We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Google Workspace security audit
Workspace security audit, UAE

Google publishes a security checklist. Almost nobody has worked through it since setup.

The checklist for medium and large businesses covers accounts, administrator accounts, apps, Drive, Gmail, Groups and monitoring. An audit works through each item against your actual tenant configuration rather than against the defaults.

Book a Workspace security auditSee what gets checked
Google Workspace security audit for UAE organisations
  • 7 areasCovered by the published checklist
  • 12 Gmail itemsOn the checklist alone
  • RestrictedThe recommended general access setting for sharing
  • Audit logReviewing it is a checklist item in itself
The four we find most often

Four settings account for most of the risk in a typical Workspace tenant.

They are not obscure. They are simply not set, because the tenant was configured to work rather than configured to be secure.

  • External sharing left broad. The checklist recommends setting general access options for file sharing to restricted, warning users when they share outside the domain, and requiring Google sign in for external collaborators. Defaults are considerably more permissive.
  • Automatic forwarding still enabled. Disabling automatic forwarding is a checklist item, and forwarding rules are a standard persistence mechanism after an account compromise, quietly copying mail to an external address for as long as nobody looks.
  • IMAP and POP still available. The checklist recommends disabling them, and legacy protocols are the route by which credential based attacks bypass modern authentication controls that everybody assumes are protecting the account.
  • Third party application grants never reviewed. Reviewing third party app access to core services is on the checklist, and in a tenant several years old the accumulated grants regularly include applications nobody currently uses or recognises.
Ask us to check these four first
What an audit covers

Eight areas where a Workspace tenant is usually weaker than assumed.

Workspace is easy to deploy and easy to leave at defaults. The published checklist exists because the settings that matter are spread across several admin sections and none of them are set correctly out of the box for a business.

Two step verification and security keys

The checklist recommends requiring two step verification for users and enforcing security keys at least for administrators and other high value accounts. Those are two separate recommendations, and most tenants have completed only the first.

Administrator accounts need heightened protection

Super administrators control all organisational data, which is why the checklist treats administrator account practices as their own topic. Standing super administrator access held by day to day working accounts is the pattern we most often find.

Drive sharing is nine separate settings

Rules for sharing outside the organisation, warnings on external sharing, preventing publishing on the web, general access set to restricted, limiting access to recipients only, requiring sign in for external collaborators, offline access, desktop access and sensitive data rules.

Gmail carries the longest list

Authentication with SPF, DKIM and DMARC, TLS with partner domains, disabling IMAP and POP, disabling automatic forwarding, comprehensive mail storage, spam filter handling, pre-delivery scanning, external recipient warnings and attachment, link and spoofing protections.

Third party app access is rarely reviewed

The checklist recommends reviewing third party app access to core services, blocking less secure apps, creating a list of trusted apps and controlling access to Google core services. Application grants accumulate silently and almost nobody revisits them.

Groups are a security surface

Using groups designed for security, adding security conditions to administrator roles, setting up private access to groups, limiting group creation to administrators and customising group access settings. Open group creation is a common and quiet exposure.

Offboarding is an explicit checklist item

Preventing unauthorised access after an employee leaves appears on the checklist directly, alongside identifying and securing compromised accounts and turning off data download where appropriate. Leaver handling is a security control rather than an HR task.

Monitoring means actually reviewing

Reviewing security settings and investigating activity, and reviewing the administrator audit log, are both listed. Collection happens automatically. Review does not, and an audit log nobody reads provides evidence after the fact and no detection before it.

The checklist areas

What the published checklist covers, area by area.

Taken from the checklist for medium and large businesses. An audit works through each item against your configuration and records the position with evidence.
AreaWhat the checklist covers
Administrator accountsHeightened protection for accounts controlling all organisational data
Accounts, authenticationTwo step verification for users, security keys for admins and high value accounts
Accounts, passwordsPreventing password reuse and using unique passwords
Accounts, compromiseActivity reports, admin alerts, login challenges, securing compromised accounts, leaver access
AppsThird party access review, less secure apps, trusted app list, core service access, added encryption
DriveExternal sharing rules and warnings, web publishing, restricted general access, recipient limits, sign in requirement, offline and desktop access, sensitive data rules
Gmail, authenticationSPF, DKIM and DMARC, plus TLS with partner domains
Gmail, accessDisabling IMAP and POP, disabling automatic forwarding, comprehensive mail storage
Gmail, protectionPre-delivery scanning, external recipient warnings, attachment, link and spoofing protections, sensitive data scanning
Groups and monitoringSecurity focused groups, admin role conditions, private access, creation limits, plus reviewing settings and the admin audit log
How we approach it

Four things that make a Workspace audit worth doing.

Configuration audits are easy to produce and easy to ignore. The value is in sequencing changes so they can actually be applied without a revolt.

