
Google Workspace Security
Google secures the platform to a standard no small business could match. Everything that actually gets organisations breached sits on the other side of that line — and almost none of it is switched on by default.
Two-step verification left optional. Super-admin on one person's account. External sharing never configured. An app somebody authorised three years ago still holding access to your Drive. A departed employee's account still valid. None of these are Google failing — they are settings nobody chose.
What an unconfigured tenant looks like
- gpp_bad2-Step Verification optionalAvailable to everyone, required of nobody
- admin_panel_settingsOne super-admin accountUsed for daily work, no second holder
- shareExternal sharing wide openNever configured, so still at the default
- extensionOld app authorisations liveApprovals do not expire on their own
What Google secures, and what you secure
Most confusion about cloud security comes from not knowing where this boundary falls. Google's half is genuinely excellent and requires nothing from you. Your half requires a decision on every item, and defaults are rarely the right answer.
Google's side
Handled for you, and handled well
- check_circlePhysical and infrastructure security of the data centres
- check_circleEncryption of data in transit and at rest
- check_circlePlatform patching, availability and resilience
- check_circleSpam, phishing and malware filtering at the gateway
- check_circleAbuse detection across the wider service
Your side
Configuration, and almost nothing is on by default
- check_circleWhether two-step verification is enforced or merely available
- check_circleWho holds administrative access, and how much of it
- check_circleWhat can be shared outside the organisation, and by whom
- check_circleWhich third-party applications may reach your data
- check_circleWhat happens to an account when somebody leaves
- check_circleWhich devices are allowed to hold company mail
Six things every tenant should have, whatever the edition
None of these require a higher edition and all of them are configuration rather than purchase. Together they prevent most of what actually happens to businesses.
Two-step verification enforced, not offered
The single highest-value control, and the one most often left optional. Enforcement is set per organisational unit with an enrolment window, so people have time to set it up rather than being locked out on a Monday morning.
More than one admin, none of them daily drivers
Two to three people holding super-admin, using ordinary accounts for their actual work. One admin is a single point of failure; five is a widened attack surface. Nobody should be reading mail from an account that can also delete the organisation.
External sharing set deliberately
Open to anyone, restricted to allowlisted domains, or off. All three are legitimate — a design studio and a clinic need different answers. What is not legitimate is never having chosen, which is the default position for most tenants bought direct.
Third-party app access reviewed
The control almost nobody looks at. An OAuth prompt somebody approved two years ago may still have standing access to your Drive or mail. Restricting which applications can connect, and reviewing what already has, is an afternoon's work with disproportionate value.
A leaver process that actually exists
Suspend, transfer, archive, delete — in that order, written down. Dormant accounts nobody removed are both a licence you are paying for and a credential still valid for someone who no longer works there.
Audit logging that means something
Admin and login logs answer who did what and when. They are only useful if the organisational structure makes the answer legible, which is a decision taken at setup rather than a report you can generate afterwards.
The one control worth more than the rest combined
If you do nothing else on this page, do this. A stolen or guessed password is how most account compromises begin, and a second factor makes that password largely useless on its own. It is available on every edition, it costs nothing extra, and it is optional by default — which is why so many organisations have it available and nobody using it.
MFA, 2FA and 2-Step Verification are the same thing
Google calls it 2-Step Verification. Buyers, auditors and client questionnaires call it multi-factor authentication or two-factor. There is no difference in what you are being asked for, and a questionnaire asking whether MFA is enforced is asking about 2SV.
The enrolment window is the whole trick
Turning enforcement on without warning locks out everyone who has not enrolled, which in practice means the migration gets blamed and enforcement gets switched back off. An enrolment period with a communicated deadline avoids the entire problem.
Not all second factors are equal
A hardware security key is materially stronger than a code from an app, which is materially stronger than an SMS. For most businesses an authenticator app is the right balance; for admin accounts and anyone handling payments, keys are worth the cost and the mild inconvenience.
