# Cis Gworkspace 3.1.4.2.1

> Ensure Google Chat externally is restricted to allowed domains

- Skill: `cyberstrikeus/cis-gworkspace-3-1-4-2-1` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-gworkspace-3-1-4-2-1`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-gworkspace-3-1-4-2-1/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-gworkspace-3-1-4-2-1

---


# Ensure Google Chat externally is restricted to allowed domains (Manual)

## Description

Control how users chat with people outside of your organization. If you allow your users to chat externally, you can also allow them to create and join spaces with people outside your organization.

## Rationale

Restricting external chat to only approved domains potentially limits the spread of company information.

## Impact

Users will not be able to chat with users in any external domain, only approved domains. This will require some admin-level approval and allowlist maintenance.

## Audit Procedure

### Using Google Workspace Admin Console

1. Log in to https://admin.google.com as an administrator
2. Select `Apps`
3. Select `Google Chat and classic Hangouts`
4. Select `External Chat Settings`
5. Select `Chat externally`
6. Verify `Allow users to send messages outside <company>` is **ON**
7. Verify `Only allow this for allowlisted domains` is **checked**

### Expected Result

`Allow users to send messages outside <company>` should be ON, and `Only allow this for allowlisted domains` should be checked.

## Remediation

### Using Google Workspace Admin Console

1. Log in to https://admin.google.com as an administrator
2. Select `Apps`
3. Select `Google Chat and classic Hangouts`
4. Select `External Chat Settings`
5. Select `Chat externally`
6. Set `Allow users to send messages outside <company>` to **ON**
7. Set `Only allow this for allowlisted domains` to **checked**
8. Select `Save`

## Default Value

- `Allow users to send messages outside <company>` is set to **ON**
- `Only allow this for allowlisted domains` is **unchecked**

## CIS Controls

| Controls Version | Control                                               | IG 1 | IG 2 | IG 3 |
| ---------------- | ----------------------------------------------------- | ---- | ---- | ---- |
| v8               | 3.3 Configure Data Access Control Lists               | x    | x    | x    |
| v7               | 14.6 Protect Information through Access Control Lists | x    | x    | x    |

## Profile

Level 1

