Hi guys!! I have a query or so. We’re managing Windows devices with Hexnode, and our company uses Google Workspace. The requirement is that end users should only be able to log in with their @company.com accounts in Gmail/Google apps, but they should not be able to log in with personal @gmail.com accounts. Can Hexnode enforce this, or is there a workaround?
Query on restricting email domain on windows devicesSolved
Tags
Replies (5)
Interesting one. Hexnode can restrict apps and enforce kiosk mode, but I don’t think it can directly block personal Gmail logins. That feels more like an identity or conditional access issue.
Yeah, exactly. Hexnode is great for device-level controls, but distinguishing between corporate vs personal Gmail accounts isn’t something it does natively. You’d need policies outside of MDM for that.
Unfortunately, Hexnode does not currently provide a direct option to block personal Gmail logins while allowing corporate accounts on Windows devices. If you have more queries, please feel free to reach out.
Regards,
Mary Romero
I have got you some methods @wilma . You can try using Microsoft’s ecosystem like:
-
Defender for Cloud Apps Create an access policy to block users from accessing sites like gmail.com with personal accounts.
-
Purview DLP & Endpoint DLP Configure a policy so that if a user tries to upload data to personal Gmail, the action is blocked. Guide: https://learn.microsoft.com/en-us/purview/endpoint-dlp-using?tabs=purview
I’ve seen some companies solve this by forcing all browser traffic through Microsoft Defender for Cloud Apps. That way, if someone tries to log into personal Gmail, it gets blocked right at the browser level. It’s effective.