There is a published security checklist for Workspace. Hardly anybody has opened it since the day the tenant was created.
The version aimed at medium and large businesses runs across accounts, administrator accounts, applications, Drive, Gmail, Groups and monitoring. An audit takes each item and holds it against what your tenant is genuinely configured to do, rather than against whatever the defaults happen to be.

- 7 areasCovered by the published checklist
- 12 Gmail itemsOn the checklist alone
- RestrictedThe recommended general access setting for sharing
- Audit logReviewing it is a checklist item in itself
Four settings carry most of the risk in an average Workspace tenant.
None of them is obscure. They are simply not configured, because somebody set the tenant up to work rather than setting it up to be secure, and those are different exercises.
- Sharing left wide open. The recommendation is to pull general file sharing back to restricted, warn people when they share outside the company, and require outside collaborators to sign in. In most tenants not one of those three has been touched since the day it was set up.
- Automatic forwarding still switched on. Disabling it is a checklist item in its own right, because a forwarding rule is the standard way somebody keeps hold of a mailbox after compromising it, quietly copying everything to an outside address for as long as nobody thinks to look.
- The legacy mail protocols still available. Switching them off is recommended explicitly, because those protocols are exactly how a credential-based attack walks around the modern authentication controls everybody assumes are protecting the account.
- Application grants that nobody has ever reviewed. Checking what outside applications can reach the core services is on the list, and in a tenant a few years old the accumulated grants routinely include products nobody uses any more or recognizes.
Eight areas where a Workspace tenant is nearly always weaker than anybody assumes.
Two-step verification and security keys
Two separate recommendations sit here. Require two-step verification for everybody, and enforce hardware security keys for administrators and anyone else worth targeting. They are not the same item, and most tenants have done the first and stopped.
Administrator accounts need heightened protection
A super administrator controls every piece of data the organization holds, which is exactly why administrator account practice gets a section of its own. What we find most often is permanent super administrator rights sitting on the account somebody uses to read their email all day.
Drive sharing is nine separate settings
The rules governing sharing beyond the company, warnings when somebody does it, publishing to the web prevented, general access pulled back to restricted, sharing limited to named recipients, outside collaborators required to sign in, plus the settings covering offline access, desktop access and anything holding sensitive data.
Gmail carries the longest list
All three authentication records, encrypted transport with partner domains, the legacy mail protocols switched off, automatic forwarding disabled, comprehensive mail storage enabled, spam filtering handled properly, scanning before delivery, warnings on external recipients, and the separate protections covering attachments, links and spoofing.
Third-party app access is rarely reviewed
Reviewing which outside applications can reach the core services, blocking the ones using weak authentication, building a list of the ones you trust, and controlling access to the core services themselves. Application grants pile up silently and almost nobody ever goes back to look at them.
Groups are a security surface
Using groups built for security rather than repurposed mailing lists, attaching security conditions to administrator roles, making group access private, restricting who can create a group to administrators, and tailoring the access settings. Letting anybody create a group is a common exposure and a very quiet one.
Offboarding is an explicit checklist item
Stopping somebody reaching things after they have left appears on the checklist in its own right, alongside finding and securing compromised accounts and switching off data download where that makes sense. Handling leavers is a security control, not an administrative task belonging to HR.
Monitoring means actually reviewing
Both reviewing the security settings and investigating activity, and reading the administrator audit log, are listed separately. Collection happens by itself. Review does not happen at all unless somebody schedules it, and a log nobody opens gives you evidence afterward and detection never.
What the published checklist covers, area by area.
Area
Administrator accounts
- What the checklist covers
- Heightened protection for accounts controlling all organizational data
Area
Accounts, authentication
- What the checklist covers
- Two-step verification across the board, hardware keys for administrators and anyone worth targeting
Area
Accounts, passwords
- What the checklist covers
- Preventing password reuse and using unique passwords
Area
Accounts, compromise
- What the checklist covers
- Activity reporting, administrator alerts, sign-in challenges, securing compromised accounts, and what happens when somebody leaves
Area
Apps
- What the checklist covers
- Reviewing outside access, blocking weakly authenticated apps, a trusted list, core service access, and additional encryption
Area
Drive
- What the checklist covers
- The external sharing rules and warnings, publishing to the web, general access pulled back, limits on recipients, a sign-in requirement, offline and desktop access, and the rules covering sensitive data
Area
Gmail, authentication
- What the checklist covers
- SPF, DKIM and DMARC, plus TLS with partner domains
Area
Gmail, access
- What the checklist covers
- Legacy mail protocols switched off, automatic forwarding disabled, comprehensive mail storage enabled
Area
Gmail, protection
- What the checklist covers
- Scanning before delivery, warnings on external recipients, the attachment, link and spoofing protections, and scanning for sensitive data
Area
Groups and monitoring
- What the checklist covers
- Groups built for security, conditions on administrator roles, private access, limits on who can create one, and reading both the settings and the administrator log
Four things that make a Workspace audit worth doing.
