Google Workspace can hold some of a small business’s most important information: email, files, calendars, shared documents, customer correspondence, internal records, and administrative controls.
Securing that environment requires more than choosing strong passwords. Administrator accounts, 2-Step Verification, Google Drive sharing, third-party application access, email authentication, employee offboarding, device access, recovery planning, and monitoring all affect the security of the Workspace environment.
Google maintains a dedicated security checklist for organizations with 1–100 users. It focuses on practical controls that smaller organizations can operate without building a large enterprise security program. Businesses with stronger regulatory, privacy, or security requirements may need additional controls from Google’s broader administrator guidance.
This Google Workspace security checklist for small business brings those areas together into a practical review that administrators can use to identify unnecessary access, strengthen account protection, and reduce avoidable security gaps.
For businesses reviewing cloud controls more broadly, the cloud security checklist for small business provides a wider framework covering accounts, data, devices, providers, recovery, and operational responsibilities.
Protect the Super Administrator Accounts First
Super administrator accounts deserve the strongest protection because they can make organization-wide changes.
Google recommends that super admins use separate accounts for ordinary day-to-day work and sign in to the super-admin account only when privileged administrative work is required. Google also recommends having more than one super administrator, with each account assigned to a separate person rather than sharing one administrator login.
This creates two important protections.
First, routine browsing, email, and everyday work do not constantly occur inside the most privileged account in the organization.
Second, the organization retains another administrative path if one super-admin account becomes unavailable or compromised.
Do not use a generic shared administrator account such as admin@company for several people. Individual administrator accounts make activity easier to attribute and access easier to revoke.
Recovery information and domain ownership credentials should also be kept securely. Losing access to the only administrator account can turn an ordinary password or device problem into a business continuity issue.
Enforce 2-Step Verification Where It Matters Most
A password should not be the only barrier protecting an important Workspace account.
Google recommends 2-Step Verification for Workspace users and places particular emphasis on administrator accounts and users who handle sensitive business information. Google is also enforcing 2SV for administrator accounts.
Small businesses should begin with super admins and other high-value accounts, then expand protection according to their risk and operating requirements.
Google supports several verification methods. Security keys provide strong phishing resistance, while passkeys, Google prompts, authenticator applications, and other supported methods may also be available depending on the account and configuration. Google describes security keys as its strongest traditional 2SV method.
Do not enforce a new authentication requirement without preparing users first. Confirm enrollment, recovery options, and emergency access before switching a policy from optional to enforced.
Separate Administrative Duties
Not every person who performs an administrative task needs full super-admin access.
Google Workspace supports administrator roles with different privileges. A person responsible for users, Gmail configuration, Drive settings, or another limited function can often receive only the privileges required for that work.
This applies the principle of least privilege.
A staff member who only needs to reset passwords should not automatically receive permission to change every Workspace security setting. Likewise, someone responsible for Drive administration may not need access to sensitive reporting or unrelated administrative functions.
Review administrator roles periodically, particularly after responsibilities change.
Give Every User an Individual Account
Google advises organizations to avoid sharing user accounts.
Each employee should normally work through an individual Workspace identity so that permissions, authentication, audit activity, files, devices, and account lifecycle decisions can be managed separately.
Shared passwords make offboarding difficult and weaken accountability.
Individual accounts also make it easier to suspend access immediately when a user leaves without interrupting other employees who may otherwise have relied on the same login.
For broader guidance on passwords, phishing, access control, and credential protection, see the QuikConsole Security Guide.
Create a Formal Joiner, Mover, and Leaver Process
User lifecycle management should not depend on someone remembering individual settings after an employee has already left.
When a person joins the business, create only the accounts and permissions required for the role.
When the person changes responsibilities, review groups, administrator privileges, shared drives, third-party applications, device access, and other permissions rather than simply adding new access on top of the old access.
