← Google Workspace audit scope

Admin & Privileged Access

9 checks · 2 sub-categories

A Google Workspace super admin can read any mailbox, export any Drive file, disable logging and lock you out of your own domain. Most small businesses have two or three more super admins than they realise — an old IT provider, a departed manager, a shared 'admin@' login. This section establishes exactly who holds the keys and what protects those accounts.

Super admin hygiene

  • Number of super admins within recommended limits

    Google recommends a small handful of super admins with named owners. We list every super admin, when they last signed in, and flag the ones nobody can account for — including accounts belonging to former staff or previous IT providers.

    • Essential Eight — Restrict administrative privileges
    • CIS GW 1.1
  • 2-Step Verification enforced on every admin

    Any admin account without 2SV is a single stolen password away from total domain compromise. We check enforcement, not just enrolment, and identify admins still relying on SMS codes.

    • Essential Eight — Multi-factor authentication
    • SCuBA GWS.COMMONCONTROLS
  • Security keys used for super admin accounts

    Hardware security keys (or passkeys) are the only phishing-resistant second factor. We report which admins are protected by them and which are still on push or code-based methods.

    • Essential Eight — Multi-factor authentication (ML3)
  • Dedicated admin accounts separated from daily mail

    Admins who browse the web and read email from the same account they administer with are a standing risk. We check whether privileged work happens on separate, non-mailbox admin identities.

  • Break-glass account documented and monitored

    At least one emergency super admin should exist, excluded from SSO dependencies, with credentials stored offline and sign-ins alerted on. We check whether one exists and whether anyone would notice if it were used.

Delegated roles and privilege sprawl

  • Use of least-privilege delegated admin roles

    Help-desk staff usually need a User Management or Help Desk role, not super admin. We map every assigned role against what the person actually does.

    • Essential Eight — Restrict administrative privileges
  • Custom admin roles reviewed for excessive privileges

    Custom roles quietly accumulate privileges over time. We flag custom roles carrying sensitive rights such as user impersonation, security settings or data export.

  • Admin role assignment changes logged and alerted

    Privilege escalation is a classic post-compromise step. We check that admin role grants raise an Alert Center rule someone actually receives.

  • Third-party / MSP admin access reviewed

    External IT providers frequently retain super admin long after an engagement ends. We identify external identities with admin rights and reseller-level access to the domain.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.