DRIVE-023: Drive for Desktop limited to authorized devices (GWS.DRIVEDOCS.5.1)
- Platform
- Google Workspace
- Category
- Drive Security & Data Protection
- Severity
- High
- Zero Trust pillar
- Devices (weight 3)
- Golden fixtures
- 5
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.DRIVEDOCS.5.1: Drive for Desktop synchronizes organizational files onto local disks, so allowing it on unmanaged hardware places a full local copy of Drive content on machines the organization cannot wipe, encrypt or inspect. Reads drive_and_docs.drive_for_desktop and fails where allowDriveForDesktop is on while restrictToAuthorizedDevices is not enforced. Drive for Desktop being off entirely is compliant and the check reports that rather than a bare pass.
Recommended value
Drive for Desktop is disabled, or restricted to company-owned authorized devices
Remediation
Admin console > Apps > Google Workspace > Drive and Docs > Features and Applications > Google Drive for Desktop. Either turn it off, or leave it on and enable 'Only allow Google Drive for Desktop on authorized devices'.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean-disabled | PASS |
| clean-restricted | PASS |
| field-missing | Not Assessed |
| known-bad | FAIL |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.DRIVEDOCS.5.1v1
- NIST SP 800-53
- AC-19, SC-28, MP-7
- MITRE ATT&CK
- T1005, T1025