Google Workspace Control Walkthroughs
Prioritised for Yam — Prioritised for the Q3 hardening engagement.
Progress is saved locally in your browser — no information is ever sent to our server. Note that because of this input is not synced across different users.
Tier 0 — do it today
| Control | Status | Est. time |
|---|---|---|
| 1 Enforce 2-Step Verification | 30 min | |
| 2 Alert recipient hygiene + suspicious-login alerts | 1 h | |
| 3 Government-backed attack alert routing | 15 min | |
| 4 Email authentication (SPF/DKIM/DMARC) | 1–2 h | |
| 5 Account inventory (incl. shared/service accounts) | 1–2 h | |
| 6 Super-admin separation & minimal count | 1 h |
Tier 1 — the working baseline
1 7 Phishing-resistant 2SV (FIDO2/passkeys only) 1 8 OAuth app access control / allowlisting 1 9 Marketplace install allowlist 1 10 Chrome managed-profile policy baseline 1 11 Legacy public-share inventory & cleanup 1 12 Web session-length control 1 13 Drive external-sharing restriction / trust rules 1 14 Basic Context-Aware Access (IP/geo) 1 15 Calendar external-sharing lockdown 1 16 Google Chat external containment 1 17 Disable user auto-forwarding & mailbox delegation 1 18 Residual mail & service hygiene 1 19 Break-glass admin + offline backup codes
draft
Tier 2 — hardening
| Control | Status | Est. time |
|---|---|---|
| 20 SSO/SAML to hardened IdP | 1–2 days | |
| 21 Advanced Protection Program (high-risk users) | 1 h | |
| 22 Native multi-party approval | 30 min | |
| 23 Gmail Security Sandbox + safety-toggle verification | 30 min | |
| 24 Data regions (storage) | 15 min | |
| 25 Handling untrusted files at rendering distance | 4–8 h | |
| 26 DLP rules (Drive/Gmail/Chat) | 1–2 days | |
| 27 Device-trust CAA via MDM | 3+ days | |
| 28 MTA-STS + TLS reporting | 1–2 h | |
| 29 Shared-drive architecture | 4–8 h | |
| 30 Vault retention & legal hold | 2–4 h | |
| 31 Audit-log export to SIEM/BigQuery | 4–8 h | |
| 32 Groups for Business exposure lockdown | 30 min | |
| 33 Disable POP/IMAP / app-specific passwords draft | 30 min |
2 20 SSO/SAML to hardened IdP 2 23 Gmail Security Sandbox + safety-toggle verification 2 22 Native multi-party approval 2 21 Advanced Protection Program (high-risk users) 2 24 Data regions (storage) 2 25 Handling untrusted files at rendering distance 2 26 DLP rules (Drive/Gmail/Chat) 2 27 Device-trust CAA via MDM 2 28 MTA-STS + TLS reporting 2 29 Shared-drive architecture 2 30 Vault retention & legal hold 2 31 Audit-log export to SIEM/BigQuery 2 32 Groups for Business exposure lockdown 2 33 Disable POP/IMAP / app-specific passwords
draft
Tier 3 — high-assurance
Everything in this tier is in draft status — shown only as a preliminary direction we're considering.
3 34 Disable Google Takeout
draft
3 35 Witnessed ceremonies + tamper-evident custody
draft
3 38 Cloud session control + admin re-auth
draft
3 36 Split-custody break-glass
draft
3 37 Continuous OAuth re-authorization sweeps
draft
3 39 Directory minimization for targeted staff
draft
3 41 Periodic access recertification
draft
3 42 Color-coded data domains (labels + IRM)
draft
3 40 Scripted JIT admin elevation
draft
3 43 Hardware-key break-glass super-admin
draft
3 44 Vault-account custody of crown jewels
draft
3 45 Mandatory-absence review
draft
3 46 Reading-room enclave (SCIF port, incl. data-copy minimization)
draft
3 47 Deny-by-default IP/geo gating
draft
3 48 CSE self-hosted / HYOK KACLS
draft
3 49 Email gateway interception
draft
3 50 Offline & desktop-sync data minimization
draft
3 51 Privileged Access Workstation for admins
draft
Tier 4 — the deep end
Everything in this tier is in draft status — shown only as a preliminary direction we're considering.
4 53 Honeytoken credential file
draft
4 52 Alert-pipeline heartbeat
draft
4 54 Cloud Identity Free decoy accounts
draft
4 55 Air-gapped recovery identity
draft
4 56 Self-hosted canary corpus
draft
4 57 Canary tokens via commercial console
draft
4 59 Config-drift & persistence sentinel (incl. mail-routing watch)
draft
4 61 Audit-the-auditors alerting
draft
4 58 WORM off-tenant log archive
draft
4 62 Config-as-code with reconciliation
draft
4 63 Travel-mode accounts
draft
4 60 Zero-standing-access delivery pattern
draft
4 64 AI-agent / prompt-injection canary
draft
4 65 Apps Script / add-on / AI-agent governance
draft
4 66 Detection engineering on exported logs
draft
4 68 Multi-tenant compartmentalization
draft
4 69 CSE with Google-partner KACLS
draft
4 67 Purple-team / adversary emulation
draft