Set up sharing boundaries for Google Drive with unified data protection rules
Set up sharing boundaries for Google Drive with unified data protection rules
![]() |
| New granular admin policies that prevent sharing between audiences based on data sensitivity |
google introducing a new capability that allows Google Workspace administrators to configure audience sharing and sensitivity-based data conditions in a single, unified rule. This unified rule flow helps organizations elevate their security posture to proactively mitigate insider risks, prevent data exfiltration, and safely unblock collaboration for high-sensitivity environments.
Previously, administrators managed user/group-based sharing controls with trust rules and data loss prevention (DLP) policies separately for Google Drive. With this launch, admins can now build granular, content-aware sharing boundaries that can evaluate data sensitivity (with classification labels or DLP conditions) and the audience with whom the data is being shared using trust rules criteria (such as organizational units, groups, or domains).
Additional details
The feature supports three audience restriction options:
- Block sharing with all external users: Prevents any file meeting the content criteria from being shared outside the organization
- Block all internal and external sharing, except with specific users (Allowlist): Restricts access to a curated list of trusted internal organizational units (OUs), groups, or external domains
- Block sharing with specific users (Denylist): Explicitly blocks sharing with specific internal organizational units, groups, or external parties (such as vendors or contractors) while permitting sharing with everyone else
Getting started
- Admins: When configuring data protection rules in the Admin console, admins should select Google Drive as the app and the “block sharing” option to use this functionality. Visit the Help Center to learn more.
- End users: There is no end user setting for this feature.
Rollout pace
- Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on September 14, 2026
Availability
- Enterprise: Enterprise Standard and Plus
- Education: Education Standard and Plus
- Other Editions: Enterprise Essentials; Frontline Standard and Plus
Resources
- Google Workspace Admin Help: Set up sharing boundaries in data protection rules
How to Configure Unified Rules in the Admin Console
- Access the Rules Engine: Log into the Google Admin Console as a Super Admin or an administrator with View and Manage DLP rule privileges. [3, 4]
- Navigate to Rule Creation: Go to Rules → Create rule → Data protection. [3, 4]
- Define Scope and App: Name your rule, provide a description, and choose the target organizational units (OUs) or groups. Under the applications selection, choose Google Drive. [1, 3]
- Set Sensitivity Criteria (Content/Labels): Define what content triggers the boundary. You can choose predefined detectors (like SSNs, PII, or financial records), custom regular expressions, or specific classification labels assigned to your documents. [4, 5]
- Enforce the Sharing Boundary: When defining the action, choose the “block sharing” option. You will be presented with three unified audience restriction boundaries: [1]
The 3 Audience Restriction Options
| Boundary Action | How it Works | Best Used For |
|---|---|---|
| Block sharing with all external users | Prevents any file meeting your sensitivity criteria from leaving the organization’s domain. | Core internal IP, source code, and widespread sensitive internal documents. |
| Block all internal and external sharing, except with specific users (Allowlist) | Restricts access exclusively to a highly curated list of trusted internal OUs, groups, or specific external domains. | Strictly regulated compliance data (e.g., PHI, HR payroll data) that only a few teams should see. |
| Block sharing with specific users (Denylist) | Explicitly blocks sharing with defined internal organizational units, groups, or external parties (such as specific vendors/competitors) while allowing the rest of the world. | Safeguarding data against high-risk internal OUs, specific contractor groups, or untrusted external domains. |
Administrative Best Practices
- Test via Audit Mode: Before fully enforcing a “Block” action, start the rule in Audit Only mode. This allows you to evaluate rule triggers in the Alert Center without disrupting ongoing user collaboration. [3, 4]
- Layer Conditions: To minimize disruptive false positives, avoid relying on single-match parameters (like any random 9-digit string). Require a combination of a detector plus nearby keywords. [4]
- Prerequisite: This unified feature rolls out directly to the Admin console, requiring no end-user setup. Ensure your Workspace tier supports advanced DLP rules (such as Enterprise, Education, or Cloud Identity Premium variants). [1, 4, 6]
- What Workspace subscription tier (e.g., Business Plus, Enterprise Standard) are you currently managing?
- What specific type of sensitive data (e.g., PII, financial spreadsheets, project blueprints) are you trying to protect?
- Do you already have organizational units (OUs) or Google Groups set up for your internal vs. external users?
Read more
. Doubled cell limits in Google Sheets now generally available
. Manage external sharing for Gemini Notebook in the Admin console
. Inside the Gemmaverse: Celebrating one billion Gemma downloads
. Personalize the content you see on Search, Discover, and News
. Gemini in Google Sheets is now available on Android devices
. The Gemini desktop app is now available for Windows
. macOS 27 Golden Gate is INCREDIBLE! – First 15 Things743. Take an interactive journey through America’s national parks
744. Seamlessly import your team and data from Microsoft to Google Workspace during setup
745. Google Workspace Weekly Recap – September 11, 2026
for more refer Gemini website click here
for more refer Artificial Intelligence website click here


