Skip to main content
Google Workspace Security Audit, India

Your Workspace tenant was configured to work, not to be secure. An audit measures the difference.

A read-only assessment of your Google Workspace tenant across admin roles, authentication, sharing, Gmail, OAuth grants, retention, alerting, and devices. You get a scored findings report, a remediation roadmap, and an admin hardening checklist. Remote-first anywhere in India, with on-site walkthroughs available in Hyderabad.

Security consultant reviewing Google Workspace admin console findings during a tenant audit
  • 5-7 daysAssessment to report
  • 70+Control checks
  • Read-onlyAuditor access, zero changes
  • Remote-firstDelivered across India
How the audit runs

Read-only access, no changes, no disruption to your users.

The most common hesitation about a tenant audit is operational: will it break anything, and what are we handing over? The engagement is designed so the honest answer to the first question is nothing.

  • You create a dedicated auditor account with read-only reporting privileges. We tell you exactly which delegated role to assign, and we never ask for super admin.
  • The assessment reads configuration and reports. It changes no settings, installs nothing, and sends nothing to your users. Nobody outside the IT team should notice it happened.
  • The auditor account is yours to suspend or delete the moment fieldwork ends. Access exists only for the days the assessment runs.
  • Everything we observe is delivered to a named recipient list under NDA. Findings never leave that circle, and nothing from your tenant is reused anywhere.
Ask us anything about access first
What the audit examines

Nine areas of your tenant, checked item by item.

Google Workspace concentrates enormous decisions into a single admin console, and most of those decisions were made once, quickly, by whoever set the tenant up. The audit works through each area against your actual configuration and records the current state with evidence, not the intended state.

Admin roles & super admin hygiene

How many super admins exist, whether they are separated from daily working accounts, whether delegated admin roles are used instead of blanket rights, and whether admin recovery options would survive a departure or a compromise.

2-Step Verification & passkeys

Whether 2SV is enforced rather than merely available, which verification methods are permitted, whether admins and high-value accounts are held to a stronger standard, and where passkeys or security keys can replace weaker factors.

Context-aware access

Whether sign-in policy considers device state, location, and IP context where your edition supports it, and whether the tenant relies on passwords alone for access decisions that deserve more scrutiny.

Drive sharing & external access

Default sharing settings, link-sharing scope, external sharing rules and warnings, files published to the web, shared drive membership, and a count of how much data is currently reachable from outside your domain.

Gmail security: SPF, DKIM, DMARC

Email authentication records checked and their enforcement state verified, plus forwarding rules, legacy IMAP and POP access, spam filter bypasses, and the attachment, link, and spoofing protections Gmail can apply before delivery.

Third-party OAuth app grants

Every application your users have granted access to Gmail, Drive, Calendar, or Contacts, enumerated with the scopes each one holds. Years-old tenants routinely carry grants for apps nobody recognises or still uses.

Vault retention & Alert Center

Whether retention rules and legal holds match your obligations where your edition includes Vault, and whether Alert Center rules are configured, routed to a human, and actually reviewed rather than accumulating unread.

Endpoint management posture

Which devices reach company data, whether mobile management is basic or advanced, whether screen locks and encryption are required, and what happens to synced data when a laptop or phone is lost or an employee leaves.

Licence edition feature gaps

What your current edition can and cannot enforce. Some controls that matter, such as context-aware access or Vault, are edition-gated, and the report separates what to configure now from what needs an edition decision first.

What you receive

Three deliverables, written to be acted on.

An audit that produces a PDF nobody opens again has failed, whatever it found. Each deliverable is written for the person who has to do something with it: the report for decision makers, the roadmap for whoever plans the work, the checklist for the admin who applies it.

Scored findings report

Every control check recorded with its current state, a severity score, and the evidence behind it. An executive summary up front gives leadership the position in two pages; the appendix gives your admin the detail.

  • Per-area scores across all nine assessment areas
  • Severity-ranked findings with evidence for each
  • What is exposed today, quantified in numbers
  • Two-page executive summary for non-technical readers

Remediation roadmap

Findings sequenced by risk reduction against user disruption. Quick, invisible wins first; changes that alter how people collaborate are batched with the communication they need to land without a revolt.

  • Low-friction changes separated from disruptive ones
  • Effort estimate and owner suggested per item
  • 30, 60, and 90 day sequencing
  • Edition-gated items flagged for a licence decision

Admin hardening checklist

A working checklist your administrator keeps after the engagement ends: the settings that matter, the state each should be in, and the review cadence that stops the tenant drifting back to where it started.

