[HN Gopher] A practical guide to securing Google Workspace for a...
___________________________________________________________________
A practical guide to securing Google Workspace for a startup
Author : gepeto42
Score : 162 points
Date : 2022-02-25 17:23 UTC (5 hours ago)
(HTM) web link (fleetdm.com)
(TXT) w3m dump (fleetdm.com)
| sinderznashes wrote:
| This is super helpful. Passing over to the orgs using Workspace
| in my world.
| latchkey wrote:
| This article covers Macs as well.
|
| I wonder about Windows.
| gepeto42 wrote:
| Hi! We will eventually cover other OSes. In the meantime, for
| Windows, Microsoft has good guides through they are usually
| very lengthy -
| https://techcommunity.microsoft.com/t5/microsoft-security-ba...
| yellow_mixer wrote:
| May I ask what you are using for endpoint management? Are you
| using JAMF, Intune, something else? Are you using an always
| on VPN to all users? All cloud based or on-prem infra? DNS
| security? Endpoint protection?
|
| Thanks for posting the guide!
| gxt wrote:
| It never made sense to me that large software suites like these
| don't offer a secure by default option on creation or as a
| progressive migration after creation. Why soo many steps...
| codegeek wrote:
| Nice guide. I would also suggest checking your domain's MX
| records to ensure you have things configured correctly including
| DKIM etc. Google has this tool that gives your domain a scan:
|
| https://toolbox.googleapps.com/apps/checkmx/
| gepeto42 wrote:
| We did mention DMARC DKIM etc but I did not put a link to this
| very useful tool. Feel free to submit a PR and we'll merge it -
| https://github.com/fleetdm/fleet/edit/main/handbook/security...
| - or if you don't mind I can also add it on my side next time I
| make an edit.
| codegeek wrote:
| Yes of course go ahead add it :)
| jiveturkey wrote:
| Neat but inadequate. My domain passes all the checks, yet I
| already know that I have SPF and DMARC set, but so that spoofs
| get through. A proper tool should have flagged that.
|
| I rather like easydmarc.com. They charge for analytic services
| but you can use their checker for free. They also have very
| easily digested guides and recommendations for setting up the
| various records.
| tomcam wrote:
| Just wanted you to know that this made a huge difference on my
| most important domain, today. I appreciate your pointing it out
| because I assumed Gmail would automagically handle everything
| codegeek wrote:
| Glad to be of help. I also found this the hard way. Google
| Workspace doesn't do this by default
| gepeto42 wrote:
| This is how we secure Workspace here at Fleet. We figured the
| guide could be useful to companies of a similar size. The next
| step would be to enable Endpoint Verification to control access
| to specific apps such as Drive so it could only be done from up
| to date, encrypted devices, but that requires a the highest
| Google subscription.
| zwass wrote:
| I'm excited to see how Guillaume is sharing our security
| journey as Fleet grows!
| staticassertion wrote:
| We've been meaning to write about this. You can actually do it
| with just Google Business, but you have to then also buy their
| Identity service, which I forget the name of. It's packaged
| into Enterprise edition but also sold separately.
|
| We also reached out to sales and got a deal, explaining we
| didn't want to pay prices designed for companies with 1000s of
| employees.
| tempnow987 wrote:
| Turning on trust devices makes users a TON happier.
|
| You'll still get a password prompt if elevating security profile
| for something higher privilege in my experience.
| gepeto42 wrote:
| That is true especially if your sessions are made very short,
| which requires the more expensive Google Workspace edition. But
| if sessions are long, the risk is users lose access to their
| 2FA and don't notice until it becomes a bigger problem...
| adev123 wrote:
| Thoughts on using Event Threat Detection / Chronicle or exporting
| logs to GCP and beyond for analysis?
|
| https://cloud.google.com/security-command-center/docs/how-to...
|
| https://cloud.google.com/logging/docs/audit/configure-gsuite...
| jscardella wrote:
| Written by a former colleague whom I trust and who knows the
| space! Very good explanations and easy to follow.
| julienfr112 wrote:
| Try to do the same for Azure Ad + intune + office 365 + ...
| Hundreds of pages....
| tempnow987 wrote:
| Haha.. I tried a bit and failed to get it to hang together with
| some poking.
|
| One user request was to STOP the "windows hello" PIN
| requirement, and just have a password (+ MFA) for login. Does
| anyone know how to do this with either standard Office 365
| subscriptions, or office 365 + Intune or similar? Would love
| not to have to do Azure AD outside of the office subscriptions.
| Microsoft has a fair number of SKU's these days that kind of
| overlap (and get renamed).
| qwertox wrote:
| I wish it had a feature in the admin section where one could
| disable different 2FA methods. For example, in my family everyone
| has SMS as a 2FA, as well as hardware tokens and device prompts.
| SMS was there from the beginning, so everyone has it activated.
| Only one account is not using hardware tokens.
|
| So what I'd like to do is to set SMS to off, and all the accounts
| which already have something like device prompts and/or at least
| one hardware token added, get SMS deactivated without user
| intervention.
| gepeto42 wrote:
| There is, though it is not ultra granular. They introduced it
| last year and we mention it in the guide.
|
| https://workspaceupdates.googleblog.com/2019/03/more-control...
|
| Essentially you can enforce 2FA or not, then, you can allow ANY
| method, any method BUT telephony based (calls and SMS), or
| hardware security key only.
|
| The middle option for most people is a great one as it allows
| Google Prompt (push notifications) as well as Google
| Authenticator style OTPs, plus security keys.
| qwertox wrote:
| Good to know, thanks! It's exactly what I need.
| 71a54xd wrote:
| Thanks for this! THis kind of domain security is usually poorly
| articulated or just not out in the open. I still think the basis
| of most risk for small companies is their domains. Lose control
| of those and well.. you're fucked. Any recs for "high security"
| domain providers?
| gepeto42 wrote:
| You are 100% right that the domain is the keys to the kingdom.
|
| Definitely only use registrars and DNS providers that have 2FA.
| Google has a registrar now, as well as DNS in GCP
| https://cloud.google.com/domains/docs/register-domain and
| https://cloud.google.com/dns. By using those you can leverage
| your Google account's security (use separate accounts for admin
| level access on GCP and enforce hardware 2FA), and control who
| gets access using IAM. AWS has similar options.
| alphabrevity wrote:
| Love how everything is out in the open....big fan of transparency
| !
| gepeto42 wrote:
| Thanks. There is no need to keep most security controls for
| common tools secret, and the more organisations discussing how
| they do it the better.
|
| For example, a small org with no security people or a non-
| profit could be made much more secure by following this, so why
| not publish it?
| mlrhazi wrote:
| Nothing about Addons/MarketApps ? should one disable all? can we
| manage the access they have to the domain/user data?
| gepeto42 wrote:
| The API Access section covers OAuth apps. Essentially you:
|
| 1. Mark Google services you consider critical as "restricted"
| (ex: Drive, gmail) 2. On Gmail and Drive, you can then allow
| apps that use lower levels of permissions, but not those who
| need "dangerous access" 3. Then on a per app basis you can mark
| apps as "trusted" which lets them access "restricted" Google
| services.
|
| It is not super granular in the sense that you can't easily say
| - Calendar2000 can be used by my sales team, and should have
| access only to the invites date and time but not attendees,
| body or attachment, but it is better than nothing!
| staticassertion wrote:
| Another tip - enabled Advanced Protection Program. You can't
| enforce this at the GSuite level but for a small company it's
| easy to just audit for it.
|
| We have everyone do this as part of onboarding and we audit once
| a month.
| hn_throwaway_99 wrote:
| One hundred percent agreed. Not sure why Google doesn't allow
| enforcement of this for Workspace accounts.
|
| This is a great guide, I just wish Google made it easier to be
| "secure by default". It's very difficult to know all the
| various toggles you need to have switched on to be secure.
| gepeto42 wrote:
| Yes! With advanced protection you get enforced security keys,
| recovery only through admins, enforced safe browsing in Chrome.
| It's a nice way to get a bunch of improved controls in one
| shot.
|
| Would be nice if Google allowed enforcing it with a grace
| period for new accounts though!
| staticassertion wrote:
| Agreed - there's basically nothing in GSuite about it, except
| the indicator on a user's page. It's enough for manual
| auditing at least. But since we handle it during our
| onboarding and we're small enough for a manual audit it works
| out alright.
| TheSisko wrote:
| I went through a very similar process earlier this month. This is
| a solid guide.
| [deleted]
| johndfsgdgdfg wrote:
| People shouldn't use Google Workspace after Google decided to
| make exisiting legacy users hostage for money. [1] Everyone
| should use Office 365 or other alternatives.
|
| [1] https://thenextweb.com/news/google-gsuite-free-
| alternatives-...
| rob-olmos wrote:
| FYI to setup an alert like "Out of domain email forwarding" --
| you have to go to Reporting > Login. If you go to Rules and click
| "create rule" it'll take you to Reporting > Admin, which won't
| have the Login event types.
___________________________________________________________________
(page generated 2022-02-25 23:00 UTC)