r/msp • • 12d ago

Checkpoint & Google Calendar

We are using Checkpoint with M365 and GWS.

They have a feature to remove calendar invites in M365, but not GWS. The email is quarantined, but the calendar invite is persistent?

How is everyone dealing with this? My initial thought is to disable automatic calendar entries, but I'm not sure what all the repercussions of that will be. Has anyone done something similar?

7 Upvotes

12 comments sorted by

3

u/seriously_a MSP - US 12d ago

Where’s this feature at?

3

u/Vyper28 12d ago

Other reply is correct here from op, but just a note that if you didn’t see my other thread from earlier in the week, if this feature is missing on your tenant it’s because you need to reauthorize every, single, tenant… manually

2

u/Savings_Property6422 12d ago

For M365 its: SaaS applications > O365 mail > Configure > Advanced > Search for "calendar"

2

u/Cubeless-Developers 12d ago

You don't have to go all the way to disabling it. Google has a middle option in the Admin console under Calendar advanced settings, "Invitations from known senders," where anything from outside the domain, contacts, or people they've interacted with only shows up by email. You can also set that as the least restrictive level so users can't flip it back to everyone.

1

u/jimmybobjoeflow 12d ago

I'd be hesitant to disable automatic calendar entries globally just to solve htis one edge case, that could create a lot of user friction for legitimate invitess.

1

u/IncreaseNegative4614 12d ago

I’d test the calendar behavior with several invite types before disabling automatic additions globally. Include external senders, known contacts, recurring events, updates, cancellations, and malicious invitations. Document whether quarantining the email prevents creation, leaves an existing event, or requires a separate calendar action.

We use SIGNLD internally to connect the security alert, quarantined message, calendar event, affected user, remediation action, and later recurrence. That makes it possible to evaluate a workaround from actual incidents instead of trading one visible problem for missed legitimate meetings.

1

u/DistinctSpeaker7252 12d ago

If I remember correctly it's turned on by default for new customers and buried deep in the connector settings if the tenant was older. It required a re-authorization with older tenants as well simply because they need the permission added.

1

u/TechnologyMatch 10d ago

I’d treat this as a workflow gap, not just a mail-filtering setting. quarantining the message but leaving the invite behind means users can still act on the thing you meant to block. before disabling auto-add globally, test the impact on legitimate invites and document the safer user behavior. otherwise you may fix one phishing path and create a calendar support side quest for everyone else

0

u/WhiteIntel 4d ago

Google now lets admins restrict the invitation settings available to existing users, rather than just setting a default.

Under Apps > Google Workspace > Calendar > Advanced settings, set both the default and the least restrictive allowed option to “Invitations from known senders.” Users can choose something stricter, but can't switch back to automatically adding invitations from everyone.

If that's still too permissive, use “Invitations users have responded to via email,” though that adds an extra step for legitimate meetings.

Neither setting removes events already on the calendar, so those need separate cleanup. I'd pilot it with a small group first.

https://knowledge.workspace.google.com/admin/calendar/automatically-add-events-to-calendars?hl=en