Google Workspace Security Best Practices for UK Businesses (2025)
Google Workspace Security Best Practices for UK Businesses (2025)
Google Workspace is used by millions of UK businesses — and is a major attack target. A compromised admin account gives attackers access to every user's Gmail, Drive, Meet, and Calendar.
10 Core Security Settings
1. Enforce 2-Step Verification for All Users
Admin Console → Security → 2-step verification. Set enforcement to 'On'. Use Google Authenticator or hardware keys. Don't rely on SMS for admin accounts (SIM-swap risk).
2. Review Super Admin Accounts
Maximum 2–3 Super Admins for a small business. Super Admin accounts should not be used for day-to-day email.
3. Configure Third-Party App Access
Admin Console → Security → API Controls. Review every OAuth app. Set a policy requiring admin approval for new third-party OAuth grants.
4. Configure Gmail Security
- Enable enhanced pre-delivery message scanning
- Turn on suspicious link warnings
- Configure DMARC, DKIM, SPF
5. Control External Sharing in Drive
Admin Console → Drive and Docs → Sharing settings. Restrict 'Anyone with the link' sharing. Enable Drive audit logging.
6. Enable Audit Logs
Enable for Gmail, Drive, Admin, and Login events. Retain for at least 6 months.
7. Configure Alert Policies
Set up alerts for: suspicious login activity, Super Admin password reset, new OAuth grants, government-backed attack warnings.
8. Review Data Region Settings
For UK GDPR compliance, consider pinning data to UK/EEA regions (Premium feature).
9. Configure Endpoint Management
Require screen lock, enable remote wipe, enforce encryption on Android devices.
10. Enable Context-Aware Access
Block access from high-risk countries. Require managed devices for sensitive app access.
Continuous Monitoring
Configuring these settings is a one-time task, but threats evolve daily. Gridisys monitors your Google Workspace continuously — every login, admin change, and OAuth grant.