When someone leaves, suspend or otherwise secure the account promptly according to the organization’s process, then determine what needs to happen to files, email, groups, application access, delegated permissions, devices, and business records before permanent deletion.
Offboarding deserves particular care when important Drive files are stored in an individual’s My Drive.
Use Shared Drives for Team-Owned Business Files Where Appropriate
Google Shared Drives differ from an individual’s My Drive because files in a Shared Drive belong to the organization rather than one individual. The files remain in the Shared Drive when a team member leaves.
This can make Shared Drives useful for business records that should survive employee turnover.
Examples may include department documents, recurring operational files, company templates, project material, or other records that belong to the organization rather than a single person.
Shared Drives still require access control. Membership, external users, file-level sharing, manager permissions, and download or copy rights can all affect exposure. Some administrative options also vary by Workspace edition.
Do not move sensitive information into a Shared Drive and assume that organizational ownership alone makes the content secure.
Review Google Drive External Sharing
External sharing is one of the most important Google Drive settings for a business to understand.
Google Workspace administrators can control external sharing at the organization, organizational-unit, or group level, depending on the setting. Google also provides options for warnings, trusted domains, and more granular sharing controls in supported configurations.
The goal should not automatically be to block every external collaboration.
Many businesses legitimately share documents with customers, suppliers, accountants, lawyers, contractors, and other partners.
Instead, decide which users genuinely need external sharing and what restrictions are appropriate.
Review whether users can share files publicly, whether external recipients are clearly identified, whether sensitive departments require tighter settings, and whether existing externally shared material is still needed.
Treat Shared Drive Access Separately From File Ownership
Shared Drives solve an ownership problem, but they do not eliminate permission problems.
A user can retain access to sensitive material because they remain a Shared Drive member, belong to a group that grants access, or have been given access to a specific file.
Periodically review important Shared Drive membership, particularly for finance, HR, leadership, customer data, internal operations, or other sensitive areas.
When external members are permitted, verify that their access still has a business purpose.
Configure Gmail Anti-Phishing and Malicious-Content Protections
Google’s small-business security checklist specifically recommends enabling stronger Gmail protections against phishing, malicious attachments, links, and external content.
These controls complement normal Gmail filtering.
Small businesses should review the Gmail security settings available in their own Admin console rather than assuming that default behavior covers every organizational requirement.
Users should also be trained to question unexpected credential requests, payment changes, shared-document messages, password-reset notices, and urgent messages that attempt to bypass normal business procedures.
Technical controls reduce risk, but they do not eliminate social engineering.
Configure SPF, DKIM, and DMARC Correctly
Email authentication helps receiving systems evaluate whether mail claiming to come from a business domain is authorized.
Google recommends configuring SPF and also recommends using DKIM and DMARC for organizations sending mail through Google Workspace.
SPF identifies authorized sending systems.
DKIM adds a cryptographic signature to outgoing messages so receiving systems can verify that the message was signed by the sending domain.
DMARC builds on SPF and DKIM and allows a domain owner to publish a policy for handling messages that fail authentication while also receiving reporting information.
DMARC should be rolled out carefully. Google’s guidance recommends having SPF and DKIM in place before progressing through DMARC enforcement.
Businesses using marketing platforms, help desks, accounting systems, CRM software, website forms, or other services that send email on their behalf should account for those legitimate senders before applying an aggressive DMARC policy.
Review Gmail Forwarding and Routing
Email forwarding can move business messages outside the expected mailbox.
Google Workspace allows administrators to configure routing and, depending on policy, users may also be allowed to configure automatic forwarding. Google includes forwarding settings among the items administrators may need to investigate after a suspected account compromise.
Review whether automatic external forwarding is necessary for the organization.
Also document deliberate routing rules so an old configuration is not later mistaken for malicious behavior.
Unexpected forwarding deserves investigation because it can allow business correspondence to continue reaching an external destination without the sender noticing.
Review Third-Party OAuth Application Access
A Workspace password is not the only way an external service can receive access to business information.
