Google Workspace gives businesses excellent security tools. But “available” isn’t the same as “switched on and configured properly”. Many Workspaces are set up quickly, then grow for years without anyone revisiting the settings.
Your Workspace holds your email, your identities, your documents and the connections to everything else. That makes it part of your security perimeter. Here are seven areas worth checking.
1. Who has administrator access
Admin accounts can change anything. They should be few, named, protected with strong multi-factor authentication and — ideally — separate from the account someone uses for everyday email.
Worth asking: how many people have admin rights, and does each of them still need them?
2. Multi-factor authentication for everyone
2-Step Verification is one of the most effective protections against account takeover. It works best when it’s enforced for every user, not left optional.
Worth asking: is it enforced, or just available?
3. Email authentication: SPF, DKIM and DMARC
These three records help receiving mail servers confirm that email claiming to come from your domain really does. Without them, it’s easier for someone to impersonate you — and your legitimate email is more likely to land in spam.
Worth asking: are all three in place, and is DMARC set to do more than just monitor?
4. External sharing in Drive
Sharing is what makes Workspace useful. It’s also how sensitive files end up visible to people outside the business — sometimes to anyone with the link.
Worth asking: what are the default sharing settings, and do you know which files are shared publicly?
5. Third-party apps with access to your data
Over time, staff connect apps to their Workspace accounts — schedulers, add-ons, AI tools. Some of those apps can read email or files.
Worth asking: which apps have access, what can they see, and who approved them?
6. Dormant accounts and leavers
Accounts belonging to people who have left, or that haven’t been used in months, are an easy target. Joiner and leaver processes should make sure access is removed promptly and data is kept where it’s needed.
Worth asking: what happens to someone’s account on their last day?
7. Logging, retention and investigation
If something did go wrong, could you find out what happened? Audit logs, retention rules and — on editions that include it — Google Vault all play a part in governance and investigation.
Worth asking: how long is data retained, and could you investigate a suspicious login or an unexpected file share?
Where to start
None of these checks requires deep technical knowledge to ask about. Answering them properly is another matter — that’s what a structured Workspace Security Review is for.