Skip to content
All resources
Checklist

Google Workspace Security Checklist for Growing Businesses

A practical Google Workspace security checklist covering admin accounts, 2-Step Verification, Drive sharing, Gmail protection, third-party apps, devices and alerts.

Updated September 19, 20267 min readReviewed by Barry SinghGoogle Workspace security checklist

/ Guide map

Which Google Workspace security settings matter most?

How do you roll these changes out without disrupting staff?

How is this different from a Microsoft 365 security checklist?

Best for

Business owners and IT managers running Google Workspace

Decision support

Which Google Workspace security settings matter most?How do you roll these changes out without disrupting staff?How is this different from a Microsoft 365 security checklist?

Direct answer

A Google Workspace security checklist should cover admin accounts, sign-in protection, file sharing, email authentication, third-party app access, devices and monitoring. Start with five checks: 2-Step Verification enforced for everyone, separate super admin accounts protected with security keys, restricted default Drive sharing, SPF, DKIM and DMARC on your domain, and control over which third-party apps can reach your data.

Which Google Workspace security settings matter most?

Most Google Workspace incidents come from three places: a phished password on an account without 2-Step Verification, a file shared with "anyone with the link" that should never have been, and a third-party app granted broad access by one click. The settings below close those gaps first, then add the monitoring that tells you when something changes.

AreaWhat to setWhy it matters
Admin accountsSeparate super admin accounts used only for admin work, protected with security keysA phished super admin controls the whole tenant
Sign-inEnforce 2-Step Verification for everyone, with a short enrollment period for new startersStops password-only account takeover
Drive sharingDefault link sharing to restricted, and warn or block external sharing where neededMost leaks are sharing mistakes, not hacks
GmailSPF, DKIM (switched on in the Admin console) and DMARC moving from p=none to quarantine or rejectStops spoofing of your domain and flags phishing
Gmail safetyEnhanced pre-delivery scanning, plus attachment and link protectionsCatches malicious mail before users see it
Third-party appsRestrict unconfigured apps in API controls and review existing OAuth grantsRemoves over-permissioned and abandoned apps
DevicesEndpoint management with screen lock and remote wipe for phones and laptopsLost devices stop being data breaches
MonitoringAlert center rules, the security health page and regular login audit reviewsYou can only respond to what you can see

How do you roll these changes out without disrupting staff?

01

Admins first

Separate and lock down super admin accounts before touching anyone else's settings.

02

2-Step Verification with a deadline

Announce it, give staff an enrollment window with instructions, then enforce.

03

Tighten Drive sharing for new files

Change the defaults going forward, then review existing public links separately.

04

Email authentication in stages

Publish DMARC at p=none, read the reports, fix legitimate senders, then move to quarantine.

05

Review app access

Remove apps nobody uses and restrict new ones to an approved list.

06

Monthly review

Check alerts, admin changes and external sharing as part of the regular IT report.

How is this different from a Microsoft 365 security checklist?

The goals are the same and the controls have different names. Google Workspace uses 2-Step Verification where Microsoft 365 uses MFA through Conditional Access, organizational units where Microsoft relies on groups for policy, and API controls where Microsoft uses app consent policies. Many businesses run both platforms, so we secure them to one baseline and report on them together.

  • Separate, key-protected super admin accounts
  • 2-Step Verification enforced for every user
  • Restricted default Drive sharing
  • SPF, DKIM and DMARC on every sending domain
  • Third-party app access reviewed and restricted
  • Alerts reviewed as part of monthly reporting

Want your Google Workspace reviewed against this checklist?

We can check your settings, show you what's open, and fix the gaps without disrupting your team.

Get Free IT Assessment

/ Choose the next step

Move from guidance to a practical review path.

Pick the route that best matches the operational question behind this resource so the next conversation starts with the right scope.

Assessment path

Review the current tenant, migration, or cloud gap

Use the free assessment when you need a practical view of Microsoft 365, Google Workspace, Azure, SharePoint, Intune, backup, identity, or migration risk before work is scoped.

Use this when you want a clearer starting point before work is scoped.

Service path

See how cloud support is structured

Review the delivery model for Microsoft 365, cloud governance, migration planning, backup, identity controls, and operating handover.

Use this when you want a clearer starting point before work is scoped.

Team path

Share the migration or tenant requirement

If the priority already has internal pressure behind it, send the users, current tools, and timeline so the team can review the next step.

Use this when you want a clearer starting point before work is scoped.

Questions buyers ask

Is Google Workspace secure by default?

Partly. Google secures the platform itself, and many sensible settings are on by default, but several important ones are left to each business: enforcing 2-Step Verification, separating admin accounts, restricting external sharing, publishing DMARC and controlling third-party apps. Those are the settings attackers rely on being left open.

Does Google Workspace need a separate backup?

Usually, yes. Google keeps the service running, but recovering from accidental deletion, a malicious insider or a compromised account is your responsibility. Google Vault is a retention and eDiscovery tool, not a backup, so a dedicated backup with tested restores is the safer choice for business data.

Which Google Workspace edition do we need for these controls?

Most of this checklist works on every business edition, including 2-Step Verification, sharing controls, email authentication and app access controls. Some features, such as Vault, advanced endpoint management and context-aware access, depend on your edition, so we map the checklist to what you already pay for before recommending an upgrade.

Can BPro Technologies audit our Google Workspace?

Yes. We review your admin console against this checklist, report what's open with a priority for each finding, and can make the changes in stages so staff aren't locked out or surprised.