Google Workspace security checklist for small business
For most small companies, Google Workspace is the company: email, files, calendar, payroll scans, customer contracts, the password-reset address for every other SaaS account. And it is usually configured the way the founder configured it in year one — one super admin (themselves), 2SV "encouraged," file sharing on "anyone with the link," and three forwarding rules nobody remembers creating. The platform that holds everything is, by default, the easiest door into everything.
The good news: Workspace is also the cheapest major security upgrade a small business can buy. Almost every high-impact control lives in one console, takes minutes, and costs nothing extra. This checklist is the ninety-minute setup pass, plus a thirty-minute monthly ritual that keeps it true. It pairs with the email security checklist (the human layer) and the SPF/DKIM/DMARC checklist (the spoofing layer) — Workspace touches all three.
1. The admin console: who holds the crown jewels
Everything in this checklist starts with one question: who can change the answers?
- Exactly two named super admins, no more, no fewer. One super admin is a bus factor of one — lose the phone with the 2SV prompt and you are in Google's account-recovery queue, begging, while the company's mail is offline. Five is a misconfiguration waiting to be phished. Two real people, documented in the ops wiki, is the whole range.
- One break-glass account that is not a person. Create a second super admin like
recovery@yourdomain.comwhose password lives (split, if you're careful) in the password manager's emergency vault and whose 2SV is a stored set of backup codes, not a phone. It is used roughly never — and on the one day a founder's account is locked, it is the whole company. - Super admin is a role, not a person's daily account. If a founder reads email from the super-admin account, their inbox is now phishing-target-zero with keys to everything. Use the principle the permission-boundaries checklist spells out for agents: daily accounts get the minimum; powers get delegated; the powerful account does almost nothing.
- Delegate, don't promote. User management can go to the office manager as a delegated admin; group and device roles separately. "Super admin" stays with two people who know what it means.
2. Enforce 2-step verification — and read the exceptions twice
Unenforced 2SV in Workspace is a checkbox, not a control. The enforcement page is Security → Authentication → 2-step verification:
- Turn it on for everyone, with a grace period, and actually enforce. "Allow users to turn on 2SV" is the default; that is opt-in, and opt-in security at small companies lands at about 60%. New users get a one-week enrollment window, then they are locked out until they enroll — which is exactly the pressure that gets to 100%.
- Prefer prompts and security keys over SMS. Google prompt is one tap and far better than SMS; passkeys are better still (see the passkeys rollout). Allow SMS during the transition, then wean. SIM-swap attacks against founders are real and cheap.
- Check the enforcement frequency is not "suspicious sign-in only." The risk-based setting sounds smart and mostly works — but it is the setting that lets a patient attacker in on the third try.
- Advanced Protection Program for the two super admins and the finance owner. It requires security keys or passkeys and blocks the sketchiest apps outright. The people holding the crown jewels get the inconvenience — that is the trade working as designed.
- Store backup codes. Every user's 2SV backup codes go into the password manager on day one. "My phone died" is the phrase that turns a security win into a lockout incident.
3. OAuth apps: the shadow IT you already approved
The scariest screen in Workspace is Security → API controls → App access control. Every third-party app the team has ever clicked "Sign in with Google" on — CRM trials, PDF converters, that meeting-notes tool — holds a scoped grant to mail, files, or calendar, and most small tenants have never looked at the list.
- Review the granted list once, now. Sort by scope. Anything with full Gmail access (read, send, delete) or Drive-wide access that nobody can explain gets revoked. Revoking is safe: the app stops working, someone complains, you re-grant a narrower scope if it earns it.
- Flip new apps from "unrestricted" to "configure." Under app access control, unconfigured third-party apps can be blocked by default; users request access, an admin approves, the grant is logged. This one toggle converts shadow IT from a silent leak into a queue you control.
- Watch for the impersonation classes. Apps named like Google ("GmaiI", "Workspace Sync") or requesting scopes unrelated to their job (a calculator asking for Gmail read) are the classic phish — the user approves the OAuth consent screen themselves, no password needed. Teach the one-line rule in the phishing drill: reading the permission list on a consent screen is the new checking the sender.
- Re-grant on a schedule, not on trust. Any OAuth grant that survives the quarterly annual review with no business owner named gets revoked by default. Apps, like keys in the rotation checklist, are guilty until in use.
4. Mail rules: audit forwarding, delegation, and filters
Business email compromise in Workspace rarely breaks the door — it is invited in by a rule the attacker (or a user, "to check email on vacation") created:
- Audit automatic forwarding company-wide, monthly. Admin console → Gmail → End user access shows forwarding, delegation, and IMAP state. Any auto-forward to a non-company address is a finding: confirm it with the user in person, then delete it. The classic BEC play is a quiet forwarding rule plus an altered invoice — the invoice-fraud checklist covers the wire half; this is the visibility half.
- Check mailbox delegation on the finance and founder mailboxes first. Delegate access is legitimate for assistants and auditors — and invisible to the mailbox owner. The finance mailbox gets a named, dated delegate list, reviewed like any other access list (the offboarding checklist owns removing them).
- Gmail filters that auto-forward or delete count as exfiltration. Users can hide rules in settings that no admin console shows by default. The monthly pass includes asking each admin-level user to screenshot their filter list — thirty seconds each, and it catches the rule that has been silently mailing your invoices somewhere else since March.
