Google publishes a security checklist. Almost nobody has worked through it since setup.
The checklist for medium and large businesses covers accounts, administrator accounts, apps, Drive, Gmail, Groups and monitoring. An audit works through each item against your actual tenant configuration rather than against the defaults.

- 7 areasCovered by the published checklist
- 12 Gmail itemsOn the checklist alone
- RestrictedThe recommended general access setting for sharing
- Audit logReviewing it is a checklist item in itself
Four settings account for most of the risk in a typical Workspace tenant.
They are not obscure. They are simply not set, because the tenant was configured to work rather than configured to be secure.
- External sharing left broad. The checklist recommends setting general access options for file sharing to restricted, warning users when they share outside the domain, and requiring Google sign in for external collaborators. Defaults are considerably more permissive.
- Automatic forwarding still enabled. Disabling automatic forwarding is a checklist item, and forwarding rules are a standard persistence mechanism after an account compromise, quietly copying mail to an external address for as long as nobody looks.
- IMAP and POP still available. The checklist recommends disabling them, and legacy protocols are the route by which credential based attacks bypass modern authentication controls that everybody assumes are protecting the account.
- Third party application grants never reviewed. Reviewing third party app access to core services is on the checklist, and in a tenant several years old the accumulated grants regularly include applications nobody currently uses or recognises.
Eight areas where a Workspace tenant is usually weaker than assumed.
Two step verification and security keys
The checklist recommends requiring two step verification for users and enforcing security keys at least for administrators and other high value accounts. Those are two separate recommendations, and most tenants have completed only the first.
Administrator accounts need heightened protection
Super administrators control all organisational data, which is why the checklist treats administrator account practices as their own topic. Standing super administrator access held by day to day working accounts is the pattern we most often find.
Drive sharing is nine separate settings
Rules for sharing outside the organisation, warnings on external sharing, preventing publishing on the web, general access set to restricted, limiting access to recipients only, requiring sign in for external collaborators, offline access, desktop access and sensitive data rules.
Gmail carries the longest list
Authentication with SPF, DKIM and DMARC, TLS with partner domains, disabling IMAP and POP, disabling automatic forwarding, comprehensive mail storage, spam filter handling, pre-delivery scanning, external recipient warnings and attachment, link and spoofing protections.
Third party app access is rarely reviewed
The checklist recommends reviewing third party app access to core services, blocking less secure apps, creating a list of trusted apps and controlling access to Google core services. Application grants accumulate silently and almost nobody revisits them.
Groups are a security surface
Using groups designed for security, adding security conditions to administrator roles, setting up private access to groups, limiting group creation to administrators and customising group access settings. Open group creation is a common and quiet exposure.
Offboarding is an explicit checklist item
Preventing unauthorised access after an employee leaves appears on the checklist directly, alongside identifying and securing compromised accounts and turning off data download where appropriate. Leaver handling is a security control rather than an HR task.
Monitoring means actually reviewing
Reviewing security settings and investigating activity, and reviewing the administrator audit log, are both listed. Collection happens automatically. Review does not, and an audit log nobody reads provides evidence after the fact and no detection before it.
What the published checklist covers, area by area.
| Area | What the checklist covers | |
|---|---|---|
| Administrator accounts | Heightened protection for accounts controlling all organisational data | |
| Accounts, authentication | Two step verification for users, security keys for admins and high value accounts | |
| Accounts, passwords | Preventing password reuse and using unique passwords | |
| Accounts, compromise | Activity reports, admin alerts, login challenges, securing compromised accounts, leaver access | |
| Apps | Third party access review, less secure apps, trusted app list, core service access, added encryption | |
| Drive | External sharing rules and warnings, web publishing, restricted general access, recipient limits, sign in requirement, offline and desktop access, sensitive data rules | |
| Gmail, authentication | SPF, DKIM and DMARC, plus TLS with partner domains | |
| Gmail, access | Disabling IMAP and POP, disabling automatic forwarding, comprehensive mail storage | |
| Gmail, protection | Pre-delivery scanning, external recipient warnings, attachment, link and spoofing protections, sensitive data scanning | |
| Groups and monitoring | Security focused groups, admin role conditions, private access, creation limits, plus reviewing settings and the admin audit log |
Four things that make a Workspace audit worth doing.
We work through the published checklist item by item
Not a generic cloud security review. The checklist for medium and large businesses is specific and public, which means findings map to recommendations your team can read for themselves rather than to our opinion about good practice.
We separate low friction changes from disruptive ones
Disabling IMAP, POP and automatic forwarding changes very little for most users and removes substantial risk. Restricting Drive sharing changes daily collaboration and needs communication, so we do not present them as a single batch.
We enumerate application grants properly
Third party app access to core services accumulates over years, and the list usually contains applications nobody remembers approving. Reviewing it produces immediate removals and a trusted app list that keeps the position from drifting again.
We leave monitoring with an owner
Reviewing security settings, investigating activity and reviewing the administrator audit log are checklist items. Without a named owner and a cadence they are aspirations, and the tenant drifts back toward where it started.
Three phases across roughly three to six weeks.
- 01Weeks 1 to 2
Assess against the checklist
Every item worked through against the actual tenant configuration, with the current state recorded rather than the intended state. Administrator account practices, application grants and Drive sharing usually produce the largest findings.
- Position recorded per checklist item
- Administrator accounts and role assignments reviewed
- Third party application grants enumerated
- External sharing exposure quantified
- 02Weeks 3 to 4
Prioritise and plan the changes
Sorted by risk reduction against user disruption. Disabling legacy protocols and automatic forwarding is high value and low friction. Tightening Drive sharing is high value and needs communication, because it changes how people collaborate.
