4.1.1.2 Ensure hardware security keys are used for all users in administrative roles and other high-value accounts
Profile Applicability
- Enterprise Level 2
Description
A hardware security key connects to a user's device using USB (A & C), Lightning, NFC, or Bluetooth connection. Also, many Android phones and Apple iPhones have built-in security keys accessible via Bluetooth and that can be assigned to a Google Workspace account.
The purpose of a physical security key is to provide an additional security layer to high value accounts; in the event of a compromise of a user's credentials (username and password) without the associated security key, the authentication process cannot be successfully completed.
Rationale
The purpose of a physical security key is to provide an additional security layer to high value accounts; in the event of a compromise of a user's credentials (username and password) without the associated security key, the authentication process cannot be successfully completed.
Hardware security keys help to protect high value accounts from targeted attacks, including phishing attempts.
Adding a hardware security key requirement to your Google privileged accounts adds another layer of depth of protection greater than any other form of two-factor authentication.
Impact
Users with hardware security keys enabled will need to have physical access to the hardware key in order complete the authentication process and this will force users to adopt a practice of making sure that the physical key is available to them at any point in time that they need to be able to log in.
If a hardware security key is lost or stolen, the impacted user can gain access to their Google account by using a backup MFA process and then remove the lost/stolen key and add another one.
If a hardware security key is stolen, the user's account is not automatically compromised as the hardware key works in conjunction with the user's account credentials (username & password).
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.comas an administrator - Go to
Securityand click onAuthentication - Under
Authentication, select2-Step Verification - Ensure the option to
Allow users to turn on 2-Step Verificationis checked - Ensure that the
Enforcementoption is set to either'On'or'On from'with a valid date present - Under
Methodsensure thatOnly security keyis selected - Under
2-Step Verification policy suspension grace periodensure that1 dayis selected - Under
Security codesensure thatDon't allow users to generate security codesis selected
Remediation
To configure this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.comas an administrator - Go to
Securityand click onAuthentication - Under
Authentication, select2-Step Verification - Select the option to
Allow users to turn on 2-Step Verification - Under
Enforcement, enable either'On'or else'On from'and configure a valid date - Under
Methods, selectOnly security keyto force the use of a security key - Under
2-Step Verification policy suspension grace period, select1 day - Under
Security codes, selectDon't allow users to generate security codes - Select
Save
Default Value
Allow users to turn on 2-Step VerificationischeckedEnforcementisOffNew user enrollment periodisNoneFrequency - Allow user to trust deviceischeckedMethodsisAny
References
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 6.5 Require MFA for Administrative Access | x | x | x |
| v7 | 4.5 Use Multifactor Authentication For All Administrative Access | x | x |