Free DIY Resource • Microsoft 365 & Google Workspace Security
Microsoft 365 and Google Workspace Security Checklist: 4 Checks You Can Run Yourself Today
Most workspace breaches don't start with a sophisticated attack. They start with one setting nobody circled back to check: an admin account without MFA, a sign-in log nobody reviewed, a sharing link left wide open. Here's what's actually at stake, a few blind spots most teams miss, and four checks you can run yourself in under an hour without needing an IT background.
Security reviews get pitched as an all-or-nothing investment, but a handful of concentrated checks catch a disproportionate share of the risk. Attackers favor the easiest path in: a reused password, a stale admin account, a sign-in nobody's watching. None of the four checks below need specialized tools or a security background, just admin access to your platform.
What's At Stake
- An account takeover that starts with one phished login, with no MFA in place to stop it from becoming full access.
- A cyber insurance claim denied after a breach, because MFA wasn't enforced the way your policy assumed it was.
- A breach you can't fully explain to your board, your insurer, or a regulator, because there's no clear record of what happened.
Other Blind Spots
- Admin accounts still active for employees or contractors who left the company months ago.
- Retention settings that don't match your actual compliance requirements, whether that's HIPAA, a client contract, or an industry standard.
- Sign-in policies that look reasonable at a glance, but fall apart the moment you check them control by control.
4 Checks You Can Run Yourself Today
0 of 4 complete
-
Enforce MFA on every admin account. Admin accounts are the highest-value target in your environment, and they're the ones most often left unprotected. Microsoft 365: Azure AD › Security › MFA status by user.
Google Workspace: Admin console › Security › 2-Step Verification enrollment. -
Pull sign-in logs for the last 30 days. One unfamiliar country or device in a sign-in log is often the earliest, cheapest warning sign you'll get. Microsoft 365: Azure AD › Sign-in logs, filter by location.
Google Workspace: Admin console › Reports › Login audit log. -
Review connected third-party apps. Every app a user has granted access to is a door into your environment that you don't control. Microsoft 365: Azure AD › Enterprise applications › User consent.
Google Workspace: Admin console › Security › API controls › App access. -
Check your default file-sharing setting. "Anyone with the link" is the default a lot of organizations never actually chose; it just came with the platform. Microsoft 365: SharePoint admin center › Policies › Sharing.
Google Workspace: Admin console › Apps › Drive and Docs › Sharing settings.
Common Questions
Do I need to run all four checks, or just the ones that apply to my platform?
Run all four regardless of whether you're on Microsoft 365, Google Workspace, or both. The specific menu paths differ by platform, but the underlying risk (unprotected admin accounts, unreviewed sign-ins, unchecked app access, and default sharing settings) is the same everywhere.
How long does this actually take?
Most teams get through all four checks in under an hour, assuming you already have admin access. The MFA and sharing-settings checks are usually the fastest; reviewing sign-in logs and connected apps takes longer if you haven't looked at either in a while.
What's the difference between this checklist and a full security review?
This checklist catches the handful of settings responsible for a large share of workspace breaches. A full review goes further: every user, every device, every policy, mapped against a specific compliance standard, with a written report you can hand to an auditor or insurer. Think of this as the fast, self-serve version of the first few pages of that report.
Will enforcing MFA disrupt my team?
There's a short adjustment period while people set up an authenticator app or register a device, but most organizations see it become routine within a week or two. The disruption of a compromised admin account is almost always worse than the friction of turning MFA on.
How often should I re-run this checklist?
Quarterly is a reasonable baseline for most small and mid-sized organizations, with an extra pass any time you onboard a new admin, change MSPs, or go through a merger, acquisition, or compliance audit.