Migrate your OAuth out-of-band flow to an alternative method before Oct. 3, 2022

1,193 views
Skip to first unread message

Adamme

unread,
May 4, 2022, 10:12:57 AM5/4/22
to GAM for Google Workspace
Received notification from Google today that all the OAuth clients in my domain used for GAM are using a legacy method that will be deprecated. Is there an alternative auth method available now or is that still in development?

Full notification below
----

We are writing to inform you that OAuth out-of-band (OOB) flow will be deprecated on October 3, 2022, to protect users from phishing and app impersonation attacks.

What do I need to know?

Starting October 3, 2022, we will block OOB requests to Google’s OAuth 2.0 authorization endpoint for existing clients. Apps using OOB in testing mode will not be affected. However, we strongly recommend you to migrate them to safer methods as these apps will be immediately blocked when switching to in production status.

Note: New OOB usage has already been disallowed since February 28, 2022.

Below are key dates for compliance

  • September 5, 2022: A user-facing warning message may be displayed to non-compliant OAuth requests
  • October 3, 2022: The OOB flow is blocked for all clients and users will see the error page.

Please check out our recent blog post about Making Google OAuth interactions safer for more information.

What do I need to do?

Migrate your app(s) to an appropriate alternative method by following these instructions:

  1. Determine your app(s) client type from your Google Cloud project by following the client links below.
  2. Migrate your app(s) to a more secure alternative method by following the instructions in the blog post above for your client type.

If necessary, you may request a one-time extension for migrating your app until January 31, 2023. Keep in mind that all OOB authorization requests will be blocked on February 1, 2023.

The following OAuth client(s) will be blocked on Oct 3, 2022.


Gabriel Clifton

unread,
May 4, 2022, 10:56:38 AM5/4/22
to GAM for Google Workspace
I received the same email this morning. I can't tell what I am currently using for GAM, rclone, and gotyourback. I did find several that students created in 2018 that I can't delete even as super admin.

Ross Scroggs

unread,
May 4, 2022, 11:07:43 AM5/4/22
to google-ap...@googlegroups.com
Standard GAM 6.16, GotYouBack 1.61 and Advanced GAM 6.16.00 and above do not use out-of-band flow.

--
You received this message because you are subscribed to the Google Groups "GAM for Google Workspace" group.
To unsubscribe from this group and stop receiving emails from it, send an email to google-apps-man...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/4da1ce12-35ed-42bf-b977-8b5056e14a65n%40googlegroups.com.

Jay Lee

unread,
May 4, 2022, 11:11:45 AM5/4/22
to GAM for Google Workspace
Reply all
Reply to author
Forward
0 new messages