OAuth allows applications to request permission to interact with Google data without requiring the user to directly give the application their Workspace password.
Google Workspace administrators can review applications that have accessed Workspace data and control their access to Google services.
Review applications that can access Gmail, Drive, Calendar, Contacts, or other sensitive data.
For each application, determine who uses it, what permissions it requests, whether it is still needed, and whether the requested access is proportionate to its purpose.
An application that was useful two years ago should not keep access indefinitely simply because nobody remembered to remove it.
Control Google Workspace Marketplace Applications
Marketplace applications can extend Workspace functionality but may also request access to organizational data.
Google provides administrators with controls over which Marketplace applications users can install, and application listings provide permission information that can help administrators evaluate what an app can access or do.
For a small business, an allowlist can be easier to govern than permitting every employee to connect any available application.
Before approving an app, review the publisher, requested permissions, privacy information, support details, business purpose, and whether an alternative requiring less access exists.
Use Organizational Units and Groups Deliberately
Google Workspace allows settings and access to be applied differently across organizational units and, for some controls, groups.
This can be useful when different departments have different security requirements.
Finance staff may need stricter external-sharing rules than a public-relations team. Administrators may need stronger authentication requirements than ordinary users. Contractors may require access to fewer services than permanent employees.
Google notes that organizational units affect which features and services users can access, while groups and security groups can also participate in access and policy design.
Avoid creating unnecessarily complex structures. A small business benefits more from a few clearly understood policies than from an elaborate hierarchy nobody maintains.
Review Device and Endpoint Access
Workspace security does not end at the browser login.
Phones, tablets, laptops, and other endpoints can hold business email, files, cached sessions, and application data.
Google endpoint-management capabilities can help administrators apply device security requirements and take action on managed work data. The exact controls depend on the organization’s Workspace edition, device type, and management configuration.
At minimum, decide which types of devices may access business accounts, require screen protection on managed devices where appropriate, keep software updated, and establish a procedure for lost or stolen devices.
For higher-risk environments, evaluate stronger device-management and access controls available in the organization’s edition rather than assuming every advanced feature is included.
Keep Browsers and Applications Updated
Google’s small-business checklist explicitly recommends keeping applications and internet browsers updated so users receive current security fixes.
This is particularly important on devices used by administrators.
A strong Workspace configuration cannot compensate for every risk created by an unsupported operating system, outdated browser, malicious extension, or compromised workstation.
Administrative devices deserve especially careful maintenance because a logged-in administrator may have access to controls affecting the entire organization.
Monitor Security Alerts and Administrative Activity
Security settings should not be configured once and then ignored indefinitely.
Google provides administrator alerts and audit or log-event data that can help organizations review changes and investigate suspicious activity. Google’s larger-business checklist specifically recommends reviewing administrator activity and security events.
Useful review questions include whether a new administrator was created, whether security settings changed unexpectedly, whether unusual sign-ins occurred, whether third-party access expanded, and whether sensitive sharing rules were modified.
Some advanced investigation and security-center capabilities depend on the Workspace edition and administrator privileges.
Do not write an incident-response procedure that assumes access to a premium security tool unless the business has confirmed that the tool is included in its subscription.
Understand Retention, Recovery, and Backup as Different Controls
Retention, recovery, and backup solve related but different problems.
Google Workspace contains native mechanisms for recovering certain deleted data and for retaining information under configured policies, but organizations should not automatically treat every retention feature as a complete backup strategy.
Google Vault is designed for information governance, retention, holds, search, and eDiscovery for supported Workspace services. Its purpose and behavior depend on retention rules, holds, licensing, and service support.
A business should separately determine how it would recover from accidental deletion, malicious deletion, ransomware affecting synchronized content, a compromised administrator, application errors, or the loss of data outside available native recovery paths.
The SaaS backup checklist provides a broader framework for separating backup, retention, recovery objectives, restore testing, and provider-native recovery features.
