Google Workspace Security Checklist

Google Workspace Security Checklist: What Should a Small Business Configure First? 

A small business should start with the Google Workspace controls that protect administrator accounts, user sign-ins, business data, and access from unmanaged devices. The highest-priority work is enabling strong authentication, securing super administrator accounts, controlling external sharing, reviewing third-party access, and turning on useful security monitoring. This Google Workspace security checklist puts those controls into a practical order so founders, office managers, and IT administrators can address the most serious gaps first. 

For businesses that rely on Gmail, Drive, Docs, Meet, Calendar, and other Workspace services, security is largely shaped by configuration. A default setup may not reflect how your business actually operates. Franklin Web Technologies recommends treating Workspace security as an administrative responsibility, not simply an employee password issue. 

Start With the Critical Settings 

The critical tier contains controls that should be addressed before spending time on lower-priority configuration. These settings reduce the risk of account takeover and limit the damage that can follow a compromised credential. 

1. Enforce Multi-Factor Authentication 

A password alone should not protect an account containing company email, documents, customer information, financial records, and internal communications. Google calls its multi-factor authentication system 2-Step Verification, commonly referred to as MFA. 

Google recommends 2-Step Verification for administrator accounts, particularly super administrators, because those accounts can control organization-wide data and settings. 

For a small business, the practical configuration is to allow employees to enroll first, communicate the requirement clearly, and then enforce the policy across the organization. Administrators should also select authentication methods that provide strong phishing resistance. Passkeys and physical security keys provide stronger protection against phishing than traditional SMS verification codes.  

Your Google Workspace MFA policy should also account for recovery. Admins should have secure backup methods available before enforcement creates a situation where someone cannot access their account. 

2. Protect Super Administrator Accounts 

A super administrator can make changes that affect every user in the Workspace environment. That makes these accounts particularly attractive to attackers. 

Google recommends having more than one super administrator, with each account assigned to a separate person. It also recommends keeping super administrator accounts separate from everyday accounts.

Do not use an account such as admin@company.com as a shared login for several employees. Individual administrator accounts provide accountability in audit records and make it easier to identify who made a configuration change. 

A sensible small-business setup includes: 

  • Separate admin and daily-use accounts for administrators. 

  • At least two independently managed super administrator accounts. 

  • More than one registered security key or another secure recovery method for critical admins. 

This is one of the most frequently overlooked areas of Google Workspace admin security. Businesses often secure employee accounts while leaving administrator access exposed. 

3. Review Account Recovery Information 

Account recovery deserves attention because a secure authentication policy can still create operational problems if administrators lose access to their recovery methods. 

Check recovery email addresses, phone numbers, security keys, passkeys, and backup codes for administrator accounts. Remove outdated recovery information and make sure backup methods are stored securely. 

Google states that backup codes can help an administrator sign in if a security key or phone is unavailable. 

Recovery details should belong to the correct individual or be managed under a documented business process. Avoid leaving recovery information tied to an employee who no longer works for the company. 

4. Remove Old and Unused Accounts 

Former employees, contractors, temporary accounts, and abandoned test accounts can create unnecessary access to business systems. 

Create a simple offboarding process that disables accounts promptly when someone leaves. Before deleting an account, review ownership of important Drive files, calendars, groups, and other business resources so information is not accidentally lost. 

Also review accounts that have not been used for a long period. An unused account with active access is still an access point that needs attention. 

Important Settings That Limit Data Exposure 

Once authentication and administrator access are under control, the next priority is reducing unnecessary access to company information. 

5. Review Google Drive Sharing 

Drive makes collaboration easy, but broad sharing can expose sensitive information outside the organization. 

Review your organization’s external sharing rules and determine who actually needs to share files with external users. Pay particular attention to confidential folders containing financial information, employee records, customer data, contracts, intellectual property, and operational documents. 

Avoid treating “Anyone with the link” as a normal sharing method for sensitive material. A link can be forwarded beyond the original recipient, making it harder to control who ultimately sees the file. 

A useful policy is to make internal sharing the normal option and require deliberate approval for sensitive external sharing. 

6. Control Third-Party Application Access 

Employees often connect Workspace accounts to external applications for productivity, project management, document handling, scheduling, and other tasks. 

The risk is not limited to the application itself. A connected application may receive permission to access parts of a user’s Google data. 

Review third-party application access in the Admin console and remove applications that are unnecessary, outdated, or no longer approved. Establish an internal process for approving applications before employees connect them to company accounts. 

Google has also removed support for less secure apps that authenticate using only a username and password for Google Workspace accounts. Since January 2025, businesses should use more secure authentication methods instead. 

7. Secure Company Devices 

Account security becomes weaker if employees access Workspace from poorly protected computers. 

Consider enabling Endpoint Verification for organizations that need visibility into devices accessing business data. Google says Endpoint Verification can provide administrators with information about devices and help control access based on device and security attributes. 

The appropriate level of device control depends on your workforce. A company handling sensitive customer or financial information may need stricter device requirements than a small team working primarily with low-risk documents. 

At minimum, establish requirements for screen locks, operating system updates, browser updates, device encryption where supported, and removal of company access from lost or retired devices. 

