Reviewing Google Workspace security settings
Google Partner · Authorized Reseller

Google Workspace Security

Google secures the platform to a standard no small business could match. Everything that actually gets organisations breached sits on the other side of that line — and almost none of it is switched on by default.

Two-step verification left optional. Super-admin on one person's account. External sharing never configured. An app somebody authorised three years ago still holding access to your Drive. A departed employee's account still valid. None of these are Google failing — they are settings nobody chose.

What an unconfigured tenant looks like

  • gpp_bad2-Step Verification optionalAvailable to everyone, required of nobody
  • admin_panel_settingsOne super-admin accountUsed for daily work, no second holder
  • shareExternal sharing wide openNever configured, so still at the default
  • extensionOld app authorisations liveApprovals do not expire on their own
Where the line sits

What Google secures, and what you secure

Most confusion about cloud security comes from not knowing where this boundary falls. Google's half is genuinely excellent and requires nothing from you. Your half requires a decision on every item, and defaults are rarely the right answer.

cloud_done

Google's side

Handled for you, and handled well

  • check_circlePhysical and infrastructure security of the data centres
  • check_circleEncryption of data in transit and at rest
  • check_circlePlatform patching, availability and resilience
  • check_circleSpam, phishing and malware filtering at the gateway
  • check_circleAbuse detection across the wider service
admin_panel_settings

Your side

Configuration, and almost nothing is on by default

  • check_circleWhether two-step verification is enforced or merely available
  • check_circleWho holds administrative access, and how much of it
  • check_circleWhat can be shared outside the organisation, and by whom
  • check_circleWhich third-party applications may reach your data
  • check_circleWhat happens to an account when somebody leaves
  • check_circleWhich devices are allowed to hold company mail
The baseline

Six things every tenant should have, whatever the edition

None of these require a higher edition and all of them are configuration rather than purchase. Together they prevent most of what actually happens to businesses.

verified_user

Two-step verification enforced, not offered

The single highest-value control, and the one most often left optional. Enforcement is set per organisational unit with an enrolment window, so people have time to set it up rather than being locked out on a Monday morning.

admin_panel_settings

More than one admin, none of them daily drivers

Two to three people holding super-admin, using ordinary accounts for their actual work. One admin is a single point of failure; five is a widened attack surface. Nobody should be reading mail from an account that can also delete the organisation.

share

External sharing set deliberately

Open to anyone, restricted to allowlisted domains, or off. All three are legitimate — a design studio and a clinic need different answers. What is not legitimate is never having chosen, which is the default position for most tenants bought direct.

extension

Third-party app access reviewed

The control almost nobody looks at. An OAuth prompt somebody approved two years ago may still have standing access to your Drive or mail. Restricting which applications can connect, and reviewing what already has, is an afternoon's work with disproportionate value.

person_off

A leaver process that actually exists

Suspend, transfer, archive, delete — in that order, written down. Dormant accounts nobody removed are both a licence you are paying for and a credential still valid for someone who no longer works there.

history

Audit logging that means something

Admin and login logs answer who did what and when. They are only useful if the organisational structure makes the answer legible, which is a decision taken at setup rather than a report you can generate afterwards.

Two-step verification

The one control worth more than the rest combined

If you do nothing else on this page, do this. A stolen or guessed password is how most account compromises begin, and a second factor makes that password largely useless on its own. It is available on every edition, it costs nothing extra, and it is optional by default — which is why so many organisations have it available and nobody using it.

balance

MFA, 2FA and 2-Step Verification are the same thing

Google calls it 2-Step Verification. Buyers, auditors and client questionnaires call it multi-factor authentication or two-factor. There is no difference in what you are being asked for, and a questionnaire asking whether MFA is enforced is asking about 2SV.

schedule

The enrolment window is the whole trick

Turning enforcement on without warning locks out everyone who has not enrolled, which in practice means the migration gets blamed and enforcement gets switched back off. An enrolment period with a communicated deadline avoids the entire problem.

key

Not all second factors are equal

A hardware security key is materially stronger than a code from an app, which is materially stronger than an SMS. For most businesses an authenticator app is the right balance; for admin accounts and anyone handling payments, keys are worth the cost and the mild inconvenience.

restart_alt

Plan the lockout before it happens

Lost phone, changed number, new device — this will occur, repeatedly. Backup codes issued in advance and an admin who can reset enrolment turn an hour of distress into two minutes. Without that, the pressure to weaken the policy becomes irresistible.

