Google Workspace configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Google Workspace, Black Cat runs 21 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Workspace connector needs.
Checks (21)
severity: high Domain Not Verified fix difficulty: medium #
Add the required DNS TXT or CNAME record to verify the Google Workspace domain
- Navigate to Google Admin Console > Account > Domains > Manage Domains
- Select the unverified domain
- Follow the verification instructions (add TXT or CNAME DNS record)
- Click Verify after DNS propagation completes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high DKIM Not Configured fix difficulty: medium #
Generate and publish a DKIM TXT record in DNS to authenticate outbound Gmail messages
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Authenticate Email
- Select the domain and click Generate New Record
- Add the DKIM TXT record to your domain's DNS
- Return to the Admin Console and click Start Authentication
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Group Spam Moderation Disabled fix difficulty: easy #
Enable spam message moderation for Google Workspace groups
- Navigate to Google Admin Console > Directory > Groups
- Select the group with spam moderation disabled
- Click Group Settings and enable spam message moderation
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Gemini Not Licensed fix difficulty: easy #
Purchase or assign Google Workspace Gemini licenses to eligible users
- Navigate to Google Admin Console > Billing > Subscriptions
- Purchase or assign Gemini licenses as needed
- Navigate to Directory > Users and assign licenses to users
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Gemini Enabled Without DLP fix difficulty: medium #
Configure DLP rules before Gemini for Workspace is exposed to users
- Navigate to Google Admin Console > Security > Data protection
- Create DLP rules to detect and protect sensitive content
- Apply the rules to the organizational units where Gemini is enabled
- Navigate to Apps > Google Workspace > Gemini to review the service toggle
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Gemini Active Without DLP fix difficulty: medium #
Configure DLP rules — Gemini usage was observed with no DLP coverage in place
- Navigate to Google Admin Console > Security > Data protection
- Create DLP rules to detect and protect sensitive content
- Apply the rules to the organizational units where Gemini is enabled
- Review recent Gemini activity in Reporting > Audit and investigation
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Automatic Email Forwarding Enabled fix difficulty: easy #
Disable automatic email forwarding in Google Workspace Gmail compliance settings
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Compliance
- Locate the Auto-Forwarding setting
- Disable automatic email forwarding for the organization
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium IMAP Access Enabled fix difficulty: easy #
Disable IMAP access in Google Workspace Gmail end user access settings
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > End User Access
- Disable IMAP access for the organization
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium POP Access Enabled fix difficulty: easy #
Disable POP access in Google Workspace Gmail end user access settings
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > End User Access
- Disable POP access for the organization
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Drive Shared Drive Creation Unrestricted fix difficulty: easy #
Restrict Google Drive shared drive creation to admins only
- Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings
- Under Shared drive creation, select Only users with Manage Shared Drive permission (admins)
- Save changes
Satisfies: ISO 27001:2022 A.8.3 SOC 2 Type II CC6.3 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Shared Drive No Admin Restrictions fix difficulty: easy #
Enable admin restrictions on the flagged Google Workspace shared drive
- Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
- Select the flagged shared drive
- Enable the setting to require admin approval for changes to shared drive settings
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Shared Drive Folder Sharing Unrestricted fix difficulty: easy #
Restrict folder sharing in the flagged Google Workspace shared drive to members only
- Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
- Select the flagged shared drive
- Review and restrict folder-level sharing settings so only members can share folders
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Chat Webhooks Enabled fix difficulty: easy #
Disable Google Chat incoming webhooks for org units that do not need them
- Navigate to Google Admin Console > Apps > Google Workspace > Google Chat > Chat apps settings
- Turn off 'Allow users to install Chat apps' > incoming webhooks for the affected org units
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Gmail Confidential Mode Disabled fix difficulty: easy #
Enable Gmail confidential mode to protect sensitive email content
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > User settings
- Enable Confidential mode
- Save changes
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Gmail Send-As External Alias fix difficulty: easy #
Review Gmail send-as aliases using external addresses
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > User settings
- Review the flagged user's send-as aliases
- Remove external aliases that are not authorized
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Gmail Unverified Send-As Alias fix difficulty: easy #
Remove or verify unverified Gmail send-as aliases
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > User settings
- Review the flagged user's unverified send-as aliases
- Verify legitimate aliases or remove them
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Meet Recording Unrestricted fix difficulty: easy #
Restrict who can record Google Meet meetings
- Navigate to Google Admin Console > Apps > Google Workspace > Google Meet > Meet video settings
- Restrict recording to hosts or specific organizational units
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Weak Password Policy fix difficulty: easy #
Increase the Google Workspace minimum password length to at least 12 characters
- Navigate to Google Admin Console > Security > Password management
- Set the minimum password length to 12 or more characters
- Enforce password strength requirements
- Save changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Spoofing Protection Disabled fix difficulty: easy #
Enable Gmail spoofing and authentication protection
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Safety
- Enable spoofing and authentication protection options
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.6 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Gmail Encrypted Attachment Protection Disabled fix difficulty: easy #
Enable Gmail attachment safety protection against encrypted attachments
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Safety
- Scroll to Attachments
- Enable protection against encrypted attachments from untrusted senders
- Save changes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Gmail Shortener Scanning Disabled fix difficulty: easy #
Enable Gmail link-shortener scanning under Links and external images
- Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Safety
- Scroll to Links and external images
- Enable identification of links behind shortened URLs
- Save changes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10