- Findings prioritised by risk and disruption
- Changes grouped into low friction and communicated batches
- Exceptions identified with business justification
- Rollback position defined per change
- 03Weeks 5 to 6
Apply, verify and hand over monitoring
Changes applied in sequence with verification on real accounts, then the monitoring practices established, since reviewing security settings and the administrator audit log are checklist items rather than optional extras.
- Changes applied and verified on real accounts
- Admin alerts configured for risky events
- Audit log review cadence established with an owner
- Reassessment scheduled
Six situations that prompt a Workspace audit.
A business that grew into Workspace
Tenants created for a handful of people and grown to hundreds carry configuration decisions made when the risk profile was completely different. Nothing prompts a review, because nothing has visibly broken.
An organisation after an account compromise
The post incident questions are consistent: was two step verification enforced, were legacy protocols disabled, was automatic forwarding possible, and would the audit log have shown it. All four are checklist items.
A firm facing customer or regulator scrutiny
Questions about external sharing, data access and administrative control need answers with configuration behind them. An assessment against a published vendor checklist is a straightforward and credible way to produce those answers.
An education institution on Workspace
Large user populations, extensive external collaboration and open group structures make sharing and group settings particularly consequential. The recommendations on restricted access and group creation limits matter more here than almost anywhere.
A company where sharing has clearly gone broad
Where files turn out to be accessible to anyone with the link, the remedy is both technical and behavioural. Setting general access to restricted and warning users on external sharing addresses each side of that.
An organisation tightening administrative control
Super administrators control all organisational data, which is why the checklist treats their protection separately. Reducing the count, separating administrative accounts from daily use and enforcing security keys is usually the first change.
How UAE organisations run their Workspace tenant.
| Feature | Audited against the checklist | Configured once at setup | Left at defaults |
|---|---|---|---|
Two step verification enforced | Yes, with keys for admins | Usually enabled | Optional |
Super admin count controlled | Minimised and reviewed | Grown over time | Unknown |
External sharing restricted | Deliberately configured | Partially | Broad |
Legacy protocols disabled | Yes | Sometimes | Enabled |
Automatic forwarding disabled | Yes | Rarely | Enabled |
Third party app grants reviewed | Regularly | Never | Never |
Email authentication complete | SPF, DKIM and DMARC | Partial | Partial or none |
Admin audit log reviewed | On a cadence | After incidents | Never |
Group creation controlled | Limited to admins | Varies | Open |
Effort to reach | Weeks | A project, once | None |
Twelve of the checklist items are Gmail settings, and they are not interchangeable.
Email remains the primary route into an organisation, and the checklist reflects that with more recommendations here than anywhere else.
- Authentication comes first. SPF, DKIM and DMARC are recommended together, and DMARC in particular is the one organisations most often have in a monitoring only state that provides visibility without providing enforcement.
- Then access. Disabling IMAP and POP removes the legacy protocol path, and disabling automatic forwarding removes the most common persistence technique after a mailbox compromise. Both are single settings with disproportionate value.
- Then protection. Enhanced pre-delivery message scanning, external recipient warnings, additional attachment protection, additional link and external content protection, and additional spoofing protection are each separate recommendations.
- And a specific warning about internal senders. The checklist recommends not bypassing spam filters for internal senders, which is a bypass organisations add for convenience and which then carries a compromised internal account straight past filtering.
Five steps, ending with somebody owning the monitoring.
- 1
Record the current state per checklist item
Accounts, administrator accounts, apps, Drive, Gmail, Groups and monitoring. Current configuration rather than intended configuration, because the two diverge in every tenant that has been running for more than a couple of years.
- 2
Quantify the exposure the findings represent
How many files are shared externally, how many application grants exist, how many accounts lack two step verification, how many super administrators there are. Numbers make prioritisation possible and make the case to management concrete.
- 3
Apply the low friction changes first
Disabling legacy protocols and automatic forwarding, enforcing security keys for administrators, configuring admin email alerts and completing email authentication. High value, low visibility to ordinary users, achievable quickly.
- 4
Plan and communicate the disruptive ones
Restricting general access for file sharing, requiring sign in for external collaborators and limiting group creation all change how people work. They succeed with communication and a documented exception route, and fail without.
- 5
Establish review and reassessment
Reviewing security settings, investigating activity and reviewing the administrator audit log with a named owner and a cadence, plus a scheduled reassessment, since both the platform and the organisation keep changing.
What organisations ask about Workspace security.
Fifteen questions to ask about your Workspace tenant.
Accounts
- Is two step verification required for everyone?Required, not available.
- Do admins use security keys?A separate recommendation.
- How many super admins are there?Usually more than needed.
- Are admin email alerts configured?For risky events.
- What happens to a leaver account?An explicit checklist item.
Data and email
- Is general access set to restricted?The recommended setting.
- Are users warned on external sharing?A separate control.
- Can users publish to the web?Recommended to prevent.
- Are IMAP and POP disabled?Recommended.
- Is automatic forwarding disabled?Also recommended.
Apps and oversight
- When were app grants last reviewed?They accumulate silently.
- Is there a trusted app list?A checklist item.
- Can anybody create groups?Recommended to limit.
- Who reads the admin audit log?Review is the item.
- Do we bypass spam filters internally?Recommended not to.
Check whether automatic forwarding is disabled in your Workspace tenant.
It is a single setting and it takes a minute. Whichever way the answer comes back, it tells you a great deal about how the rest of the checklist would score.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Email Security Audit
Authentication, policy, exceptions, routing, mailboxes
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
Google Workspace
Google Workspace setup and migration
Access Rights Review
Certification that removes access, not one that gets approved
Shadow IT Discovery
Find the SaaS nobody sanctioned, without driving it underground
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Data Discovery Audit
Where the sensitive data is, and who can reach it