Devices & Endpoint Access
9 checks · 2 sub-categories
Workspace data ends up on phones, laptops and home computers. Without at least basic endpoint management, a lost phone with a signed-in Gmail app is a data breach, and there is no way to remotely remove company data from it.
Mobile and BYOD
Mobile management level (basic vs advanced)
Basic management gives you remote account wipe; advanced adds policy enforcement. We report which is active and for which OUs.
- Essential Eight (supporting)
- CIS GW 7.1
Screen lock and passcode requirements enforced
An unlocked phone is an unlocked mailbox. We check whether a passcode or biometric lock is required on devices holding Workspace data.
Remote wipe capability and account wipe on offboarding
We confirm remote wipe is available and that offboarding actually removes corporate data from personal devices.
Device approval and inventory
New devices should require admin approval on sensitive OUs. We report the device inventory, including unmanaged and jailbroken devices where visible.
Desktop, browser and access context
Endpoint verification coverage on computers
Endpoint verification gives visibility of the laptops accessing Workspace, including OS version and disk encryption state.
Chrome browser management and policy
Managed Chrome enforces updates, safe browsing and extension policy. We check enrolment coverage and key policies.
- Essential Eight — Patch applications (supporting)
Context-Aware Access policies
Where licensed, access can be restricted by device state, IP range or geography. We check whether any policies exist and whether they cover admins.
Session length for Google services
Indefinite web sessions mean a stolen laptop stays signed in. We check the enforced session duration for staff and admins.
- SCuBA GWS.COMMONCONTROLS
Login challenges and geographic sign-in anomalies
We check whether extra verification is enforced on suspicious sign-ins and review recent sign-ins from unexpected countries.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.