Getting Started
Ok, so firstly I’m assuming that you’re not already enforcing multi-factor authentication (2-Step verification) and that no-one has voluntarily turned it on.
If you think that some people might have turned it on already then I’ll show you how to re-set that later in this post.
Also, you’ll want to do this outside of normal working hours as there may be some disruption to people’s accounts initially!
Step 1: Set yourself up first
First you’re going to set up Multi-Factor Authentication for yourself as the super administrator.
Go to your Google account / Security. Click on one of the options below the How you Sign into Google section. I’d recommend ‘Authenticator’.
Follow the steps to set up Authenticator as your Multi-Factor Authentication option.
Once you’ve added the authenticator app, make sure you turn on 2-Step verification – there’s two buttons you need to click!
Step 2: Enforce 2-Step Verification (Multi-Factor Authentication)
Return to the Admin Console and go to Security / Authentication / 2 Step verification
Click in the radio button next to Enforcement On from and enter a date – probably the next working day.
Then under Methods click next to Any except verification codes via text, phone call.
Click on Save.
Step 3: Re-set logins for everyone
Now you’re going to force people to sign in and set up Multi-factor authentication the next time they log in.
Go to Admin Console / Directory and then Users.
Click on each user in turn, go to the Security tab, and reset the sign-in cookies to sign them out of their account.
While you’re there, remove the recovery phone number if they have one, just to ensure stronger security and less likelihood of issues with text messages.
Step 4: Remove previous enrollments
Remember how I said earlier you could re-set their multi-factor authentication status? This is where you do it. If they’re already enrolled click on the pencil icon next to 2-step verification and change the status to Off.
Now, when your users next log in, they’ll be prompted to Enroll in 2 Step verification and when they do, the only options they’ll be given will be Passkeys / Security Keys or the Authenticator app.
Want more personalised help?
I hope this article was of assistance to you, but if you want more personalised help with your Google Workspace issue then why not get in touch?