Context-Aware Access GoogleWorkspace-context_aware_access

3 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'context_aware_access' without specifying an eventName attribute here.
ACCESS_DENY_EVENTA user's access to a resource was denied by a Context-Aware Access policy.
ACCESS_DENY_INTERNAL_ERROR_EVENTA Context-Aware Access policy evaluation failed due to an internal error, denying access.

any: Context-Aware Access (any event)

#
Application
GoogleWorkspace-context_aware_access

Description

Source-only rules that filter on applicationName 'context_aware_access' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

ACCESS_DENY_EVENT: Access Deny Event

#
Application
GoogleWorkspace-context_aware_access

Description

A user's access to a resource was denied by a Context-Aware Access policy.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

ACCESS_DENY_INTERNAL_ERROR_EVENT: Access Deny Internal Error Event

#
Application
GoogleWorkspace-context_aware_access

Description

A Context-Aware Access policy evaluation failed due to an internal error, denying access.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #