We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Google Workspace security audit
Workspace security audit for US businesses

There is a published security checklist for Workspace. Hardly anybody has opened it since the day the tenant was created.

The version aimed at medium and large businesses runs across accounts, administrator accounts, applications, Drive, Gmail, Groups and monitoring. An audit takes each item and holds it against what your tenant is genuinely configured to do, rather than against whatever the defaults happen to be.

Book a Workspace security auditSee what gets checked
Google Workspace security audit for US organizations
  • 7 areasCovered by the published checklist
  • 12 Gmail itemsOn the checklist alone
  • RestrictedThe recommended general access setting for sharing
  • Audit logReviewing it is a checklist item in itself
The four we find most often

Four settings carry most of the risk in an average Workspace tenant.

None of them is obscure. They are simply not configured, because somebody set the tenant up to work rather than setting it up to be secure, and those are different exercises.

  • Sharing left wide open. The recommendation is to pull general file sharing back to restricted, warn people when they share outside the company, and require outside collaborators to sign in. In most tenants not one of those three has been touched since the day it was set up.
  • Automatic forwarding still switched on. Disabling it is a checklist item in its own right, because a forwarding rule is the standard way somebody keeps hold of a mailbox after compromising it, quietly copying everything to an outside address for as long as nobody thinks to look.
  • The legacy mail protocols still available. Switching them off is recommended explicitly, because those protocols are exactly how a credential-based attack walks around the modern authentication controls everybody assumes are protecting the account.
  • Application grants that nobody has ever reviewed. Checking what outside applications can reach the core services is on the list, and in a tenant a few years old the accumulated grants routinely include products nobody uses any more or recognizes.
Ask us to check these four first
What an audit covers

Eight areas where a Workspace tenant is nearly always weaker than anybody assumes.

Workspace is straightforward to deploy and equally straightforward to leave exactly as it arrived. The checklist exists precisely because the settings that matter are scattered across several admin sections, and not one of them is configured correctly for a business by default.

Two-step verification and security keys

Two separate recommendations sit here. Require two-step verification for everybody, and enforce hardware security keys for administrators and anyone else worth targeting. They are not the same item, and most tenants have done the first and stopped.

Administrator accounts need heightened protection

A super administrator controls every piece of data the organization holds, which is exactly why administrator account practice gets a section of its own. What we find most often is permanent super administrator rights sitting on the account somebody uses to read their email all day.

Drive sharing is nine separate settings

The rules governing sharing beyond the company, warnings when somebody does it, publishing to the web prevented, general access pulled back to restricted, sharing limited to named recipients, outside collaborators required to sign in, plus the settings covering offline access, desktop access and anything holding sensitive data.

Gmail carries the longest list

All three authentication records, encrypted transport with partner domains, the legacy mail protocols switched off, automatic forwarding disabled, comprehensive mail storage enabled, spam filtering handled properly, scanning before delivery, warnings on external recipients, and the separate protections covering attachments, links and spoofing.

Third-party app access is rarely reviewed

Reviewing which outside applications can reach the core services, blocking the ones using weak authentication, building a list of the ones you trust, and controlling access to the core services themselves. Application grants pile up silently and almost nobody ever goes back to look at them.

Groups are a security surface

Using groups built for security rather than repurposed mailing lists, attaching security conditions to administrator roles, making group access private, restricting who can create a group to administrators, and tailoring the access settings. Letting anybody create a group is a common exposure and a very quiet one.

Offboarding is an explicit checklist item

Stopping somebody reaching things after they have left appears on the checklist in its own right, alongside finding and securing compromised accounts and switching off data download where that makes sense. Handling leavers is a security control, not an administrative task belonging to HR.

Monitoring means actually reviewing

Both reviewing the security settings and investigating activity, and reading the administrator audit log, are listed separately. Collection happens by itself. Review does not happen at all unless somebody schedules it, and a log nobody opens gives you evidence afterward and detection never.

The checklist areas

What the published checklist covers, area by area.

