{"id":3824,"date":"2021-12-17T10:03:24","date_gmt":"2021-12-17T18:03:24","guid":{"rendered":"https:\/\/SUMMALAI.COM\/?p=3824"},"modified":"2021-12-17T10:03:27","modified_gmt":"2021-12-17T18:03:27","slug":"how-to-setup-bcc-on-a-users-email-on-google-workspace","status":"publish","type":"post","link":"https:\/\/SUMMALAI.COM\/?p=3824","title":{"rendered":"How to Setup BCC on a User&#8217;s Email on Google Workspace."},"content":{"rendered":"\n<p>When I was recently working on a Google Workspace deployment project, customer asked me if its possible to watch users emails, So I did some research and testing to find if its really possible.<\/p>\n\n\n\n<p>Author \u2013 Goldy Arora \u2013 Google Workspace Certified Consultant<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">So Can Google Workspace Admin Read My Email?<\/h2>\n\n\n\n<p><strong>Google allows Google Workspace administrators to monitor and audit users emails. An Administrator may use Google Vault, Content Compliance rules, Audit API or Email delegation to view and audit users emails. It is recommend for Google Workspace Administrators to consider their local laws before performing email auditing on their users mailboxes.<\/strong><br>Play Video<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Monitor Your Users Emails in Google Workspace via Content compliance Rule<\/h2>\n\n\n\n<p>I\u2019ll show you how you can get bcc copy of your users\/employees emails without knowing their Google Workspace password.<\/p>\n\n\n\n<p>You should be a&nbsp;Google Workspace Administrator, and must be using Google Workspace Basic, Business, Government, Education or Enterprise edition as it does not work for Google Workspace Free.<\/p>\n\n\n\n<p><strong>Article Overview-:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>In this article you will see how being a Google Workspace&nbsp;Administrator you can get a copy of your users sent and received emails without knowing their passwords or putting forwarding in their mailboxes<\/li><li><strong>Note-:&nbsp;<\/strong>This option is primarily meant for auditing, you need to keep your country law and organizational policy in mind before attempting this method of getting access to your users emails.<\/li><li>For any feedback or query, feel free to write me<\/li><\/ul>\n\n\n\n<p><strong>Scenario -:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>For auditing purpose you would like to track incoming and\/or outgoing (including intra-domain) emails of one or all of your Google Apps users, without asking or changing their password or putting a forwarding rule in their mailboxes<\/li><\/ul>\n\n\n\n<p><strong>Solution Explanation-:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>To achieve this, you will create a server side rule in Google Workspace (formerly Google Apps) which you can apply on either one user, or an OU or even at all users<\/li><li>This rule will state, that any message which contain @yourdomain.com in the message header, then send its copy to the id which you define<\/li><\/ul>\n\n\n\n<p><strong>System Requirements-:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>This solution will only work with Basic, Business, Education and Government edition of Google Workspace (Google Apps), and not with free edition<\/li><\/ul>\n\n\n\n<p>https:\/\/youtube.com\/watch?v=y0dmpQvQ7F0%3Fcontrols%3D1%26rel%3D0%26playsinline%3D0%26modestbranding%3D0%26autoplay%3D0%26enablejsapi%3D1%26origin%3Dhttps%253A%252F%252Fwww.goldyarora.com%26widgetid%3D1<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 1 &#8211; LOGIN TO GOOGLE WORKSPACE CONTROL PANEL<\/h2>\n\n\n\n<p>To achieve this, we need to login to our Google Workspace admin console, watch the video to see 3 possible ways to access admin console.<\/p>\n\n\n\n<p>I assume you have administration permission to perform this task,<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 2 &#8211; NAVIGATE TO APPS<\/h2>\n\n\n\n<p>Once you are logged into Google Workspace Control Panel, click on APPS icon from the Dashboard.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2015\/05\/51534ebb-127c-4f40-9142-1e428e43223f.png\" alt=\"Click on Apps in G suite control panel\" title=\"How your employer can access your emails without password 2\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2015\/05\/wpid7099-Step_3_-_Navigate_and_click_on_click_on_GMAIL.png\" alt=\"Navigate and click on Gmail\" title=\"How your employer can access your emails without password 3\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 3 &#8211; GO TO GMAIL<\/h2>\n\n\n\n<p>As we will be applying a server side to our Gmail application, which will get us bcc copy of all sent and received emails of our users<\/p>\n\n\n\n<p>Click on the GMAIL icon as shown in the screenshot<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 4 &#8211; CLICK ON ADVANCE SETTINGS<\/h2>\n\n\n\n<p>The rule we want to apply is a part of Gmail advance settings, go ahead and click on it<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2018\/01\/Click-on-Advanced-settings-in-g-suite-admin-console.png\" alt=\"Click on Advanced settings in g suite admin console\" title=\"How your employer can access your emails without password 4\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2016\/08\/Step_5_-_Select_Parent_or_Child_organizational_unit_as_re.png\" alt=\"Step 5 Select Parent or Child organizational unit as re\" title=\"How your employer can access your emails without password 5\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 5 &#8211; SELECT ORGANIZATION UNIT<\/h2>\n\n\n\n<p>If you want to receive bcc copy of all the users in your domain, you can select the parent organization unit.