A practical guide to securing Google Workspace for a startup
1–10 of 64 posts
Re: A practical guide to securing Google Workspace for a startup
#2Re: A practical guide to securing Google Workspace for a startup
#3Re: A practical guide to securing Google Workspace for a startup
#4This is how we secure Workspace here at Fleet. We figured the guide could be useful to companies of a similar size. The next step would be to enable Endpoint Verification to control access to specific apps such as Drive so it could only be done from up to date, encrypted devices, but that requires a the highest Google subscription.
Re: A practical guide to securing Google Workspace for a startup
#5Re: A practical guide to securing Google Workspace for a startup
#6Love how everything is out in the open....big fan of transparency !
For example, a small org with no security people or a non-profit could be made much more secure by following this, so why not publish it?
Re: A practical guide to securing Google Workspace for a startup
#7Re: A practical guide to securing Google Workspace for a startup
#8We have everyone do this as part of onboarding and we audit once a month.
Re: A practical guide to securing Google Workspace for a startup
#9Re: A practical guide to securing Google Workspace for a startup
#10Thanks for this! THis kind of domain security is usually poorly articulated or just not out in the open. I still think the basis of most risk for small companies is their domains. Lose control of those and well.. you're fucked. Any recs for "high security" domain providers?
Definitely only use registrars and DNS providers that have 2FA. Google has a registrar now, as well as DNS in GCP https://cloud.google.com/domains/docs/register-domain and https://cloud.google.com/dns. By using those you can leverage your Google account's security (use separate accounts for admin level access on GCP and enforce hardware 2FA), and control who gets access using IAM. AWS has similar options.