We work through the published checklist item by item

Not a generic cloud security review. The checklist for medium and large businesses is specific and public, which means findings map to recommendations your team can read for themselves rather than to our opinion about good practice.

We separate low friction changes from disruptive ones

Disabling IMAP, POP and automatic forwarding changes very little for most users and removes substantial risk. Restricting Drive sharing changes daily collaboration and needs communication, so we do not present them as a single batch.

We enumerate application grants properly

Third party app access to core services accumulates over years, and the list usually contains applications nobody remembers approving. Reviewing it produces immediate removals and a trusted app list that keeps the position from drifting again.

We leave monitoring with an owner

Reviewing security settings, investigating activity and reviewing the administrator audit log are checklist items. Without a named owner and a cadence they are aspirations, and the tenant drifts back toward where it started.

How an engagement runs

Three phases across roughly three to six weeks.

Short, because the configuration is centralised. Most of the elapsed time is the change control needed to apply findings without disrupting how people work.
  1. 01
    Weeks 1 to 2

    Assess against the checklist

    Every item worked through against the actual tenant configuration, with the current state recorded rather than the intended state. Administrator account practices, application grants and Drive sharing usually produce the largest findings.

    • Position recorded per checklist item
    • Administrator accounts and role assignments reviewed
    • Third party application grants enumerated
    • External sharing exposure quantified
  2. 02
    Weeks 3 to 4

    Prioritise and plan the changes

    Sorted by risk reduction against user disruption. Disabling legacy protocols and automatic forwarding is high value and low friction. Tightening Drive sharing is high value and needs communication, because it changes how people collaborate.

    • Findings prioritised by risk and disruption
    • Changes grouped into low friction and communicated batches
    • Exceptions identified with business justification
    • Rollback position defined per change
  3. 03
    Weeks 5 to 6

    Apply, verify and hand over monitoring

    Changes applied in sequence with verification on real accounts, then the monitoring practices established, since reviewing security settings and the administrator audit log are checklist items rather than optional extras.

    • Changes applied and verified on real accounts
    • Admin alerts configured for risky events
    • Audit log review cadence established with an owner
    • Reassessment scheduled
Where this comes up

Six situations that prompt a Workspace audit.

Google Workspace is often adopted quickly by a growing business, and the security review happens years later when something forces it.

A business that grew into Workspace

Tenants created for a handful of people and grown to hundreds carry configuration decisions made when the risk profile was completely different. Nothing prompts a review, because nothing has visibly broken.

An organisation after an account compromise

The post incident questions are consistent: was two step verification enforced, were legacy protocols disabled, was automatic forwarding possible, and would the audit log have shown it. All four are checklist items.

A firm facing customer or regulator scrutiny

Questions about external sharing, data access and administrative control need answers with configuration behind them. An assessment against a published vendor checklist is a straightforward and credible way to produce those answers.

An education institution on Workspace

Large user populations, extensive external collaboration and open group structures make sharing and group settings particularly consequential. The recommendations on restricted access and group creation limits matter more here than almost anywhere.

A company where sharing has clearly gone broad

Where files turn out to be accessible to anyone with the link, the remedy is both technical and behavioural. Setting general access to restricted and warning users on external sharing addresses each side of that.

An organisation tightening administrative control

Super administrators control all organisational data, which is why the checklist treats their protection separately. Reducing the count, separating administrative accounts from daily use and enforcing security keys is usually the first change.

Three positions

How UAE organisations run their Workspace tenant.

The middle column describes most tenants. Settings were tightened once during a project and have not been revisited as the organisation and the platform both changed.
Two step verification enforced
Audited against the checklistYes, with keys for admins
Configured once at setupUsually enabled
Left at defaultsOptional
Super admin count controlled
Audited against the checklistMinimised and reviewed
Configured once at setupGrown over time
Left at defaultsUnknown
External sharing restricted
Audited against the checklistDeliberately configured
Configured once at setupPartially
Left at defaultsBroad
Legacy protocols disabled
Audited against the checklistYes
Configured once at setupSometimes
Left at defaultsEnabled
Automatic forwarding disabled
Audited against the checklistYes
Configured once at setupRarely
Left at defaultsEnabled
Third party app grants reviewed
Audited against the checklistRegularly
Configured once at setupNever
Left at defaultsNever
Email authentication complete
Audited against the checklistSPF, DKIM and DMARC
Configured once at setupPartial
Left at defaultsPartial or none
Admin audit log reviewed
Audited against the checklistOn a cadence
Configured once at setupAfter incidents
Left at defaultsNever
Group creation controlled
Audited against the checklistLimited to admins
Configured once at setupVaries
Left at defaultsOpen
Effort to reach
Audited against the checklistWeeks
Configured once at setupA project, once
Left at defaultsNone
Feature
Audited against the checklist
Configured once at setup
Left at defaults
Two step verification enforced
Yes, with keys for adminsUsually enabledOptional
Super admin count controlled
Minimised and reviewedGrown over timeUnknown
External sharing restricted
Deliberately configuredPartiallyBroad
Legacy protocols disabled
YesSometimesEnabled
Automatic forwarding disabled
YesRarelyEnabled
Third party app grants reviewed
RegularlyNeverNever
Email authentication complete
SPF, DKIM and DMARCPartialPartial or none
Admin audit log reviewed
On a cadenceAfter incidentsNever
Group creation controlled
Limited to adminsVariesOpen
Effort to reach
WeeksA project, onceNone
Email deserves separate attention

