[HN Gopher] A practical guide to securing Google Workspace for a...
       ___________________________________________________________________
        
       A practical guide to securing Google Workspace for a startup
        
       Author : gepeto42
       Score  : 162 points
       Date   : 2022-02-25 17:23 UTC (5 hours ago)
        
 (HTM) web link (fleetdm.com)
 (TXT) w3m dump (fleetdm.com)
        
       | sinderznashes wrote:
       | This is super helpful. Passing over to the orgs using Workspace
       | in my world.
        
       | latchkey wrote:
       | This article covers Macs as well.
       | 
       | I wonder about Windows.
        
         | gepeto42 wrote:
         | Hi! We will eventually cover other OSes. In the meantime, for
         | Windows, Microsoft has good guides through they are usually
         | very lengthy -
         | https://techcommunity.microsoft.com/t5/microsoft-security-ba...
        
           | yellow_mixer wrote:
           | May I ask what you are using for endpoint management? Are you
           | using JAMF, Intune, something else? Are you using an always
           | on VPN to all users? All cloud based or on-prem infra? DNS
           | security? Endpoint protection?
           | 
           | Thanks for posting the guide!
        
       | gxt wrote:
       | It never made sense to me that large software suites like these
       | don't offer a secure by default option on creation or as a
       | progressive migration after creation. Why soo many steps...
        
       | codegeek wrote:
       | Nice guide. I would also suggest checking your domain's MX
       | records to ensure you have things configured correctly including
       | DKIM etc. Google has this tool that gives your domain a scan:
       | 
       | https://toolbox.googleapps.com/apps/checkmx/
        
         | gepeto42 wrote:
         | We did mention DMARC DKIM etc but I did not put a link to this
         | very useful tool. Feel free to submit a PR and we'll merge it -
         | https://github.com/fleetdm/fleet/edit/main/handbook/security...
         | - or if you don't mind I can also add it on my side next time I
         | make an edit.
        
           | codegeek wrote:
           | Yes of course go ahead add it :)
        
         | jiveturkey wrote:
         | Neat but inadequate. My domain passes all the checks, yet I
         | already know that I have SPF and DMARC set, but so that spoofs
         | get through. A proper tool should have flagged that.
         | 
         | I rather like easydmarc.com. They charge for analytic services
         | but you can use their checker for free. They also have very
         | easily digested guides and recommendations for setting up the
         | various records.
        
         | tomcam wrote:
         | Just wanted you to know that this made a huge difference on my
         | most important domain, today. I appreciate your pointing it out
         | because I assumed Gmail would automagically handle everything
        
           | codegeek wrote:
           | Glad to be of help. I also found this the hard way. Google
           | Workspace doesn't do this by default
        
       | gepeto42 wrote:
       | This is how we secure Workspace here at Fleet. We figured the
       | guide could be useful to companies of a similar size. The next
       | step would be to enable Endpoint Verification to control access
       | to specific apps such as Drive so it could only be done from up
       | to date, encrypted devices, but that requires a the highest
       | Google subscription.
        
         | zwass wrote:
         | I'm excited to see how Guillaume is sharing our security
         | journey as Fleet grows!
        
         | staticassertion wrote:
         | We've been meaning to write about this. You can actually do it
         | with just Google Business, but you have to then also buy their
         | Identity service, which I forget the name of. It's packaged
         | into Enterprise edition but also sold separately.
         | 
         | We also reached out to sales and got a deal, explaining we
         | didn't want to pay prices designed for companies with 1000s of
         | employees.
        
       | tempnow987 wrote:
       | Turning on trust devices makes users a TON happier.
       | 
       | You'll still get a password prompt if elevating security profile
       | for something higher privilege in my experience.
        
         | gepeto42 wrote:
         | That is true especially if your sessions are made very short,
         | which requires the more expensive Google Workspace edition. But
         | if sessions are long, the risk is users lose access to their
         | 2FA and don't notice until it becomes a bigger problem...
        
       | adev123 wrote:
       | Thoughts on using Event Threat Detection / Chronicle or exporting
       | logs to GCP and beyond for analysis?
       | 
       | https://cloud.google.com/security-command-center/docs/how-to...
       | 
       | https://cloud.google.com/logging/docs/audit/configure-gsuite...
        
       | jscardella wrote:
       | Written by a former colleague whom I trust and who knows the
       | space! Very good explanations and easy to follow.
        
       | julienfr112 wrote:
       | Try to do the same for Azure Ad + intune + office 365 + ...
       | Hundreds of pages....
        
         | tempnow987 wrote:
         | Haha.. I tried a bit and failed to get it to hang together with
         | some poking.
         | 
         | One user request was to STOP the "windows hello" PIN
         | requirement, and just have a password (+ MFA) for login. Does
         | anyone know how to do this with either standard Office 365
         | subscriptions, or office 365 + Intune or similar? Would love
         | not to have to do Azure AD outside of the office subscriptions.
         | Microsoft has a fair number of SKU's these days that kind of
         | overlap (and get renamed).
        