Drawn from the checklist aimed at medium and large businesses. An audit takes each item, holds it against your configuration, and records where you stand with the evidence attached.

Area

Administrator accounts

What the checklist covers
Heightened protection for accounts controlling all organizational data

Area

Accounts, authentication

What the checklist covers
Two-step verification across the board, hardware keys for administrators and anyone worth targeting

Area

Accounts, passwords

What the checklist covers
Preventing password reuse and using unique passwords

Area

Accounts, compromise

What the checklist covers
Activity reporting, administrator alerts, sign-in challenges, securing compromised accounts, and what happens when somebody leaves

Area

Apps

What the checklist covers
Reviewing outside access, blocking weakly authenticated apps, a trusted list, core service access, and additional encryption

Area

Drive

What the checklist covers
The external sharing rules and warnings, publishing to the web, general access pulled back, limits on recipients, a sign-in requirement, offline and desktop access, and the rules covering sensitive data

Area

Gmail, authentication

What the checklist covers
SPF, DKIM and DMARC, plus TLS with partner domains

Area

Gmail, access

What the checklist covers
Legacy mail protocols switched off, automatic forwarding disabled, comprehensive mail storage enabled

Area

Gmail, protection

What the checklist covers
Scanning before delivery, warnings on external recipients, the attachment, link and spoofing protections, and scanning for sensitive data

Area

Groups and monitoring

What the checklist covers
Groups built for security, conditions on administrator roles, private access, limits on who can create one, and reading both the settings and the administrator log
AreaWhat the checklist covers
Administrator accountsHeightened protection for accounts controlling all organizational data
Accounts, authenticationTwo-step verification across the board, hardware keys for administrators and anyone worth targeting
Accounts, passwordsPreventing password reuse and using unique passwords
Accounts, compromiseActivity reporting, administrator alerts, sign-in challenges, securing compromised accounts, and what happens when somebody leaves
AppsReviewing outside access, blocking weakly authenticated apps, a trusted list, core service access, and additional encryption
DriveThe external sharing rules and warnings, publishing to the web, general access pulled back, limits on recipients, a sign-in requirement, offline and desktop access, and the rules covering sensitive data
Gmail, authenticationSPF, DKIM and DMARC, plus TLS with partner domains
Gmail, accessLegacy mail protocols switched off, automatic forwarding disabled, comprehensive mail storage enabled
Gmail, protectionScanning before delivery, warnings on external recipients, the attachment, link and spoofing protections, and scanning for sensitive data
Groups and monitoringGroups built for security, conditions on administrator roles, private access, limits on who can create one, and reading both the settings and the administrator log
How we approach it

Four things that make a Workspace audit worth doing.

A configuration audit is easy to produce and just as easy to file away unread. The value sits entirely in ordering the changes so they can actually be applied without provoking a revolt.

We work through the published checklist item by item

This is not a generic cloud security review. The checklist for medium and large businesses is specific and publicly available, which means every finding maps to a recommendation your own team can go and read rather than to our opinion about what good looks like.

We separate low-friction changes from disruptive ones

Switching off the legacy protocols and automatic forwarding changes almost nothing for most people while removing a great deal of risk. Restricting Drive sharing changes how people collaborate every day and needs telling them first. Those two do not belong in the same batch, so we do not present them as one.

We enumerate application grants properly

Outside applications reaching the core services accumulate quietly across years, and the list almost always contains things nobody remembers approving. Going through it produces removals the same afternoon, plus a trusted list that stops the position drifting all over again.

We leave monitoring with an owner

Reviewing the settings, investigating activity and reading the administrator log are all checklist items in their own right. Without somebody named as responsible and a date in the calendar, all three are aspirations, and the tenant quietly returns to roughly where it began.

How an engagement runs

Three phases across roughly three to six weeks.

