What's changed: Created Associate Google Workspace Administrator Chapter 4 (Domain 4 "Security/access": strengthening auth = enforce 2SV/security keys-passkeys/SAML SSO/password policy/recovery; access control and response = context-aware access/security dashboard/alert center/block less secure apps/compromise suspend-reset-session revocation).
4.1Strengthening authentication (2-step verification, SSO)
Understand enforcing 2-step verification (2SV) and stronger methods (security keys/passkeys), SAML SSO federation with an external IdP, password policy (length, reuse, strength), and configuring secure account recovery.
Account takeover is one of the biggest threats. The first line of defense is strengthening authentication, anchored by 2-step verification (2SV) and single sign-on.
4.1.12-step verification and methods
2-step verification (2SV) requires a second factor in addition to a password, so a leaked password alone is not enough. Admins can enforce 2SV per OU/group. Methods include SMS/app codes, Google prompts, and the strongest security keys (FIDO) and passkeys. Security keys/passkeys are the most phishing-resistant. Map "basic takeover defense = enforce 2SV" and "strongest = security keys/passkeys."
4.1.2SSO and password policy
To make an external IdP (Okta, Entra ID, etc.) the source of truth, configure SAML SSO and delegate Workspace login to the IdP (one sign-in for many services). When Workspace authenticates itself, set a password policy (minimum length, strength, no reuse) per OU. Also set up secure account recovery (recovery email/phone, admin reset). Map "delegate auth to an IdP = SAML SSO" and "self-auth strength = password policy."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

