Skip to content

Google Workspace configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Google Workspace, Black Cat runs 21 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Workspace connector needs.

Checks (21)

severity: high Domain Not Verified fix difficulty: medium #

Add the required DNS TXT or CNAME record to verify the Google Workspace domain

  1. Navigate to Google Admin Console > Account > Domains > Manage Domains
  2. Select the unverified domain
  3. Follow the verification instructions (add TXT or CNAME DNS record)
  4. Click Verify after DNS propagation completes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high DKIM Not Configured fix difficulty: medium #

Generate and publish a DKIM TXT record in DNS to authenticate outbound Gmail messages

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Authenticate Email
  2. Select the domain and click Generate New Record
  3. Add the DKIM TXT record to your domain's DNS
  4. Return to the Admin Console and click Start Authentication

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Group Spam Moderation Disabled fix difficulty: easy #

Enable spam message moderation for Google Workspace groups

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group with spam moderation disabled
  3. Click Group Settings and enable spam message moderation
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Gemini Not Licensed fix difficulty: easy #

Purchase or assign Google Workspace Gemini licenses to eligible users

  1. Navigate to Google Admin Console > Billing > Subscriptions
  2. Purchase or assign Gemini licenses as needed
  3. Navigate to Directory > Users and assign licenses to users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Gemini Enabled Without DLP fix difficulty: medium #

Configure DLP rules before Gemini for Workspace is exposed to users

  1. Navigate to Google Admin Console > Security > Data protection
  2. Create DLP rules to detect and protect sensitive content
  3. Apply the rules to the organizational units where Gemini is enabled
  4. Navigate to Apps > Google Workspace > Gemini to review the service toggle

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Gemini Active Without DLP fix difficulty: medium #

Configure DLP rules — Gemini usage was observed with no DLP coverage in place

  1. Navigate to Google Admin Console > Security > Data protection
  2. Create DLP rules to detect and protect sensitive content
  3. Apply the rules to the organizational units where Gemini is enabled
  4. Review recent Gemini activity in Reporting > Audit and investigation

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Automatic Email Forwarding Enabled fix difficulty: easy #

Disable automatic email forwarding in Google Workspace Gmail compliance settings

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Compliance
  2. Locate the Auto-Forwarding setting
  3. Disable automatic email forwarding for the organization
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium IMAP Access Enabled fix difficulty: easy #

Disable IMAP access in Google Workspace Gmail end user access settings

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > End User Access
  2. Disable IMAP access for the organization
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium POP Access Enabled fix difficulty: easy #

Disable POP access in Google Workspace Gmail end user access settings

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > End User Access
  2. Disable POP access for the organization
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Drive Shared Drive Creation Unrestricted fix difficulty: easy #

Restrict Google Drive shared drive creation to admins only

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings
  2. Under Shared drive creation, select Only users with Manage Shared Drive permission (admins)
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.3 SOC 2 Type II CC6.3 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Shared Drive No Admin Restrictions fix difficulty: easy #

Enable admin restrictions on the flagged Google Workspace shared drive

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
  2. Select the flagged shared drive
  3. Enable the setting to require admin approval for changes to shared drive settings
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Shared Drive Folder Sharing Unrestricted fix difficulty: easy #

Restrict folder sharing in the flagged Google Workspace shared drive to members only

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
  2. Select the flagged shared drive
  3. Review and restrict folder-level sharing settings so only members can share folders
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Chat Webhooks Enabled fix difficulty: easy #

Disable Google Chat incoming webhooks for org units that do not need them

  1. Navigate to Google Admin Console > Apps > Google Workspace > Google Chat > Chat apps settings
  2. Turn off 'Allow users to install Chat apps' > incoming webhooks for the affected org units
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Gmail Confidential Mode Disabled fix difficulty: easy #

Enable Gmail confidential mode to protect sensitive email content

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > User settings
  2. Enable Confidential mode
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Gmail Send-As External Alias fix difficulty: easy #

Review Gmail send-as aliases using external addresses

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > User settings
  2. Review the flagged user's send-as aliases
  3. Remove external aliases that are not authorized

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Gmail Unverified Send-As Alias fix difficulty: easy #

Remove or verify unverified Gmail send-as aliases

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > User settings
  2. Review the flagged user's unverified send-as aliases
  3. Verify legitimate aliases or remove them

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Meet Recording Unrestricted fix difficulty: easy #

Restrict who can record Google Meet meetings

  1. Navigate to Google Admin Console > Apps > Google Workspace > Google Meet > Meet video settings
  2. Restrict recording to hosts or specific organizational units
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Weak Password Policy fix difficulty: easy #

Increase the Google Workspace minimum password length to at least 12 characters

  1. Navigate to Google Admin Console > Security > Password management
  2. Set the minimum password length to 12 or more characters
  3. Enforce password strength requirements
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Spoofing Protection Disabled fix difficulty: easy #

Enable Gmail spoofing and authentication protection

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Safety
  2. Enable spoofing and authentication protection options
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.6 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Gmail Encrypted Attachment Protection Disabled fix difficulty: easy #

Enable Gmail attachment safety protection against encrypted attachments

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Safety
  2. Scroll to Attachments
  3. Enable protection against encrypted attachments from untrusted senders
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Gmail Shortener Scanning Disabled fix difficulty: easy #

Enable Gmail link-shortener scanning under Links and external images

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Safety
  2. Scroll to Links and external images
  3. Enable identification of links behind shortened URLs
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Google Workspace checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial