Skip to main content

Enforce Session Security in Google Workspace

How to enable Device Bound Session Credentials (DBSC) to protect user sessions in Google Workspace.

Written by Kavi Harshawat
Updated over 2 weeks ago

Overview

Device Bound Session Credentials (DBSC) protect user sessions by cryptographically binding them to the user's device. This prevents session token theft attacks, where an attacker steals a session cookie to gain access to an account without needing the user's password or MFA. When DBSC is enabled, stolen session tokens cannot be used from another device.

Prerequisites

  • Super Admin access to the Google Admin console

Instructions

  1. Sign in to the Google Admin console

  2. Navigate to Security > Access and data control > Google Session control

  3. Select the organizational unit you want to apply this setting to

  4. Under Device Bound Session Credentials (DBSC), check Enable DBSC

  5. Click Save

Note: DBSC is currently in beta. Enabling it may require users to sign in more frequently than usual.

Did this answer your question?