A Google Workspace tenant that's been running for a year or two without a dedicated admin review tends to accumulate the same set of problems — default settings that haven't been hardened, third-party apps with excessive permissions, and sharing controls that are far more open than anyone realizes.
This is a practical checklist for Workspace admins managing 25 to 200 users. It covers the controls that matter most for SMBs and takes a direct, implementation-focused approach rather than a theoretical overview.
1. Enforce 2-Step Verification for All Users
Google's 2-Step Verification is the identity protection baseline. It should be enforced — not just encouraged — across all users in your organization. The Admin Console allows you to set enrollment periods and enforcement dates by organizational unit, which lets you phase rollout for teams that need preparation time.
Go to Admin Console → Security → 2-step verification → Allow users to turn on 2SV, then set enforcement. For higher-security users (admins, executives, finance), require hardware security keys rather than SMS or authenticator apps.
2. Audit Third-Party App Access
When a user installs a Google Workspace Marketplace app or grants OAuth access to a third-party service, that app gains access to their data — sometimes with broader permissions than the user realizes. Over time, a typical Workspace environment accumulates dozens of authorized apps, many no longer actively used.
Admin Console → Security → API controls → Manage third-party app access. Review all apps with access to core Workspace data. Revoke any that are no longer in use or that have excessive scope relative to their function. Consider restricting new installs to admin-approved apps only.
3. Configure Drive Sharing Controls
Google Drive's default sharing settings are designed for broad collaboration, not for controlled data environments. By default, users can share files externally with anyone who has the link — which means sensitive documents can leave your organization with a single click.
Admin Console → Apps → Google Workspace → Drive and Docs → Sharing settings. Restrict external sharing to specific trusted domains where possible. Disable link sharing with "anyone with the link" for users handling sensitive data. Enable drive audit logs to track external sharing events.
4. Set Up Google Vault for Retention
Google Vault provides litigation hold, audit, and retention capabilities for Gmail, Drive, Chat, and Meet. For organizations subject to any compliance or legal discovery obligations, Vault configuration is not optional.
Even for organizations without formal compliance requirements, retention policies in Vault protect against accidental deletion of important communications and provide an audit trail for security investigations.
5. Review Admin Role Assignments
Super Admin is the highest privilege role in Google Workspace. Most organizations should have no more than two or three Super Admin accounts — and those accounts should not be the same accounts used for daily email and calendar use. Dedicated admin accounts with strong authentication, used only for administrative tasks, significantly reduce your exposure.
Admin Console → Account → Admin roles. Review who holds Super Admin. Create delegated admin roles for specific functions (User Management, Groups Admin, Help Desk Admin) and assign the minimum necessary privileges. Document admin role assignments and review them quarterly.
A structured Google Workspace security review covers all of these areas — and produces a written findings report your team can work from directly.
