What's changed: Created Associate Google Workspace Administrator Chapter 4 (Domain 4 "Security/access": strengthening auth = enforce 2SV/security keys-passkeys/SAML SSO/password policy/recovery; access control and response = context-aware access/security dashboard/alert center/block less secure apps/compromise suspend-reset-session revocation).
4.1Strengthening authentication (2-step verification, SSO)
Understand enforcing 2-step verification (2SV) and stronger methods (security keys/passkeys), SAML SSO federation with an external IdP, password policy (length, reuse, strength), and configuring secure account recovery.
Account takeover is one of the biggest threats. The first line of defense is strengthening authentication, anchored by 2-step verification (2SV) and single sign-on.
4.1.12-step verification and methods
2-step verification (2SV) requires a second factor in addition to a password, so a leaked password alone is not enough. Admins can enforce 2SV per OU/group. Methods include SMS/app codes, Google prompts, and the strongest security keys (FIDO) and passkeys. Security keys/passkeys are the most phishing-resistant. Map "basic takeover defense = enforce 2SV" and "strongest = security keys/passkeys."
4.1.2SSO and password policy
To make an external IdP (Okta, Entra ID, etc.) the source of truth, configure SAML SSO and delegate Workspace login to the IdP (one sign-in for many services). When Workspace authenticates itself, set a password policy (minimum length, strength, no reuse) per OU. Also set up secure account recovery (recovery email/phone, admin reset). Map "delegate auth to an IdP = SAML SSO" and "self-auth strength = password policy."
Common: requirement → means. E.g., "basic way to reduce takeover" = enforce 2SV; "most phishing-resistant" = security keys/passkeys; "unify login via an external IdP" = SAML SSO; "minimum length or no reuse" = password policy; "enforce 2SV only for an OU" = per-OU enforcement.
Watch the mix-ups: (1) 2SV ranges from codes/prompts to security keys in strength (keys/passkeys are strongest). (2) SSO (SAML) is auth delegation, while provisioning (SCIM/GCDS) is account creation—different things. (3) Enforcement can roll out gradually per OU/group.
4.1.3Section summary
- Enforce 2SV per OU/group; strongest is security keys/passkeys (phishing-resistant)
- Unify login via external IdP = SAML SSO (auth delegation)
- For self-auth, set password policy (length/strength/no reuse) and secure recovery
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which is the basic takeover defense making a leaked password alone insufficient?
Q2. Which 2-step verification method is the most phishing-resistant?
Q3. To delegate login to an external IdP (Okta, Entra ID) and sign in once for many services, what do you use?
Q4. When Workspace authenticates itself, what defines minimum length and no reuse?
Q5. Which correctly relates SSO (SAML) and provisioning (SCIM/GCDS)?
Q6. To roll out gradually, you want to enforce 2SV only for a certain OU. Which best fits?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

