Get started with the security health page

Supported editions for this feature: Frontline Standard; Enterprise Standard and Enterprise Plus; Education Standard and Education Plus; Enterprise Essentials Plus. Compare your edition

This feature is available with Cloud Identity Premium edition. Compare editions 

Some features in the security center—for example, data related to Gmail and Drive—are not available with Cloud Identity Premium.

The security health page allows you to monitor the configuration of your security-related Admin console settings—all from one location in the Google Admin console—and to make changes to those settings.

To view the security health page:

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2.  In the Admin console, go to Menu and then Securityand thenSecurity center  and thenSecurity health.

Loading times for the security health page vary depending on your configuration.

Notes:

  • Enterprise edition customers receive all security health settings. With Frontline Standard, Essentials editions, and Cloud Identity Premium Edition, you receive a subset of security health features. See the availability information in each settings section below for details.
  • Changes to Admin console settings might take up to 24 hours before propagating to the security health page. Changes made to the settings through the Admin console can be audited in the Admin Console audit log.
  • Super admins can view all settings on the security health page. Other admins need to be granted specific administrator privileges to view security health settings. 

Status column

View the number of organizational units for which a setting is enabled or disabled. On each row, the status for these settings is displayed. For example, Enabled for 1 org unit, or Disabled for 10 org units.

View organizational units with risky configurations

To view your Google Admin console settings and make changes, under Status, click the blue links (for example, 5 org units). This opens a window that displays a tree structure with a list of organizational units with risky configurations. Click any of the organizational units in this window to directly access the security settings for that organizational unit. You can then make adjustments to your settings if needed.

Note that organizational units that inherit setting status might also be affected by your changes. For more details, see How the organizational structure works.

View security recommendations

Depending on the setting status, the far-right column displays a gray icon that you can click for a list of security recommendations, or it displays a green checkbox to indicate a secure configuration. Click the gray icons for more details and instructions.

Security health page

Security health settings

You can monitor the security health of the following settings:

Category Setting
Gmail
  • Automatic email forwarding
  • Comprehensive mail storage
  • Bypassing spam filters for internal senders
  • POP and IMAP access for users
  • DKIM
  • SPF record
  • DMARC
  • Approved senders without authentication
  • Approved domain senders
  • Email whitelist IPs
  • Add spam headers setting to all default routing rules
  • MX record configuration
  • MTA-STS configuration

Supported editions: Enterprise Plus, Education, Enterprise Essentials Plus

  • Attachment safety
  • Links and external images safety
  • Spoofing and authentication safety

Supported editions: Enterprise Plus, Enterprise Essentials Plus

Drive

  • Drive sharing settings
  • Warning for out-of-domain sharing
  • Access Checker
  • Drive add-ons
  • Access to offline docs
  • Desktop access to Drive
  • File publishing on the web 
  • Google sign-in requirement for external collaborators

Supported editions: Enterprise Plus, Education, Enterprise Essentials Plus

Device management

  • Blocking of compromised mobile devices
  • Mobile management
  • Mobile password requirements
  • Device encryption
  • Mobile inactivity reports
  • Auto account wipe
  • Application verification
  • Installation of mobile applications from unknown sources
  • External media storage

Supported editions: Frontline Standard, Enterprise, Education, Enterprise Essentials PlusCloud Identity Premium

Security
  • Two-step verification for users
  • Two-step verification for admins
  • Security key enforcement for admins

Supported editions: Frontline Standard, Enterprise, Education, Cloud Identity Premium, Enterprise Essentials Plus

  • Security key enforcement for users

Supported editions: Enterprise Plus, Enterprise Essentials Plus

Hangouts

  • Hangouts out of domain warning

See External Chat Settings.

Supported edition: Enterprise Plus, Education

Groups

  • Groups creation and membership

Supported editions: Enterprise Plus, Education, Enterprise Essentials Plus

Marketplace apps

  • Google Workspace Marketplace applications usage

Supported editions: Enterprise Plus, Education, Enterprise Essentials Plus

Calendar
  • Calendar sharing policy

Supported editions: Enterprise Plus, Education, Enterprise Essentials Plus

  • Access to Calendar when offline

Supported editions: Enterprise Plus, Enterprise Essentials Plus

Sites

  • Sites sharing policy

Supported editions: Enterprise Plus, Education, Enterprise Essentials Plus

About making changes to your settings

Security considerations versus business needs
In addition to security considerations and best practices, you may have business needs to enable or disable certain settings. Balance these priorities when evaluating the status of your settings.

Organizational units and inheritance
You can enable or disable settings for an organizational unit. You can also configure a child organization to override the setting in a parent organization; otherwise, the child organization inherits the parent setting.

Limitations with multiple domains
You can't set different policies or configuration settings for specific domains. All settings in the Google Admin console apply to all domains that are part of your account. For more information, see Limitations with multiple domains.

For more details and instructions about the security center, see About the security center.

Was this helpful?

How can we improve it?
Search
Clear search
Close search
Main menu
4206276199764591521
true
Search Help Center
true
true
true
false
false