Google Workspace security for admins in 2026: what each plan actually includes, the best-practices checklist from Google's own documentation, the phishing protections worth turning on today, and where the built-in tools stop.
Key takeaways
- Google Workspace's security features are tier-gated more than most admins realize: Vault arrives at Business Plus, while data loss prevention and context-aware access are Enterprise features, so the first security decision is a plan decision.
- Google's strongest recommended protection remains 2-Step Verification with security keys, which Google calls the most secure form of 2SV, enforced for admins first and everyone after.
- The built-in tools protect accounts and data, but they do not manage how a team works in email: shared credentials for shared addresses remain the most common self-inflicted Workspace vulnerability, and the fix is structural, not a setting.
Table of contents
Google Workspace ships with more security than most admins ever switch on, and the honest problem is knowing which protections exist, which plan they live on, and which settings deserve the next hour of your time. Google's own security checklist runs to thirteen sections, and most guides, this one included until this update, covered a fraction of it.
This guide is the admin's version: what each plan includes, the settings that matter most in priority order, the phishing protections specifically, and the places where Workspace's built-in tools genuinely stop. Every claim is pinned to Google's own documentation, updated July 22, 2026.
What each Google Workspace plan includes for security
| Security capability | Business Starter | Business Standard | Business Plus | Enterprise |
|---|---|---|---|---|
| 2-Step Verification, including security keys | Yes | Yes | Yes | Yes |
| Advanced phishing and malware protection | Yes | Yes | Yes | Yes |
| Endpoint management | Fundamental | Fundamental | Advanced | Enterprise |
| Google Vault | Yes | Yes | ||
| Data loss prevention, Gmail and Drive | Yes | |||
| Context-aware access | Yes | |||
| Security center: dashboard, investigation tool, security health page | Yes |
Two notes on the table. The security sandbox, which detonates attachments before delivery, is supported on Business Standard and Business Plus as well as Enterprise, but not on Business Starter. And the security center row means Enterprise Standard and Enterprise Plus specifically; Google also supports it on Frontline Standard and Plus, Education Standard and Plus, and Enterprise Essentials Plus.
Google Workspace security best practices
Google publishes its own security checklist for administrators, thirteen sections deep, and the honest summary is that a handful of settings do most of the protecting. Here they are in the order an admin should spend an hour on them.
-
Enforce 2-Step Verification, admins first. Turn on enforcement, not just availability, and use security keys for admin and high-value accounts, which Google's documentation calls the most secure form of 2SV. Add backup codes for account recovery before you need them.
-
Check your admin roster. Fewer super admins, each with a dedicated admin account separate from their daily one, and every admin on security keys. Most Workspace break-ins are account break-ins.
-
Turn on the phishing and malware protections below. They are settings, not defaults, on several plans, and the next section walks them.
-
Review third-party app access. The apps your users have granted OAuth access to are part of your attack surface; the Admin console lists them, and unused ones should go.
-
Set up endpoint management at the level your plan allows. Fundamental management comes with every plan and inventories devices; Advanced, from Business Plus, adds enforcement like screen locks and remote wipe.
-
Use the monitoring your tier gives you. On Business plans that means the built-in reports; the security dashboard and security center below are Enterprise-family features, and either way the habit matters more than the surface, so put a recurring slot on an admin's calendar.
Every item above lives in Google's own checklist at knowledge.workspace.google.com, and the sections below expand the two that repay the most attention.
Protecting Google Workspace from phishing
Phishing is where Workspace admins earn their keep, because Google's protections are real but several are settings you must choose. In the Admin console, Gmail's safety settings include protections against spoofing of your own domain and employee names, links and external images checks, and attachment scanning, each with the choice of warning the user or quarantining outright; quarantine is the stricter and usually better answer for spoofing of your own domain. On plans that include it, the security sandbox detonates attachments in a virtual environment before delivery, catching what signature scanning misses.
Two habits complete the settings. Report and review: users can report phishing from inside Gmail, and an admin reviewing those reports weekly learns what is actually reaching the company. And test your own domain's posture: SPF, DKIM, and DMARC records are what stop others from spoofing you, and Google's Admin Toolbox checks them in a minute.
Drag AI
The inbox your team and your AI work in together
Shared inbox, live chat, and AI in Gmail, with an MCP server your AI tools can drive.
Monitoring: the security center and dashboard
Seeing what is happening is a tier question, and a stricter one than most guides admit: every plan gets basic reporting, but the security dashboard and the full security center, with its investigation tool for tracing incidents, are Enterprise-family features, on Enterprise Standard and Plus and the equivalent Frontline and Education editions, not the Business tiers. Business-tier admins get the sandbox and Gmail's safety settings covered above, plus reporting, and the honest monitoring practice at that tier is the manual one: a monthly review of login activity, external sharing, and user phishing reports from the reports the plan does include.
Put that review on a named admin's calendar rather than everyone's good intentions: monitoring that belongs to nobody happens never, whatever the tier.
Where the built-in tools stop
Everything above protects accounts, devices, and data. None of it manages how a team actually works in email, and that is where the most common self-inflicted vulnerability lives: the shared address. When support@ or info@ is a real mailbox whose password several people know, every protection in this guide weakens at once, because 2SV on a shared credential is a shared secret, offboarding means changing a password everyone uses, and the audit trail says one user did everything.
The structural fix is to stop sharing credentials entirely. Drag turns shared addresses into a shared inbox where each person uses their own Google account and permission-based access replaces the shared password: access is granted per person, revoked instantly when someone leaves, and every action is attributable. Drag itself is built to a posture worth stating on a security page: it does not duplicate emails across mailboxes, does not store your emails on its servers, and is a Google Cloud Partner with CASA Tier 2 verification and GDPR compliance. Plans start at $12 per user per month with a 7-day trial and no card required.

How this guide is verified
Every setting, tier gate, and recommendation on this page comes from Google's own Workspace administrator documentation, principally the security checklist at knowledge.workspace.google.com, last updated July 22, 2026, and the per-feature pages it links. Drag's security posture is stated exactly as our trust documentation states it. No third-party statistics sources are used. This guide is re-verified when Google updates the checklist, with changes recorded rather than silently overwritten.
Google Workspace security FAQs
Is Google Workspace secure by default?
The infrastructure is, but several of the strongest protections are choices: 2-Step Verification enforcement, the stricter phishing settings, and endpoint enforcement all require an admin to turn them on. Default Workspace is safe; configured Workspace is safer by a distance.
How do I secure Google Workspace from phishing?
Turn on Gmail's safety settings for spoofing, links, and attachments in the Admin console, choose quarantine over warn for spoofing of your own domain, enable the security sandbox if your plan includes it, verify your SPF, DKIM, and DMARC records, and review user phishing reports weekly.
What security features does Google Workspace Business Starter include?
The essentials: 2-Step Verification including security keys, fundamental endpoint management, Gmail's core phishing and malware protections, and basic reporting. Vault, data loss prevention, context-aware access, and the full security center live on higher tiers.
What is the most secure form of 2-Step Verification?
Security keys, per Google's own documentation. Enforce them for admin accounts first, keep backup codes stored safely, and roll enforcement out to everyone once admins are covered.
Does Google Workspace include DLP?
Data loss prevention is an Enterprise-tier feature (with Gmail and Drive DLP at that level), so on Business plans the practical substitutes are sharing policies, careful group settings, and monitoring external sharing from the dashboard.
Co-founder
Building Drag for nearly ten years: shared inboxes, boards, and now the AI and agent layer, all on Gmail, plus HeyHelp for the personal inbox. Writes the honest versions of the comparisons.
