MFA for Google Workspace: the Cyber Essentials v3.3 setup
Google Workspace 2-Step Verification for Cyber Essentials v3.3: enrolment, effective enforcement, administrator recovery and current OAuth client guidance.

Section 01
MFA for Google Workspace: the Cyber Essentials v3.3 setup
Google Workspace uses 2-Step Verification (2SV). Your rollout must produce effective MFA for users authenticating to this in-scope cloud service. Read the MFA pillar for the scheme baseline.
Section 02
2SV enforcement for all users
Follow Google's current deployment guidance:
1. In Google Admin, open Security → Authentication → 2-Step Verification.
2. Select the relevant organisational unit or configuration group and allow enrolment.
3. Prepare users, supported methods and recovery before enforcing the policy.
4. Choose the enforcement date and new-user enrolment setting appropriate to your rollout. A fourteen-day window is a local planning choice, not a certification grace period.
5. Review allowed methods and trusted-device settings. Confirm the actual authentication and session behaviour.
6. Verify enforcement for ordinary users, administrators and relevant guest access before assessment.
A registered method is not enough if users can still sign in without the required protection. Review policy coverage as well as enrolment reports.
Section 03
Admin hardening
Google's Advanced Protection Program supports passkeys or security keys. It is an additional protection option, not a Cyber Essentials requirement for every Super Admin and not a universal two-hardware-key mandate.
We recommend phishing-resistant credentials for privileged access. Prepare backup and recovery before enrolling or restricting methods, and confirm any Google administrator-specific requirements applicable to your account. Product requirements can be stricter than the Cyber Essentials baseline.
Section 04
Current email client authentication
Google removed password-only less-secure-app access on 1 May 2025. The former Less Secure Apps enforcement menu is unavailable; there is no toggle to turn off for a current rollout.
Use supported OAuth-capable clients and review app access controls. POP and IMAP are protocols that can use OAuth, not synonyms for basic authentication. Disable protocols you do not need as hardening, and verify that any retained application or app-password route cannot undermine your intended MFA enforcement.
Section 05
Organisational units for granular rollout
Organisational units or configuration groups can help stage enrolment and apply stronger methods to administrators. Avoid leaving a pilot or contractor group permanently outside required enforcement. Where an external identity provider supplies SSO, verify that its MFA and the resulting Google sign-in satisfy the policy, including direct sign-in and recovery routes.
Section 06
What to show the assessor
Prepare the effective 2SV enforcement configuration, user coverage and representative sign-in results. Explain supported clients, SSO, recovery and any technical identities. APP enrolment is supporting evidence for optional hardening; it is not a substitute for covering all required users.
Section 07
SMS: use sparingly
Cyber Essentials does not ban SMS for administrators. The NCSC recommends suitable alternatives because SMS is weaker. Select methods according to the actual Google policy, accessibility and risk; label a stricter organisation policy as your hardening choice.
Section 08
Common failures
Allowed but not enforced
Users can enrol but are still able to complete password-only cloud authentication. Complete the rollout and verify enforcement.
Uncovered organisational units
A group was excluded during rollout and never brought under the effective policy. Review all intended users and services.
Retired setup instructions
The old Less Secure Apps menu no longer provides a current control. Use OAuth-capable clients and current app access controls.
Client authentication misunderstood
A POP or IMAP connection may use modern OAuth. Check the authentication mode and actual MFA policy rather than treating the protocol name as a failure.
Section 09
Preparing for assessment
Allow enough time for user enrolment, client migration and recovery tests. Completion depends on your environment; no under-an-hour implementation is guaranteed. Record the policies and sign-in results that demonstrate the final control.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
MFA for Microsoft 365: the Cyber Essentials v3.3 configuration
Configure Microsoft 365 MFA for Cyber Essentials v3.3: Security Defaults and Conditional Access, current number matching, administrator recovery and evidence of enforcement.
Read articleTechnical Guides
MFA conditional access under Cyber Essentials v3.3: what works, what fails
Review Conditional Access for Cyber Essentials v3.3: effective MFA, location exclusions, authenticated sessions, device trust and safe administrator recovery.
Read articleTechnical Guides
Multi-factor authentication for Cyber Essentials v3.3: the complete pillar guide
MFA is the single most common reason Cyber Essentials v3.3 submissions fail. This pillar explains which accounts need MFA, which methods are acceptable, and how to implement it across Microsoft 365, Google Workspace, and line-of-business SaaS.
Read article