What sits where

Which controls need a higher edition

The useful thing to notice is how much of the list is available everywhere. Six of these ten prevent most incidents, and none of them cost more than the licence you already hold.

ControlWhat it doesAvailable
2-Step VerificationA second factor beyond the password, enforceable per organisational unit.All editions
Admin role separationDelegated roles so routine tasks do not need super-admin.All editions
External sharing controlsWho may share outside the organisation, and with which domains.All editions
Third-party app access controlWhich OAuth applications may connect to your data.All editions
Audit and login logsWho signed in, who changed what. Retention and depth vary by edition.All editions, deeper higher up
Basic device managementRequire a screen lock, wipe company data from a mobile device.All editions
Advanced endpoint managementStronger device policy, richer controls over what a device may do.Higher editions
Vault — retention, search, holdRetain, search and export across the organisation; hold data beyond deletion.Higher editions
Context-aware accessAccess conditional on device, location or security posture, not just password.Higher editions
Data loss preventionRules that detect and block sensitive content leaving the organisation.Higher editions
info

Edition names, availability and what each tier includes are set by Google and revised from time to time, and Google's India price list does not display every edition. We confirm the current position with Google for your organisation rather than quoting from memory. How the editions are named and priced is covered on our pricing page.

The overlooked one

The apps you connected and forgot

Every organisation has a list of third-party applications holding standing access to its mail and files, and almost none of them have looked at it. This is not an exotic threat — it is the ordinary consequence of people clicking Allow on a prompt that asked for more than it needed.

  • warning

    A prompt someone approved in 2022 can still hold access today — approvals do not expire on their own

  • warning

    The access granted is frequently broader than the task required, because nobody reads the scope list

  • warning

    A compromised third-party service inherits whatever access you granted it

  • warning

    Staff who have left may have connected personal tools that still hold organisational access

  • warning

    Restricting unverified apps, and reviewing what is already connected, costs an afternoon

The remedy is unglamorous: review what is connected, remove what is not in use, and restrict which applications may connect in future. It is available on every edition and takes an afternoon.

Reviewing connected applications in the Google Workspace admin console
If it has already happened

When an account has been compromised

The instinct is to change the password and consider it handled. That is the first step and the least sufficient one, because two things survive a password reset.

crisis_alert

Assume the password is the smallest problem

Reset it, certainly, and immediately sign out active sessions — a password change alone does not end a session someone is already inside. Then revoke app tokens, because a granted OAuth connection survives a password reset.

search_check

Check what was changed, not just what was read

Forwarding rules and filters are what attackers set up first, because they outlive the intrusion. A rule quietly copying invoices to an external address is the one that turns a compromise into a loss.

fact_check

Read the logs before drawing conclusions

Login and admin audit logs will show where and when access occurred and what was altered. Guessing from symptoms wastes the window in which you could still contain it.

policy

Fix the cause, not the instance

An account compromised because 2SV was optional will be followed by another one. The remediation worth doing is the control that was missing, not just the cleanup.

If this is happening now rather than hypothetically, call rather than read. The number is +91 99467 89916.