- Turn on the security sandbox and attachment warnings in Gmail settings (where your edition includes them), and leave the external-image warning on: tracking pixels in phishing mail are still the cheapest recon tool an attacker has.
5. Sharing defaults: match reality, not paranoia
Drive sharing is where small businesses oscillate between "anyone with the link" (leaks) and "locked down" (users forge workarounds with personal accounts, which leaks worse). Pick defaults that match how the company actually works:
- Default link sharing: "restricted." People share with named collaborators; the link blast goes out only when someone deliberately chooses it. The deletion-request checklist and any customer contract both get dramatically easier when files are shared with people, not with the internet.
- Turn off "anyone with the link" for Shared Drives containing financials and HR. Those two folders hold the documents that cost the most when leaked and answer the questions the customer questionnaire asks.
- Set an external-sharing rule you can actually live with. "View only, no download, no commenting by outsiders" for the company-wide folders; full collaboration inside teams. If contractors need real access, guest them properly into the domain — managed, reviewable, and removable by the vendor offboarding checklist.
- Kill "publish to the web" by default. It is the setting that turns an internal pricing sheet into a public URL because someone wanted to embed it in a slide.
6. Offboarding and the license trap
Workspace's quiet failure mode: an offboarded employee keeps mail flowing for months because deleting the account deletes the mailbox archive someone will need for the contract dispute.
- Suspend first, delete later. Day one of an exit: suspend the account (access dead, mailbox intact), forward no mail yet, and reset the password so active sessions die. Deletion is a decision for month three, not minute one — the offboarding runbook owns this file.
- Transfer the artifacts that matter: Drive files to a shared drive (ownership moves with the file), calendar to a delegate, and the mailbox itself — either a paid archive-license or a Google Takeout export into cold storage, per the retention policy.
- Revoke the OAuth grants, not just the password. A suspended user's third-party app tokens die with the account — but the shared API keys and the OAuth grants other users made for that person's tools do not. The exit-day sweep is the same one as the access checklist: password, sessions, 2SV factors, delegated access, devices, tokens.
- Watch the license bill as the audit. An unused paid license that survives three monthly invoices is the system's way of telling you an offboarding step was skipped.
7. Email authentication: your domain, not your provider's problem
Workspace sends mail as your domain; the world has no way to know that unless your DNS says so. This is a fifteen-minute setup with a permanent payoff (the deep how-to lives in the SPF/DKIM/DMARC checklist):
- DKIM: generate in the admin console, publish, and click "start authenticating." Default Google mail signs with its own key unless you turn DKIM on for your domain — the step everyone skips.
- SPF: one
include:_spf.google.comrecord, nothing else in it unless you genuinely send from elsewhere — two SPF records is the classic self-inflicted wound. - DMARC: start at
p=nonewith reports, watch for two weeks, then tighten. Moving straight top=rejecton a domain with legacy senders is how a small business stops receiving its own invoices — from the utility company. - Then keep the blast radius small: if mail rules, OAuth, and admin access are locked down, the spoofing layer is the last cheap door — and this is the one that makes the BEC email fail its first check.
8. Sessions, devices, and the audit trail
- Set web session duration for admin accounts to hours, not weeks. A laptop that stays logged in to the super-admin console for a month is a shared laptop's lost-library-book problem. User sessions can stay long; admin sessions get short.
- Check devices if your edition has device management — and at minimum, review "recently active" sessions monthly. An old iPhone still holding a Gmail session from a former employee is the offboarding step that was skipped.
- Export the audit logs you can. Admin console → Reporting → Audit gives admin, login, and Drive events. Export monthly into the same evidence folder as the retention policy — when the day comes, "here is the log" beats "we would probably find it."
- Turn on login challenge / suspicious-login emails so the system tells you before you read about it in a customer's reply-all.
9. The mistakes small teams make anyway
- One founder super admin, enforced never. The setup is perfect until the founder's phone goes swimming. Break-glass account or it is a single point of failure wearing a security badge.
- 2SV enforced… except for the executives. The exception list is the target list. Executives get keys and a five-minute tutorial, not an exemption.
- The domain admin email is also the CEO's email. Keep the registry-contact, DNS, and recovery addresses separate from the daily inbox — the same hygiene as the domain checklist.
- "We'll review OAuth after the busy season." The grant you approved in January for a tool the team stopped using in February is still holding a Gmail read scope. Tools expire; grants don't.
- Deleting the mailbox on day one. The contract dispute in month four is why "suspend first" exists.
10. Close the loop: the monthly 30-minute pass
- The pass, minute by minute: forwarding & delegation review (5), new OAuth grants since last month (5), 2SV enrollment gaps — target zero (5), new admin-role changes (5), Drive external-sharing changes in the sensitive folders (5), session & device anomalies (5). One recurring calendar event, one person named in the event, one line of notes.
- Feed the evidence file. The monthly pass produces exactly the artifacts enterprise buyers and cyber-insurance renewals ask for: enforced MFA with screenshots, an OAuth review log, a named admin list. The annual review and the questionnaire responses are then ninety minutes of assembly instead of an afternoon of archaeology.
- Keep the boundary honest: Workspace security is the identity-and-mail layer. The endpoints (the laptop runbook, the server hardening, the device fleet) are separate checklists — one afternoon, done in order, is a materially harder company.
- Remember the economics: ninety minutes once, thirty minutes a month, for the platform that holds the company's mail, money trail, and contracts. That is the highest control-per-dollar ratio in small-business security.