Google Workspace ships with defaults chosen to get a business running quickly, not to keep it safe. That is a reasonable trade for Google to make and a bad one for you to leave in place. Everything below is a console setting, not a purchase.
Two-step verification, enforced
Making it available is not the same as enforcing it. Until enforcement is on, adoption sits wherever staff left it, which is usually low. Enforce it for everyone, with a short grace period for enrolment.
- Enforce for all users, not just administrators
- Require security keys for super-admin accounts, which resist phishing in a way codes do not
- Disable SMS as a method where you can, since it is the weakest option still commonly offered
- Keep at least two admin accounts enrolled, so losing one device does not lock you out of the tenant
Sharing defaults
This is the setting most often left wrong, and the one most likely to leak a document. Out of the box, a Workspace tenant can be more permissive about external sharing than most businesses expect.
| Setting | Default risk | Recommended |
|---|---|---|
| External sharing | Often broader than intended | Restrict to allow-listed domains where practical |
| Link sharing default | Can default to anyone with the link | Restricted to named recipients |
| Shared drive membership | Managers can add externals | Restrict to administrators |
| Access expiry | No expiry | Set expiry on external access |
Third-party app access
By default users can often grant third-party applications access to their Google account, including mail and files. That is a genuine data-exfiltration route and one that no firewall will see. Restrict app access to reviewed applications and require admin approval for anything requesting sensitive scopes.
The route nobody watches
OAuth app access is the control most often overlooked in a Workspace tenant. A user approving a convenient-looking app can hand over mailbox access without any password being compromised.
Admin role separation
- Nobody should do daily work signed in as super-admin
- Use delegated admin roles scoped to what each person actually needs
- Keep a break-glass super-admin account, documented and stored securely, excluded from routine use
- Alert on new admin role assignments, since privilege escalation is what an attacker does after the first foothold
Alerts that reach a person
Workspace can alert on suspicious sign-ins, mass downloads and admin changes. Configure them and route them to a named individual rather than a shared mailbox. An alert nobody reads is worse than no alert, because it creates the impression of monitoring.
Data that survives an employee leaving
Company files belong in shared drives, which are owned by the organisation, rather than in My Drive, which is owned by the user. Configure this at deployment. Fixing ownership after two years of files landing in personal drives is a substantially larger job.
Inherited a Workspace tenant?
We audit existing Google Workspace tenants against this baseline and fix what is open, without disrupting how your staff work.
Frequently asked questions
Is Google Workspace secure by default?
It is secure enough to start with and not secure enough to leave alone. Defaults favour getting a business productive quickly. Two-step verification enforcement, sharing restrictions, third-party app control and admin role separation all need configuring deliberately.
What is the most commonly missed setting?
Third-party app access. Users can often grant applications access to their mail and files without any admin involvement, which is a real data-exfiltration route that no firewall or endpoint tool will see. Restricting it takes minutes.
Should we use security keys?
For super-admin accounts, yes. They resist phishing in a way that codes and prompts do not, and admin accounts are the highest-value target in any tenant. For general staff, app-based verification is usually a reasonable balance of security and practicality.
Why do shared drives matter for security?
Because ownership determines what happens when someone leaves. Files in shared drives belong to the organisation and stay put. Files in personal My Drive leave with the account unless ownership is transferred first, which is easy to forget during an exit.
Can we apply this to an existing tenant?
Yes, and we do it regularly. The main consideration is sequencing, since tightening sharing defaults on a live tenant can break existing links. We audit first, identify what would break, and stage the changes rather than applying everything at once.
Usman K.
· IT Support LeadIT support lead at Azizi Technologies. Manages 24/7 helpdesk, Microsoft 365 migrations, server administration, and managed IT contracts for Dubai SMBs. Microsoft Certified. Mentioned by name in client reviews for fast resolution.
Need a quote for Google Workspace Setup Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.