| name | implementing-google-workspace-admin-security |
| description | Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration. . Use when working with implementing google workspace admin security. |
| domain | cybersecurity |
| tags | ["Google-Workspace","admin-security","MFA","DMARC","DLP","OAuth","cloud-security"] |
| subdomain | identity-access-management |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.AA-01","PR.AA-02","PR.AA-05","PR.AA-06"] |
Implementing Google Workspace Admin Security
Overview
Cybersecurity skill for implementing google workspace admin security. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"implementing google workspace admin security"
-
"Implements comprehensive Google Workspace security hardening including admin con"
-
Deploying or hardening a Google Workspace environment for enterprise use
-
CIS benchmark compliance assessment for Google Workspace configuration
-
Protecting against business email compromise (BEC) and phishing attacks targeting Google accounts
-
Implementing Data Loss Prevention controls for Gmail and Google Drive
-
Restricting OAuth application access and third-party integrations
-
Configuring admin account security with Advanced Protection Program enrollment
Do not use for Microsoft 365 environments; Google Workspace has distinct admin console settings and API configurations that differ from Azure AD/Entra ID controls.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Google Workspace Business Plus, Enterprise Standard, or Enterprise Plus license
- Super Admin access to the Google Admin Console (admin.google.com)
- DNS management access for SPF, DKIM, and DMARC record configuration
- Google Cloud Identity or Cloud Identity Premium for advanced security features
- FIDO2 security keys for super admin accounts (YubiKey 5 Series recommended)
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}