Twelve of the checklist items are Gmail settings, and they are not interchangeable.

Email remains the primary route into an organisation, and the checklist reflects that with more recommendations here than anywhere else.

  • Authentication comes first. SPF, DKIM and DMARC are recommended together, and DMARC in particular is the one organisations most often have in a monitoring only state that provides visibility without providing enforcement.
  • Then access. Disabling IMAP and POP removes the legacy protocol path, and disabling automatic forwarding removes the most common persistence technique after a mailbox compromise. Both are single settings with disproportionate value.
  • Then protection. Enhanced pre-delivery message scanning, external recipient warnings, additional attachment protection, additional link and external content protection, and additional spoofing protection are each separate recommendations.
  • And a specific warning about internal senders. The checklist recommends not bypassing spam filters for internal senders, which is a bypass organisations add for convenience and which then carries a compromised internal account straight past filtering.
Ask us to review your Gmail configuration
How an engagement runs

Five steps, ending with somebody owning the monitoring.

A tenant that is audited and then unmonitored drifts back within a year. The final step is what makes the rest durable.
  1. 1

    Record the current state per checklist item

    Accounts, administrator accounts, apps, Drive, Gmail, Groups and monitoring. Current configuration rather than intended configuration, because the two diverge in every tenant that has been running for more than a couple of years.

  2. 2

    Quantify the exposure the findings represent

    How many files are shared externally, how many application grants exist, how many accounts lack two step verification, how many super administrators there are. Numbers make prioritisation possible and make the case to management concrete.

  3. 3

    Apply the low friction changes first

    Disabling legacy protocols and automatic forwarding, enforcing security keys for administrators, configuring admin email alerts and completing email authentication. High value, low visibility to ordinary users, achievable quickly.

  4. 4

    Plan and communicate the disruptive ones

    Restricting general access for file sharing, requiring sign in for external collaborators and limiting group creation all change how people work. They succeed with communication and a documented exception route, and fail without.

  5. 5

    Establish review and reassessment

    Reviewing security settings, investigating activity and reviewing the administrator audit log with a named owner and a cadence, plus a scheduled reassessment, since both the platform and the organisation keep changing.

Straight answers

What organisations ask about Workspace security.

Yes. Google publishes a security checklist for medium and large businesses covering administrator accounts, accounts, apps, Drive, Gmail, Groups and monitoring. An audit works through it against your tenant rather than against general practice.

Usually enforcing two step verification for everyone, with security keys for administrators and other high value accounts. Those are two separate recommendations on the checklist and most tenants have implemented only the first of them.

The checklist recommends it. Legacy protocols provide an access path that can bypass the modern authentication controls an organisation believes are protecting accounts, which makes them a favoured route in credential based attacks.

Because it is the standard persistence technique after a mailbox compromise. A forwarding rule quietly copies mail to an external address indefinitely, and disabling automatic forwarding removes the mechanism entirely rather than relying on detection.

The checklist recommends setting general access options for file sharing to restricted, alongside warning users when they share outside the domain, limiting file access to recipients only and requiring Google sign in for external collaborators.

The checklist lists preventing users from publishing on the web as a recommendation. Published files are accessible without any authentication at all, and organisations are frequently unaware how many exist until somebody looks.

Regularly, and the checklist recommends reviewing third party app access to core services alongside creating a list of trusted apps. In a tenant several years old, the accumulated grants usually include applications nobody currently recognises.

SPF, DKIM and DMARC are recommended together, plus enforcing TLS with partner domains. DMARC is the one most often present in a monitoring only state, which gives visibility of abuse without preventing any of it.

The checklist specifically recommends against it. Bypasses are added for convenience, and they mean a compromised internal account can send phishing to colleagues that passes straight through the filtering everybody assumes is protecting them.

As few as the organisation can operate with, and separated from daily working accounts. Super administrators control all organisational data, which is why the checklist treats their protection as a topic in its own right.

The checklist recommends using groups designed for security, adding security conditions to administrator roles, setting up private access to groups, limiting group creation to administrators and customising group access settings.