We work through the published checklist item by item
This is not a generic cloud security review. The checklist for medium and large businesses is specific and publicly available, which means every finding maps to a recommendation your own team can go and read rather than to our opinion about what good looks like.
We separate low-friction changes from disruptive ones
Switching off the legacy protocols and automatic forwarding changes almost nothing for most people while removing a great deal of risk. Restricting Drive sharing changes how people collaborate every day and needs telling them first. Those two do not belong in the same batch, so we do not present them as one.
We enumerate application grants properly
Outside applications reaching the core services accumulate quietly across years, and the list almost always contains things nobody remembers approving. Going through it produces removals the same afternoon, plus a trusted list that stops the position drifting all over again.
We leave monitoring with an owner
Reviewing the settings, investigating activity and reading the administrator log are all checklist items in their own right. Without somebody named as responsible and a date in the calendar, all three are aspirations, and the tenant quietly returns to roughly where it began.
Three phases across roughly three to six weeks.
- 01Weeks 1 to 2
Assess against the checklist
Every item taken in turn against the real configuration, recording where things genuinely stand rather than where somebody intended them to be. Administrator account practice, the application grants and Drive sharing are where the biggest findings nearly always come from.
- Position recorded per checklist item
- Administrator accounts and role assignments reviewed
- Third-party application grants enumerated
- External sharing exposure quantified
- 02Weeks 3 to 4
Prioritize and plan the changes
Ordered by how much risk each removes set against how much it inconveniences people. Switching off the legacy protocols and automatic forwarding is high value and almost nobody notices. Tightening Drive sharing is equally valuable and needs telling people first, because it genuinely changes how they work together.
- Findings prioritized by risk and disruption
- Changes grouped into low-friction and communicated batches
- Exceptions identified with business justification
- Rollback position defined per change
- 03Weeks 5 to 6
Apply, verify, and hand over monitoring
The changes go in sequence, each verified against real accounts rather than assumed, and then the monitoring practices get established, because reviewing the security settings and reading the administrator log are both checklist items rather than optional extras somebody might get to.
- Changes applied and verified on real accounts
- Admin alerts configured for risky events
- Audit log review cadence established with an owner
- Reassessment scheduled
Six situations that prompt a Workspace audit.
A business that grew into Workspace
A tenant created for six people and now carrying six hundred still holds configuration decisions made when the risk looked nothing like it does today. Nothing ever prompts a review, because from the outside nothing has broken.
An organization after an account compromise
The questions asked afterward are always the same four. Was two-step verification actually enforced. Were the legacy protocols switched off. Could somebody have set up forwarding. And would the audit log have shown any of it. Every one of those is a checklist item.
A firm facing customer, insurer, or SOC 2 scrutiny
Security questionnaires, insurance applications and SOC 2 audits all ask about external sharing, who can reach what data, and how administrative control is handled, and every answer needs actual configuration standing behind it. Assessing against a published checklist from the vendor themselves is a straightforward and credible way to produce those answers.
An education institution on Workspace
A large population, a great deal of collaboration with people outside, and group structures open by tradition all make the sharing and group settings unusually consequential. The recommendations about restricted access and limiting who can create a group matter more in this environment than almost any other.
A company where sharing has clearly gone broad
When it emerges that files are readable by anybody holding the link, the fix has both a technical and a human half. Pulling general access back to restricted handles the first, and warning people at the moment they share outside handles the second.
An organization tightening administrative control
A super administrator can reach everything the company holds, which is exactly why protecting those accounts gets its own section. Cutting how many there are, separating administrative accounts from the ones people use daily, and requiring hardware keys is nearly always the first change we make.