  • Setting-by-setting hardening reference for your tenant
  • Quarterly review cadence with named checks
  • Joiner and leaver handling steps for Workspace
  • Alert Center rules worth enabling and routing
Why GR IT for this audit

Four reasons teams pick us to look at their tenant.

Configuration audits are easy to sell and easy to do badly. What separates a useful one is whether the people running it administer the platform for a living and whether the output survives contact with your actual workload.

We run Workspace every day, not just audit it

GR IT deploys, migrates, and administers Google Workspace for businesses in Hyderabad and across India. The audit is informed by what breaks in real tenants, which is why the roadmap separates the changes users will never notice from the ones that need communication.

Evidence-backed, never opinion-backed

Every finding carries the configuration state we observed and where we observed it. Your team can verify each item themselves in the admin console, which makes the report a shared fact base rather than an outside opinion.

Reports both your admin and your board can read

A two-page scored summary for leadership, a full technical appendix for whoever holds the admin role. One engagement, two audiences, no translation work left for you to do in between.

We can fix what we find, but you are not locked in

Remediation is an optional, separately scoped follow-on. The roadmap is written so any competent administrator can execute it, including yours. We would rather earn the follow-on than force it.

India regulatory context

How a Workspace audit maps to the frameworks Indian organisations answer to.

A tenant audit is not a certification, but it produces exactly the configuration evidence these frameworks keep asking for. If you are working toward any of them, the audit does double duty.
FrameworkWhat it expectsWhat the audit contributes
DPDP Act 2023Reasonable security safeguards for personal data, and breach notification obligationsEvidence of access control, sharing restrictions, and retention on the tenant where employee and customer personal data actually lives
CERT-In directionsPrompt incident reporting and retention of system logs for a rolling 180 daysVerification that audit logging is intact, Alert Center is routed to a human, and log retention supports an investigation
ISO 27001Operating evidence for access control, cryptography, logging, and supplier controls in Annex AScored configuration evidence for the cloud collaboration platform, ready to drop into your ISMS evidence pack
SOC 2Demonstrated control design and operation across the Trust Services CriteriaFindings and remediation records that show security controls on the productivity suite are designed, applied, and reviewed
Who books this audit

Six situations that prompt a Workspace security review.

Google Workspace is usually adopted fast by a growing organisation, and the security review happens years later when something forces the question. These are the six situations we see most.

Startups that grew into their tenant

A tenant created for five people now serves a hundred and fifty, carrying every default and every quick decision from the early days. Nothing has visibly broken, which is exactly why nobody has looked. Funding rounds and enterprise customers tend to force the look.

Agencies and client-facing teams

Design studios, marketing agencies, and consultancies share heavily with clients by design. The audit distinguishes deliberate external collaboration from files that are simply open to anyone with the link, and quantifies the second category.

Edtech and education on Workspace

Large user populations, student personal data under the DPDP Act, and open collaboration cultures make sharing defaults and group settings unusually consequential. The audit prioritises the controls that protect student data first.

Companies running Workspace alongside Microsoft 365

Mixed estates are common in India, one suite for email and another for files or Teams. Each platform gets audited on its own terms, and we run the Microsoft 365 equivalent as a separate engagement so neither tenant hides behind the other.

Organisations after an incident

A phished mailbox, a forwarding rule discovered months late, files found public that should never have been. The post-incident audit answers what the exposure actually was, what allowed it, and which settings close the path for good.

Teams preparing for DPDP or ISO 27001

Compliance programmes keep asking for evidence about the platform where the personal data actually lives. The audit produces that evidence in a form your consultant or auditor can use directly, before the formal assessment finds the gaps for you.

Common misconfigurations vs hardened baseline

Where typical tenants stand, and what the audit measures against.

