A practical guide to securing Google Workspace for a startup
fleetdm.com
fleetdm.com
I used Google Workspace for a startup. Startup went idle for a while. Google sent a message to me warning the account would be terminated unless I logged in on some short timeline. GMail filed its own email as spam. Boom. Everything from that startup was gone.
I used Google Workspace for my family domain. Google decided to discontinue GSuite/Free. Now, I'm SOL.
I've had similar experiences with Youtube. I build a major startup with Google as a partner. Videos were on Youtube. Google had 4 engineers assigned to us. Youtube has a bug which took us down. There was no way to resolve the bug, even with a team supporting us (in a different part of Google). We had to migrate off.
I've more recently been involved in businesses integrating with Workspace. On the API side, Google suddenly required a security audit for our business integrations to keep working. That's tens of thousands of dollars. Many small businesses went under when Google introduced this. (https://www.prescientsecurity.com/google-oauth-api-verificat...)
We also had an extension, which is in the process of breaking with Manifest V3 (https://www.eff.org/deeplinks/2021/12/chrome-users-beware-ma...). Again, many Google partners are going out-of-business over this.
Each time I've done business with Google, I've eventually been !@#$%.
These are all true stories, but they're not all the true stories I have. I have a much longer collection of stories of being !@#$% by Google. Some I can't talk about have to do with Workspace security issues. BOY was that a rabbit hole. If I could talk about it, you'd never do business with Google either. Google has excellent security for their data, but not for your data.
Google doesn't mind killing your livelihood with random changes like these. It happens over, and over, and over. Everyone thinks it won't happen to them, until it does.
Even search which used to be its crowning achievement isn't great for most terms. SEO dominates google completely.
I've always thought it madness to even rely on gmail for a business, who can cancel you whenever.
I've had multi-million dollar engagements with Google, and you're just as vulnerable to this stuff as the free ones. I've had things escalated through one of Eric Schmidt's direct reports, and I was still vulnerable.
And as a footnote, I do subscribe to Google One on my soon-to-be-terminated Workspace account. I'm not sure why Google is terminating a service I paid for.
If you pay Google, you can talk to human beings, perhaps, but they're no more empowered to solve your problem than their web pages.
Microsoft and Amazon have always provided real support. Things get escalated to engineers who fix things if need be. Things also don't get whack-a-moled for no reason; they're aware that bankrupting my business isn't good for their business, even if the short-term ROI on sustaining a legacy API or something is negative.
I rather like easydmarc.com. They charge for analytic services but you can use their checker for free. They also have very easily digested guides and recommendations for setting up the various records.
We also reached out to sales and got a deal, explaining we didn't want to pay prices designed for companies with 1000s of employees.
It’s also been a while since I’ve seen a nice quick Mac OS security settings list to go ahead and toggle.
My only request would be additional guide for iOS security. The iVerify app suggests some good defaults
We have everyone do this as part of onboarding and we audit once a month.
Would be nice if Google allowed enforcing it with a grace period for new accounts though!
This is a great guide, I just wish Google made it easier to be "secure by default". It's very difficult to know all the various toggles you need to have switched on to be secure.
https://cloud.google.com/security-command-center/docs/how-to...
https://cloud.google.com/logging/docs/audit/configure-gsuite...
And looking this up:
> If your total annual Google Cloud spend or commit is less than $15 million, the annual cost of Security Command Center Premium is 5% of the larger of the following:
> Your committed annual Google Cloud spend (for deals up to the term of your commit), or Your actual annual current annualized Google Cloud spend (for deals up to one year) There is a minimum annual cost of $25,000.
Yeah I need to be a few orders of magnitude bigger before this is anything close to sane.
Definitely only use registrars and DNS providers that have 2FA. Google has a registrar now, as well as DNS in GCP https://cloud.google.com/domains/docs/register-domain and https://cloud.google.com/dns. By using those you can leverage your Google account's security (use separate accounts for admin level access on GCP and enforce hardware 2FA), and control who gets access using IAM. AWS has similar options.
Someone in marketing got an email from some contracted SEO consultant, which said "I need your domain transfer codes". Marketing goes to a VP and overrides everyone ops, everyone in security, and basically everyone who would say "no" because tech people just get in the way.
So suddenly, the domain is transferred to Bluehost using their DNS, the MX records that served 8000 mailboxes are pointed at some "cPanel with five free POP3 accounts" service, and the subdomain that ran your SaaS no longer resolves. But your landing page has better SEO.
For example, a small org with no security people or a non-profit could be made much more secure by following this, so why not publish it?
On the other hand, the workflow of “manually download file, modify file in app, manually upload file” is clumsy and error prone, often leaving files stranded on the laptop.
On the gripping hand, google drive (as it is called again) seems to crash every few days so perhaps your restriction isn’t much of a limitation :-(
So what I'd like to do is to set SMS to off, and all the accounts which already have something like device prompts and/or at least one hardware token added, get SMS deactivated without user intervention.
https://workspaceupdates.googleblog.com/2019/03/more-control...
Essentially you can enforce 2FA or not, then, you can allow ANY method, any method BUT telephony based (calls and SMS), or hardware security key only.
The middle option for most people is a great one as it allows Google Prompt (push notifications) as well as Google Authenticator style OTPs, plus security keys.
You'll still get a password prompt if elevating security profile for something higher privilege in my experience.
1. Mark Google services you consider critical as "restricted" (ex: Drive, gmail) 2. On Gmail and Drive, you can then allow apps that use lower levels of permissions, but not those who need "dangerous access" 3. Then on a per app basis you can mark apps as "trusted" which lets them access "restricted" Google services.
It is not super granular in the sense that you can't easily say - Calendar2000 can be used by my sales team, and should have access only to the invites date and time but not attendees, body or attachment, but it is better than nothing!
I recently seen many youtubers having their channel hijacked due to hackers taking over their Google account.
I wonder about Windows.
Thanks for posting the guide!
One user request was to STOP the "windows hello" PIN requirement, and just have a password (+ MFA) for login. Does anyone know how to do this with either standard Office 365 subscriptions, or office 365 + Intune or similar? Would love not to have to do Azure AD outside of the office subscriptions. Microsoft has a fair number of SKU's these days that kind of overlap (and get renamed).
From the Endpoint Manager (endpoint.microsoft.com) hit "Devices" and then "Windows Enrollment". Click "Windows Hello for Business", and click "Disabled".
[1] https://thenextweb.com/news/google-gsuite-free-alternatives-...