Google Workspace Control Walkthroughs
Step-by-step hardening guides for Google Workspace.
Progress is saved locally in your browser — no information is ever sent to our server.
Tier 0 — do it today
| Control | Status | Est. time |
|---|---|---|
| 1 Enforce 2-Step Verification | 30 min | |
| 2 Alert recipient hygiene + suspicious-login alerts | 1 h | |
| 3 Government-backed attack alert routing | 15 min | |
| 4 Email authentication (SPF/DKIM/DMARC) | 1–2 h | |
| 5 Account inventory (incl. shared/service accounts) | 2–4 h | |
| 6 Super-admin separation & minimal count | 1 h |
Tier 1 — the working baseline
1 7 Phishing-resistant 2SV (FIDO2/passkeys only) 1 8 OAuth app access control / allowlisting 1 9 Marketplace install allowlist 1 10 Chrome managed-profile policy baseline 1 11 Legacy public-share inventory & cleanup 1 12 Web session-length control 1 13 Drive external-sharing restriction / trust rules 1 14 Basic Context-Aware Access (IP/geo) 1 15 Calendar external-sharing lockdown 1 16 Google Chat external containment 1 17 Disable user auto-forwarding & mailbox delegation 1 18 Residual mail & service hygiene 1 19 Break-glass admin + offline backup codes
draft
1 20 Basic mobile device management
draft
1 21 Leaver offboarding runbook
draft
Tier 2 — hardening
| Control | Status | Est. time |
|---|---|---|
| 22 SSO/SAML to hardened IdP | 1–2 days | |
| 23 Advanced Protection Program (high-risk users) | 1 h | |
| 24 Native multi-party approval | 30 min | |
| 25 Gmail Security Sandbox + safety-toggle verification | 30 min | |
| 26 Data regions (storage) | 15 min | |
| 27 Handling untrusted files at rendering distance | 4–8 h | |
| 28 DLP rules (Drive/Gmail/Chat) | 1–2 days | |
| 29 Device-trust CAA via MDM | 3+ days | |
| 30 MTA-STS + TLS reporting | 1–2 h | |
| 31 Shared-drive architecture | 4–8 h | |
| 32 Vault retention & legal hold | 2–4 h | |
| 33 Audit-log export to SIEM/BigQuery | 4–8 h | |
| 34 Groups for Business exposure lockdown | 30 min | |
| 35 Disable POP/IMAP / app-specific passwords draft | 30 min |
2 22 SSO/SAML to hardened IdP 2 25 Gmail Security Sandbox + safety-toggle verification 2 24 Native multi-party approval 2 23 Advanced Protection Program (high-risk users) 2 26 Data regions (storage) 2 27 Handling untrusted files at rendering distance 2 28 DLP rules (Drive/Gmail/Chat) 2 29 Device-trust CAA via MDM 2 30 MTA-STS + TLS reporting 2 31 Shared-drive architecture 2 32 Vault retention & legal hold 2 33 Audit-log export to SIEM/BigQuery 2 34 Groups for Business exposure lockdown 2 35 Disable POP/IMAP / app-specific passwords
draft
Tier 3 — high-assurance
Everything in this tier is in draft status — shown only as a preliminary direction we're considering.
3 36 Disable Google Takeout
draft
3 37 Witnessed ceremonies + tamper-evident custody
draft
3 40 Cloud session control + admin re-auth
draft
3 38 Split-custody break-glass
draft
3 39 Continuous OAuth re-authorization sweeps
draft
3 41 Directory minimization for targeted staff
draft
3 43 Periodic access recertification
draft
3 44 Color-coded data domains (labels + IRM)
draft
3 42 Scripted JIT admin elevation
draft
3 45 Hardware-key break-glass super-admin
draft
3 46 Vault-account custody of crown jewels
draft
3 47 Mandatory-absence review
draft
3 48 Reading-room enclave (SCIF port, incl. data-copy minimization)
draft
3 49 Deny-by-default IP/geo gating
draft
3 50 CSE self-hosted / HYOK KACLS
draft
3 51 Email gateway interception
draft
3 52 Offline & desktop-sync data minimization
draft
3 53 Privileged Access Workstation for admins
draft
Tier 4 — the deep end
Everything in this tier is in draft status — shown only as a preliminary direction we're considering.
4 55 Honeytoken credential file
draft
4 54 Alert-pipeline heartbeat
draft
4 56 Cloud Identity Free decoy accounts
draft
4 57 Air-gapped recovery identity
draft
4 58 Self-hosted canary corpus
draft
4 59 Canary tokens via commercial console
draft
4 61 Config-drift & persistence sentinel (incl. mail-routing watch)
draft
4 63 Audit-the-auditors alerting
draft
4 60 WORM off-tenant log archive
draft
4 64 Config-as-code with reconciliation
draft
4 65 Travel-mode accounts
draft
4 62 Zero-standing-access delivery pattern
draft
4 66 AI-agent / prompt-injection canary
draft
4 67 Apps Script / add-on / AI-agent governance
draft
4 68 Detection engineering on exported logs
draft
4 70 Multi-tenant compartmentalization
draft
4 71 CSE with Google-partner KACLS
draft
4 69 Purple-team / adversary emulation
draft