Do Not Confuse Google Vault With Ordinary File Backup
Vault can preserve information under retention rules or legal holds, but that does not mean administrators should treat it exactly like a conventional backup system.
Its primary role is governance and eDiscovery.
Before relying on Vault for a business requirement, confirm which Workspace services are covered, which users require licensing, what retention rules apply, and what happens when data falls outside those rules.
Recovery planning should begin with the failure scenario the business needs to survive rather than the name of the product being used.
Review Google Takeout and Data Export Requirements
Data export is another area that should be governed intentionally.
Google provides Workspace data-export mechanisms, and administrators can control or use export capabilities depending on the method and organizational configuration.
A business should decide who is permitted to export organizational data and why.
Large exports can create additional copies of sensitive information outside normal Workspace access controls. If exports are required for migration, archival, compliance, or another operational need, determine where the exported files will be stored and who can access them afterward.
Export should not become an unmanaged substitute for a designed backup and recovery process.
Establish Rules for Gemini and Connected AI Features
Generative AI adds another governance layer to Google Workspace.
Google administrators can control access to Gemini features, and Google documents controls that can restrict Gemini’s access to Workspace data. Access also remains affected by the permissions of the underlying user and content.
Small businesses should decide which users may use AI features and what types of company information are appropriate for AI-assisted work.
This is not purely a technical decision. It also involves confidentiality, accuracy, customer information, intellectual property, approval requirements, and employee responsibilities.
The AI policy template for small business provides a useful framework for setting those expectations without assuming that every AI task should be prohibited or automatically permitted.
Treat Gemini Permissions as Part of Existing Access Governance
AI does not remove the importance of normal access control.
If an employee has access to information they should not have, adding an AI interface can make that underlying permission problem more visible or easier to query.
Review Drive sharing, groups, Shared Drive membership, and account privileges before treating AI settings as a separate security layer.
The safer approach is to secure the underlying data first, then govern how AI features may interact with it.
Prepare an Account-Compromise Procedure Before You Need It
A small business should know what to do if an employee or administrator account appears compromised.
Google’s administrator guidance for compromised accounts includes suspending affected access, investigating unauthorized activity, reviewing administrator changes where relevant, resetting credentials, and revoking OAuth access as appropriate.
Your internal response process should identify who can suspend accounts, who can reset authentication, who reviews logs, who checks forwarding and OAuth applications, and who decides when access can safely be restored.
The procedure should also cover communication if the compromised account was used to send fraudulent invoices, request payments, share malicious files, or contact customers.
Review Security After Staff Changes
Role changes and departures are natural points for security review.
When someone leaves, check more than the Workspace user account.
Review administrator roles, groups, Shared Drive membership, delegated mailboxes, OAuth applications, managed devices, recovery contacts, forwarding, calendars, business files, and any credentials stored outside Workspace.
An employee can lose access to their primary account while still retaining access through another system or shared credential.
Offboarding is complete only when the business has considered the full access path.
Use a Stronger Baseline for Sensitive Businesses
Google’s small-business checklist is a baseline, not a universal ceiling.
Google explicitly notes that a small organization may have security requirements similar to a much larger business when it handles sensitive or regulated information.
A financial, healthcare, legal, government-contracted, or otherwise sensitive organization may need stronger controls, specialist review, contractual safeguards, or regulatory measures that go beyond a general Workspace checklist.
The broader cybersecurity, digital security, data protection, privacy, and modern cyber defense guide places account and cloud controls within the wider security responsibilities a business may need to manage.
Check Your Workspace Edition Before Following Advanced Instructions
Google Workspace editions do not expose every security feature in exactly the same way.
Advanced investigation tools, certain data-protection functions, device controls, Context-Aware Access, Shared Drive controls, and other administrative capabilities can depend on edition, licensing, user role, or configuration. Google repeatedly notes edition differences throughout its security documentation.