Short, because everything is configured from one place. Most of the elapsed time goes on the change control needed to apply what we find without disrupting how people actually work.
  1. 01
    Weeks 1 to 2

    Assess against the checklist

    Every item taken in turn against the real configuration, recording where things genuinely stand rather than where somebody intended them to be. Administrator account practice, the application grants and Drive sharing are where the biggest findings nearly always come from.

    • Position recorded per checklist item
    • Administrator accounts and role assignments reviewed
    • Third-party application grants enumerated
    • External sharing exposure quantified
  2. 02
    Weeks 3 to 4

    Prioritize and plan the changes

    Ordered by how much risk each removes set against how much it inconveniences people. Switching off the legacy protocols and automatic forwarding is high value and almost nobody notices. Tightening Drive sharing is equally valuable and needs telling people first, because it genuinely changes how they work together.

    • Findings prioritized by risk and disruption
    • Changes grouped into low-friction and communicated batches
    • Exceptions identified with business justification
    • Rollback position defined per change
  3. 03
    Weeks 5 to 6

    Apply, verify, and hand over monitoring

    The changes go in sequence, each verified against real accounts rather than assumed, and then the monitoring practices get established, because reviewing the security settings and reading the administrator log are both checklist items rather than optional extras somebody might get to.

    • Changes applied and verified on real accounts
    • Admin alerts configured for risky events
    • Audit log review cadence established with an owner
    • Reassessment scheduled
Where this comes up

Six situations that prompt a Workspace audit.

Workspace usually arrives fast in a growing business, and the security review happens several years later, when something external forces the question.

A business that grew into Workspace

A tenant created for six people and now carrying six hundred still holds configuration decisions made when the risk looked nothing like it does today. Nothing ever prompts a review, because from the outside nothing has broken.

An organization after an account compromise

The questions asked afterward are always the same four. Was two-step verification actually enforced. Were the legacy protocols switched off. Could somebody have set up forwarding. And would the audit log have shown any of it. Every one of those is a checklist item.

A firm facing customer, insurer, or SOC 2 scrutiny

Security questionnaires, insurance applications and SOC 2 audits all ask about external sharing, who can reach what data, and how administrative control is handled, and every answer needs actual configuration standing behind it. Assessing against a published checklist from the vendor themselves is a straightforward and credible way to produce those answers.

An education institution on Workspace

A large population, a great deal of collaboration with people outside, and group structures open by tradition all make the sharing and group settings unusually consequential. The recommendations about restricted access and limiting who can create a group matter more in this environment than almost any other.

A company where sharing has clearly gone broad

When it emerges that files are readable by anybody holding the link, the fix has both a technical and a human half. Pulling general access back to restricted handles the first, and warning people at the moment they share outside handles the second.

An organization tightening administrative control

A super administrator can reach everything the company holds, which is exactly why protecting those accounts gets its own section. Cutting how many there are, separating administrative accounts from the ones people use daily, and requiring hardware keys is nearly always the first change we make.

Three positions

How US organizations run their Workspace tenant.

The middle column describes most tenants we open. Somebody tightened the settings once during a project, and nothing has been revisited since, while both the company and the platform underneath it kept changing.
Two-step verification enforced
Audited against the checklistYes, with keys for admins
Configured once at setupUsually enabled
Left at defaultsOptional
Super admin count controlled
Audited against the checklistMinimized and reviewed
Configured once at setupGrown over time
Left at defaultsUnknown
External sharing restricted
Audited against the checklistDeliberately configured
Configured once at setupPartially
Left at defaultsBroad
Legacy protocols disabled
Audited against the checklistYes
Configured once at setupSometimes
Left at defaultsEnabled
Automatic forwarding disabled
Audited against the checklistYes
Configured once at setupRarely
Left at defaultsEnabled
Third-party app grants reviewed
Audited against the checklistRegularly
Configured once at setupNever
Left at defaultsNever
Email authentication complete
Audited against the checklistSPF, DKIM and DMARC
Configured once at setupPartial
Left at defaultsPartial or none
Admin audit log reviewed
Audited against the checklistOn a cadence
Configured once at setupAfter incidents
Left at defaultsNever
Group creation controlled
Audited against the checklistLimited to admins
Configured once at setupVaries
Left at defaultsOpen
Effort to reach
Audited against the checklistWeeks
Configured once at setupA project, once
Left at defaultsNone
Feature
Audited against the checklist
Configured once at setup
Left at defaults
Two-step verification enforced
Yes, with keys for adminsUsually enabledOptional
Super admin count controlled
Minimized and reviewedGrown over timeUnknown
External sharing restricted
Deliberately configuredPartiallyBroad
Legacy protocols disabled
YesSometimesEnabled
Automatic forwarding disabled
YesRarelyEnabled
Third-party app grants reviewed
RegularlyNeverNever
Email authentication complete
SPF, DKIM and DMARCPartialPartial or none
Admin audit log reviewed
On a cadenceAfter incidentsNever
Group creation controlled
Limited to adminsVariesOpen
Effort to reach
WeeksA project, onceNone
Email deserves separate attention

