← Google Workspace audit scope

Devices & Endpoint Access

9 checks · 2 sub-categories

Workspace data ends up on phones, laptops and home computers. Without at least basic endpoint management, a lost phone with a signed-in Gmail app is a data breach, and there is no way to remotely remove company data from it.

Mobile and BYOD

  • Mobile management level (basic vs advanced)

    Basic management gives you remote account wipe; advanced adds policy enforcement. We report which is active and for which OUs.

    • Essential Eight (supporting)
    • CIS GW 7.1
  • Screen lock and passcode requirements enforced

    An unlocked phone is an unlocked mailbox. We check whether a passcode or biometric lock is required on devices holding Workspace data.

  • Remote wipe capability and account wipe on offboarding

    We confirm remote wipe is available and that offboarding actually removes corporate data from personal devices.

  • Device approval and inventory

    New devices should require admin approval on sensitive OUs. We report the device inventory, including unmanaged and jailbroken devices where visible.

Desktop, browser and access context

  • Endpoint verification coverage on computers

    Endpoint verification gives visibility of the laptops accessing Workspace, including OS version and disk encryption state.

  • Chrome browser management and policy

    Managed Chrome enforces updates, safe browsing and extension policy. We check enrolment coverage and key policies.

    • Essential Eight — Patch applications (supporting)
  • Context-Aware Access policies

    Where licensed, access can be restricted by device state, IP range or geography. We check whether any policies exist and whether they cover admins.

  • Session length for Google services

    Indefinite web sessions mean a stolen laptop stays signed in. We check the enforced session duration for staff and admins.

    • SCuBA GWS.COMMONCONTROLS
  • Login challenges and geographic sign-in anomalies

    We check whether extra verification is enforced on suspicious sign-ins and review recent sign-ins from unexpected countries.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.