The left column is not a caricature. It describes the majority of tenants we assess, including well-run ones, because these settings default to convenience and nobody revisits them. The audit scores your tenant against the right column.
Feature
Typical tenant
Configured once at setup
Hardened baseline
What the audit measures against
2-Step Verification
Available, partially adoptedEnforced for all, stronger factors for admins
Super admin accounts
The accounts that control all organisational data.
Several, used for daily workMinimal count, separated from daily accounts
Drive link sharing default
Broad, often anyone-with-linkRestricted, external sharing deliberate and warned
Files published to the web
Unknown countEnumerated, reviewed, and controlled
Email authentication
SPF only, or DMARC in monitoring modeSPF, DKIM, and DMARC at enforcement
Automatic forwarding & legacy IMAP/POP
Still enabledDisabled tenant-wide
Third-party OAuth grants
Accumulating unreviewed for yearsEnumerated, trimmed, trusted-app list in place
Alert Center
Default rules, nobody assignedRules tuned, routed to a named owner
Device access to company data
Any device that signs inManaged devices, screen lock and wipe enforced
Review cadence
After incidents, if thenQuarterly, on a written checklist
How the engagement runs

Six steps from scoping call to a hardened tenant.

Remote-first from our Gachibowli, Hyderabad HQ for organisations anywhere in India. Hyderabad teams can have the scoping session and the findings walkthrough on-site if they prefer a room and a whiteboard.
  1. 1

    Scoping

    1-2 days

    A short call to capture user count, domains, editions in use, whether Microsoft 365 also exists in the estate, and any compliance driver such as DPDP readiness or ISO 27001. You get a written scope and timeline before anything starts.

  2. 2

    Auditor access

    Half a day

    Your admin creates a dedicated read-only auditor account using the delegated role we specify. No super admin rights, no passwords shared, and the account is yours to suspend the moment fieldwork ends.

  3. 3

    Assessment

    3-4 days

    We work through the nine areas and 70+ control checks against your live configuration, capturing evidence as we go. Zero settings changed, nothing visible to your users. If we find something critical, you hear about it the same day, not in the report.

  4. 4

    Scored report

    1-2 days

    Findings are scored, prioritised, and written up as the three deliverables: the scored findings report, the remediation roadmap, and the admin hardening checklist. Internal QA before anything reaches you.

  5. 5

    Walkthrough

    1 session

    A live read-out with your stakeholders, remote or on-site in Hyderabad. We take questions until the findings are understood, and we are direct about which items are urgent and which merely look dramatic.

  6. 6

    Optional remediation

    Scoped separately

    If you want us to apply the roadmap, we scope it as a follow-on with explicit change control: low-friction changes first, disruptive changes batched with user communication. Your own team can equally run the roadmap without us.

The engagement in numbers

What a Workspace audit involves, honestly stated.

No inflated claims. These are the shape and boundaries of the engagement as we actually run it.
70+
Control checks

Across admin, authentication, sharing, Gmail, OAuth, retention, alerting, devices, and licensing.

9
Assessment areas

The same surface every time, so nothing is skipped because it looked fine from the outside.

5-7 days
Assessment to report

For most tenants. Multiple domains or very large user counts sit at the longer end.

3
Deliverables

Scored findings report, remediation roadmap, admin hardening checklist. All yours to keep.

0
Settings changed

The audit is read-only. Remediation is a separate, explicitly approved piece of work.

1 session
Findings walkthrough

A live read-out with your team, on video or in person for Hyderabad organisations.

Decision-blocking questions

What organisations ask before booking a Workspace audit.

Try this yourself

Twelve questions to ask about your own tenant.

Each of these maps to a check in the audit. The ones your team hesitates on are usually the ones nobody has revisited since the tenant was created.

Access & admin

  • How many super admins do we have?
    Most tenants have more than they can name.
  • Is 2SV enforced for every account?
    Enforced, not just available.
  • Do admins use passkeys or security keys?
    A stronger standard for high-value accounts.
  • What happens to a leaver account on day one?
    Sessions, app passwords, and shared files included.

Data & email

  • What is our default link-sharing scope?
    And who decided it.
  • How many files are shared outside the domain?
    A number, not a feeling.
  • Are SPF, DKIM, and DMARC all enforcing?
    DMARC in monitoring mode enforces nothing.
  • Is automatic forwarding disabled?
    The classic persistence trick after a mailbox compromise.

Oversight

  • When were OAuth app grants last reviewed?
    They accumulate silently for years.
  • Who reads the Alert Center?
    Alerts nobody reads are decoration.
  • Do retention rules match our obligations?
    Where your edition includes Vault.
  • Can an unmanaged personal device sync company data?
    For most tenants, yes.
Next step

Find out what your Workspace tenant actually looks like.

A three-minute form and a short scoping call. We reply within 4 business hours, and the assessment itself changes nothing and disrupts nobody. Remote-first across India, on-site walkthroughs in Hyderabad.