8. Review External Email and Phishing Protection 

Gmail is one of the most valuable targets in a business account because an attacker can use a compromised mailbox to impersonate employees, intercept conversations, and send convincing messages to customers or suppliers. 

Review Gmail security controls that help identify suspicious messages and consider additional protections for high-risk users. 

Employees should also know how to report suspicious messages. Security technology can reduce exposure, but users still need a clear process for reporting unusual login requests, payment instructions, password prompts, and unexpected attachments. 

Recommended Settings for Ongoing Control 

The recommended tier focuses on visibility, maintenance, and gradual improvement. These controls may not be the first settings you configure, but they help prevent security from becoming a one-time project. 

9. Monitor the Admin and Security Audit Logs 

A Google Workspace security audit should not be limited to the day after an incident. 

Review administrative actions, login activity, suspicious events, and other relevant security records regularly. Look for unusual administrator changes, unexpected sign-ins, unfamiliar applications, and activity involving accounts that should no longer be active. 

The purpose is not to inspect every event manually. Establish a review routine and define which events require investigation. 

10. Minimize Administrator Permissions 

Not every IT employee needs super administrator access. 

Use administrator roles that provide only the permissions required for a person’s responsibilities. A person managing users may not need access to every security or billing function. 

Reducing administrative privileges limits the number of accounts that can make high-impact changes and makes the environment easier to manage. 

11. Review Groups and Mailing Lists 

Google Groups can quietly become a source of information exposure. 

Review who can join groups, who can post, who can view conversations, and who manages each group. Pay special attention to groups used for finance, human resources, leadership, customer information, and internal operations. 

Remove former employees and inactive accounts from groups during offboarding. 

12. Establish a Security Alert Process 

Security alerts only help if someone reviews and acts on them. 

Assign responsibility for monitoring important alerts and define what happens after an alert is received. A small company does not necessarily need a large security team, but someone should own the process. 

Document escalation steps for suspicious sign-ins, compromised accounts, unauthorized application access, and unexpected administrative changes. 

A Practical Priority Order for Small Businesses 

A security configuration is easier to maintain when administrators know what to do first. Rather than changing dozens of settings at once, use a staged process. 

Critical: Enforce MFA, protect super administrator accounts, secure account recovery, remove inactive accounts, and review administrator privileges. 

Important: Tighten Drive sharing, review third-party application access, secure devices, strengthen Gmail protections, and review groups. 

Recommended: Monitor audit logs, establish alert procedures, document security policies, and schedule recurring reviews. 

This order gives small businesses a sensible starting point without turning security configuration into an overwhelming project. It also provides a useful framework for future Google Workspace security best practices. 

Common Configuration Mistakes to Avoid 

Small businesses often make security harder than it needs to be by focusing on isolated settings instead of access. 

One common mistake is creating a single shared administrator account. Shared credentials remove accountability and make it difficult to investigate administrative activity. 

Another is enforcing MFA without preparing recovery options. Strong authentication is valuable, but administrators should have secure backup methods before a policy becomes mandatory. 

Broad Drive sharing is another recurring issue. Employees may share files externally for convenience without realizing that sensitive information can remain accessible long after the original business need has ended. 

Businesses also sometimes install security tools without reviewing Workspace’s own administrative controls. Third-party products can have a role, but basic Google Workspace security settings should be properly configured first. 

Finally, avoid treating security as a setup task that ends after implementation. Employee turnover, new applications, device changes, and changes in business operations can all create new access risks. 

How Often Should a Small Business Review Workspace Security? 

A basic review should take place at least quarterly, with more frequent checks for organizations handling sensitive information. 

A recurring review can cover administrator accounts, inactive users, MFA enrollment, recovery methods, external sharing, third-party applications, groups, device access, and security alerts. 

A more detailed review should follow major organizational changes such as acquisitions, leadership changes, large employee departures, new business applications, or a security incident. 

Google’s administrative guidance also emphasizes ongoing monitoring, administrator account protection, and recovery preparation rather than relying on passwords alone.  

Build a Security Baseline That Fits Your Business 

There is no single Google Workspace configuration that fits every small business. A company managing public marketing material has different information risks from an accounting firm, healthcare organization, legal practice, or technology company. 

Start by identifying your most sensitive information and the people who can access it. Then work outward through authentication, administrator permissions, data sharing, devices, applications, and monitoring. 

That approach makes a secure Google Workspace environment easier to maintain because each control has a clear business purpose. 

A well-configured Workspace environment should make the secure choice the normal choice. Employees should not need to understand every technical control, but administrators should know why access is granted, who can change it, and how suspicious activity will be handled. 

Final Thoughts 

Small businesses do not need to configure every Google Workspace security feature on the first day. They need to address the controls that have the greatest effect on account access and business data first. 

Start with MFA and administrator protection. Then tighten sharing, application access, device controls, and monitoring. Keep recovery methods current and review the environment on a recurring schedule. 

For organizations that want an expert review, Franklin Web Technologies can help assess the current configuration, identify gaps, and prioritize practical improvements. A focused review can provide a clearer picture of your current security posture and the changes that deserve attention first. 

If your business has not reviewed its Workspace configuration recently, Request a Security Consultation and turn your security settings into a documented, repeatable baseline.