To better protect your organization’s information, Google will soon require all administrator accounts to have 2-Step Verification (2SV) enabled. As a Google Workspace administrator, you will need to confirm your identity with 2SV, which requires your password plus something additional, such as your phone or a security key.
Enforcement timeline
The enforcement will be rolled out gradually over the coming years. Enhforcement is now being implemented for organizations with Workspace for Education, Workspace for Nonprofits, Cloud Identity, or Android Enterprise. You should enable 2SV for the admin accounts in your organization before Google enforces it.
Super administrators can expect a notification roughly 90 days before enforcement takes effect. All other admins will be notified approximately 60 days prior, via email and mobile phone. Admins will also see a reminder when they log in with their Google account and another at the top of the Google Admin console’s Home page. During this notification period, Google's 2SV enforcement policy will supersede any existing organizational 2SV policies.
Notification and reminders
When an administrator signs in to their account during the notification period, they will receive a reminder to enable 2SV by the mandatory date. If the admin doesn’t enable 2SV:
- After 7 days, they will continue to receive reminders in the Admin console to enroll in 2SV.
- After 15 days, they will not be able to access Workspace apps on mobile devices until they enroll in 2SV.
- After 30 days, they will not be able to access web apps until they enroll in 2SV.
Exact notification times can vary based on the organization, its profile, and the specific products it uses. These are standard deadlines intended to allow admins enough time to enroll.
2SV enforcement details to consider
- 2SV enforcement is applied immediately when a user is made an admin.
- Admins subject to the Google-set 2SV enforcement policy cannot bypass it. If an admin cannot enable 2SV, the only solution is to remove their admin rights.
- Service accounts do not require 2SV, but the admin account they impersonate must be enrolled.
- You can review an admin's enforcement status in the Admin console. For the steps, go to Track users’ enrollment, and add the 2-Step verification enforcement column.