Skip to content

Google Workspace access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Google Workspace, Black Cat runs 17 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Workspace connector needs.

Checks (17)

severity: medium Admin With App Password fix difficulty: medium #

Disable less secure app access for Google Workspace admins and migrate to OAuth authentication

  1. Navigate to Google Admin Console > Security > Less Secure Apps
  2. Disable access for less secure apps for admin OUs
  3. Instruct admin users to revoke existing app passwords
  4. Migrate admin workflows to use OAuth-based authentication

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low User With App Password fix difficulty: easy #

Disable less secure app access organization-wide in Google Workspace

  1. Navigate to Google Admin Console > Security > Less Secure Apps
  2. Disable access for less secure apps organization-wide
  3. Notify users to revoke existing app passwords in their account settings

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium OAuth App With Restricted Scopes fix difficulty: medium #

Revoke Google Workspace user-authorized OAuth apps with restricted or sensitive scopes

  1. Navigate to Google Admin Console > Security > API Controls > App Access Control
  2. Review the user's authorized third-party apps
  3. Revoke access for apps with restricted or sensitive scopes
  4. Configure API access control to block untrusted apps

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Dormant Users fix difficulty: medium #

Suspend or delete dormant Google Workspace accounts after verifying with HR

  1. Navigate to Google Admin Console > Directory > Users
  2. Filter users by last sign-in date to identify dormant accounts
  3. Suspend or delete accounts that are no longer in use
  4. Document the review decision for compliance records

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Never Logged In Users fix difficulty: medium #

Remove Google Workspace accounts that have never been used after confirming with the manager

  1. Navigate to Google Admin Console > Directory > Users
  2. Filter users who have never signed in
  3. Contact the user or manager to confirm whether the account is needed
  4. Suspend or delete unneeded accounts

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high OAuth App Critical Scopes fix difficulty: medium #

Block or limit Google Workspace OAuth apps that have been granted critical scopes

  1. Navigate to Google Admin Console > Security > API Controls > App Access Control
  2. Identify OAuth apps with critical scopes (Gmail, Drive full access)
  3. Block or limit the app unless it is business-approved
  4. Configure app trust policies to prevent future unauthorized apps

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium OAuth App With Restricted Scopes Widely Authorized fix difficulty: medium #

Revoke admin-authorized Google Workspace OAuth apps with restricted scopes that are not business-critical

  1. Navigate to Google Admin Console > Security > API Controls > App Access Control
  2. Review apps with restricted scopes that have been widely authorized
  3. Revoke admin authorization if the app is not business-critical
  4. Document approved apps in your security policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC6.2 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium OAuth App AI With Data Scopes fix difficulty: medium #

Block or limit Google Workspace AI apps that have been granted data access scopes

  1. Navigate to Google Admin Console > Security > API Controls > App Access Control
  2. Identify AI apps that have been granted data access scopes
  3. Evaluate whether the AI app needs data access for its function
  4. Block or limit data scope access for unapproved AI apps

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC5.3 CIS Controls v8 CIS-03.1 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Super Admin Count Excessive fix difficulty: medium #

Reduce Google Workspace Super Admin count to 2-4 by demoting unnecessary admins to specific roles

  1. Navigate to Google Admin Console > Account > Admin Roles
  2. Review users assigned the Super Admin role
  3. Demote unnecessary super admins to more specific admin roles
  4. Keep only 2-4 super admin accounts

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.2 SOC 2 Type II CC6.3 CIS Controls v8 CIS-05.4 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Super Admin Redundancy Missing fix difficulty: easy #

Assign a second trusted user the Super Admin role in Google Workspace for redundancy

  1. Navigate to Google Admin Console > Account > Admin Roles
  2. Verify at least two super admin accounts exist
  3. If only one exists, assign a second trusted user the Super Admin role
  4. Ensure both super admins have 2-Step Verification enrolled

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.2 SOC 2 Type II CC6.3 CIS Controls v8 CIS-05.4 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high SSO Not Configured fix difficulty: hard #

Configure SSO with a third-party IdP in Google Workspace for centralized authentication

  1. Navigate to Google Admin Console > Security > Authentication > SSO with third-party IdP
  2. Click Add SSO Profile
  3. Configure the IdP settings (sign-in URL, certificate, etc.)
  4. Test the SSO flow with a pilot group before full rollout

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-02 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Gemini Unmanaged Actors fix difficulty: medium #

Review Gemini actors absent from Directory user records

  1. Navigate to Google Admin Console > Directory > Users
  2. Cross-reference actors from the Gemini audit log against the user list
  3. Investigate and remove access for any deprovisioned or unrecognized identities

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Super Admin Account Recovery Enabled fix difficulty: easy #

Disable super admin self-service account recovery in Google Workspace

  1. Navigate to Google Admin Console > Security > Account recovery > Super admin account recovery
  2. Turn off 'Allow super admins to recover their account' so recovery requires another super admin
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Gmail App Passwords Active fix difficulty: easy #

Revoke application-specific passwords that bypass 2-Step Verification

  1. Navigate to Google Admin Console > Directory > Users
  2. Select the flagged user and open Security
  3. Revoke the application-specific passwords
  4. Disable app passwords org-wide under Security > Less secure apps where possible

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Gmail Delegate Privileged fix difficulty: medium #

Remove mailbox delegation from privileged admin accounts

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > User settings
  2. Review mailbox delegation for admin accounts
  3. Remove delegation that is not strictly required

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.2 SOC 2 Type II CC6.3 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Gmail Stale Delegates fix difficulty: easy #

Remove mailbox delegates from suspended user accounts

  1. Navigate to Google Admin Console > Directory > Users
  2. Identify suspended users that still have active mailbox delegates
  3. Remove the delegation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.3 SOC 2 Type II CC6.2 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Weak Session Control fix difficulty: easy #

Reduce the Google Workspace web session duration to at most 12 hours

  1. Navigate to Google Admin Console > Security > Google session control
  2. Set the web session length to 12 hours or less
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Google Workspace checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial