Skip to content
Technical Guides

MFA for Google Workspace: the Cyber Essentials v3.3 setup

Google Workspace 2-Step Verification for Cyber Essentials v3.3: enrolment, effective enforcement, administrator recovery and current OAuth client guidance.

turned-on MacBook Pro

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

MFA for Google Workspace: the Cyber Essentials v3.3 setup

Google Workspace uses 2-Step Verification (2SV). Your rollout must produce effective MFA for users authenticating to this in-scope cloud service. Read the MFA pillar for the scheme baseline.

Section 02

2SV enforcement for all users

Follow Google's current deployment guidance:

1. In Google Admin, open Security → Authentication → 2-Step Verification.

2. Select the relevant organisational unit or configuration group and allow enrolment.

3. Prepare users, supported methods and recovery before enforcing the policy.

4. Choose the enforcement date and new-user enrolment setting appropriate to your rollout. A fourteen-day window is a local planning choice, not a certification grace period.

5. Review allowed methods and trusted-device settings. Confirm the actual authentication and session behaviour.

6. Verify enforcement for ordinary users, administrators and relevant guest access before assessment.

A registered method is not enough if users can still sign in without the required protection. Review policy coverage as well as enrolment reports.

Section 03

Admin hardening

Google's Advanced Protection Program supports passkeys or security keys. It is an additional protection option, not a Cyber Essentials requirement for every Super Admin and not a universal two-hardware-key mandate.

We recommend phishing-resistant credentials for privileged access. Prepare backup and recovery before enrolling or restricting methods, and confirm any Google administrator-specific requirements applicable to your account. Product requirements can be stricter than the Cyber Essentials baseline.

Section 04

Current email client authentication

Google removed password-only less-secure-app access on 1 May 2025. The former Less Secure Apps enforcement menu is unavailable; there is no toggle to turn off for a current rollout.

Use supported OAuth-capable clients and review app access controls. POP and IMAP are protocols that can use OAuth, not synonyms for basic authentication. Disable protocols you do not need as hardening, and verify that any retained application or app-password route cannot undermine your intended MFA enforcement.

Section 05

Organisational units for granular rollout

Organisational units or configuration groups can help stage enrolment and apply stronger methods to administrators. Avoid leaving a pilot or contractor group permanently outside required enforcement. Where an external identity provider supplies SSO, verify that its MFA and the resulting Google sign-in satisfy the policy, including direct sign-in and recovery routes.

Section 06

What to show the assessor

Prepare the effective 2SV enforcement configuration, user coverage and representative sign-in results. Explain supported clients, SSO, recovery and any technical identities. APP enrolment is supporting evidence for optional hardening; it is not a substitute for covering all required users.

Section 07

SMS: use sparingly

Cyber Essentials does not ban SMS for administrators. The NCSC recommends suitable alternatives because SMS is weaker. Select methods according to the actual Google policy, accessibility and risk; label a stricter organisation policy as your hardening choice.

Section 08

Common failures

Allowed but not enforced

Users can enrol but are still able to complete password-only cloud authentication. Complete the rollout and verify enforcement.

Uncovered organisational units

A group was excluded during rollout and never brought under the effective policy. Review all intended users and services.

Retired setup instructions

The old Less Secure Apps menu no longer provides a current control. Use OAuth-capable clients and current app access controls.

Client authentication misunderstood

A POP or IMAP connection may use modern OAuth. Check the authentication mode and actual MFA policy rather than treating the protocol name as a failure.

Section 09

Preparing for assessment

Allow enough time for user enrolment, client migration and recovery tests. Completion depends on your environment; no under-an-hour implementation is guaranteed. Record the policies and sign-in results that demonstrate the final control.

Start Cyber Essentials | Buy CE Micro £299.99 | MFA pillar

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group