Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
Productivity SuitePLAIN-LANGUAGE GUIDE

Google Workspace setup guide

Gmail, Drive, Docs, and Meet with a single admin console. Work through the ten requirements below — each has a diagram and a checklist you can follow click by click.

Print checklist ↧
Before you store CUI here

Handling CUI in Workspace requires Assured Controls and careful scoping. Confirm an authorization path before you store CUI.

REQUIREMENT 01 OF 10

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3
IN PLAIN WORDS

Multi-factor means you need two things to log in: your password plus proof it's really you, like a physical security key you plug in or tap. Phishing-resistant means even a fake website can't trick the key, because the key only works on the real Google site. It's like a house key that refuses to turn in any lock except your own front door.

WHY IT MATTERS

Passwords get stolen or guessed all the time, and without a phishing-resistant second factor an attacker who has your password can walk right into your accounts and your CUI.

TOOLS YOU WILL USE
2-Step VerificationSecurity keysPasskeysOrganizational units
HOW THE SETUP FLOWS
  1. 1Turn on 2SV
  2. 2Create Admins OU
  3. 3Require security key
  4. 4Distribute keys
  5. 5Enforce
  6. 6Verify enrollment
STEP-BY-STEP CHECKLIST
Pro tip

Register at least two keys per admin (one primary, one backup) so a lost key never locks you out of the whole tenant.

Government cloud & CUI

For CUI, pair phishing-resistant MFA with Google Workspace Assured Controls/Assured Workloads; the standard commercial tenant is only DoD IL2 and is not sufficient for CUI on its own.

EVIDENCE TO KEEP
2-Step Verification enrollment reportScreenshot of 'Only security key' policy on Admins OUList of issued security keys/passkeys
See the full IT-01 practice guide →
FAQ

Frequently asked questions

What does the Google Workspace setup guide cover?

It walks through ten security requirements — including phishing-resistant multi-factor authentication, least-privilege access control, asset & account inventory, and more — mapped to the DoW Brilliant at the Basics IT Top 10 and to NIST SP 800-171 / CMMC Level 2. Each requirement has a plain-language explanation, a process-flow diagram, and a click-by-click checklist.

Where do I perform these Workspace steps?

In the Google Admin console (admin.google.com). Every step names the exact portal or console path to follow.

Is my checklist progress saved anywhere?

Your step checklist progress is saved only in your own browser (local storage). Nothing is sent to the site, and you can reset it at any time.

Can Google Workspace hold CUI?

Handling CUI requires Google Workspace Assured Controls and careful scoping; the standard commercial tenant is only DoD Impact Level 2. Confirm an authorization path before you store CUI.

How do I strengthen Workspace for defense data?

Enforce phishing-resistant 2-Step Verification, apply client-side encryption with customer-held keys, and scope CUI users into a dedicated organizational unit inside an Assured Workloads boundary.