4.1.1.1 Ensure 2-Step Verification (MFA) is enforced for all users in administrative roles
Profile Applicability
- Enterprise Level 1
Description
Enforce 2-Step Verification (Multi-Factor Authentication) for all users assigned administrative roles. These include roles such as:
- Help Desk Admin
- Groups Admin
- Super Admin
- Services Admin
- User Management Admin
- Mobile Admin
- Android Admin
- Custom Admin Roles
Rationale
Add an extra layer of security to users accounts by asking users to verify their identity when they enter a username and password. 2-Step Verification (Multi-factor authentication) requires an individual to present a minimum of two separate forms of authentication before access is granted. 2-Step Verification provides additional assurance that the individual attempting to gain access is who they claim to be. With 2-Step Verification, an attacker would need to compromise at least two different authentication mechanisms, increasing the difficulty of compromise and thus reducing the risk.
Impact
Implementation of 2-Step Verification (multi-factor authentication) for all users in administrative roles will necessitate a change to user routine. All users in administrative roles will be required to enroll in 2-Step Verification using phone, SMS, or an authentication application. After enrollment, use of 2-Step Verification will be required for future access to the environment.
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.comas an administrator - Go to
Securityand click on2-Step Verification - Select the appropriate group with
ALL ADMIN ROLES-- Create this group if needed - Under
Authentication, ensureAllow users to turn on 2-Step Verificationischecked - Ensure
Enforcementis set toOn - Ensure
New user enrollment periodis set to2 weeks - Under
Frequency, ensureAllow user to trust deviceisunchecked - Under
Methods, ensureAny except verification codes via text, phone callisselected
Remediation
To verify this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.comas an administrator - Go to
Securityand click on2-Step Verification - Select the appropriate group with
ALL ADMIN ROLES-- Create this group if needed - Under
Authentication, setAllow users to turn on 2-Step Verificationtochecked - Set
EnforcementtoOn - Set
New user enrollment periodis set to2 weeks - Under
Frequency, setAllow user to trust devicetounchecked - Under
Methods, setAny except verification codes via text, phone calltoselected - Select
Save
Default Value
Allow users to turn on 2-Step VerificationischeckedEnforcementisOffNew user enrollment periodisNoneFrequency - Allow user to trust deviceischeckedMethodsisAny
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 6.5 Require MFA for Administrative Access | x | x | x |
| v7 | 4.5 Use Multifactor Authentication For All Administrative Access | x | x |