SecureMyEmail
← All articles
Google Workspace18 June 2026 · 6 min read

What a Google Workspace security audit actually checks

Google Workspace admin console open on a laptop in an Australian office

Most Australian businesses assume Google Workspace is secure because Google is secure. Google's infrastructure is excellent. The gap is almost never Google — it's the tenant configuration sitting on top of it, most of which ships permissive by default so nothing breaks on day one.

Identity: who can get in

2-Step Verification is the single highest-value control, but 'we have 2FA' rarely means everyone has it. Enforcement is usually applied to an org unit, then new hires land somewhere else, or a handful of shared and service accounts get an exception that never expires.

Super-admin sprawl is the quiet twin of that problem. A tenant set up years ago by a departed IT provider commonly carries three to six super-admins, several of which nobody can account for.

  • 2SV coverage per user, including exceptions and grace periods
  • Number of super-admins and whether each is a named, current person
  • Dormant accounts still licensed and still able to sign in
  • Legacy protocols (POP, IMAP, less-secure app access) that bypass 2SV entirely

Data movement: what can leave

A compromised mailbox is a nuisance. A compromised mailbox with an auto-forward rule is an ongoing intelligence feed for an attacker, and it's the mechanism behind most invoice-redirection losses we see.

  • Auto-forwarding rules to external domains, per user
  • Drive files shared 'anyone with the link' and to external accounts
  • Third-party OAuth apps holding read or write scopes on mail and Drive
  • Delegation and mail-send-as permissions granted between staff

Domain trust: who can pretend to be you

SPF, DKIM and DMARC determine whether an attacker can send mail that appears to come from your own domain to your own clients. A missing or permissive DMARC policy is common and cheap to fix, and it protects people outside your business as much as inside it.

Visibility: what you'd know afterwards

The last group of checks is about the day after an incident. Admin audit logging retention, alerting on suspicious sign-ins, and whether anyone actually receives those alerts. Without this, the honest answer to an insurer's question about scope of compromise is 'we don't know' — which is the expensive answer.

None of these require new software. They're settings you already own, and an audit simply tells you which ones are currently working against you.

Want to know where your own tenant stands?

The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.