2026 AoS Guardian Security: Hardening Google Workspace

URL to Google Workspace document:

Google Workspace Resiliency-HowTo

How-To: Hardening Google Workspace
Gmail account-takeover defenses and Google Classroom safety controls
Audience: Archdiocese of Seattle – School administrators and IT security staff

Publisher:  Office of the Chief Information Security Officer

Content Owner:  Office of the Chief Information Security Officer

Posted:  9/24/2026

Introduction: 

This document is a practical reference for hardening Google Workspace. It covers two related but distinct concerns: protecting Gmail and core Workspace accounts against credential phishing, OAuth abuse, and session-token theft (Sections 1 through 9); and hardening Google Classroom against student safety risks, roster integrity issues, and unauthorized access (Section 10). It is written for an administrator who already manages a Workspace tenant and is comfortable in the Admin console.

Modern attacks against Workspace rarely break encryption or exploit Google directly. They steal a session cookie, trick a user into granting an OAuth scope, or social-engineer the help desk into resetting an account. Classroom adds a different threat model on top of that: minors and adult learners share an environment where the consequences of a misconfiguration are not just data loss but also exposure of vulnerable users. The controls below are organized so the highest-impact, lowest-friction items come first.