ADMIN-022: Early Access applications disabled (GWS.COMMONCONTROLS.16.2)
- Platform
- Google Workspace
- Category
- Admin & User Management
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.COMMONCONTROLS.16.2 recommends disabling user access to Early Access applications, which are pre-release features that have not completed Google's full review and may carry unassessed risk. This check reads the early_access_apps.service_status Cloud Identity policy and flags any organizational unit where serviceState is ENABLED.
Recommended value
early_access_apps serviceState not ENABLED (Early Access applications disabled) in all organizational units.
Remediation
In the Google Admin console, under Apps > Additional Google services > Early Access Apps, turn the service OFF for everyone so users cannot enable pre-release Early Access applications.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.COMMONCONTROLS.16.2v1
- NIST SP 800-53
- CM-7, SA-22