Google Workspace security — common questions

help

Is Google Workspace secure?

expand_more

The platform is, and that is not really the question. Google handles infrastructure security, encryption, patching and gateway filtering to a standard no small business could match. What breaches organisations is almost always on the customer's side of the line: two-step verification left optional, super-admin on one person's account, external sharing never configured, third-party apps holding standing access, and dormant accounts nobody removed. Almost none of those are switched on by default, which means a tenant bought direct and never configured is running on Google's security with none of your own.

help

What is the difference between MFA and 2-Step Verification?

expand_more

None that matters. Google calls it 2-Step Verification; the rest of the industry, including most client security questionnaires and auditors, says multi-factor or two-factor authentication. If a questionnaire asks whether MFA is enforced across your organisation, it is asking whether you have 2-Step Verification enforced — and the honest answer for most unconfigured tenants is that it is available but not required, which is not the same thing.

help

How do we enforce two-step verification without locking everyone out?

expand_more

With an enrolment period. Enforcement is set per organisational unit with a window during which people can enrol, and a communicated deadline. Turning it on without warning locks out everyone who has not set it up, which reliably results in enforcement being switched back off and nobody trying again for a year. Issue backup codes in advance and make sure an administrator can reset an individual's enrolment, because lost phones are a certainty rather than a risk.

help

Which security features need a higher edition?

expand_more

The baseline that prevents most incidents — 2-Step Verification, admin role separation, sharing controls, third-party app restrictions, audit logs and basic device management — is available across the editions. What sits higher up is Vault for retention, search and legal hold; context-aware access, where access depends on device and location rather than password alone; data loss prevention; and stronger endpoint management. Edition availability and naming change from time to time, and Google's India price list does not show every edition, so we confirm the current position with Google rather than quoting from memory.

help

Do we need data loss prevention?

expand_more

Most businesses we work with do not, and we would rather say so than sell it. DLP sits in the higher editions and is genuinely valuable where a specific category of sensitive data must not leave — payment card details, health records, regulated client data. For a typical trading, retail or services business in Kerala it is an expensive answer to a problem that sharing controls and access discipline already handle. Where it is warranted, it is usually because a regulator or a client contract says so rather than because someone chose it.

help

What about third-party apps connected to our account?

expand_more

This is the control almost nobody reviews, and it is worth an afternoon. Every OAuth prompt somebody approved is standing access that does not expire on its own, the scope granted is usually broader than the task needed, and a compromised third-party service inherits whatever you gave it. You can restrict which applications may connect and review what already has. Staff who left years ago may still have personal tools holding organisational access.

help

Can we control which devices access company email?

expand_more

Yes, and the depth depends on your edition. Basic device management — requiring a screen lock and being able to wipe company data from a mobile device — is broadly available. Stronger endpoint policy sits in higher editions. What matters more than the feature is the decision behind it: whether personal phones may hold company mail at all, and what you are permitted to do to that device if it is lost. That should be agreed in writing before it is configured, because the difference between wiping a device and wiping an account matters a great deal to the person holding the phone.

help

Someone's account has been compromised. What now?

expand_more

Reset the password and sign out active sessions — a password change alone does not end a session the attacker is already inside. Revoke third-party app tokens, because a granted OAuth connection survives a password reset. Then check for forwarding rules and filters, which is what attackers set up first because they outlive the intrusion; a rule quietly copying invoices to an outside address is how a compromise becomes a financial loss. Read the login and admin audit logs before drawing conclusions. Finally, fix the control that was missing rather than only the instance.

help

Does this cover email authentication like SPF and DMARC?

expand_more

Those are covered separately on our Google Workspace email security page, because they solve a different problem. The controls on this page protect your organisation's accounts and data from unauthorised access. SPF, DKIM and DMARC protect your domain from being impersonated to other people — they stop a forged message that looks like it came from you reaching your customer. Both matter; they are not substitutes. We configure domain authentication as part of any implementation or migration.

Have your security posture reviewed

We will go through what is actually configured in your tenant — enforcement, admin roles, sharing, connected applications, dormant accounts — and tell you what is worth changing and what is already fine. Most of what we find costs nothing to fix.

  • check_circle

    The baseline applied without waiting for a higher edition

  • check_circle

    Two-step verification enforced with a workable enrolment window

  • check_circle

    Connected third-party apps reviewed and restricted

  • check_circle

    A written leaver process, so dormant accounts stop accumulating

We harden tenants for businesses across Kerala and the rest of India. Or call +91 99467 89916 or email admin@techgeum.com.

call