Instiq
Chapter 4 · Security policy and access control·v1.0.0·Updated 6/28/2026·~13 min

What's changed: Created Associate Google Workspace Administrator Chapter 4 (Domain 4 "Security/access": strengthening auth = enforce 2SV/security keys-passkeys/SAML SSO/password policy/recovery; access control and response = context-aware access/security dashboard/alert center/block less secure apps/compromise suspend-reset-session revocation).

4.2Access control and security response

Key points

Understand context-aware access to control access by device/location/IP, the security dashboard and alert center to understand and respond to threats, blocking less secure apps, and operations to protect accounts during compromise.

Even with strong authentication, context-based control and detecting/responding to anomalies are essential. Cover condition-based access control and the means to surface and respond to threats.

4.2.1Context-aware access

Context-aware access allows/restricts access based on conditions a user must meet (device posture, location/country, IP range, whether a corporate device, etc.)—a zero-trust mindset. E.g., allow Drive only from managed devices, block from a certain country. Map "control access by condition = context-aware access."

4.2.2Surfacing and responding to threats

Use the security dashboard to overview the org security posture (sharing, spam, auth) and the alert center to receive and act on alerts like suspicious logins or phishing (linked to the investigation tool). Block less secure apps using old auth, and protect suspected-compromised accounts via suspend / password reset / session revocation. Map "overview threats = security dashboard," "receive and respond to alerts = alert center," and "cut off old risky connections = block less secure apps."

Exam point

Common: requirement → means. E.g., "allow access only from managed devices" = context-aware access; "overview the org security posture" = security dashboard; "get notified of suspicious logins and respond" = alert center; "stop old insecure connections" = block less secure apps; "immediately protect a compromised account" = suspend/reset/session revocation.

Warning

Watch the mix-ups: (1) Context-aware access is condition-based control, a layer separate from auth strengthening (2SV/SSO)—combine them. (2) The dashboard overviews, while the alert center handles individual notifications—different roles. (3) Some advanced security features depend on edition.

Diagram of context-aware access (device/location/IP conditions), security dashboard (overview), alert center (respond to alerts), blocking less secure apps, and compromise response (suspend/reset/session revocation).
Conditional control and response

4.2.3Section summary

  • Context-aware access = allow/restrict by conditions (device/location/IP)
  • Overview via the security dashboard; receive and respond to alerts in the alert center
  • Block less secure apps; on compromise, protect via suspend/reset/session revocation

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To allow Drive access only from managed (corporate) devices and restrict others, what do you use?

Q2. To overview the org-wide security posture (sharing, spam, auth) at a glance, what do you use?

Q3. To receive and act/investigate on suspicious-login or phishing notifications, what do you use?

Q4. Which is the appropriate handling of "less secure apps" using old auth?

Q5. When an account is suspected compromised, which immediate protection is most appropriate?

Q6. Which correctly relates context-aware access and 2-step verification?

Check your understandingPractice questions for Chapter 4: Security policy and access control

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.