Twelve items on the checklist are Gmail settings alone, and none of them substitutes for another.

Mail is still the way most attackers get in, and the checklist reflects that by carrying more recommendations here than in any other section.

  • Authentication comes first, and all three records are recommended together. The last of the three is the one companies most often leave in a monitoring-only state, which gives you visibility into the problem while doing nothing whatsoever to stop it.
  • Then access. Switching off the legacy mail protocols closes that route entirely, and disabling automatic forwarding removes the single most common way somebody holds onto a mailbox after compromising it. Both are one setting each, and both are worth far more than the effort suggests.
  • Then the protections. Enhanced scanning before a message is delivered, warnings when somebody is emailing outside the company, extra attachment handling, extra checking of links and external content, and additional spoofing defenses. Each of those is a separate recommendation rather than one switch.
  • And one specific warning about internal senders. The advice is not to bypass spam filtering for mail from inside the company, which is exactly the exception organizations add for convenience, and which then waves a compromised internal account straight through every filter you own.
Ask us to review your Gmail configuration
How an engagement runs

Five steps, ending with somebody owning the monitoring.

A tenant audited once and then left alone is back where it started inside a year. That last step is the only thing that makes everything before it stick.
  1. 1

    Record the current state per checklist item

    Accounts, administrator accounts, applications, Drive, Gmail, Groups and monitoring. What is genuinely configured rather than what somebody meant to configure, because those two part company in every tenant that has been running more than a couple of years.

  2. 2

    Quantify the exposure the findings represent

    The number of files shared outside the company, the number of application grants standing, the number of accounts without two-step verification, and the number of super administrators. Numbers are what make prioritizing possible, and they are what turns a conversation with management from a preference into a case.

  3. 3

    Apply the low-friction changes first

    Legacy protocols and automatic forwarding switched off, hardware keys required for administrators, alerting configured, and the mail authentication records finished. High value, almost invisible to anybody doing their job, and achievable within days.

  4. 4

    Plan and communicate the disruptive ones

    Pulling back general file sharing, requiring outside collaborators to sign in, and limiting who can create a group all change how people work day to day. With communication beforehand and a documented way to request an exception they succeed. Without either, they get reversed within a month.

  5. 5

    Establish review and reassessment

    Reviewing the settings, investigating activity and reading the administrator log, each with somebody named as responsible and a rhythm to it, plus a reassessment already in the calendar, because both the platform and the company will keep changing underneath you.

Straight answers

What organizations ask about Workspace security.

Yes. There is a published security checklist aimed at medium and large businesses, covering administrator accounts, ordinary accounts, applications, Drive, Gmail, Groups and monitoring. An audit works through it against your tenant specifically rather than against general good practice.

Usually requiring two-step verification across the whole company, with hardware keys on top for administrators and anybody else worth targeting. Those are two distinct recommendations, and most tenants have done the first and never got to the second.

