Overview
Device Bound Session Credentials (DBSC) protect user sessions by cryptographically binding them to the user's device. This prevents session token theft attacks, where an attacker steals a session cookie to gain access to an account without needing the user's password or MFA. When DBSC is enabled, stolen session tokens cannot be used from another device.
Prerequisites
Super Admin access to the Google Admin console
Instructions
Sign in to the Google Admin console
Navigate to Security > Access and data control > Google Session control
Select the organizational unit you want to apply this setting to
Under Device Bound Session Credentials (DBSC), check Enable DBSC
Click Save
Note: DBSC is currently in beta. Enabling it may require users to sign in more frequently than usual.