How US organizations run their Workspace tenant.
| Feature | Audited against the checklist | Configured once at setup | Left at defaults |
|---|---|---|---|
Two-step verification enforced | Yes, with keys for admins | Usually enabled | Optional |
Super admin count controlled | Minimized and reviewed | Grown over time | Unknown |
External sharing restricted | Deliberately configured | Partially | Broad |
Legacy protocols disabled | Yes | Sometimes | Enabled |
Automatic forwarding disabled | Yes | Rarely | Enabled |
Third-party app grants reviewed | Regularly | Never | Never |
Email authentication complete | SPF, DKIM and DMARC | Partial | Partial or none |
Admin audit log reviewed | On a cadence | After incidents | Never |
Group creation controlled | Limited to admins | Varies | Open |
Effort to reach | Weeks | A project, once | None |
Twelve items on the checklist are Gmail settings alone, and none of them substitutes for another.
Mail is still the way most attackers get in, and the checklist reflects that by carrying more recommendations here than in any other section.
- Authentication comes first, and all three records are recommended together. The last of the three is the one companies most often leave in a monitoring-only state, which gives you visibility into the problem while doing nothing whatsoever to stop it.
- Then access. Switching off the legacy mail protocols closes that route entirely, and disabling automatic forwarding removes the single most common way somebody holds onto a mailbox after compromising it. Both are one setting each, and both are worth far more than the effort suggests.
- Then the protections. Enhanced scanning before a message is delivered, warnings when somebody is emailing outside the company, extra attachment handling, extra checking of links and external content, and additional spoofing defenses. Each of those is a separate recommendation rather than one switch.
- And one specific warning about internal senders. The advice is not to bypass spam filtering for mail from inside the company, which is exactly the exception organizations add for convenience, and which then waves a compromised internal account straight through every filter you own.
Five steps, ending with somebody owning the monitoring.
- 1
Record the current state per checklist item
Accounts, administrator accounts, applications, Drive, Gmail, Groups and monitoring. What is genuinely configured rather than what somebody meant to configure, because those two part company in every tenant that has been running more than a couple of years.
- 2
Quantify the exposure the findings represent
The number of files shared outside the company, the number of application grants standing, the number of accounts without two-step verification, and the number of super administrators. Numbers are what make prioritizing possible, and they are what turns a conversation with management from a preference into a case.
- 3
Apply the low-friction changes first
Legacy protocols and automatic forwarding switched off, hardware keys required for administrators, alerting configured, and the mail authentication records finished. High value, almost invisible to anybody doing their job, and achievable within days.
- 4
Plan and communicate the disruptive ones
Pulling back general file sharing, requiring outside collaborators to sign in, and limiting who can create a group all change how people work day to day. With communication beforehand and a documented way to request an exception they succeed. Without either, they get reversed within a month.
- 5
Establish review and reassessment
Reviewing the settings, investigating activity and reading the administrator log, each with somebody named as responsible and a rhythm to it, plus a reassessment already in the calendar, because both the platform and the company will keep changing underneath you.
What organizations ask about Workspace security.
Fifteen questions to ask about your Workspace tenant.
Accounts
- Is two-step verification required for everyone?Required, not available.
- Do admins use security keys?A separate recommendation.
- How many super admins are there?Usually more than needed.
- Are admin email alerts configured?For risky events.
- What happens to a leaver account?An explicit checklist item.
Data and email
- Is general access set to restricted?The recommended setting.
- Are users warned on external sharing?A separate control.
- Can users publish to the web?Recommended to prevent.
- Are IMAP and POP disabled?Recommended.
- Is automatic forwarding disabled?Also recommended.
Apps and oversight
- When were app grants last reviewed?They accumulate silently.
- Is there a trusted app list?A checklist item.
- Can anybody create groups?Recommended to limit.
- Who reads the admin audit log?Review is the item.
- Do we bypass spam filters internally?Recommended not to.
Go and check whether automatic forwarding is switched off in your tenant.
One setting, about a minute of your time. Whichever way it comes back, it tells you a great deal about how the rest of that checklist would score if anybody worked through it.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Independent Microsoft 365 tenant security audit for US organizations
Learn moreEmail Security Audit
Email security audits for US organizations: sending domain inventory
Learn moreCloud Security Posture Audit
Cloud security posture audits for US organizations: true inventory
Learn moreIT Compliance
HIPAA, SOC 2, NIST, CMMC, CCPA readiness
Learn more