Phishing-Resistant Multi-Factor Authentication
Multi-factor means you need two things to log in: your password plus proof it's really you, like a physical security key you plug in or tap. Phishing-resistant means even a fake website can't trick the key, because the key only works on the real Google site. It's like a house key that refuses to turn in any lock except your own front door.
Passwords get stolen or guessed all the time, and without a phishing-resistant second factor an attacker who has your password can walk right into your accounts and your CUI.
- 1Turn on 2SV
- 2Create Admins OU
- 3Require security key
- 4Distribute keys
- 5Enforce
- 6Verify enrollment
Register at least two keys per admin (one primary, one backup) so a lost key never locks you out of the whole tenant.
For CUI, pair phishing-resistant MFA with Google Workspace Assured Controls/Assured Workloads; the standard commercial tenant is only DoD IL2 and is not sufficient for CUI on its own.