Google says getting more IT admins involved can prevent account hacks
Two-step verification changes to require double permission.

Francis Scialabba
• less than 3 min read
Your machine data knows things: Unlock it with Splunk and get game-changing insights—plus a critical resource to power AI. Tapping into machine data can boost your security and reliability. See more.
A new Google security update might have some IT managers pulling a George Costanza and yelling, “Turn your key, Maura!”
Later this year, security teams will be able to require two administrators’ approval “to complete a sensitive action, such as changing 2SV settings for a user,” the tech giant announced last Wednesday, amid a number of other security-related product updates.
Mandatory two-step verification is also coming to some Google Workspace enterprise accounts, the company said.
The updates aim to thwart phishing attempts and other social engineering attacks and head off the potential for future data breaches, Google’s Yulie Kwon Kim and Andy Wen wrote in a blog post. They noted that the expanded capabilities are meant “to help security teams defend against account takeovers.”
As IT Brew previously reported, Cloudflare has identified email as the primary attack vector for cybersecurity incidents, and email phishing as a significant threat—especially when the sender masquerades as someone an employee trusts IRL.
Two-step verification already cuts in half the number of accounts that are hijacked through methods like social engineering attacks, Google said. However, such schemes can still succeed when they redirect messages and calls from the user’s phone and trick a two-factor authentication system into believing a login or change was requested by the legitimate user.
Under Google’s forthcoming controls, companies could require more than one set of eyeballs to verify some of these settings changes.
“Once it’s been implemented, when an admin initiates a highly sensitive action like a 2SV settings change, any other admin can approve,” Wen, director of product management for Google Workspace, told BleepingComputer. “With this initial framework release, we currently are supporting just 2SV settings change and expanding this capability to other actions based on admin feedback.”
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