<\/p>\n\n\n\n<p>If you want to apply it on a specific function such as sales or accounting OR even only on a few users, you may create a new organizational unit and put required users in it,&nbsp;here are instructions by Google for it.<\/p>\n\n\n\n<p>After selecting right orgnaizational unit, scroll down to find \u201cContent Compliance\u201d and click on \u201cConfigure\u201d as shown in the screenshot below<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 6 &#8211; DEFINE RULE&#8217;S SCOPE<\/h2>\n\n\n\n<p>Adding a description for your rule is recommended to ensure other administrators in your domain can refer to it and understand this rule\u2019s objective in your absence<\/p>\n\n\n\n<p>Select which emails you want to get as bcc for users, you can select any or all including inbound, outbound, internal sending or recieving, for the sake of this example, am only considering inbound and outbound, and not the intradoamin ones.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2016\/08\/Step_6_-_Define_the_applicability_of_your_rule__whether_i.png\" alt=\"Step 6 Define the applicability of your rule whether i\" title=\"How your employer can access your emails without password 6\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2016\/08\/Step_7_-_Define_the_expression_of_the_rule__its_like_an_I.png\" alt=\"Step 7\" title=\"How your employer can access your emails without password 7\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 7 &#8211; DEFINE THE EXPRESSION<\/h2>\n\n\n\n<p>Lets define our condition, think of it like IF\/Else statement-:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Select \u201cIf any of the following match the message\u201d<\/li><li>Click on \u201cAdd\u201d to add a condition statement<\/li><li>Click on \u201cAdvance Content Match\u201d<\/li><li>Location should be \u201cFull Headers\u201d<\/li><li>Match Type should be \u201cContain Text\u201d<\/li><li>Content should be \u201cyourdomainanme.com\u201d (you need to change yourdomainname.com to your actual domain name)<\/li><li>Save your condition<\/li><\/ol>\n\n\n\n<p>Explanation -: In this step, we have created a condition (IF statement) stating if \u201c@yourdomain.com\u201d is found in the message header, then match the condition, now if your users either send or receive message through their corporate id, @yourdomain.com will surely be there in the headers, as its not possible to send\/receive without it from\/to their corporate id, however if your requirement is a bit complex, you may also use regex expressions to define your criteria.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 8 &#8211; WHO SHOULD GET BCC?<\/h2>\n\n\n\n<ol class=\"wp-block-list\"><li>Scroll down and click on \u201cAdd more recipients\u201d<\/li><li>Click on Advance<\/li><li>Checkbox \u201cChange Envelope Recipient\u201d<\/li><li>Select \u201creplace envelope recipient\u201d<\/li><li>Enter the email id on which you would like to get bcc copy<\/li><li>Scroll below and follow the next step in this article<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2016\/08\/add-more-receipients-1-1030x849-1.png\" alt=\"add more receipients 1 1030x849 1\" title=\"How your employer can access your emails without password 8\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/nitrocdn.com\/aGxIKXvSLxnUSlbHydJcoISvYKUQqJTv\/assets\/static\/optimized\/rev-e094d0b\/wp-content\/uploads\/2016\/08\/save-the-bcc-rule-1-1030x933-1.png\" alt=\"save the bcc rule 1 1030x933 1\" title=\"How your employer can access your emails without password 9\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 9 &#8211; PREPEND SUBJECT (RECOMMENDED)<\/h2>\n\n\n\n<ol class=\"wp-block-list\"><li>In this step, we\u2019ll define a way to separate these bcc emails from your regular ones, so you can easily identify them and filter\/label them if required.<ol><li>Click on \u201cPrepend subject\u201d<\/li><li>Add any thing you would like to prepend in the subject of these bcc emails, for example {{BCC}}<\/li><li>Now all theses bcc copies that you\u2019ll get will have {{BCC}} in front of the subject line, which will help you make filter in Gmail and put them under a label\/folder.<\/li><li>Save your changes<\/li><\/ol><\/li><\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">STEP 10 &#8211; DONE!<\/h2>\n\n\n\n<p>Congratulations, you will now get a bcc copy of your users in the mailbox you put in your condition as shown in the above example)<\/p>\n\n\n\n<p>Ref: https:\/\/www.goldyarora.com\/how-you-can-access-your-users-email-without-knowing-their-password-in-google-apps\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When I was recently working on a Google Workspace deployment project, customer asked me if its possible to watch users emails, So I did some research and testing to find if its really possible. Author \u2013 Goldy Arora \u2013 Google Workspace Certified Consultant So Can Google Workspace Admin Read My Email? Google allows Google Workspace <a class=\"read-more\" href=\"https:\/\/SUMMALAI.COM\/?p=3824\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[810,497],"tags":[978],"class_list":["post-3824","post","type-post","status-publish","format-standard","hentry","category-google-workspace","category-solutions","tag-watch-users-emails"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/3824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3824"}],"version-history":[{"count":2,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/3824\/revisions"}],"predecessor-version":[{"id":3838,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/3824\/revisions\/3838"}],"wp:attachment":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}