Turn off IMAP and POP access in Google Workspace for Australian SMEs
Reviewed by Neil Frick — September 2026

▶ Watch the short explainer for this tip
Many Australian small and medium businesses (SMEs) use Google Workspace for their email but leave mailbox access methods enabled long after staff stop using them. Unneeded IMAP and POP access gives apps another way to retrieve business email. Turning it off can reduce exposure, provided you first check which staff and systems still depend on it.
What does turning off IMAP and POP access do?
This setting disables the ability for email clients to connect to Google Workspace Gmail accounts using the Internet Message Access Protocol (IMAP) or Post Office Protocol (POP). It blocks these mailbox retrieval methods regardless of whether the client uses OAuth. It does not disable SMTP sending or Gmail API access, and it does not remove email already downloaded to a device.
| Configuration fact | Recommended approach or expected behaviour |
|---|---|
| Admin console location | Apps > Google Workspace > Gmail > End User Access > POP and IMAP access |
| Administrator access | Use an administrator account with permission to manage Gmail settings. |
| Scope | Select the organisational unit you intend to change and check inherited settings. |
| Recommended setting | Turn off both POP and IMAP where no business dependency remains. |
| Affected clients | Clients retrieving mail through POP or IMAP, including OAuth-enabled clients, lose that access. |
| Unaffected access methods | Gmail on the web and the official Gmail app remain available. SMTP and Gmail API access are controlled separately. |
| Propagation time | Allow up to 24 hours for changes to take effect, although they typically apply sooner. |
| Licensing | For Google Workspace subscriptions that include Gmail, this admin setting normally needs no additional licence or paid add-on. |
Inventory dependencies and pilot the change before a wider rollout. No DNS record change is needed for this control.
Why disable unused IMAP and POP access?
Turning off access your business does not need reduces the number of ways an app can retrieve mailbox data. This is useful when staff already work in Gmail on the web or the official Gmail app and no approved integration needs POP or IMAP.
IMAP and POP are email protocols, not authentication methods. Both can use OAuth, so an IMAP connection is not automatically an insecure username-and-password connection. Google Workspace no longer supports ordinary username-and-password sign-in for less secure apps; disabling these protocols is a separate control, not the way to retire that sign-in method.
Keep 2-Step Verification, preferably with phishing-resistant methods such as security keys or passkeys, and review third-party app access as well. Disabling POP and IMAP does not enforce those controls or stop phishing messages reaching staff.
What risks remain when mailbox access is unnecessary?
An unnecessary mail client or integration can become another place where sensitive customer records, payroll details or invoice conversations are accessed and stored. If an attacker obtains a usable OAuth token or another permitted credential, an enabled protocol may provide a route to mailbox data. Turning off that protocol closes that route, but leaves other access methods to manage.
For an Australian SME, a mailbox compromise can lead to invoice fraud, data exposure and business disruption. It does not automatically mean a regulatory penalty or an invalid insurance policy. Privacy obligations depend on the business and incident, while insurance cover depends on the policy wording and circumstances.
How do you turn off IMAP and POP safely?
Use a pilot organisational unit before changing access for the whole business. Google's instructions for controlling POP and IMAP access explain the available settings: https://support.google.com/a/answer/105694.
An audit can review the configuration and any access exceptions.
- Inventory mail clients, mailbox-reading integrations and users that rely on POP or IMAP.
- Tell affected staff what will change and arrange a supported replacement for each dependency.
- Sign in to admin.google.com with an administrator account authorised to manage Gmail settings.
- Go to Apps > Google Workspace > Gmail > End User Access > POP and IMAP access.
- Select the pilot organisational unit and check whether its settings are inherited.
- Disable both POP and IMAP access for that unit, save the change and allow for propagation.
- Test affected clients and normal Gmail access, then expand the rollout to other units without approved dependencies.
Does this Google Workspace setting need an extra licence?
For Google Workspace subscriptions that include Gmail, the POP and IMAP admin control normally needs no additional licence or paid add-on. The practical cost is staff time: identifying dependencies, helping users change clients and testing the rollout. A small business using only Gmail on the web may have fewer dependencies than one with desktop clients and mailbox-reading integrations.
Which rollout mistakes can disrupt an Australian business?
The biggest mistake is switching access off before identifying who uses it. Outlook profiles configured for IMAP or POP, older desktop clients and CRM tools that read mail through these protocols will be affected. An OAuth-enabled IMAP client still needs IMAP enabled; changing its authentication method does not bypass the block.
