Google Workspace identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Google Workspace, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Workspace connector needs.
Checks (5)
severity: high Admin Without 2-Step Verification fix difficulty: medium #
Enforce 2-Step Verification enrollment for all Google Workspace admin accounts
- Navigate to Google Admin Console > Security > 2-Step Verification
- Enable 2-Step Verification enforcement for admin accounts
- Set enforcement date and grace period
- Notify admin users to enroll in 2-Step Verification
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Admin 2-Step Verification Not Enforced fix difficulty: easy #
Set Google Workspace 2-Step Verification to Enforced for admin organizational units
- Navigate to Google Admin Console > Security > 2-Step Verification
- Select the admin organizational unit
- Set 2-Step Verification to Enforced
- Save changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Delegated Admin Without 2-Step Verification fix difficulty: medium #
Require 2-Step Verification enrollment for all Google Workspace delegated admin accounts
- Navigate to Google Admin Console > Security > 2-Step Verification
- Ensure enforcement applies to all admin roles including delegated admins
- Notify delegated admins to enroll in 2-Step Verification
- Set enforcement date
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high User Without 2-Step Verification fix difficulty: medium #
Enforce 2-Step Verification enrollment for all Google Workspace users
- Navigate to Google Admin Console > Security > 2-Step Verification
- Enable 2-Step Verification for all users
- Set an enforcement date with adequate grace period
- Communicate the requirement to all users
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high User 2-Step Verification Not Enforced fix difficulty: easy #
Set Google Workspace 2-Step Verification to Enforced for the root organizational unit
- Navigate to Google Admin Console > Security > 2-Step Verification
- Set 2-Step Verification to Enforced for the root organizational unit
- Save changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC5.2 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4