For that reason, avoid copying a security configuration from an unrelated organization without confirming that the same feature exists in your tenant.
The Admin console and Google’s current documentation should be treated as the authoritative references for the options available to your organization.
Monthly and Quarterly Google Workspace Security Review
A checklist is most useful when it becomes a recurring process rather than a one-time project.
A small organization does not need to rebuild its entire configuration every month, but high-risk areas should be revisited as employees, applications, sharing patterns, and business processes change.
A practical review can cover the following:
- Confirm that every super-admin account is still required and individually assigned.
- Confirm that administrator accounts use appropriate 2-Step Verification.
- Review administrator roles for unnecessary privileges.
- Check new, suspended, inactive, and departed user accounts.
- Review critical groups and Shared Drive membership.
- Check external Drive sharing for sensitive business areas.
- Review third-party OAuth applications and remove unused access.
- Review Workspace Marketplace applications.
- Confirm SPF, DKIM, and DMARC remain aligned with legitimate sending services.
- Review unexpected Gmail forwarding or routing changes.
- Check security alerts and important administrator activity.
- Review lost, inactive, or unmanaged devices where applicable.
- Confirm backup and recovery procedures still match business requirements.
- Test at least one important recovery process periodically.
- Review whether Gemini and other AI use still matches company policy.
- Remove old integrations, accounts, permissions, and access paths that no longer have a business purpose.
Frequently Asked Questions
What is the most important Google Workspace security setting for a small business?
There is no single setting that replaces the others, but administrator account protection deserves immediate attention because administrators can make organization-wide changes. Strong authentication, separate administrative accounts, and limited privileges provide an important foundation.
Should every Google Workspace user have 2-Step Verification?
Google recommends 2SV for users and places particular emphasis on administrators and people handling sensitive information. Administrators should plan enrollment and recovery carefully before enforcing a policy.
Should small businesses use security keys?
Security keys are one of the strongest phishing-resistant 2SV options supported by Google and are particularly relevant for administrator and high-value accounts. The appropriate deployment depends on the organization’s users, devices, recovery process, and risk.
Should Google Drive external sharing be disabled completely?
Not necessarily. Many businesses need legitimate external collaboration. The better approach is to decide who needs external sharing, apply suitable restrictions, and review sensitive sharing rather than enabling unrestricted access by default.
Are Shared Drives more secure than My Drive?
Shared Drives solve important ownership and continuity problems because the organization owns the files rather than an individual. Security still depends on membership, permissions, external sharing, and the sensitivity of the content.
Is Google Vault a backup?
Vault is primarily an information-governance and eDiscovery system that uses retention rules and holds for supported Workspace data. Businesses should evaluate backup and recovery separately rather than assuming retention and backup are interchangeable.
Should a small business allow every Workspace Marketplace application?
That creates unnecessary exposure. Administrators should evaluate application permissions and consider restricting installation to approved applications where appropriate.
What should be reviewed when an employee leaves?
The account itself is only part of the review. Administrator privileges, groups, Shared Drives, files, forwarding, third-party applications, devices, delegated access, and other connected systems may also require attention.
Do all Google Workspace editions include the same security controls?
No. Some security, investigation, data-protection, device-management, and access-control capabilities vary by Workspace edition and administrator privilege.
Final Thoughts
A strong Google Workspace security checklist for small business should focus on the areas where ordinary administrative decisions can materially change risk.
Protect administrator accounts first. Use stronger authentication. Limit privileges. Control external sharing. Review third-party applications. Authenticate business email properly. Plan user offboarding. Understand the difference between retention and backup. Monitor meaningful changes. Govern AI access instead of treating it as a separate, isolated technology.
Most importantly, treat Workspace security as an ongoing administrative responsibility.
The configuration that was appropriate when a business had five employees may no longer be appropriate after new staff, contractors, integrations, Shared Drives, AI tools, and customer data have been added.
Regular review keeps those changes from quietly turning into permanent access and security problems.


