CEO administers it. His philosophy on security is quite a bit tighter than mine generally is. But, I respect that...
LOL there’s problem number one right there... he simply read that Google thinks it’s insecure and went with it. He needs professional IT security help, but probably can’t afford it.
I’m sure he’d tell you all about what the security hole is for Mail.App to be allowed to third party auth, too. Hahaha. And I’m not saying that in a nice way.
Mac Mail.App doesn’t require IMAP and does Google’s own “they claim it’s better” auth mechanism these days, so he must have blocked that auth mechanism.
Jussssst as a check though, have you opened up Keychain and deleted anything Google related for that account? It could be your Mac got caught with one of a couple of bugs in past updates doing Google Auth and the only way to get it to behave again after that is dumping the keychain stuff so it will start over.
Have to do that while Mail is shut down and also log into accounts.google.com and go to the Security menu and revoke any “Third Party Apps with Account Access” associated with your Mac.
Ahhh. I bet that’s what he turned off. No third party apps allowed to auth. So in fact, check that first. If your Mac isn’t in there, no point in fixing the keychain. He’s disallowed it there.
It’s interesting that he left the old ActiveSync interface allowed if he’s that security “aware”. Gag. He probably doesn’t know he did. Forgot it’s a grandfathered thing for GSuite users only since MSFT makes Google pay a licensing fee to use it. Which is what got it killed for all free GMail accounts. Google wasn’t about to pay for all of those licenses. Ha. That or he’s got Outlook addicts he can’t fix. Hahahaha.
As I recall, Google does need more granularity there. With all of these websites saying “log in with Google!” I could see some problems arising from morons using their company GSuite accounts to auth to websites like that and then being all ****y if they got fired and lost the account. But really, that’s on them. Pick the right Google account. Ha.
I’ll have to look and see if they give the admin a way to see what third party apps authenticated via Google and kill individual ones. Now you have me curious. They didn’t used to. Been a while since I looked.
We leverage the crap out of Google auth. Primary auth whenever possible is AD. AD is synced to GSuite. We don’t have to even log into GSuite Admin to add or dump a user. It’s just reading an OU. From there if some system doesn’t allow AD sync, we just tie it to Google auth.
If you get fired, all I have to do for 90% of our systems is just disable you in AD. It propagates to Google and a couple other things and you’re gone. All the important stuff. VPN access, mobile access, logins to nearly everything. Toast. It’ll even toss you off the network or VPN in real time.
Well anyway. For the most part the Gmail web interface is usually very adequate to use on a Mac running Chrome. Safari? Meh. Not so great. Firefox is also decent. But there’s a couple of things Mail.App does better that we wouldn’t block it for those reasons. If Mail.App auth to Google gets compromised, so does the Google web interface. Same mechanism.