The checklist recommends it. Legacy protocols provide an access path that can bypass the modern authentication controls an organization believes are protecting accounts, which makes them a favored route in credential-based attacks.

Because it is how somebody keeps hold of a mailbox after taking it over. A forwarding rule copies everything to an outside address indefinitely and says nothing to anybody. Switching the capability off removes the mechanism outright, rather than leaving you dependent on noticing it.

Four related recommendations. Pull general file sharing back to restricted, warn people at the moment they share outside the company, limit access to the named recipients only, and require anybody outside to sign in properly.

Regularly, and the advice pairs reviewing what outside applications can reach the core services with maintaining a list of the ones you trust. In a tenant a few years old, what has accumulated almost always includes products nobody in the building recognizes any more.

All three authentication records are recommended together, with encrypted transport enforced to partner domains alongside. The third of the three is the one most often sitting in a monitoring-only state, showing you the abuse in a report while preventing not one message of it.

As few as the organization can operate with, and separated from daily working accounts. Super administrators control all organizational data, which is why the checklist treats their protection as a topic in its own right. Minimize the number, enforce security keys on them, and review the list regularly.

Rarely, and reading the administrator log is a checklist item precisely because of that. The distinction worth holding onto is between collection, which happens by itself, and review, which happens only where somebody owns it against a date.

Some of it yes, most of it no. Switching off the legacy protocols and automatic forwarding is invisible to almost everybody. Restricting external sharing changes how people collaborate every day, and it lands successfully only with communication first and a documented way to ask for an exception.

The structure is similar and the specifics differ entirely. Both platforms publish security guidance, both default to usability over restriction, and both accumulate application grants and sharing exposure that nobody revisits after deployment. If you run both platforms, the two audits together cover the whole collaboration estate.

Three to six weeks for most organizations, with the assessment itself quick and the change control taking the remaining time. Tenants with several domains or organizational units and heavy external collaboration sit at the longer end. Each engagement is scoped per organization by user count, domains, and organizational units. The free first step: check whether automatic forwarding is disabled in your tenant. It is one setting, and the answer is informative about the rest.
Tenant check

Fifteen questions to ask about your Workspace tenant.

Every one of these maps to a published item. The ones people hesitate over are invariably the ones nobody has looked at since the tenant was first created.

Accounts

  • Is two-step verification required for everyone?
    Required, not available.
  • Do admins use security keys?
    A separate recommendation.
  • How many super admins are there?
    Usually more than needed.
  • Are admin email alerts configured?
    For risky events.
  • What happens to a leaver account?
    An explicit checklist item.

Data and email

  • Is general access set to restricted?
    The recommended setting.
  • Are users warned on external sharing?
    A separate control.
  • Can users publish to the web?
    Recommended to prevent.
  • Are IMAP and POP disabled?
    Recommended.
  • Is automatic forwarding disabled?
    Also recommended.

Apps and oversight

  • When were app grants last reviewed?
    They accumulate silently.
  • Is there a trusted app list?
    A checklist item.
  • Can anybody create groups?
    Recommended to limit.
  • Who reads the admin audit log?
    Review is the item.
  • Do we bypass spam filters internally?
    Recommended not to.
Related reading

The pages around this one.

Microsoft 365 security audit

The same exercise on the other platform.

Learn more

Email security audit

Email specifically, across platforms.

Learn more

Google Workspace services

The wider Workspace practice: administration, migration, and support.

Learn more
Next step

Go and check whether automatic forwarding is switched off in your tenant.

One setting, about a minute of your time. Whichever way it comes back, it tells you a great deal about how the rest of that checklist would score if anybody worked through it.

Book a Workspace security auditSee the audit practice

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Independent Microsoft 365 tenant security audit for US organizations

Learn more

Email Security Audit

Email security audits for US organizations: sending domain inventory

Learn more

Cloud Security Posture Audit

Cloud security posture audits for US organizations: true inventory

Learn more

IT Compliance

HIPAA, SOC 2, NIST, CMMC, CCPA readiness

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA