Google Workspace: Admin audit events where strong authentication is allowed without enforcement (MFA disabled)

Alerts on Google Workspace admin changes that set strong authentication/MFA enforcement to false.

FreeReviewedSigma · Medium · v4
Product
gcp
Service
google_workspace.admin
Author
Austin Songer (SigmaHQ), DRL 1.1
Published
2021-08-26
Updated
2026-07-31

What it detects

This rule identifies Google Workspace administrative audit events where strong authentication enforcement is set to false via the Admin SDK security settings. Attackers may try to weaken account protections by disabling MFA enforcement, increasing the likelihood of credential theft leading to account takeover. The detection relies on Google Workspace admin audit telemetry capturing the relevant security-setting change with new_value set to 'false' for the specified event names.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.