2FA in Google Workspace: 2-step verification and security keys

By the QuantumSec team

2-step verification is the single measure that stops the most attacks in Google Workspace, but not all methods protect equally. This guide explains how to roll out 2SV across the organization and why security keys and passkeys are far superior to SMS.

Why 2FA is the most cost-effective defense

Credential theft via phishing is the main entry vector into cloud environments. 2-step verification (2SV) blocks the vast majority of unauthorized access even if the password is leaked, because the attacker also needs the second factor. It is by far the measure that prevents the most incidents per euro invested.

Why SMS isn't enough

Not all second factors protect equally. SMS codes are vulnerable to SIM swapping and interception, and both SMS and TOTP codes can be captured in real-time phishing attacks (adversary-in-the-middle). Physical security keys (FIDO2) and passkeys are phishing-resistant because they're bound to the legitimate domain.

How to enforce 2SV across the organization

From the admin console you can make 2SV mandatory for all users, with an enrollment period for them to sign up. It's best to start with administrators and high-value accounts, define controlled exceptions only when essential and monitor that no users are left without a second factor.

Security keys and passkeys for administrators

For the most sensitive accounts (super admins, finance, management) it's advisable to require security keys or passkeys, and ideally enroll them in Google's Advanced Protection Program. This practically eliminates the risk of credential phishing on the accounts whose compromise would be most severe.

FAQ

Can I force all employees to use 2FA?

Yes. From the admin console you can apply mandatory 2SV at the organization or organizational unit level, with an enrollment period. It's the recommended configuration for any company.

What happens if an employee loses their key or phone?

It's handled with backup codes generated in advance and an admin-controlled recovery process. It's worth having that procedure defined before making 2SV mandatory.