Rarely, and reviewing the administrator audit log is a checklist item. The distinction that matters is between collection, which happens automatically, and review, which only happens where somebody owns it on a defined cadence.

Some will and some will not. Disabling legacy protocols and automatic forwarding is usually invisible. Restricting external sharing changes daily collaboration and needs communication and a documented exception route to land successfully.

The structure is similar and the specifics differ entirely. Both platforms publish security guidance, both default to usability over restriction, and both accumulate application grants and sharing exposure that nobody revisits after deployment.

We scope by user count and how many domains and organisational units are involved. The free first step: check whether automatic forwarding is disabled in your tenant. It is one setting, and the answer is informative about the rest.

The checklist covers the areas listed in it, and Chrome and device settings are frequently in scope for a broader tenant review. We scope those explicitly rather than assuming, since they involve different administrative areas and different owners.

It appears on the checklist under Gmail. Ensuring that message copies are retained consistently matters for investigation and for retention obligations, and organisations frequently discover the setting only when they need the messages it would have kept.

Through the administrative reporting available for Drive sharing, quantified as a number before any policy change. That figure is what makes the case internally, because abstract concerns about oversharing rarely move a decision on their own.

It changes it. Requiring Google sign in for external collaborators and limiting file access to recipients only both work, and both need communicating with the people who collaborate externally every day, along with a route for genuine exceptions.

A category the checklist recommends blocking access for. They authenticate in ways that bypass modern protections, and blocking them closes a path that is otherwise available regardless of how well the rest of the tenant is configured.

The checklist lists adding another layer of encryption to users apps data as a recommendation. Whether it suits your organisation depends on your data sensitivity and your key management capability, and it is a deliberate decision rather than a default.

Minimise the number, separate them from daily working accounts, enforce security keys on them, and review the list regularly. Super administrators control all organisational data, which is why the checklist treats their protection separately.

Risky events, which is how the checklist frames it. Suspicious logins, administrative changes, large data downloads and new administrator assignments are the common ones, and configuring them is a short task with a long payoff.

Adding user login challenges for suspicious attempts is a checklist recommendation. It introduces friction only where the sign in looks unusual, which makes it one of the higher value and lower disruption settings available.

Turning off Google data download as needed appears on the checklist under preventing compromised accounts. Bulk export is a common exfiltration route after a compromise, and controlling it limits how much leaves before anybody notices.

Preventing unauthorised access after an employee leaves is an explicit checklist item. In practice that means removing access promptly, resetting sign in cookies and application passwords, and reviewing what the account had shared externally.

Three to six weeks for most organisations, with the assessment itself quick and the change control taking the remaining time. Tenants with several domains or organisational units and heavy external collaboration sit at the longer end.
Tenant check

Fifteen questions to ask about your Workspace tenant.

Each of these maps to a published checklist item. The ones people hesitate on are usually the ones that have never been revisited since the tenant was created.

Accounts

  • Is two step verification required for everyone?
    Required, not available.
  • Do admins use security keys?
    A separate recommendation.
  • How many super admins are there?
    Usually more than needed.
  • Are admin email alerts configured?
    For risky events.
  • What happens to a leaver account?
    An explicit checklist item.

Data and email

  • Is general access set to restricted?
    The recommended setting.
  • Are users warned on external sharing?
    A separate control.
  • Can users publish to the web?
    Recommended to prevent.
  • Are IMAP and POP disabled?
    Recommended.
  • Is automatic forwarding disabled?
    Also recommended.

Apps and oversight

  • When were app grants last reviewed?
    They accumulate silently.
  • Is there a trusted app list?
    A checklist item.
  • Can anybody create groups?
    Recommended to limit.
  • Who reads the admin audit log?
    Review is the item.
  • Do we bypass spam filters internally?
    Recommended not to.
Related reading

The pages around this one.

Microsoft 365 security audit

The same exercise on the other platform.

Learn more

Email security audit

Email specifically, across platforms.

Learn more

DMARC audit

The authentication piece in depth.

Learn more
Next step

Check whether automatic forwarding is disabled in your Workspace tenant.

It is a single setting and it takes a minute. Whichever way the answer comes back, it tells you a great deal about how the rest of the checklist would score.

Book a Workspace security auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Email Security Audit

Authentication, policy, exceptions, routing, mailboxes

Learn more

DMARC Audit UAE

Stop exact-domain spoofing, and keep your mail delivering

Learn more

Google Workspace

Google Workspace setup and migration

Learn more

Access Rights Review

Certification that removes access, not one that gets approved

Learn more

Shadow IT Discovery

Find the SaaS nobody sanctioned, without driving it underground

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Data Discovery Audit

Where the sensitive data is, and who can reach it

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy