Google Workspace Admin Console: 8 Settings to Configure Before You Go to 25 People

A deliberately configured Google Workspace tenant gives a growing company enterprise-grade identity, email, and file security from the same Admin console a 4-person startup already pays for. Eight settings establish that baseline:

Verified against the Google Workspace Admin console on 2026-08-10.

Prerequisites

These settings are best configured for scale on day one of a new tenant, and every one of them can be applied to a tenant that has been running on defaults since the founding team set it up.

Step 1: Create Organizational Units

Every user starts in the top-level organizational unit, which means every setting applies to everyone. Organizational units let you give engineering, sales, and contractors different rules later without reworking anything.

  1. Go to Directory → Organizational units.
  2. Hover over your organization and click Create new organizational unit.
  3. Enter a name (the "/" character is not allowed) and click Create.

A simple split such as Employees and Contractors is enough to start. The structure exists so the settings below can be scoped the day you need exceptions.

Step 2: Enforce 2-Step Verification

Password-only accounts are the single largest risk in a default tenant. Enforcement closes it for everyone at once.

  1. Go to Security → Authentication → 2-step verification.
  2. Check Allow users to turn on 2-Step Verification.
  3. Have users enroll first, then set Enforcement to On.

To stage the rollout, select an organizational unit at the side and enforce there first. Users who have already added a security key or phone number to their account can sign in once enforcement starts.

Step 3: Scope Admin Roles and Add a Backup Admin

One person holding the only super admin account is a single point of failure, and five people holding super admin is an audit finding. Both configurations are common at this stage.

  1. Go to Directory → Users and click the user's name.
  2. Scroll down and click Admin roles and privileges.
  3. Next to the role, click the slider so it reads Assigned, then click Save.

Keep two super admins, and give everyone else a prebuilt scoped role such as Help Desk Admin or Groups Admin. Role changes typically apply within minutes but can take up to 24 hours.

Step 4: Turn On DKIM Email Authentication

Without DKIM, receiving mail servers have a weaker basis for trusting mail from your domain, and deliverability suffers as sending volume grows.

  1. Go to Apps → Google Workspace → Gmail → Authenticate email.
  2. In the Selected domain menu, choose your domain and click Generate New Record.
  3. Add the displayed DKIM values to your DNS at your domain provider.
  4. Return to the same screen and click Start authentication.

The status at the top of the page changes to Authenticating email once DKIM is working. Allow up to 48 hours.

Step 5: Harden Gmail Safety Settings

The default filters are solid; the stronger protections ship turned off.

  1. Go to Apps → Google Workspace → Gmail → Safety.
  2. Enable the spoofing and authentication protections, including protection against domain spoofing and employee name impersonation.
  3. Enable enhanced pre-delivery message scanning.

Suspicious messages get a short delivery delay in exchange for deeper checks, a trade worth making for every organizational unit.

Step 6: Set Drive External Sharing Rules

Default Drive settings let any user share any file with anyone. A deliberate policy keeps client deliverables flowing while closing accidental exposure.

  1. Go to Apps → Google Workspace → Drive and Docs → Sharing settings.
  2. Under Sharing options, choose whether sharing outside the organization is on, allowlisted to trusted domains, or off.
  3. Keep the external warning indicator on so users see when a file or shared drive involves someone outside the company.

Scope stricter rules to the organizational units that handle sensitive data rather than turning sharing off company-wide.

Step 7: Control Third-Party App Access

Every "Sign in with Google" grant is an app holding a token to your company data, and by default users can grant them freely.

  1. Go to Security → Access and data control → API controls.
  2. On the Settings card, select Unconfigured third-party apps and choose a restrictive default, such as allowing only Google sign-in.
  3. Use Manage App Access to mark the apps your company actually uses as trusted, limited, or blocked.

New tools then arrive through a request instead of appearing in your token list months later.

Step 8: Set Web Session Length

Sessions that never expire mean a lost laptop is a live session into email and Drive.

  1. Go to Security → Access and data control → Google session control.
  2. Under Web session duration, choose a reauthentication interval that fits how your team works.

Users must sign out and back in before the new length applies. The Admin console itself always uses a one-hour session, which you cannot change.

Verify the Configuration

Troubleshooting

Well-configured tenants stay quiet, and the settings above are the difference between an Admin console that runs itself and one that produces surprises. ScaleIt configures, monitors, and manages Google Workspace for startups and SMBs as part of managed IT support, so your team gets the hardened setup without the console time. Book a free call and we will review your tenant against this checklist.

Verified against the Google Workspace Admin console on 2026-08-10. Vendor docs: support.google.com/a/answer/9176657, support.google.com/a/answer/174124, support.google.com/a/answer/60781, support.google.com/a/answer/7281227, support.google.com/a/answer/7576830.