How-to

How to enforce two-step verification

Two-step verification in Google Workspace is enabled per organizational unit and only becomes mandatory once enforcement is switched on with a new-user enrolment period. Enforcing it before users enrol locks them out, so allow an enrolment window of at least 1 week.

Rollout facts
Click pathSecurity, Authentication, 2-step verification
ScopeApplied per organizational unit or group
Enrolment periodGrace window for new users, set in days
Strongest methodSecurity keys or passkeys, not SMS codes
Lockout riskEnforcing before enrolment blocks sign-in immediately

Order of operations that avoids lockouts

Turn two-step verification on as available first, communicate a deadline, then monitor enrolment in the security report. Only when enrolment is complete do you switch to enforcement, and only then on the units you have confirmed.

Set a new-user enrolment period so that someone onboarded after enforcement has time to register a method. Without it, a new starter cannot complete their first sign-in without administrator intervention.

Choose methods, not just enforcement

SMS codes satisfy the setting but are the weakest method and are defeated by SIM swap and phishing proxies. Passkeys and hardware security keys resist both, and are what we require on admin accounts without exception.

Plan the recovery path before enforcement: who verifies identity when a phone is lost, and how fast. A rollout without that answer generates its own outage on the first Monday after enforcement.

  • Enable as available, then enforce once enrolment is confirmed.
  • Require security keys or passkeys for every administrator.
  • Document the identity-verification path for lost devices before enforcing.

What we see that others don't say

The failures we are called into after a two-step rollout are almost never technical: they are enforcement switched on before the enrolment report was checked, locking out the users who never read the announcement.

What this doesn't cover

  • Legacy applications using app passwords may fail after enforcement and need reworking rather than exemption.
  • We configure and monitor the rollout; individual device enrolment stays with each user.

Questions we get asked

What happens if I enforce 2FA before users enrol?
Users who have not registered a second factor cannot sign in at all. Enable it as available first, confirm enrolment in the security report, then enforce per organizational unit.
Is SMS good enough as a second factor?
It is better than nothing but the weakest option, defeated by SIM swap and real-time phishing proxies. Passkeys or hardware security keys are the standard we require for administrators.

How this page is verified

Reviewed by Pearl Lemon Cloud security desk, Workspace security and compliance reviewers. Last checked .

  • Click path and enrolment period options checked in the current Google Admin console at the review date.
  • Lockout pattern drawn from remediation work on client rollouts.

Sources you can check

Related pages

Want two-step enforced without a lockout Monday?

We run the enrolment window, chase the stragglers, harden the admin accounts with keys, and enforce unit by unit on a dated plan.