Skip to main content

Using Quarantine Manager in Google Apps

Fairly recently Quarantine Manager was introduced to Google Apps. This is a tool that works alongside SPAM filtering, objectionable content and content compliance rules you may have setup. Essentially the Quarantine Manager holds messages that fall into the categories you have defined for administrators to view before approving or rejecting the messages.

We have used this to block all SPAM messages going to students. This is a brief look at how to set it up.  Please note, it is very important to have authenticated email setup - this prevents things like group notifications every ending up in SPAM.

Step 1 - define some Quarantine Names

Head to email settings. You will find 'Manage Quarantines' below 'Authenticated email' near the bottom:
Click on 'ADD' - top left
Give the quarantine a name and description of what it is going to do. Decide if you just want to drop the message or send a rejection email. See example below:
This in itself does nothing - you have to link it to a compliance rule.

Step 2 - link to a compliance rule

Next go to 'User Setting' in the Gmail admin console. Select the sub-OU you want to apply the rule to and the type of compliance. In the example below I'm defining a SPAM policy - but it could be content compliance or objectionable content. 
Select edit:
Click the box at the bottom and choose the Quarantine you created. Click save and save again (appears bottom right).

This will Quarantine all SPAM (or whatever messages you set up) from this point on. Messages received prior to the rule being set up are not affected. However, SPAM folders are automatically cleared every 30 days - so within that time frame users SPAM folders will always be empty.

Step 3 - Review Quarantined messages

There you can select all the Quarantines you have set up - and allow messages if appropriate.

I've blanked out the usernames - but you can see the typical rubbish people get. These few steps prevent them from ever seeing any of it. The messages also still appear in Vault if you ever need to find them.

Popular posts from this blog

Delete a specific email using GAM

If a user send an inappropriate email to a loads of people or get stung by some sort of email exploit you can quickly delete the email from all of the recipients using a GAM command.
Step 1 - get the email header Go into Google Vault and search for the offending user or someone known to have got the message.
Click show details and grab the email ID. This will be a long string of characters followed by
Step 2 - find out who has the email Go into Google Vault and find the original message sent by the offending user. Look at the details to see who got it. Copy the list and dump it into a spreadsheet. Clean up to just a list of emails with a column header 'mail'. Save as a csv file.
Step 3 - delete messages with GAM Put your CSV file in your GAM folder - this e.g. assumes its called mail.csv
gam csv mail.csv gam user ~mail delete messages query rfc822msgid:MESSAGEIDHERE doit

The alternative nuke option is:
gam all users delete messages query rfc822msgid:MESSAGEI…

How to push bookmarks to users in Chrome via the management console

With the release of Chrome and ChomeOS 37 an update to the management console has arrived that allows you to push bookmarks to users.

Under Device Management > Chrome > User Settings > User Experience you will now find the option to add managed bookmarks.

In the example above, the bookmarks are applied to the sub-OU of 'students' - so all our students will get these bookmarks. Simply add your url and the bookmark name, click the + and save. These will appear in a folder called 'yourdomain bookmarks' - see below:

Be aware that to get these bookmarks applied on a Windows/OS-X device the user must be signed into Chrome. Update: if you install the latest group policy template you can push the bookmarks via policy on PCs - details are given here.
Video Guide:

Managed Android Apps on ChromeOS on an Edu G Suite Domain

Android Apps via the Play Store have been available on consumer accounts for some time on selected devices. We have 1:1 Acer R11's and have recently had the opportunity to trial them on G Suite Edu accounts.

From the point of view of the end user, they see the Play Store App appear on the shelf and have to agree to the terms and conditions. After that, force installed and pinned apps are immediately installed and they get access to the Google for Work Store. This only contains apps you have approved for that user.

For the administrator the steps are:

Enable Play Store Apps for the domainEnable access to the Play Store for specific Sub-OUs or usersAdd apps to Play for WorkSet permissions for each app - can install, force install or pin to shelf. This can be done differently for each app and each OU and is therefore very granular. 
Issues so far

Apps take a while to appear in the Play Store for users. Initially only force installed apps appear.You cannot set the permissions of multipl…