Google Workspace: essential admin console settings
Security and management settings to configure from day one of your Google Workspace deployment to protect your business.
Updated on 14 May 2024
Secure Google Workspace from day one
The Google Workspace admin console is the control center for your cloud environment. The default settings offer a reasonable level of security, but several essential settings must be adjusted from deployment to protect your data and your users. This guide covers the priority configurations every administrator should put in place.
Authentication and access
Two-factor authentication (2FA) is the first measure to enable. Go to Security > Authentication > 2-Step Verification and enforce 2FA for all users. Allow a grace period of 1 to 2 weeks so everyone can set up their second factor (authenticator app, security key or push notification).
Super-administrator accounts must use physical security keys (FIDO2) as their second factor. These keys offer the strongest protection against phishing. Limit the number of super-administrators to 2-3 people and create delegated roles for routine tasks.
Configure password policies: minimum length of 12 characters, blocking of compromised passwords and optional expiration. Google Workspace automatically checks passwords against known breach databases.
File sharing and data
External file sharing is one of the most common risks. In Apps > Google Workspace > Drive and Docs > Sharing settings, configure the external sharing rules. You can allow external sharing only with trusted domains or require approval for each external share.
Enable external sharing warnings. When a user shares a file with an external address, Google displays a warning that asks for confirmation. This friction reduces accidental shares.
Shared Drives belong to the organization rather than an individual. Use them for team and project files. When an employee leaves the company, the files remain accessible without intervention.
Applications and devices
Control which third-party applications can access Google Workspace data. In Security > API Controls > Third-party apps, block unapproved applications and create an allowlist of authorized applications. This measure prevents malicious applications from accessing your users’ emails and files.
Mobile device management (MDM) protects company data on smartphones. Enable basic mobile device management to enforce a screen lock and allow remote wipe in case of loss or theft.
Alerts and monitoring
Enable the predefined security alerts in Security > Alert center. The essential alerts include suspicious sign-ins, detected phishing attempts, administrator setting changes and external sharing of sensitive files.
The audit log records all administrative actions and user activity. Review it regularly to detect abnormal behavior. Security reports in the admin console provide an overview of your organization’s security posture.
LCMH, a Google Workspace reseller in Alsace, configures the admin console according to security best practices for SMBs.
For more on security, read our article on data protection in Google Workspace.
Sources
- Google, Google Workspace Admin Help. support.google.com/a
- Google, Security Best Practices. support.google.com/a/answer/7587183
- Google, 2-Step Verification. support.google.com/a/answer/175197
Frequently asked questions
- Who should have access to the admin console?
- Limit super-administrator access to 2-3 people at most. Create delegated administrator roles for routine tasks (user management, support). Every super-administrator must have 2FA enabled with a physical security key.
- Should you enable 2FA for all users?
- Yes, it is the most important security measure. Google Workspace lets you enforce 2FA for all users from the admin console. Allow a grace period of 1 to 2 weeks so everyone can set up their second factor.
- How do you monitor suspicious activity?
- The admin console offers predefined security alerts: suspicious sign-in, phishing attempt, external sharing of sensitive files. Enable these alerts and configure email notifications for administrators.
Related Articles
Google Drive: security best practices for SMBs
How to secure your Google Drive files in business: permissions, external sharing, DLP and organization best practices.
Temporary Admin Roles in Google Workspace: What Changes
Google Workspace can now assign an admin role with an expiration date. How it works, which editions get it, its limits, and how to roll it out.
Google Workspace Backup: why and how to back up your cloud data
Google Workspace does not back up your data for you. Why a backup strategy is essential and what solutions exist.
Securing your business data with Google Workspace
How Google Workspace protects your business data: encryption, authentication, GDPR compliance and security best practices.
Workspace Client-Side Encryption: the Simple Setup
Google adds a simplified setup for Workspace client-side encryption. What changes, which editions qualify, the real cost, and what it does not solve.
Google Workspace: keep your data in Europe with data regions
How to configure Google Workspace data regions to store your data in Europe and meet digital sovereignty requirements.