- Login to admin.google.com with your Google Workspace administrator account
- Select the 'Security' section in the menu on the left hand side
- Select 'Authentication' > '2-step verification'
- Here, you can see if MFA (multi-factor authentication) is enforced or not:
- If MFA is not enforced, this must be enabled as soon as possible (NCSC: Turn on 2-step verification (2SV))
- Lineal & the UK NCSC recommend that MFA methods are restricted to either 'Any except verification codes via text, phone call' or even better, 'Only security key' (NCSC: Recommended types of MFA)
- NOTE: Do not enforce 'Only security key' without prior planning & training for end users
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article