Insights · Small businesses on Google Workspace

Which Google Workspace settings actually matter, in order?

In a small Google Workspace account, five settings carry most of the risk, in this order: enforce 2-Step Verification for every user, keep at least two super admin accounts used only for administration, control which third-party apps can reach company data, make new Drive files private by default, and authenticate outgoing email with SPF, DKIM and DMARC.

Why does the order of Google Workspace settings matter?

The order of Google Workspace settings matters because a small business cannot review every option at once. CISA's Secure Cloud Business Applications (SCuBA) baselines for Google Workspace, developed with Google and released for public comment on 12 December 2023, cover nine separate services, from Gmail and Drive to Calendar, Meet, Chat and Sites (CISA, 12 December 2023). A sensible order starts with how attackers actually get in. Verizon's 2026 Data Breach Investigations Report found that the human element was involved in 62% of breaches, and that abuse of user credentials was the initial access vector in 13% (via Help Net Security, 25 May 2026). For a business that runs on Workspace and owns no servers, the user account is the front door.

The sequence in this article follows Google's own Security checklist for small businesses with 1 to 100 users, last updated on 1 October 2026, and cross-checks each step against the SCuBA Google Workspace baselines published by CISA on GitHub (both consulted 6 October 2026). The five settings below come first because each closes a path that needs no technical skill to exploit: a reused password, an everyday admin account, an app approved without reading, a file open to anyone with the link, and a spoofable email domain. Settings written for federal agencies, such as disabling Google Takeout, come later and are covered at the end.

Is 2-Step Verification enforced, or only allowed?

Google Workspace distinguishes between allowing 2-Step Verification and enforcing it, and the difference decides whether the setting protects anyone. Google's guide Deploy 2-Step Verification, last updated 1 October 2026, describes the setting "Allow users to turn on 2-Step Verification" with enforcement set to Off as voluntary: users who never enroll keep signing in with a password alone. Enforcement can start immediately or from a chosen date, and administrators can give new employees an enrollment window from 1 day to 6 months. Google also lets administrators restrict methods to any method, any method except text and phone codes, or security keys and passkeys only (Google Workspace Admin Help, consulted 6 October 2026).

The SCuBA common controls baseline sets the target clearly. Policy GWS.COMMONCONTROLS.1.1 requires phishing-resistant multi-factor authentication for all users, policy 1.2 requires another enforced method where that is not yet possible, and policy 1.3 says text messages and voice calls shall not be used (CISA SCuBA, consulted 6 October 2026). For a small business, a realistic first step is to enforce 2-Step Verification for every user with text and phone codes excluded, then move super admins to security keys or passkeys. The 2-Step Verification enrollment report in the Admin console shows who has not enrolled before the enforcement date arrives.

Who are our super admins, and do they use those accounts every day?

Super admin accounts in Google Workspace can change every setting and reset any password, so they need tighter handling. Google's small business checklist recommends creating an additional super admin account managed by a separate person, signing out of super admin accounts when not performing a specific task, and using limited admin roles for daily work (Google Workspace Admin Help, consulted 6 October 2026). The SCuBA baseline policy GWS.COMMONCONTROLS.6.2 asks for at least two and at most eight distinct super admins (CISA SCuBA, consulted 6 October 2026). If the owner's everyday mailbox is the only super admin, one phished password hands over the whole tenant, and nobody else can recover it.

Which third-party apps can read our company email and files?

Third-party app access is the Google Workspace setting most small businesses have never opened. When a user signs in to a scheduling tool or an AI assistant with Google and approves the requested permissions, that app can read the email, files or calendar those permissions cover until the access is revoked. The SCuBA baseline asks administrators to restrict third-party access to Workspace services (GWS.COMMONCONTROLS.10.1), to block apps that have not been reviewed (10.4) and to prevent access by less secure apps (10.5) (CISA SCuBA, consulted 6 October 2026). The pressure on this setting is growing: Verizon's 2026 DBIR reported that 45% of employees now use AI tools regularly at work, up from 15% a year earlier (via Help Net Security, 25 May 2026). A practical first pass is to list the connected apps, mark the ones the business relies on as trusted, and remove access for the rest.

Who can see a new Google Drive file by default?

Google Drive file visibility depends on a default that most administrators never change. Google's small business checklist recommends turning off link sharing for new files so that only the creator can open a file until it is explicitly shared, and turning on a warning when users share files with people outside the company (Google Workspace Admin Help, consulted 6 October 2026). The SCuBA Drive baseline makes the same points as policies: "private to owner" as the default for new items (GWS.DRIVEDOCS.1.8), warnings when sharing outside the organization (1.3 and 1.9), and no "anyone with the link" access where external sharing is allowed (1.5) (CISA SCuBA, consulted 6 October 2026). A business that shares with many clients can still make private the default, then review files already shared publicly, starting with client and financial folders.

Is our email domain authenticated, and is Gmail scanning what arrives?

Email authentication protects the company's domain from being used in phishing sent to its own clients and suppliers. Google's Email sender guidelines, in force since 1 February 2024, require every sender to Gmail accounts to set up SPF or DKIM, and require senders of more than 5,000 messages a day to set up SPF, DKIM and DMARC, with DMARC allowed at a policy of none (Gmail Help, consulted 6 October 2026). A smaller sender still benefits from all three, because DMARC tells receiving servers what to do with mail that falsely uses the domain. On the receiving side, Google's small business checklist recommends turning on enhanced pre-delivery message scanning and additional screening for malicious attachments, links and external images in Gmail (Google Workspace Admin Help, consulted 6 October 2026).

Which Google Workspace settings can wait until later?

Several SCuBA Google Workspace policies are written for federal agencies and can follow the first five settings in a small business. Examples include disabling Google Takeout (GWS.COMMONCONTROLS.12.1), forcing re-authentication after a 12-hour session (4.1) and restricting external Drive sharing to an allowlist of domains (GWS.DRIVEDOCS.1.1) (CISA SCuBA, consulted 6 October 2026). Each reduces risk but changes how staff work, so they belong in a second pass. Two exceptions apply. Google's checklist itself says that small businesses with regulatory requirements, such as healthcare or financial planning, should follow its checklist for medium and large businesses instead (Google Workspace Admin Help, consulted 6 October 2026). And CISA publishes ScubaGoggles, an assessment tool that compares a tenant's configuration against the SCuBA baselines and reports where it differs (CISA, 12 December 2023).

Want to know where your own environment stands? The first step is a free, read-only security assessment.

Get a free security assessment
FAQ
Will enforcing 2-Step Verification lock staff out of their accounts?
Not if it is rolled out in stages. Google lets administrators set an enforcement start date, shows users reminders to enroll when they sign in, and allows an enrollment window of 1 day to 6 months for new employees. Checking the enrollment report before the start date shows who still needs help.
Do we need DMARC if we send fewer than 5,000 emails a day?
Gmail only requires SPF or DKIM from senders below that volume. DMARC is still worth setting up, starting at a policy of none, because it is the record that tells receiving mail servers how to treat messages that falsely use your domain.
How often should a small business review these settings?
A quarterly review is a reasonable rhythm, plus an extra check whenever someone gains or loses an admin role, a new app is connected company wide, or the business starts handling regulated data such as health or financial records.