Overview
To help protect you from data loss, you can use Incydr to monitor when files are downloaded as reports from your business data in Salesforce, moved to and from cloud storage environments (such as Google Drive or Microsoft OneDrive), or emailed as attachments through Gmail or Office 365.
This article explains how to deauthorize those data connections so that Incydr no longer has access to user data in those environments. You can also resume monitoring cloud storage data connections to resolve errors, reconfigure cloud storage scoping, or restart the collection of file activity from data connections after a pause.
For information about disconnecting an automated integration, see Configure Incydr Flows.
Considerations
- You cannot deauthorize a cloud storage data connection (Google Drive, OneDrive, or Box, for example) or email service data connection (such as Gmail or Office 365) while the status is Initializing. Wait for the connection to indicate that it has a status of Monitoring or Error before attempting to deauthorize.
- If needed, you can use this process to reconfigure scoping for monitoring a cloud storage connection's users or groups.
- Google Workspace administrators must have the Super Admin role in order to share file activity data with Incydr without errors. For more information see Resolve Google Drive security data errors.
- Deauthorization is not available for automated integrations. For more information, see Configure Incydr Flows.
- Cloud storage and email service connections are not available in the Incydr federal environment.
Deauthorize a data connection
Deauthorize a Salesforce, cloud storage, or email service data connection to stop monitoring it for new event activity.
For cloud storage data connections, you can resume monitoring that connection for up to 90 days after you deauthorize it. After 90 days, Incydr removes the cloud storage or email service's configuration and authorization information. To resume monitoring that connection again after 90 days have elapsed, you must set it up as a new connection.
For Salesforce, Gmail, and Microsoft Office 365 data connections, Incydr removes the connection's configuration and authorization information immediately after deauthorization. To resume monitoring one of these data connections, you must set it up again as a new connection.
For all connections, events that have been collected prior to deauthorization remain searchable in Forensic Search for up to 90 days.
- Sign in to the Incydr console.
- Select Administration > Integrations > Data Connections.
- Locate the connection to deauthorize in the table, then click View details
.
- Click Deauthorize.
- When the dialog box opens, read the information and then click Deauthorize.
At this point, Incydr stops collecting new file activity from the data connection. - If you do not plan to resume monitoring the connection, remove Incydr's access in the external console.
Removing Incydr's access in the external console is optional, but may increase security. After deauthorization, Incydr immediately stops monitoring or accessing that environment.
Remove Incydr's access in Box
Remove Incydr's access in Google Drive or Gmail
Remove Incydr's access in Microsoft OneDrive, SharePoint, or Office 365 email
Remove Incydr's access in Salesforce
Resume monitoring a data connection
You can resume monitoring cloud storage connections for up to 90 days after you deauthorized the initial connection. Incydr removes connections that have been deactivated for over 90 days. To resume monitoring a Salesforce, Gmail, or Microsoft Office 365 email service after deauthorization, set it up as a new connection.
- Sign in to the Incydr console.
- Select Administration > Integrations > Data Connections.
- Locate the connection to resume monitoring in the table, then click View details
.
- Click Resume Monitoring.
You can resume monitoring only connections with a status of Deauthorized. You cannot resume monitoring a Salesforce, Gmail, or Microsoft Office 365 email service. Instead, set it up as a new connection to monitor that service again. - Follow the prompts to authorize Incydr to monitor file events on that connection.
Option to update administrator email address
If you are resuming monitoring of a Google Drive environment, you can change the administrator's email address if needed. When doing so, you can change the username in the email address, but the domain used (such as "@example.com") must remain the same. This new email address must be associated with a Google Workspace administrator that has the Super Admin role.
Use cases
You can deauthorize and then resume monitoring a cloud storage connection to update the scoping used or resolve errors. In most cases, errors caused by permissions or licensing issues within the cloud storage environment can be resolved by deauthorizing the connection and then immediately resuming its monitoring.
Some use cases for using the deauthorization and resume monitoring processes for a cloud storage connection are detailed in the following articles:
- Reconfigure scoping for user and group monitoring
- Resolve Google Drive security data errors
- Resolve maximum user drives exceeded errors
External resources
- Microsoft: Integrating Applications with Azure Active Directory
- Google: OAuth: Managing API client access
Comments
Please sign in to leave a comment.