Overview
POP and IMAP allow users to access Gmail through third-party email clients using basic password authentication, which is less secure than modern OAuth 2.0. Disabling these protocols ensures all email access requires modern authentication, reducing the risk of credential-based attacks.
Prerequisites
Super Admin access to the Google Admin console
Instructions
Sign in to the Google Admin console
Navigate to Apps > Google Workspace > Gmail > End User Access
Select the organizational unit you want to apply this setting to
Scroll to POP and IMAP access
Uncheck Enable POP access for all users
Uncheck Enable IMAP access for all users
Click Save
โ ๏ธ Disabling POP and IMAP will prevent users from accessing Gmail through third-party email clients like Outlook or Apple Mail using a password. Users will need to use Gmail on the web, the Gmail mobile app, or a third-party app that supports OAuth 2.0 authentication.
Note: If your organization requires Outlook, consider using Google Workspace Sync for Microsoft Outlook (GWSMO), which syncs with Google Workspace using secure modern authentication instead of POP or IMAP.
