block/remove windows/Mac Devices

73 views
Skip to first unread message

blessing saw

unread,
Sep 29, 2025, 12:22:58 PM (6 days ago) Sep 29
to GAM for Google Workspace
How can I block windows/mac devices with deviceID on my GAM 7.22.07 .

I noted that If I need Windows device block/unblock, I need GAMADV-XTD3 but I also saw that GAMADV-XTD3 has been replaced with GAM7 . 


blessing saw

unread,
Sep 29, 2025, 12:24:44 PM (6 days ago) Sep 29
to GAM for Google Workspace

I tried with 

`gam update device 74ce097e-6f99-42d2-bce8-5eb6308c4963 action block`

and the error is 

`ERROR: Invalid choice (block): Expected <cancelwipe|wipe>`

Ross Scroggs

unread,
Sep 29, 2025, 1:03:38 PM (6 days ago) Sep 29
to google-ap...@googlegroups.com
You block device users, not devices.


gam info device 74ce097e-6f99-42d2-bce8-5eb6308c4963

Get the Device User value from the output

gam block deviceuser /devices/74ce097e-6f99-42d2-bce8-5eb6308c4963/deviceUsers/5b138017-1234-5668-81ee-142bf4feb909

Ross
----
Ross Scroggs



--
You received this message because you are subscribed to the Google Groups "GAM for Google Workspace" group.
To unsubscribe from this group and stop receiving emails from it, send an email to google-apps-man...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/google-apps-manager/b47f3c63-a307-4ea2-8e09-29b7ad24f033n%40googlegroups.com.

Jay Lee

unread,
Sep 29, 2025, 3:00:16 PM (6 days ago) Sep 29
to google-ap...@googlegroups.com
Note that block does not work for these desktop OS devices the way it does for mobile Android/iOS devices. To really block a given device's data access to Wrokspace you need to create a context aware access level and assign it to the service:


Jay Lee


Message has been deleted
Message has been deleted
Message has been deleted
Message has been deleted
Message has been deleted

blessing saw

unread,
Sep 30, 2025, 6:32:31 PM (5 days ago) Sep 30
to GAM for Google Workspace
I need to block devices, not users, since the use case here is that users may have multiple devices and only those registered with us should be allowed. There should at least be an option to issue a delete device command, as the option is already visible on the UI.Screenshot 2025-09-30 at 6.59.28 AM.png

Jay Lee

unread,
Sep 30, 2025, 6:43:30 PM (5 days ago) Sep 30
to google-ap...@googlegroups.com
Yes, and blocking a desktop device doesn't actually do anything unless you have a CAA access level in place.

Jay Lee

The waiting

unread,
Sep 30, 2025, 6:54:46 PM (5 days ago) Sep 30
to google-ap...@googlegroups.com
Hi Jay,

Yes, I have already set up the CAA access level. My current goal is to block the previous devices that had access to the workspace.

You received this message because you are subscribed to a topic in the Google Groups "GAM for Google Workspace" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/google-apps-manager/-GEwn9gWHwA/unsubscribe.
To unsubscribe from this group and all its topics, send an email to google-apps-man...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/google-apps-manager/CA%2BVVBp_AQVeRfv2LTqwQUnMrky%2B2HGBQPDCxqDtNnwny4Tirrg%40mail.gmail.com.

Ross Scroggs

unread,
Sep 30, 2025, 7:01:53 PM (5 days ago) Sep 30
to google-ap...@googlegroups.com
See: https://github.com/GAM-team/GAM/wiki/Mobile-Devices#manage-mobile-devices

You will use the Device Resource ID in the command.

Ross
----
Ross Scroggs


On Sep 30, 2025, at 3:54 PM, The waiting <hope.ne...@gmail.com> wrote:

Hi Jay,

Yes, I have already set up the CAA access level. My current goal is to block the previous devices that had access to the workspace.

On Wed, Oct 1, 2025 at 6:43 AM Jay Lee <jay...@gmail.com> wrote:
Yes, and blocking a desktop device doesn't actually do anything unless you have a CAA access level in place.

Jay Lee

On Tue, Sep 30, 2025, 6:32 PM blessing saw <hope.ne...@gmail.com> wrote:
I need to block devices, not users, since the use case here is that users may have multiple devices and only those registered with us should be allowed. There should at least be an option to issue a delete device command, as the option is already visible on the UI.<Screenshot 2025-09-30 at 6.59.28 AM.png>
Reply all
Reply to author
Forward
0 new messages