Issue
When attempting to access Google Groups from NinjaOne SaaS Backup, you receive the error message "This app is blocked".
Environment
NinjaOne SaaS Backup
Issue
When attempting to access Google Groups from NinjaOne SaaS Backup, you receive the error message "This app is blocked".
Cause
NinjaOne SaaS Backup does not have permission to access the restricted data. There are multiple reasons this situation can occur. Review the following sections for troubleshooting steps.
Resolution
To troubleshoot this issue, review the steps below and complete as necessary. If a proposed solution does not resolve the issue, try the next one.
Common Solutions
Ensure the Apps are Trusted
There are multiple Client ID's that you must set to Trusted to allow NinjaOne SaaS Backup to access Google Vaults and Google Groups. To do so, perform the following steps:
- Log in as an administrator to the Google administrator portal.
- Navigate to API Controls → Manage Third-Party App Access → Add App → OAuth App Name or Client ID.
-
Search for the app IDs listed below:
Marketplace Name OAuth Client ID Purpose Dropsuite 644855987626-fjin7vh14lkjnojp99plfqgogcu2olbh.apps.googleusercontent.com G Suite login authorization NinjaOne SaaS Backup (Dropsuite) 691302468273-neonu87stp4pgi60farb18jl7sbgbakm.apps.googleusercontent.com General backup authorization NinjaOne SaaS Backup (Dropsuite) for Google Groups 651888057438-e3180fh1ik4ncmf9arq1m84pe9qarnm8.apps.googleusercontent.com Google Groups backup authorization - Select each of the above apps from the list, then click Access to Google Data.
- Click the Trusted radio button.
- Click SAVE.
Check for a Manual Block
It's also possible that an administrator may have manually moved the app to the Blocked list. You can check for and resolve this issue with the following steps:
- In the Google administrator portal, navigate to Third-Party App Access and filter by Blocked.
- Ensure that none of the above Client IDs are on the Blocked list.
Clear Your Browser Session
If you have multiple Google accounts open in the same browser window, Google may be trying to authorize the app against other partner domains rather than the targeted ones.
If you are using a standard browser window that might also be logged into your own reseller account or other personal Google account, you can open a new Incognito (Chrome) or InPrivate (Edge / Safari) window and log in using only the target tenant's Super Admin credentials, then restart the setup process. If the issues still occur, you can proceed to the next step.
Confirm the Google Vault License
NinjaOne SaaS Backup for Google Groups requires the Google Vault API (ediscovery scope) to back up historical group data. Google enforces this at the OAuth level, which means no admin configuration change can bypass it.
Check these conditions to ensure your Google Vault license is active.
- Check whether your Google Vault is listed in Admin Console → billing → subscriptions. If your tenant does not have Vault, Google will block this app regardless of any other configuration. The tenant must either upgrade to Business Plus/Enterprise Standard or Plus/Frontline Standard (Vault is included), or purchase the standalone Google Vault add-on. This is a Google billing issue, and our NinjaOne support team cannot resolve it.
- Check if your vault license is specifically assigned to you or the affected user. Check the assigned vault by navigating to Admin Console → Directory → Users → [Affected User] → Licenses. Wait about 15 minutes after the assigned vault license is assigned to the user before testing. If your license is confirmed for both the domain and the affected user, and the issues persist, you can proceed to the next step.
Check the Account Status
Rule out a suspended account by logging in to Gmail or Google Drive directly at gmail.com or drive.google.com. If you cannot log in, your account is suspended. You can navigate to Admin Console → Directory → Users, find the account, and look for the red Suspended label. Click Reactivate. Reactivation takes effect almost immediately. Retry the login. If the account is not suspended, you can proceed to the next step.
Verify the App is Listed
If you don't see the app listed, check whether this is a missing app or a global kill switch by navigating to API Controls → Settings → App access control.
