Secure Google Workspace for businesses — use MFA, SSO and the Standard tier

Secure Google Workspace for businesses by enforcing multi-factor authentication, single sign-on and device policy, and by using Google Workspace Standard (or higher) so you have retention and e-discovery. Start with enforced 2-step verification and a central admin audit within the first week.

First week

In the first week focus on the access basics that stop most opportunistic compromises. Make two changes immediately: enable organisation-wide multi-factor authentication (MFA) and enforce a single sign-on (SSO) route where possible. MFA closes credential stuffing and password-reuse attacks; SSO lets you revoke access centrally when someone leaves or a device is lost. Configure login session lengths and block legacy authentication protocols on accounts that don’t need them.

Practical tasks to complete in days, not weeks:

  • Turn on enforced 2-step verification for all staff.
  • Set up SSO with your identity provider and retire local admin accounts.
  • Create one admin-only console account and restrict it with an external hardware key.

Keep a short runbook for the helpdesk: how to reissue MFA tokens, how to suspend an account, and who signs off on emergency access. These three items are what stops most urgent incidents from turning into regulated breaches.

First month

After the immediate lock-down, move to data and device controls. Decide which users need unrestricted drive sharing, who should have external sharing disabled, and what devices must be managed. Use Google’s endpoint management or your MDM to enforce disk encryption and screen locks on mobile devices. Apply basic DLP rules to block or flag exports of spreadsheets containing bank details or personal data.

From our experience, Google Workspace Business Starter is priced attractively but skips the compliance controls (retention, e-discovery, Google Vault) most regulated UK businesses need. Standard tier is where GWS becomes appropriate for a regulated business, not the entry SKU. That observation should steer procurement conversations: if you handle regulated data, budget for Standard (or higher) rather than relying on Business Starter’s lower cost.

Checklist for month one:

  • Enable Google Vault or equivalent retention and e-discovery where required.
  • Apply device policies and require managed devices for email access.
  • Roll out targeted DLP rules for payroll, HR and client files.

First quarter

Quarter one is about testing and embedding. Run phishing simulations or tabletop exercises, review admin audit logs, and tighten permissions on shared drives. Schedule role-based access reviews: managers should confirm who still needs edit rights on shared folders. Use group-based access rather than individually assigned permissions to simplify future reviews.

Audit the environment—look for inactive accounts, third-party app permissions, and service accounts with broad privileges. Revoke any OAuth apps that request excessive scopes. Create an incident playbook that lists who notifies clients, when to inform the ICO, and how long forensic preserves are kept. Make sure your backup or archiving solution aligns with retention policies configured in Google Workspace.

If you want ongoing help with configuration or troubleshooting, consider a support contract: for example, our team provides managed admin support and periodic audits through a single contact point to reduce time spent on routine admin tasks. See our Google Workspace support for business page for the type of services that make this sustainable: Google Workspace support for business.

First year

Across the first year build governance and continuous improvement into the calendar. Schedule quarterly access reviews, annual policy refreshes, and a mid-year phishing exercise. Track exceptions and approvals so auditors can see why a user had extended external sharing for a limited period. Maintain a clear relationship between policy documents, technical controls, and evidence stored in your compliance toolset.

Longer-term controls to implement during year one:

  • Data classification and automated DLP at the file level.
  • Periodic third-party app reviews and vendor risk checks.
  • Segmentation of admin duties—no single person should be able to change retention and bypass MFA on production accounts.

Plan to review licensing annually against needs: if regulation or client contracts demand retention and e-discovery, move to Standard or higher at renewal. Make one person accountable for the annual compliance evidence pack so audits don’t become a scramble.

Related reading

FAQ

Do I need Google Workspace Standard or is Business Starter enough?

Most regulated organisations need retention and e-discovery; in our experience Business Starter omits those controls, so you should plan to use Google Workspace Standard or higher when compliance is required.

How quickly should I enforce MFA across my company?

Enforce MFA within the first week of a migration or policy change; making it mandatory immediately reduces the window for credential-based breaches and simplifies later audits.

What should I check during a quarterly security review?

Check inactive accounts, admin privilege changes, third-party app permissions, and the results of any phishing tests; each review should produce a short remediation plan with deadlines.

How long before an auditor expects evidence of retention and e-discovery?

Have retention and e-discovery configured at contract renewal or within 90 days of being told you will face audit; auditors expect technical evidence (logs, Vault holds) rather than verbal assurances.