| name | cis-gworkspace-3.1.3.1.1 |
| description | Ensure users cannot delegate access to their mailbox |
| category | cis-gworkspace |
| version | 1.3.0 |
| author | cyberstrike-official |
| tags | ["cis","gcp","google-workspace","gmail","delegation","email-security"] |
| cis_id | 3.1.3.1.1 |
| cis_benchmark | CIS Google Workspace Foundations Benchmark v1.3.0 |
| tech_stack | ["gcp","google-workspace"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
3.1.3.1.1 Ensure users cannot delegate access to their mailbox
Overview
| Property | Value |
|---|
| CIS ID | 3.1.3.1.1 |
| Level | L1 |
| Profile Applicability | Enterprise Level 1 |
| Assessment Type | Manual |
| Section | Gmail > User Settings |
Description
Mail delegation allows the delegate to read, send, and delete messages on their behalf. For example, a manager can delegate Gmail access to another person in their organization, such as an administrative assistant.
Rationale
Only administrators should be able to delegate access to a user's mailboxes.
Impact
Existing delegations will be hidden, when this feature is disabled.
Default Value
Let users delegate access to their mailbox to other users in the domain is unchecked
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to https://admin.google.com as an administrator
- Select Apps
- Select Google Workspace
- Select Gmail
- Under
User Settings - Mail delegation, ensure Let users delegate access to their mailbox to other users in the domain is unchecked
Remediation
To configure this setting via the Google Workspace Admin Console:
- Log in to https://admin.google.com as an administrator
- Select Apps
- Select Google Workspace
- Select Gmail
- Under
User Settings - Mail delegation, set Let users delegate access to their mailbox to other users in the domain to unchecked
- Select Save
CIS Controls