Cloud & Suites
Google Workspace: 10 security policies to enable on day one
You use Google Workspace ? In 60–90 minutes, secure the essentials.
- Mandatory MFA (enforcement) for everyone.
- Context-aware access : block suspicious logins (country, non-compliant device).
- Admin roles : no more permanent "super" admin; named accounts + logs.
- Drive sharing : no "Public on the Web", limits on external domains, alerts on overly broad links.
- Basic DLP : monitoring of sensitive numbers, mass exports.
- OAuth : only allow verified apps (limit scopes).
- Gmail : SPF/DKIM/DMARC, external sender banners, sandbox attachments (depending on edition).
- Endpoint Management : encryption, password, screen lock.
- Logging/Vault : appropriate legal retention, alerts on risky behavior.
- Training : 30 min anti-phishing + sharing rules.