Admins: 
    • Review and update the "Gemini conversation history" settings before we enforce these settings (expected by the end of May 2025). Visit the Help Center to learn more about configuring Gemini app conversation history settings for your users.
    • If no changes are made, the default settings will apply: “Gemini conversation history” set to ON and "Conversation retention” set to 18 months. Activity older than 18 months will be automatically deleted.

  • End Users: 
    • Users cannot override the Gemini conversation history settings configured by their admin.
    • These admin settings will override any individual user changes previously made to their Gemini Apps Activity settings (gemini.google.com or Gemini mobile app).

Rollout pace


We will publish a separate Workspace Updates blog post once we begin to enforce these settings, which is expected by the end of May 2025.


Availability

  • Available for all Google Workspace users with access to the Gemini app.

Resources