Google Workspace's default settings optimise for ease of collaboration โ which means they often leave security gaps wide open. These eight checks take under an hour and cover the misconfigurations most commonly exploited in Google Workspace breaches.
Google Workspace is used by millions of small businesses, and the Google Admin console has powerful security controls โ most of which are either off by default or buried three levels deep in settings. The result is that most tenants are running with significant gaps they don't know about.
This checklist is based on the controls we scan automatically for every Google Workspace tenant enrolled in Workspace Posture Pro. Each item includes exactly where to find the setting and what to change.
Unlike M365, Google Workspace has a few security quirks that catch admins off guard:
๐ก Quick win: Google's Security Health page (Admin console โ Security โ Security health) gives you an instant overview of the most critical settings and flags anything that's at risk. Check it first โ it takes 30 seconds.
Configuration drift is the enemy. A setting that was correct last quarter can change when:
Running this checklist monthly is better than quarterly. Automating it is better than monthly. The value isn't in the initial audit โ it's in catching the change that happened two Tuesdays ago before it becomes a breach.
Practical tips, new threat intel, and product updates. No spam โ unsubscribe anytime.
Workspace Posture Pro connects read-only to your Google Workspace tenant and runs all 8 checks monthly. You get a plain-English digest with your posture score, what changed since last month, and prioritised remediation steps. Setup takes 2 minutes โ no IT ticket needed.
Start Workspace Posture Pro โ $19/mo โ