5 Google Workspace settings forSOC2 &ISO27001
Google Workspace provides default settings that leave companies exposed to audit findings.
Google Workspace offers default settings that leave companies exposed. Not in a subtle way. In obvious ways that any security person would mark in five minutes.
This is not a bug. Google favors frictionless connection over secure default settings. The easier it is to register and start using everything, the more people adopt their products.
Here are five settings to be corrected right now. SOC 2 or ISO 27001, each of these maps to control your auditor will check.
2FA is not applied by default
By 2026, two-factor authentication is still optional by default on Google Workspace. Every employee can log in with a single password.
Go to Admin Console → Security → Authentication → 2-Step VerificationActivate the application for the entire organization, select a deadline, and after that date no one logs in without 2FA.
Large-domain Google registration is allowed everywhere
By default, employees can use “Register with Google” on any third-party app. When someone clicks that button, they often give the app access to email, contacts, Drive files, everything.
Some of these apps will also ping every collaborator in the organization so that the tools that no one has approved reach the people no one intended.
Go to Admin Console → Security →APIControls → Access to third-party applicationsBlock all third-party apps by default. Allow only "Email Registration," the basic application domain that doesn't share anything but your email address. If an employee needs to connect a tool to Drive or anything else, asking for it, an administrator reviews it and there's a record of what has been approved.
DKIM, DMARC and SPF are not enabled by default
Google Workspace does not set DKIM, DMARC, or SPF for your domain.Without them, anyone on the internet can send emails pretending you are customers, partners, employees, they have no way to say that the email is fake.
SPF: Add a TXT record to DNS: v=spf1 include:_spf.google.com ~all. This tells the receiving servers that only Google is allowed to send emails for your domain.
DKIM: Go to Admin Console → Apps → Google Workspace → Gmail → Authenticate EmailGenerate the DKIM key and add the TXT record to the DNS.
DMARC: Add a TXT record: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com. Start with p=none to the monitor, then move to p=quarantine, then p=reject once everything seems clean.
Cloudflare makes free DMARC monitoring. shows who sends emails on behalf of your domain Once the reports are clean, move on to rejection and fake emails are blocked before they reach anyone.
The entire installation is free of charge and takes about 30 minutes.
Gmail security settings are too permitted
Gmail has built-in protection against malicious attachments, suspicious links, and spoofing attempts.
Go to Admin Console → Apps → Google Workspace → Gmail → SafetyEnable Enhanced Message Scanning Before Delivery so that Gmail can scan attachments and links before they reach your mailbox. Enable protection against encrypted attachments from untrusted senders, scripts from untrusted senders and abnormal attachment types. Also enable protection against links behind short URLs and against links pointing to untrusted domains.
These settings exist. They work. They just sit there, waiting for someone to turn them back.
Set a session timeout
By default, Google sessions remain alive for a very long time. If someone steals a session cookie, they have access as long as that session lives.
Go to Admin Console → Security → Google session controlA good standard is 1 week. If it feels too aggressive, 30 days is the absolute maximum. Re-authenticating once a week takes a few seconds. Leaving sessions open for months is a risk that no one should take.
Wrap up
Most companies assume this works out of the box. No. And that’s what makes it so frustrating, because these are just settings. There are no expensive tools, no security team, no consultancy involvement. Only settings that Google has left behind.
For a small company, it takes about an hour. If you need a wider view of What measures should be taken to ensure complianceFor the larger one, shadow IT cleaning will take longer as you’ll find dozens of applications already connected that no one remembers to approve.
Your team won’t even notice most of these changes, but your company will be much harder to attack. Stripe security checklist covering 2FA, SSO, and payout settings.