<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ORINEX Workspace field guides</title>
    <link>https://www.orinexsystems.com/guides/</link>
    <description>Practical technical notes for Google Workspace administrators, based on real K-12 administration.</description>
    <language>en-us</language>
    <atom:link href="https://www.orinexsystems.com/guides/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Google Workspace summer rollover checklist for K-12</title>
      <link>https://www.orinexsystems.com/guides/google-workspace-summer-rollover</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-workspace-summer-rollover</guid>
      <description>Rollover is four populations, one hard deadline, and an ordering constraint that will merge two grade levels if you get it backwards. Most of the work is decisions made in May, not clicks made in July.</description>
      <category>K-12 operations</category>
    </item>
    <item>
      <title>Graduating students: suspend, transfer, archive, or delete?</title>
      <link>https://www.orinexsystems.com/guides/graduating-students-google-workspace</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/graduating-students-google-workspace</guid>
      <description>There is no single right answer, but there is a right order. Students can only move their own work while they can still sign in, and two separate settings have to be on before the transfer tool works at all.</description>
      <category>K-12 operations</category>
    </item>
    <item>
      <title>What actually has to happen when a teacher leaves your district</title>
      <link>https://www.orinexsystems.com/guides/google-workspace-teacher-offboarding</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-workspace-teacher-offboarding</guid>
      <description>Suspending the account is the easy part. The work is everything attached to it: Drive ownership that does not transfer the way you expect, delegation nobody remembers granting, and a deletion window that closes permanently after twenty days.</description>
      <category>K-12 operations</category>
    </item>
    <item>
      <title>Why your ChromeOS device counts don't match Google Admin Console</title>
      <link>https://www.orinexsystems.com/guides/chromeos-device-counts-dont-match</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/chromeos-device-counts-dont-match</guid>
      <description>Two systems read the same Google Workspace tenant and report different Chromebook totals. It is almost always deprovisioned devices or a child organizational unit roll-up. Google documents the behavior without documenting its consequence.</description>
      <category>ChromeOS and devices</category>
    </item>
    <item>
      <title>Disable, deprovision, or delete? What actually happens to a Chromebook</title>
      <link>https://www.orinexsystems.com/guides/chromebook-disable-deprovision-delete</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/chromebook-disable-deprovision-delete</guid>
      <description>Disabling and deprovisioning a ChromeOS device do very different things, and deleting one is not an option Google offers at all. The deprovision reason you pick is a license decision, and picking the wrong one can cost you the license permanently.</description>
      <category>ChromeOS and devices</category>
    </item>
    <item>
      <title>How long do Google Workspace directory changes take to appear?</title>
      <link>https://www.orinexsystems.com/guides/google-directory-api-write-lag</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-directory-api-write-lag</guid>
      <description>We measured it. Unsuspending an account was visible on a direct account lookup faster than we could detect, and took about eleven seconds to reach the filtered lists and searches administrators actually look at. Google's own published bound is far more conservative.</description>
      <category>Administration and security</category>
    </item>
    <item>
      <title>How to clean up years of old Google Groups without breaking everything</title>
      <link>https://www.orinexsystems.com/guides/clean-up-old-google-groups</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/clean-up-old-google-groups</guid>
      <description>A group is four things at once and only one of them is visible from the Groups list. Deleting it revokes every permission it was silently holding, and in a school the things that break are the ones that only happen once a year.</description>
      <category>Administration and security</category>
    </item>
    <item>
      <title>What to check after a Google Workspace account is compromised</title>
      <link>https://www.orinexsystems.com/guides/google-workspace-compromised-account</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-workspace-compromised-account</guid>
      <description>Resetting the password is not containment. The controls overlap, but no single one of them covers everything — and the persistence someone leaves behind survives all of them if you do not go looking for it specifically.</description>
      <category>Administration and security</category>
    </item>
    <item>
      <title>Google Drive share phishing: why the email is real and the document is malicious</title>
      <link>https://www.orinexsystems.com/guides/google-drive-share-phishing</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-drive-share-phishing</guid>
      <description>A Google Drive sharing notification can be generated by Google itself, pass every email authentication check, and still hand a staff member a phishing document carrying the superintendent's name. What is actually happening, what Google's own protections do and do not catch, and what to tell staff.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>How to investigate a malicious Google Drive share in Google Workspace</title>
      <link>https://www.orinexsystems.com/guides/investigate-google-drive-phishing</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/investigate-google-drive-phishing</guid>
      <description>A staff member reports a shared document that turned out to be phishing. What to capture first, how to identify the account that actually shared it, what your Drive and Gmail logs can and cannot show for a file your organization does not own, and where the edition line falls between Education Fundamentals, Standard and Plus.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>How to remediate Google Drive share phishing in Google Workspace</title>
      <link>https://www.orinexsystems.com/guides/google-drive-phishing-remediation</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-drive-phishing-remediation</guid>
      <description>An incident-response workflow for a malicious Drive share that reached your staff: what to preserve, how to pull the notification out of inboxes on each Education edition, what can and cannot be done about the shared file itself, and how to close it out. Education Fundamentals and Standard/Plus are handled separately, and so is the ORINEX Compliance workflow.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>Why blocking the sender doesn't stop Google Drive share phishing</title>
      <link>https://www.orinexsystems.com/guides/block-google-drive-phishing-email</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/block-google-drive-phishing-email</guid>
      <description>The first instinct after a malicious Drive share is to block the sender. In a Drive-share attack the sender is Google, the account that shared the file is someone else, and the person named in the document is a third party. Which of the three you can block, what each block actually does, and what works instead.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>Using Gmail content compliance to quarantine Google Drive phishing</title>
      <link>https://www.orinexsystems.com/guides/google-drive-phishing-content-compliance</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-drive-phishing-content-compliance</guid>