       | qwertox wrote:
       | I wish it had a feature in the admin section where one could
       | disable different 2FA methods. For example, in my family everyone
       | has SMS as a 2FA, as well as hardware tokens and device prompts.
       | SMS was there from the beginning, so everyone has it activated.
       | Only one account is not using hardware tokens.
       | 
       | So what I'd like to do is to set SMS to off, and all the accounts
       | which already have something like device prompts and/or at least
       | one hardware token added, get SMS deactivated without user
       | intervention.
        
         | gepeto42 wrote:
         | There is, though it is not ultra granular. They introduced it
         | last year and we mention it in the guide.
         | 
         | https://workspaceupdates.googleblog.com/2019/03/more-control...
         | 
         | Essentially you can enforce 2FA or not, then, you can allow ANY
         | method, any method BUT telephony based (calls and SMS), or
         | hardware security key only.
         | 
         | The middle option for most people is a great one as it allows
         | Google Prompt (push notifications) as well as Google
         | Authenticator style OTPs, plus security keys.
        
           | qwertox wrote:
           | Good to know, thanks! It's exactly what I need.
        
       | 71a54xd wrote:
       | Thanks for this! THis kind of domain security is usually poorly
       | articulated or just not out in the open. I still think the basis
       | of most risk for small companies is their domains. Lose control
       | of those and well.. you're fucked. Any recs for "high security"
       | domain providers?
        
         | gepeto42 wrote:
         | You are 100% right that the domain is the keys to the kingdom.
         | 
         | Definitely only use registrars and DNS providers that have 2FA.
         | Google has a registrar now, as well as DNS in GCP
         | https://cloud.google.com/domains/docs/register-domain and
         | https://cloud.google.com/dns. By using those you can leverage
         | your Google account's security (use separate accounts for admin
         | level access on GCP and enforce hardware 2FA), and control who
         | gets access using IAM. AWS has similar options.
        
       | alphabrevity wrote:
       | Love how everything is out in the open....big fan of transparency
       | !
        
         | gepeto42 wrote:
         | Thanks. There is no need to keep most security controls for
         | common tools secret, and the more organisations discussing how
         | they do it the better.
         | 
         | For example, a small org with no security people or a non-
         | profit could be made much more secure by following this, so why
         | not publish it?
        
       | mlrhazi wrote:
       | Nothing about Addons/MarketApps ? should one disable all? can we
       | manage the access they have to the domain/user data?
        
         | gepeto42 wrote:
         | The API Access section covers OAuth apps. Essentially you:
         | 
         | 1. Mark Google services you consider critical as "restricted"
         | (ex: Drive, gmail) 2. On Gmail and Drive, you can then allow
         | apps that use lower levels of permissions, but not those who
         | need "dangerous access" 3. Then on a per app basis you can mark
         | apps as "trusted" which lets them access "restricted" Google
         | services.
         | 
         | It is not super granular in the sense that you can't easily say
         | - Calendar2000 can be used by my sales team, and should have
         | access only to the invites date and time but not attendees,
         | body or attachment, but it is better than nothing!
        
       | staticassertion wrote:
       | Another tip - enabled Advanced Protection Program. You can't
       | enforce this at the GSuite level but for a small company it's
       | easy to just audit for it.
       | 
       | We have everyone do this as part of onboarding and we audit once
       | a month.
        
         | hn_throwaway_99 wrote:
         | One hundred percent agreed. Not sure why Google doesn't allow
         | enforcement of this for Workspace accounts.
         | 
         | This is a great guide, I just wish Google made it easier to be
         | "secure by default". It's very difficult to know all the
         | various toggles you need to have switched on to be secure.
        
         | gepeto42 wrote:
         | Yes! With advanced protection you get enforced security keys,
         | recovery only through admins, enforced safe browsing in Chrome.
         | It's a nice way to get a bunch of improved controls in one
         | shot.
         | 
         | Would be nice if Google allowed enforcing it with a grace
         | period for new accounts though!
        
           | staticassertion wrote:
           | Agreed - there's basically nothing in GSuite about it, except
           | the indicator on a user's page. It's enough for manual
           | auditing at least. But since we handle it during our
           | onboarding and we're small enough for a manual audit it works
           | out alright.
        
       | TheSisko wrote:
       | I went through a very similar process earlier this month. This is
       | a solid guide.
        
       | [deleted]
        
       | johndfsgdgdfg wrote:
       | People shouldn't use Google Workspace after Google decided to
       | make exisiting legacy users hostage for money. [1] Everyone
       | should use Office 365 or other alternatives.
       | 
       | [1] https://thenextweb.com/news/google-gsuite-free-
       | alternatives-...
        
       | rob-olmos wrote:
       | FYI to setup an alert like "Out of domain email forwarding" --
       | you have to go to Reporting > Login. If you go to Rules and click
       | "create rule" it'll take you to Reporting > Admin, which won't
       | have the Login event types.
        
       ___________________________________________________________________
       (page generated 2022-02-25 23:00 UTC)