Skip to main content

Require Phishing-Resistant MFA in Google Workspace

How to enable Google Advanced Protection to require phishing-resistant MFA for users in Google Workspace.

Written by Kavi Harshawat
Updated over 2 weeks ago

Overview

Google Advanced Protection enforces the strongest account security settings available, requiring phishing-resistant MFA methods such as hardware security keys or passkeys. Enabling this ensures users can't fall back to less secure verification methods like SMS codes.

Prerequisites

  • Super Admin access to the Google Admin console

  • Advanced Protection enabled for your organization

  • 2-Step Verification enabled for your organization (required by Advanced Protection)

  • Security keys or passkeys provisioned for enrolled users

Instructions

  1. Sign in to the Google Admin console

  2. Navigate to Security > Authentication > Advanced Protection Program

  3. Select the organizational unit containing the users you want to enable

  4. Ensure Enable user enrollment is selected

  5. Under security codes, select Allow security codes without remote access

  6. Click Save

Note: For full details on deploying Advanced Protection across your organization, refer to Google's official documentation on enabling user enrollment in the Advanced Protection Program.

Did this answer your question?