User Security & 2-Step Verification
14 checks · 3 sub-categories
Almost every Workspace breach we see starts with one ordinary staff account: no second factor, a reused password, or an account belonging to someone who left eighteen months ago and was never suspended. This section produces the list of accounts an attacker would target first.
2-Step Verification coverage
2SV enforced for all users, not just available
'Allow users to turn on 2SV' is not protection. We report whether enforcement is on, which organisational units are exempt, and the exact list of users signing in with a password alone.
- Essential Eight — Multi-factor authentication
- CIS GW 1.2
- Cyber Essentials
New-user 2SV enrolment grace period sensible
Long enrolment grace periods leave new starters unprotected for weeks. We check the enrolment window and whether anyone is permanently sitting inside it.
Weak second factors identified
SMS and voice codes are phishable and SIM-swappable. We report the mix of methods in use and who should be moved to Authenticator, prompts or passkeys.
Users with 2SV bypass or exemption
Temporary exemptions granted during a rollout tend to become permanent. Every active exception is listed with the account it belongs to.
Passkey adoption reviewed
Passkeys remove passwords from the sign-in flow entirely. We report adoption and whether the domain policy allows passwordless sign-in for staff.
Password and recovery controls
Minimum password length and strength enforced
We check the enforced minimum length, whether strength is required, and whether the policy applies to every organisational unit or just the default one.
- CIS GW 1.3
- Cyber Essentials
Password reuse prevention enabled
Allowing password reuse defeats a reset after a phishing incident. We check whether the domain forbids reuse.
Enforce password policy at next sign-in
A tightened policy only bites if it is enforced on existing users, not just new ones. We check whether the setting was applied retroactively.
Self-service account recovery settings appropriate
Self-service recovery for admins and, in many cases, for staff, is a social-engineering path into the tenant. We report the current stance for both groups.
- SCuBA GWS.COMMONCONTROLS
Recovery phone and email coverage
Missing or stale recovery details cause avoidable lockouts and slow incident response. We report coverage across the user base.
Account lifecycle and at-risk users
Dormant and never-used accounts identified
Licensed accounts with no sign-in for 30, 60 or 90+ days are both a cost and a risk. We list them with last-login dates so you can suspend, archive or reclaim licences.
Suspended accounts still holding data access
Suspension is not the same as offboarding. We check for suspended accounts that still own Shared Drive content, group memberships or active app tokens.
Accounts flagged in Google's compromised-credential signals
Google surfaces accounts with leaked or suspicious sign-in signals. We collect them into a single at-risk list rather than leaving them buried in the console.
Super-admin and executive accounts under Advanced Protection
Google's Advanced Protection Program hardens high-value accounts against phishing. We check whether the people most likely to be targeted are enrolled.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.