Plan the lockout before it happens
Lost phone, changed number, new device — this will occur, repeatedly. Backup codes issued in advance and an admin who can reset enrolment turn an hour of distress into two minutes. Without that, the pressure to weaken the policy becomes irresistible.
Which controls need a higher edition
The useful thing to notice is how much of the list is available everywhere. Six of these ten prevent most incidents, and none of them cost more than the licence you already hold.
| Control | What it does | Available |
|---|---|---|
| 2-Step Verification | A second factor beyond the password, enforceable per organisational unit. | All editions |
| Admin role separation | Delegated roles so routine tasks do not need super-admin. | All editions |
| External sharing controls | Who may share outside the organisation, and with which domains. | All editions |
| Third-party app access control | Which OAuth applications may connect to your data. | All editions |
| Audit and login logs | Who signed in, who changed what. Retention and depth vary by edition. | All editions, deeper higher up |
| Basic device management | Require a screen lock, wipe company data from a mobile device. | All editions |
| Advanced endpoint management | Stronger device policy, richer controls over what a device may do. | Higher editions |
| Vault — retention, search, hold | Retain, search and export across the organisation; hold data beyond deletion. | Higher editions |
| Context-aware access | Access conditional on device, location or security posture, not just password. | Higher editions |
| Data loss prevention | Rules that detect and block sensitive content leaving the organisation. | Higher editions |
Edition names, availability and what each tier includes are set by Google and revised from time to time, and Google's India price list does not display every edition. We confirm the current position with Google for your organisation rather than quoting from memory. How the editions are named and priced is covered on our pricing page.
The apps you connected and forgot
Every organisation has a list of third-party applications holding standing access to its mail and files, and almost none of them have looked at it. This is not an exotic threat — it is the ordinary consequence of people clicking Allow on a prompt that asked for more than it needed.
- warning
A prompt someone approved in 2022 can still hold access today — approvals do not expire on their own
- warning
The access granted is frequently broader than the task required, because nobody reads the scope list
- warning
A compromised third-party service inherits whatever access you granted it
- warning
Staff who have left may have connected personal tools that still hold organisational access
- warning
Restricting unverified apps, and reviewing what is already connected, costs an afternoon
The remedy is unglamorous: review what is connected, remove what is not in use, and restrict which applications may connect in future. It is available on every edition and takes an afternoon.

When an account has been compromised
The instinct is to change the password and consider it handled. That is the first step and the least sufficient one, because two things survive a password reset.
Assume the password is the smallest problem
Reset it, certainly, and immediately sign out active sessions — a password change alone does not end a session someone is already inside. Then revoke app tokens, because a granted OAuth connection survives a password reset.
Check what was changed, not just what was read
Forwarding rules and filters are what attackers set up first, because they outlive the intrusion. A rule quietly copying invoices to an external address is the one that turns a compromise into a loss.
Read the logs before drawing conclusions
Login and admin audit logs will show where and when access occurred and what was altered. Guessing from symptoms wastes the window in which you could still contain it.
Fix the cause, not the instance
An account compromised because 2SV was optional will be followed by another one. The remediation worth doing is the control that was missing, not just the cleanup.
If this is happening now rather than hypothetically, call rather than read. The number is +91 99467 89916.
Google Workspace security — common questions
helpIs Google Workspace secure?
expand_more
The platform is, and that is not really the question. Google handles infrastructure security, encryption, patching and gateway filtering to a standard no small business could match. What breaches organisations is almost always on the customer's side of the line: two-step verification left optional, super-admin on one person's account, external sharing never configured, third-party apps holding standing access, and dormant accounts nobody removed. Almost none of those are switched on by default, which means a tenant bought direct and never configured is running on Google's security with none of your own.
helpWhat is the difference between MFA and 2-Step Verification?
expand_more
None that matters. Google calls it 2-Step Verification; the rest of the industry, including most client security questionnaires and auditors, says multi-factor or two-factor authentication. If a questionnaire asks whether MFA is enforced across your organisation, it is asking whether you have 2-Step Verification enforced — and the honest answer for most unconfigured tenants is that it is available but not required, which is not the same thing.
