3.1.3.1.1 Ensure users cannot delegate access to their mailbox
Overview
| Property | Value |
|---|---|
| CIS ID | 3.1.3.1.1 |
| Level | L1 |
| Profile Applicability | Enterprise Level 1 |
| Assessment Type | Manual |
| Section | Gmail > User Settings |
Description
Mail delegation allows the delegate to read, send, and delete messages on their behalf. For example, a manager can delegate Gmail access to another person in their organization, such as an administrative assistant.
Rationale
Only administrators should be able to delegate access to a user's mailboxes.
Impact
Existing delegations will be hidden, when this feature is disabled.
Default Value
Let users delegate access to their mailbox to other users in the domain is unchecked
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to https://admin.google.com as an administrator
- Select Apps
- Select Google Workspace
- Select Gmail
- Under
User Settings-Mail delegation, ensureLet users delegate access to their mailbox to other users in the domainis unchecked
Remediation
To configure this setting via the Google Workspace Admin Console:
- Log in to https://admin.google.com as an administrator
- Select Apps
- Select Google Workspace
- Select Gmail
- Under
User Settings-Mail delegation, setLet users delegate access to their mailbox to other users in the domainto unchecked - Select Save
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 3.3 Configure Data Access Control Lists | x | x | x |
| v7 | 14.6 Protect Information through Access Control Lists | x | x | x |