Do not assume every scan-to-email printer depends on POP or IMAP. Most send mail using SMTP, which this setting does not disable. Some devices use POP-before-SMTP authentication or retrieve messages, so check the actual configuration rather than treating all printers the same.
Where a business dependency remains, consider moving it to a supported alternative. If an exception is necessary, limit it to a dedicated organisational unit, use OAuth where supported, document the owner and review date, and check which additional users could inherit that access. Advise staff before the rollout and provide clear instructions for the replacement workflow.
How can you check the change worked?
Check that the saved policy applies to the test user's organisational unit, including any inheritance or overrides. Allow up to 24 hours for propagation, although changes typically apply sooner.
Use an approved test account and a client that successfully retrieved mail before the change. After propagation, start a fresh connection and confirm that new POP and IMAP retrieval is blocked. A connection error alone is not proof: expired credentials, network faults and client problems can also cause failures.
Confirm that Gmail on the web and the official Gmail app still work, and test any critical sending or mailbox integrations separately. Previously downloaded messages may remain visible in a client even after new retrieval is blocked. Keep a record of the test results and review exceptions after the rollout.
How does this fit a broader Google Workspace security audit?
Disabling unused POP and IMAP access is one part of a broader review. A Google Workspace security audit can also examine 2-Step Verification, administrator privileges, third-party OAuth access, app passwords, email authentication and Google Drive sharing. Each control addresses a different risk.
This change supports broader cybersecurity controls but alone does not establish compliance with the Privacy Act or the Notifiable Data Breaches scheme. It is also not a substitute for assessing the applicable ACSC Essential Eight requirements.
Learn what SecureMyEmail reviews in an email-security audit.
Turn off IMAP and POP where your business does not need them, but inventory dependencies and test first. The change reduces mailbox access paths; it does not replace 2-Step Verification, app-access reviews or your broader cybersecurity controls.
Disclaimer: This information is general in nature and may not apply to your specific circumstances. You should seek professional advice before making any changes to your IT systems. Netlogyx IT is not responsible for any outcomes resulting from the use of this information.
Frequently asked questions
- Will disabling IMAP and POP affect all my staff's email access?
- No. Gmail on the web and the official Gmail app remain available, but clients configured to retrieve mail using POP or IMAP lose that access. This includes OAuth-enabled IMAP clients. Check how each client connects before making the change.
- Is this setting enough to protect my Google Workspace from all cyber threats?
- No. Disabling unused POP and IMAP reduces access paths, but it does not prevent phishing or protect every way into an account. Use 2-Step Verification, review third-party app access and administrator privileges, and maintain broader security controls.
- Does disabling IMAP and POP help with ACSC Essential Eight compliance for Australian businesses?
- It can support broader security hardening, but it does not by itself satisfy an Essential Eight requirement or maturity level. It is not a substitute for patching applications, restricting administrative privileges or implementing multi-factor authentication. Assess those controls separately against the applicable ACSC guidance.
- What if some of my business applications or devices rely on IMAP or POP?
- Replace the dependency where practical or retain a narrowly scoped, documented exception. OAuth improves authentication but cannot make POP or IMAP work when the protocol is disabled. If access must remain enabled, use OAuth where supported and review the integration's permissions. Check printers separately because most scan-to-email functions use SMTP rather than POP or IMAP.
- Does turning off IMAP and POP cost extra with my Google Workspace plan?
- No additional licence or paid add-on is normally needed for this control on Google Workspace subscriptions that include Gmail. Allow for the staff time involved in checking dependencies, changing workflows and testing.
- How does this impact my cyber insurance policy in Australia?
- The effect depends on your policy wording and insurer's requirements. Disabling unused protocols may support your security controls, but it does not guarantee cover or payment of a claim. Ask your broker or insurer how the policy treats authentication, mailbox access and documented exceptions.
- How long does it take to disable POP and IMAP access?
- Changes can take up to 24 hours, although they typically apply sooner. Test with a fresh client connection after propagation and confirm the user's effective organisational-unit settings before concluding the rollout is complete.
Sources
Every reference below was link-checked when this article was published.
- 1.Control access to less secure appsGoogle Workspace Admin Help
- 2.Protect your business with 2-Step VerificationGoogle Workspace Admin Help
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