If the Unconfigured third-party apps setting is set to Don't allow users to access any third-party apps, it means the admin has blocked all unapproved third-party apps globally. Adding the app to the trusted list alone is not enough. The global policy overrides it unless you explicitly add and trust the app.
Follow these steps to resolve the issue:
- In Manage App Access, click Add App → OAuth App Name or Client ID
- Paste the OAuth Client ID above and click Search.
- Place your cursor over the result and click Select.
- Check the relevant organizational units (or top-level for all users)
- Set access to Trusted and click Save.
- Wait about 15 minutes before testing.
Verify the App is Configured
If your app is unconfigured, it has never been approved and might be sitting in the administrator’s review queue. Follow these steps to resolve the Issue:
- Navigate to API Controls → Apps pending review
- Locate the NinjaOne app and click Configure access
- Select the relevant organizational units and set access to Trusted
- Optionally select "Notify users who requested access" so blocked users are informed automatically
- Click Save.
- Wait about 15 minutes before testing.
Restricting the Google Drive service also automatically restricts the Google Forms API. If third-party form add-ons have stopped working, this is likely the cause.
Other Potential Solutions
If the app appears to be globally configured correctly, but specific users are still being blocked, here are additional troubleshooting steps you can take:
Verify that the Organizational Unit (OU) is trusted
The app may be trusted at the top domain level, but not within the specific OU to which the affected user belongs. OU-level settings override global settings.
Steps to Resolve the Issue:
- Confirm which OU the affected user belongs to by navigating to Admin Console → Directory → Users.
- Navigate to Security → API Controls → Manage App Access.
- Find the NinjaOne app and click Change access.
- Click Select org units to view the organizational tree
- Locate and check the box for the specific OU the affected user belongs to
- Set access to Trusted for that OU and click Save.
- Wait approximately 15 minutes before testing.
Check Context-Aware Access (CAA) Policies
If the user is on an Enterprise, Education, or Frontline Standard plan, and the block occurs only on specific devices (personal phones), in specific locations (home WiFi), or for specific IP addresses, the administrator has likely configured Context-Aware Access (CAA) policies.
Steps to Resolve the Issue:
- Navigate to Admin Console → Security → Access and data control → Context-Aware Access
- Click Assign access levels and check if a strict policy is assigned to the NinjaOne app or to all third-party apps globally.
- Choose one of the following three options:
- Option A: Have the user log in from a compliant, company-managed device, or an approved IP address that satisfies the CAA rule.
- Option B: Unassign the strict access level from the NinjaOne app to exempt it from the CAA policy
- Option C: Temporarily set the access level to Monitor mode. This action allows the login to proceed while logging the violation, confirming CAA is the root cause without fully removing the policy.
Verify the User is Not Flagged as Under 18 Years Old (Google Workspace for Education)
Google Workspace for Education strictly blocks all unconfigured third-party apps for users under 18 years old. Global API settings do not override this. The specific OU must be explicitly configured.
Steps to Resolve the Issue:
- Navigate to Security → API Controls → Manage App Access
- Locate the NinjaOne app (or click Add App using the OAuth Client ID if not listed)
- Click Change access → Select org units
- Explicitly check the box for the OU containing the under-18 users
- Set access to Trusted. By setting the application status to Trusted, the administrator confirms that the institution has obtained any required parental consent.
- Click Save
- Wait about 15 minutes before testing.
Getting Help
If you have followed the steps above and the issue persists, open a support ticket and include the following information:
- A screenshot of Admin Console → Billing → Subscriptions showing the Vault license status.
- A screenshot of API Controls → Manage App Access showing the NinjaOne SaaS Backup/Dropsuite for Google Groups App and its current status.
- The full URL from the browser address bar at the moment the error appears. The URL string itself contains diagnostic information.
- The steps in this guide that you have completed.
Additional Resources
For more information about managing third-party apps in Google Workspace, refer to Google's documentation below.
- Control which apps access Google Workspace data (external link)
- Review & manage third-party app access requests (external link).