SyncTrix logoSyncTrix
All articles
Security10 min read

Google Workspace security defaults worth changing

The out-of-box configuration optimises for nothing breaking, not for your data staying put. Six settings that matter, and what each one prevents.

By Marcus Hale
Google Workspace security defaults worth changing

Google Workspace ships configured so that nothing blocks a new customer on day one. That is a reasonable default for Google and a poor one for you, because every permissive setting is a decision deferred rather than a decision made. These are the settings that matter most, roughly in the order worth doing them.

01Enforce two-step verification, do not just enable it

Turning 2FA on makes it available. Enforcing it makes it mandatory, and the gap between those two states is where account compromise happens. An organisation that 'has 2FA' but has not enforced it typically has a third of accounts unprotected, and those are disproportionately the long-tenured accounts with the most access.

Enforce with a grace period so people can enrol, then let it close. Security keys are the strongest factor and are worth mandating for admin accounts specifically, since those are the accounts an attacker actually wants.

02Separate admin accounts from daily accounts

A super-admin who reads mail and browses the web from the same account has merged their highest-privilege credential with their largest attack surface. The convention that solves this is boring and effective: named admin accounts used only for administration, with ordinary accounts for daily work.

Keep at least two super-admins so you cannot lock yourself out, and no more than a handful. Everything else should be a delegated role scoped to what that person actually administers - help desk, groups, mobile devices - rather than full super-admin because it was quicker to grant.

03Decide your external sharing policy deliberately

Drive defaults allow sharing outside the organisation, including link sharing. For many businesses that is genuinely correct - it is how you work with clients. The mistake is not the permissiveness itself, it is never having made the decision.

The middle position most organisations want is external sharing allowed, but with warnings on external recipients, link sharing restricted to specific people rather than anyone-with-the-link, and an allowlist for trusted partner domains where the traffic is routine.

PostureExternal sharingSuits
OpenAnyone with linkRarely appropriate
WarnedAllowed, with promptsMost businesses
AllowlistedTrusted domains onlyRegulated or client-sensitive work
ClosedInternal onlyHandling restricted data
Sharing postures and who they suit

04Set retention before you need it

Without a retention policy, deleted mail is gone at the end of the standard purge window and nothing brings it back. With one, you decide how long messages and files are recoverable regardless of what a user deletes - which is what a legal hold or an investigation actually depends on.

This is worth doing early because retention only applies going forward. A policy configured the week you need it does not recover the message that was deleted last month, which is invariably the message in question.

05Restrict third-party app access

Any user can, by default, grant a third-party application access to their Drive and Gmail via OAuth. That is a data exfiltration path that requires no credential theft at all - just a convincing application and one employee clicking through a consent screen.

Move to a model where apps accessing sensitive scopes must be explicitly trusted, and review the list of what is already authorised. Most organisations doing this for the first time find several applications nobody remembers approving, and at least one that is no longer in use but still holds access.

06Turn on DLP if you have Enterprise

Data loss prevention is an Enterprise-tier feature, and if you are paying for that tier it is worth the configuration effort. Rules that detect card numbers, national identifiers or your own document classifications can warn, block or quarantine before the data leaves.

Start in audit-only mode. DLP rules written from a policy document rather than from observed traffic generate false positives at a rate that destroys their credibility, and a rule everyone has learned to click past protects nothing.

07Review the audit logs you already have

Workspace logs admin actions, login attempts, Drive access and mail routing by default. The value is not in having them - it is in someone looking. Set up alerts for the handful of events that genuinely matter: super-admin role grants, changes to 2FA enforcement, mass downloads from Drive, and modifications to mail routing or forwarding rules.

Domain-wide forwarding rules deserve particular attention. A rule quietly forwarding a finance mailbox to an external address is one of the oldest and most effective techniques there is, and it is invisible unless you are watching for it.

Topics

google workspace security settingsworkspace admin console securitygoogle workspace 2fa enforcementworkspace external sharing policygoogle workspace dlpworkspace admin best practices

Marcus Hale

Security Lead · SyncTrix

Writes about the engineering decisions behind production systems - architecture, delivery and the trade-offs that only show up at scale.

Building something like this?

SyncTrix engineers AI, SaaS, platform and cloud systems for enterprises and high-growth teams. Tell us what you're shipping and we'll scope it with you.