      <description>Gmail's content compliance rules can examine the headers and body of inbound mail and quarantine, reject, or modify what matches. A methodology for turning one preserved Drive-share phishing notification into a rule that catches the campaign without touching legitimate Drive notifications, and why there is no universal rule to copy.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>Can a Google Workspace admin delete a phishing email from everyone's inbox?</title>
      <link>https://www.orinexsystems.com/guides/google-workspace-delete-phishing-email</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/google-workspace-delete-phishing-email</guid>
      <description>Yes on Education Standard and Plus, from the Admin console's security investigation tool. On Education Fundamentals the console can tell you who received it but cannot remove it; removal needs the Gmail API through GAM or another tool. An edition-by-edition comparison of what your license actually gives you, verified against Google's documentation.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>How to reduce Google Drive share phishing in Google Workspace</title>
      <link>https://www.orinexsystems.com/guides/block-google-drive-share-phishing</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/block-google-drive-share-phishing</guid>
      <description>There is no setting that safely eliminates Drive-share phishing for every district without also affecting legitimate external collaboration. What Google's own protections do, the difference between users sharing files out and users receiving files in, where the allowlist and trust rules draw the line and which editions have them, and a K-12 approach that tightens receiving where it costs the least.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>K-12 impersonation phishing: why attackers pretend to be superintendents, HR and finance</title>
      <link>https://www.orinexsystems.com/guides/k12-impersonation-phishing</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/k12-impersonation-phishing</guid>
      <description>The lures that work on school staff borrow the names on the district letterhead and the routines those names control: payroll, benefits, evaluations, payments. Why those roles, how the messages arrive (including through Google's own Drive notifications), why a familiar name beats an unfamiliar address, and what district IT can actually do about it.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>Why SPF, DKIM and DMARC don't stop Google Drive share phishing</title>
      <link>https://www.orinexsystems.com/guides/dmarc-google-drive-phishing</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/dmarc-google-drive-phishing</guid>
      <description>SPF, DKIM and DMARC authenticate the domain that sent a message, and they work. A Google Drive share notification is sent by Google, so it authenticates as Google's, correctly, while the account that shared the file, the document and the link inside it sit outside anything authentication examines. A short, sourced explanation of why a pass is expected and what it does and does not tell you.</description>
      <category>Phishing and incident response</category>
    </item>
    <item>
      <title>How to remove a user from all Google Groups with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-remove-user-from-all-groups</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-remove-user-from-all-groups</guid>
      <description>One GAM7 command takes a user out of every group they belong to. Here is the command, the preview to run first, and what it does that is easy to miss: owned groups, nested groups, and everything that was shared to those groups.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to find every Google Group a user belongs to with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-find-all-groups-a-user-belongs-to</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-find-all-groups-a-user-belongs-to</guid>
      <description>One GAM7 command lists the groups a user was added to. A second lists those groups and the groups they sit inside, which is what decides what the person can actually reach. Here are both.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to move Google Workspace users to another OU with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-move-users-to-another-ou</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-move-users-to-another-ou</guid>
      <description>GAM7 moves one user, or everyone in an organizational unit, with a single command. Here is each form, the preview to run first, how to leave suspended accounts where they are, and how long the new settings take to apply.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to list suspended users with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-list-suspended-users</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-list-suspended-users</guid>
      <description>One GAM7 command lists every suspended account in your domain. Here is the command, the form Google uses in its own examples, and why the list matters more than it looks: suspension by itself does not free an account's license.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to sign a user out of Google Workspace with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-sign-user-out</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-sign-user-out</guid>
      <description>One GAM7 command signs a user out of every web and device session. Here is the command, what Google says about how fast it takes effect, and why a district that uses single sign-on needs one more step.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to archive suspended users with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-archive-suspended-users</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-archive-suspended-users</guid>
      <description>Google publishes its own GAM command for archiving every suspended account in an Education domain. Here it is, the preview to run first, and what archiving changes: the license it frees, and what it takes to bring an account back.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to transfer Google Drive ownership with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-transfer-drive-ownership</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-transfer-drive-ownership</guid>
      <description>One GAM7 command moves ownership of a user's Drive files to someone else. Here is the command, its built-in preview, what it leaves the old account by default, and what happens to files in the old owner's trash.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to deprovision Chromebooks safely with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-deprovision-chromebooks</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-deprovision-chromebooks</guid>
      <description>GAM7 deprovisions a Chromebook with one command and two safety catches built in. Here is the preview, the command, the reason you have to choose, and what deprovisioning means for the device afterwards.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to find users suspended for more than 90 days with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-find-users-suspended-for-days</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-find-users-suspended-for-days</guid>
      <description>GAM7 can select suspended accounts by how long ago they were disabled. Here is the 90-day command, how its options fit together, and the one combination that quietly includes archived accounts too.</description>
      <category>GAM guides</category>
    </item>
    <item>
      <title>How to export Google Groups and their members with GAM</title>
      <link>https://www.orinexsystems.com/guides/gam-export-groups-and-members</link>
      <guid isPermaLink="true">https://www.orinexsystems.com/guides/gam-export-groups-and-members</guid>
      <description>One GAM7 command exports every group in your domain with its members, one row per membership. Here is the command, how to expand nested groups into the people inside them, and which of the two exports to keep.</description>
      <category>GAM guides</category>
    </item>
  </channel>
</rss>
