Key security settings
The most important security settings to configure in your Google Workspace Admin console — protecting your organization's accounts, data, and email.
- Difficulty
- Intermediate
- You’ll need
- Admin access
As a Google Workspace admin, you have access to powerful security controls that protect your entire organization. This guide covers the settings you should check and configure — ideally as soon as your Workspace is set up.
Quick summary
The most important security actions: enforce 2-step verification, set a strong password policy, review which third-party apps have access, watch the Alert center, and turn on Gmail's spam and phishing protections. Most of these live under Security in the Admin console at admin.google.com. The Gmail and Drive settings live under Apps → Google Workspace instead.
What you'll need
- Admin access to admin.google.com
- About 20–30 minutes to review and configure each section
1. Enforce 2-step verification
This is the single most impactful security measure. See Turning on 2-step verification for the full steps.
Where to find it: Admin console → Security → Authentication → 2-step verification.
What to do: Tick Allow users to turn on 2-Step Verification, then set Enforcement to On, or to Turn on enforcement from date if you want to give people a run-up. Google's note is that a chosen start date takes effect within 24 to 48 hours, so use the plain On option if you need an exact moment.
There is a separate New user enrollment period setting for people who join later. You choose the length yourself, anywhere from 1 day to 6 months. A week is a sensible starting point, but it is your choice, not a Google default.
Google is making 2-step verification compulsory for admins
Google has started requiring 2-step verification on administrator accounts, and says the rollout will continue gradually over the coming years. Super admins get roughly 90 days' notice and other admins about 60. After the deadline, an admin who still hasn't enrolled loses access to Workspace mobile apps at 15 days and web apps at 30 days. Admins covered by this policy can't opt out — the only way around it is to remove their admin role. Enrol your admins before Google gets there.
2. Set a strong password policy
Go to Admin console → Security → Authentication → Password management.
In the Strength section, tick "Enforce strong password." Google scores the password for randomness and checks it against common and known-breached passwords. It does not require a set number of capitals, numbers or symbols — length and unpredictability are what count.
In the Length section, set a minimum and maximum. Google accepts anything in the 8 to 100 character range. We recommend a minimum of at least 16 characters, matching the guidance in How to create strong passwords.
Leave "Allow password reuse" unchecked so people can't go back to an old password. Google doesn't let you choose how far back its reuse check looks.
Click Save.
Don't set passwords to expire on a schedule
Google turns password expiry off by default, and says so in its own documentation: research has shown little positive impact on security. Only switch it on if a compliance rule makes you.
3. Review login and activity alerts
Set up alerts so you know when something unusual happens.
Where to find it: Admin console → Security → Alert center. There's also a bell icon at the top of any Admin console page.
Alerts worth paying attention to include:
- Leaked password — Google has detected compromised credentials and will force a reset
- Suspicious login — a sign-in that looks like it wasn't the account holder
- User suspended — Google has suspended an account it believes is compromised
- Admin password reset — a password was reset on an admin or super admin account
- Government-backed attacks — Google believes a state-backed attacker targeted an account
Make sure alert emails go to an address you regularly check.
4. Audit third-party app access
Apps connected to Google Workspace can read email, access Drive files, and more. Review what's connected.
Where to find it: Admin console → Security → Access and data control → API controls. The app lists sit under App access control — click Manage App Access.
Review the lists of apps. Google splits them three ways: Configured apps (ones you've already given an access setting), Accessed apps (ones that have actually reached Google data) and Apps pending review (ones people have asked for). Look for anything you don't recognize.
Point to an app and click View details to see the access level it has and the exact Google data scopes configured for it.
Set anything you don't need to Blocked. A blocked app can't reach any Google data. The other settings are Trusted, Limited and Specific Google data.
Unrecognized apps can mean a security breach
If you see an app that no one in your team installed or recognizes, it may have been authorized by a compromised account. Block it and investigate.
5. Configure Gmail's spam, phishing and malware settings
Google already filters most spam, but these admin settings add extra layers. They sit in two different places.
Spam, Phishing and Malware: Admin console → Apps → Google Workspace → Gmail → Spam, Phishing and Malware.
