Secure your workspace · Part 3 of 4 · 2 min read
Google Workspace: ten checks for your admin.
A focused checklist for account protection, app permissions, sharing, logs, and recovery in Google Workspace.
Ten checks to complete with your administrator.
Use this with the administrator responsible for your Google Workspace tenant. The boxes are a session checklist, not a security score or a saved audit. Record evidence, exceptions, owners, and dates in your team's own tracker.
Review 2-Step Verification enrollment and enforcement. Choose strong methods appropriate to the users, and prepare account recovery before enforcing a new policy.
Review super administrators and delegated roles. Use the minimum privileges needed and separate routine work from administrative activity.
Document who can recover an administrator account and how. Protect recovery methods, avoid reliance on one employee or device, and test the process safely.
Inspect third-party application access, OAuth scopes, and ownership. Restrict access where appropriate and provide a documented approval route for needed tools.
Review SPF, DKIM, and DMARC across all legitimate senders. Test and monitor changes so an enforcement policy does not unexpectedly block approved mail.
Inspect external sharing, link access, shared drives, and sensitive folders. Check existing files as well as defaults for new ones. Notify users about changed collaboration rules.
Identify managed and unmanaged devices, patch ownership, encryption expectations, and lost-device procedures. Confirm which controls your edition supports.
Check forwarding, delegation, routing rules, and recovery information. Investigate unfamiliar settings with the security owner.
Confirm available events, retention, administrator access, and alert delivery. Assign an investigator and verify that a test event can be found.
Use a test account and file to establish what an administrator can restore. Plan data transfer before deleting an employee account, and distinguish Vault retention from your recovery requirements.
Before changing a setting, verify its availability in your edition and test the effect on a small group. Document any exception and the person authorized to accept it.
References: Google's small-business security checklist · CISA ScubaGoggles. Use the provider's current instructions for your edition.
Edited September 29, 2026. Research and source dates are retained; this edit is not a fresh review of every statistic or legal development.
