Google Workspace Control Walkthroughs

Step-by-step hardening guides for Google Workspace.

Progress is saved locally in your browser — no information is ever sent to our server.

compliance ↗

Tier 0 — do it today

Control Status Est. time
1 Enforce 2-Step Verification 30 min
2 Alert recipient hygiene + suspicious-login alerts 1 h
3 Government-backed attack alert routing 15 min
4 Email authentication (SPF/DKIM/DMARC) 1–2 h
5 Account inventory (incl. shared/service accounts) 2–4 h
6 Super-admin separation & minimal count 1 h

Tier 1 — the working baseline

Control Status Est. time
7 Phishing-resistant 2SV (FIDO2/passkeys only) 30 min
8 OAuth app access control / allowlisting 2–4 h
9 Marketplace install allowlist 1–2 h
10 Chrome managed-profile policy baseline 2–4 h
11 Legacy public-share inventory & cleanup 2–4 h
12 Web session-length control 15 min
13 Drive external-sharing restriction / trust rules 1–2 h
14 Basic Context-Aware Access (IP/geo) 2–4 h
15 Calendar external-sharing lockdown 15 min
16 Google Chat external containment 15 min
17 Disable user auto-forwarding & mailbox delegation 30 min
18 Residual mail & service hygiene 1 h
19 Break-glass admin + offline backup codes draft 2–4 h
20 Basic mobile device management draft 1 h
21 Leaver offboarding runbook draft 1–2 h

Tier 2 — hardening

Control Status Est. time
22 SSO/SAML to hardened IdP 1–2 days
23 Advanced Protection Program (high-risk users) 1 h
24 Native multi-party approval 30 min
25 Gmail Security Sandbox + safety-toggle verification 30 min
26 Data regions (storage) 15 min
27 Handling untrusted files at rendering distance 4–8 h
28 DLP rules (Drive/Gmail/Chat) 1–2 days
29 Device-trust CAA via MDM 3+ days
30 MTA-STS + TLS reporting 1–2 h
31 Shared-drive architecture 4–8 h
32 Vault retention & legal hold 2–4 h
33 Audit-log export to SIEM/BigQuery 4–8 h
34 Groups for Business exposure lockdown 30 min
35 Disable POP/IMAP / app-specific passwords draft 30 min

Tier 3 — high-assurance

Everything in this tier is in draft status — shown only as a preliminary direction we're considering.

Control Status Est. time
36 Disable Google Takeout draft
37 Witnessed ceremonies + tamper-evident custody draft
38 Split-custody break-glass draft
39 Continuous OAuth re-authorization sweeps draft
40 Cloud session control + admin re-auth draft
41 Directory minimization for targeted staff draft
42 Scripted JIT admin elevation draft
43 Periodic access recertification draft
44 Color-coded data domains (labels + IRM) draft
45 Hardware-key break-glass super-admin draft
46 Vault-account custody of crown jewels draft
47 Mandatory-absence review draft
48 Reading-room enclave (SCIF port, incl. data-copy minimization) draft
49 Deny-by-default IP/geo gating draft
50 CSE self-hosted / HYOK KACLS draft
51 Email gateway interception draft
52 Offline & desktop-sync data minimization draft 2–4 h
53 Privileged Access Workstation for admins draft 1–2 days

Tier 4 — the deep end

Everything in this tier is in draft status — shown only as a preliminary direction we're considering.

Control Status Est. time
54 Alert-pipeline heartbeat draft
55 Honeytoken credential file draft
56 Cloud Identity Free decoy accounts draft
57 Air-gapped recovery identity draft
58 Self-hosted canary corpus draft
59 Canary tokens via commercial console draft
60 WORM off-tenant log archive draft
61 Config-drift & persistence sentinel (incl. mail-routing watch) draft
62 Zero-standing-access delivery pattern draft
63 Audit-the-auditors alerting draft
64 Config-as-code with reconciliation draft
65 Travel-mode accounts draft
66 AI-agent / prompt-injection canary draft
67 Apps Script / add-on / AI-agent governance draft
68 Detection engineering on exported logs draft
69 Purple-team / adversary emulation draft
70 Multi-tenant compartmentalization draft
71 CSE with Google-partner KACLS draft 3+ days