- Enhanced pre-delivery message scanning — when Gmail spots something suspicious, it holds the message back briefly for extra checks before delivering it. Tick the box to turn it on.
Safety: Admin console → Apps → Google Workspace → Gmail → Safety. This is where Google's advanced phishing and malware protections live, in three groups:
- Attachments — protection against encrypted attachments, attachments carrying scripts, and file types that are unusual for your domain
- Links and external images — unmasks shortened URLs, scans linked images, and warns people before they open a link to an untrusted domain
- Spoofing and authentication — covers look-alike domain names, emails using one of your own staff names, messages pretending to come from your domain, and unauthenticated mail generally
For the attachment and spoofing settings you also pick what Gmail does with a suspect message: keep it in the inbox with a warning (the default), move it to spam, or quarantine it for an admin to review. The links and images settings are simple on/off boxes.
6. Manage data sharing settings for Drive
Control who can share files outside your organization.
Where to find it: Admin console → Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options.
- External sharing — switch it On or Off. With it On, you get further options to limit sharing, such as warning people before they share externally or blocking link sharing. You can also restrict sharing to an allowlist of trusted domains.
- External warning indicator — on by default. A shared drive or file that is owned by, or shared with, someone outside your organization is flagged, which helps catch accidental sharing. You can turn it off, but there's rarely a good reason to.
Google notes that sharing changes can take up to 24 hours to take effect, and that old and new settings may both apply during that window.
7. Review admin roles
Only people who genuinely need admin access should have it.
Where to find it: Admin console → Directory → Users → click the person → Admin roles and privileges.
- Review who holds the Super Admin role. Google's own advice is to have at least two, so one can reset the other's password, but it shouldn't be everyone.
- Consider using one of the narrower prebuilt roles — Help Desk Admin, User Management Admin, Groups Admin and so on — for people who only need to reset passwords or manage specific users.
8. Check your recovery information
Make sure admin accounts have a recovery phone number and email address on file.
Where to find it: Admin console → Directory → Users → click the person → Security → Recovery information. Enter a recovery email address and phone number, then Save.
Use an email address that person can actually sign in to and that isn't their Workspace address, and a mobile number that only they use. This is what lets you recover access if an admin account is ever locked out. If you'd rather let people do their own resets, the setting is at Security → Authentication → Account recovery.
Common questions
How do I know if any accounts have been compromised?
Go to Admin console → Reporting → Audit and investigation → User log events. (This is the report that used to be called the login audit log.) Look for logins from unusual locations, at unusual times, or from new devices. Google will also often flag suspicious activity automatically in the Alert center.
What is Google Vault and do I need it?
Google Vault is Google's information governance and eDiscovery tool. It lets you retain, hold, search, and export Workspace data. Google is explicit that it is not a data archive, and it isn't a backup either: once a retention rule expires, deleted data that isn't on hold can be purged for good.
A Vault licence is included with Business Plus, Frontline Standard and Plus, Enterprise Standard and Plus, all Education editions, Enterprise Essentials and Enterprise Essentials Plus (domain-verified only), and G Suite Business. It is not included with Business Starter or Business Standard. Since 1 November 2025, an admin also needs a Vault licence of their own to use Vault at all. If you're in a regulated industry, ask your legal advisor whether you need it.
Can I restrict which countries users can sign in from?
Google's feature for this is Context-Aware Access, which controls access using things like location, IP address and device security status. The catch is the edition: it isn't included with any Business plan. Google lists it for Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus, and Cloud Identity Premium. On a Business edition, the policy simply won't apply to your users. Ask us if you want to talk through whether an upgrade is worth it.
Related guides
- Turning on 2-step verification
- The Google Admin console, explained
- Recovering a deleted user or files
Need a hand?
Learn more
Last updated
Turning on 2-step verification
How to enable 2-step verification (2FA) for your Google Workspace account — the most important step you can take to protect your business email and files.
Managing company devices (overview)
An overview of Google Workspace's mobile device management (MDM) tools — how to enforce security policies on phones and computers used to access company data.