Your Google Workspace admin account can reach everything. Lock it down before real work starts, then set the same baseline for everyone.
Admin Console → Security → Authentication → .
Set it to (not just "Allow").
Choose a start date (immediate is fine for a new account).
Methods, best first:
- (Google Authenticator, Authy): secure, works offline.
- (YubiKey and similar): strongest, phishing-resistant.
- : fallback only, weakest (SIM-swap risk) but better than nothing.
Passkeys replace passwords with something phishing-resistant and quicker to use, and they're where authentication is heading.
Enable for the organisation: Admin Console → Security → Authentication → → turn . Set enforcement to for the strongest setup, or to let people opt in.
Recovery is what stops a lockout becoming a disaster, especially for the admin account.
- : an external address, not @yourorg.org, so you're not locked out if Workspace itself has issues.
- : a number your team can reach.
- : generate and store them in your password manager.
- : create one for another trusted person, so no single account is a single point of failure.
Admin Console → Security → Security settings:
Photos help people recognise each other in Gmail and Meet. Enable editing in Admin Console → Directory → Directory settings → → . If photos don't appear on Calendar or booking pages, see the profile-photo fix in Setting up Google Workspace . Once the basics are in place, you may want staff to sign into other tools (Slack, Asana) with their Google account instead of a separate password each. There are real trade-offs. We've written them up: SSO, yes or no? Use recovery codes, then the recovery email or phone. A second super admin can restore access, which is why Step 3 matters.
Use backup codes, sign in via recovery phone or email, or have the second super admin temporarily disable 2FA, then re-enable it.
Passkeys are per-device. Add the new device's passkey while signed in on an existing one, or use a backup method.
A Moral Fabric pattern, free for any nonprofit to use and adapt.