Supported editions for this feature: Frontline Plus; Enterprise Standard and Enterprise Plus; Education Standard and Education Plus; Enterprise Essentials Plus. Compare your edition
You can use data protection rules with sharing boundaries to restrict the sharing of Google Drive files in your organization. By combining trust rules and data loss prevention (DLP) restrictions in one rule, you can:
- Target sensitive content using data-based restrictions.
- Control access using allowlists or denylists.
- Apply rules to specific organizational units, groups, or domains.
Create a data protection rule with sharing conditions
-
In the Google Admin console, go to Menu
Rules
Create rule
Data protection.
Requires having the View and Manage DLP rule privileges.
- Enter the name and (optionally) a description for the rule.
- In the Apps section, for Google Drive, check the Drive files box.
- Click Continue.
In the Actions section, for the Google Drive action, select Block sharing.
Note: Sharing conditions are only supported for block actions in Drive files.
Click Continue.
(Optional) To add conditions that specify the content type to scan (for example, All content) and what to scan for (for example, Matches predefined data type), in the Content conditions section, click Add Condition.
In the Sharing conditions section, choose one of the following options:
- Block all internal and external sharing, except with specific users (allowlist)—Select the organizational units, groups, or domains that you want to allow sharing with.
- Block sharing with specific users (denylist)—Select the organizational units, groups, or domains that you want to block.
Click Continue.
On the Review page, for Rule status, choose an option:
- Active—Your rule runs immediately.
- Inactive—Your rule isn't applied until you activate it.
Click Create.