Topic
This article discusses Shared Drive Permission Restore capabilities in NinjaOne SaaS Backup.
Environment
- NinjaOne SaaS Backup
- Google Workspace
Description
Shared Drive Permissions Restore is a vital feature that enhances security and streamlines data management in Google Workspace. By restoring associated permissions when users recover entire shared drives, folders, or files, this capability ensures the integrity and confidentiality of sensitive information.
Getting Started
When restoring shared drives, folders, or files within a shared drive, our system automatically restores associated permissions. Review the following sections to get started.
Verification of Permissions
To confirm the successful restoration of permissions within the shared drive hierarchy, follow these steps:
Shared Drive Level
- Click Shared Drive.
- Choose the specific shared drive you wish to verify and select it.
-
Once selected, click the blue information button.
Figure 1: Information button (click to enlarge)
A dialog will appear, displaying the associated roles. To verify the restoration of role permissions at the shared drive level within the hierarchy, follow these steps:
Folder Level
- Click Shared Drive
-
Move your cursor over the specific folder within the shared drive. NinjaOne will display the "Show Permission" text beside the key icon.
Figure 3: Show Permissions (click to enlarge) - Click Show Permissions.
A dialog will appear, offering two options to view the details of associated permissions:
- Direct Access: Displays email addresses, user groups, or domains authorized to access the folder and its associated permissions.
- Access Link: Provides a link to access the folder and its associated permissions without specifying email addresses, user groups, or domains.
File Level
- Click Shared Drive.
- Navigate to the specific file you want to manage permissions for within the shared drive.
-
Click the selected file to open it. On the right-hand side, you will find information about the file's associated permissions.
Figure 5: File permissions (click to enlarge)
You have two options to view associated permissions:
- Direct Access: Displays email addresses, user groups, or domains authorized to access the file and its associated permissions.
- Access Link: Provides a link to access the file and its associated permissions without specifying email addresses, user groups, or domains.
Unlike shared drives and folders, files have versioning. Each version may have different permissions. You can view permissions for each version separately by selecting the desired version.
Record Keeping
All activities related to Shared Drive permissions are recorded in the Audit Log menu, ensuring transparency and compliance with security standards.
Frequently-Asked Questions (FAQ)
Can certain shared drives, folders, or files lack associated permissions?
Yes, if created before this feature was introduced, some items may not have their associated permissions restored.
What happens if discrepancies are found during the permissions restore process?
A: The system compares existing permissions in Google Workspace with backup permissions in our database. If discrepancies are detected, appropriate actions are taken to ensure the integrity of access.
How does the permissions restore process work?
When users initiate the restoration process for a shared drive, folder, or file, our system executes a series of steps to ensure the accurate reinstatement of permissions. Here's how it works:
- Comparison of Actual and Backup Permissions: Our system first compares the current (existing) permissions in Google Workspace (GWS) with the backup permissions stored in our database.
- Handling Missing Permissions: If the actual permissions do not exist in the backup database, our system merges these current permissions with the restored items (shared drive, folder, file). This proactive approach ensures that restored items remain accessible, particularly when accounts associated with authorized parties are no longer active.
- Dealing with Existing Permissions: In cases where the actual permissions already exist in the backup database:
- If the permission levels match (no discrepancy), our system does not perform any updates, as the permissions are already aligned.
- If there is a discrepancy in permission levels, our system updates the backup permissions to match the higher permission level. This measure is implemented to prevent potential loss of access to files or folders due to lower permissions.