helpHow do we enforce two-step verification without locking everyone out?
expand_more
With an enrolment period. Enforcement is set per organisational unit with a window during which people can enrol, and a communicated deadline. Turning it on without warning locks out everyone who has not set it up, which reliably results in enforcement being switched back off and nobody trying again for a year. Issue backup codes in advance and make sure an administrator can reset an individual's enrolment, because lost phones are a certainty rather than a risk.
helpWhich security features need a higher edition?
expand_more
The baseline that prevents most incidents — 2-Step Verification, admin role separation, sharing controls, third-party app restrictions, audit logs and basic device management — is available across the editions. What sits higher up is Vault for retention, search and legal hold; context-aware access, where access depends on device and location rather than password alone; data loss prevention; and stronger endpoint management. Edition availability and naming change from time to time, and Google's India price list does not show every edition, so we confirm the current position with Google rather than quoting from memory.
helpDo we need data loss prevention?
expand_more
Most businesses we work with do not, and we would rather say so than sell it. DLP sits in the higher editions and is genuinely valuable where a specific category of sensitive data must not leave — payment card details, health records, regulated client data. For a typical trading, retail or services business in Kerala it is an expensive answer to a problem that sharing controls and access discipline already handle. Where it is warranted, it is usually because a regulator or a client contract says so rather than because someone chose it.
helpWhat about third-party apps connected to our account?
expand_more
This is the control almost nobody reviews, and it is worth an afternoon. Every OAuth prompt somebody approved is standing access that does not expire on its own, the scope granted is usually broader than the task needed, and a compromised third-party service inherits whatever you gave it. You can restrict which applications may connect and review what already has. Staff who left years ago may still have personal tools holding organisational access.
helpCan we control which devices access company email?
expand_more
Yes, and the depth depends on your edition. Basic device management — requiring a screen lock and being able to wipe company data from a mobile device — is broadly available. Stronger endpoint policy sits in higher editions. What matters more than the feature is the decision behind it: whether personal phones may hold company mail at all, and what you are permitted to do to that device if it is lost. That should be agreed in writing before it is configured, because the difference between wiping a device and wiping an account matters a great deal to the person holding the phone.
helpSomeone's account has been compromised. What now?
expand_more
Reset the password and sign out active sessions — a password change alone does not end a session the attacker is already inside. Revoke third-party app tokens, because a granted OAuth connection survives a password reset. Then check for forwarding rules and filters, which is what attackers set up first because they outlive the intrusion; a rule quietly copying invoices to an outside address is how a compromise becomes a financial loss. Read the login and admin audit logs before drawing conclusions. Finally, fix the control that was missing rather than only the instance.
helpDoes this cover email authentication like SPF and DMARC?
expand_more
Those are covered separately on our Google Workspace email security page, because they solve a different problem. The controls on this page protect your organisation's accounts and data from unauthorised access. SPF, DKIM and DMARC protect your domain from being impersonated to other people — they stop a forged message that looks like it came from you reaching your customer. Both matter; they are not substitutes. We configure domain authentication as part of any implementation or migration.
Related pages
Google Workspace Implementation
Where the security baseline is actually applied — structure, policy and rollout.
Google Workspace Support
What breaks, and who to call when something looks wrong.
Google Workspace Email Security
The outward-facing half — SPF, DKIM and DMARC, and getting to enforcement.
Google Workspace Pricing in India
Which requirements decide the edition, and what each costs in INR.
Have your security posture reviewed
We will go through what is actually configured in your tenant — enforcement, admin roles, sharing, connected applications, dormant accounts — and tell you what is worth changing and what is already fine. Most of what we find costs nothing to fix.
- check_circle
The baseline applied without waiting for a higher edition
- check_circle
Two-step verification enforced with a workable enrolment window
- check_circle
Connected third-party apps reviewed and restricted
- check_circle
A written leaver process, so dormant accounts stop accumulating
We harden tenants for businesses across Kerala and the rest of India. Or call +91 99467 89916 or email admin@techgeum.com.