By default, users have the ability to authorize any third party applications that may have access to users' Gmail, Drive, etc.
If you have not yet restricted access to the third party apps the steps from a Googler are as follows:
1. Trust applcations users are using
2. Restrict API access (All scopes except for sign-in)
3. Review the applications and remove trust for unauthorized applications
When an appliaction is not trusted and requested scope includes a restricted scope, authorization will fail with 400 error which you can customize for your users.
Link to recommendation on r/gsuite:
/ g3fhvb3
Workspace Admins Info
View the Google Workspace Admins Public Calendar of upcoming events: https://calendar.google.com/calendar/...
Add it to your list of calendars via email: [email protected]
Get access to the Shared drive with documents from this event and other past events along with the collection of Community Docs. Workspace Admins Community Comment Access Group: https://groups.google.com/a/workspace...
To access the Workspace Admins [Public] shared drive, be sure to join the group above first: https://drive.google.com/drive/folder...
Google Workspace Recap podcast discussing each weeks new feature releases: https://workspacerecap.com
C2C Global, The Independent Google Cloud Community: https://www.c2cglobal.com/
Google Cloud Community, The official Google Cloud Community: https://www.googlecloudcommunity.com