What problem does it solve?
This Skill provides a structured, repeatable approach to hardening Google Workspace tenant administration and reducing the risk of account compromise, phishing, data exfiltration, and unauthorized third-party access.
Core Features & Use Cases
- Admin account hardening: Enforce Advanced Protection for super admins, create break-glass accounts, and audit admin roles.
- Phishing-resistant MFA: Enforce 2-Step Verification with security keys and context-aware access policies.
- Email authentication & anti-phishing: Guide SPF, DKIM, DMARC rollout and enable advanced email protections.
- Data protection & sharing controls: Deploy DLP rules, restrict external Drive sharing, and configure Groups and Shared Drive policies.
- OAuth and API controls: Audit and allowlist third-party apps, revoke unapproved tokens, and restrict API scopes.
- Use Case: Rapidly secure a newly acquired tenant by enforcing MFA, deploying email authentication, tightening sharing settings, and auditing OAuth access with an automated agent.
Quick Start
Run the workspace audit agent with service account credentials and an admin-delegated email to generate a security assessment report.