Update
[September 28, 2023] Rollout has resumed. [September 8, 2023] We have paused rollout for this feature while we evaluate performance and quality. We will provide an update once rollout resumes.
What’s changing
Last year, we introduced stronger safeguards around sensitive actions taken in your Google Workspace accounts. We’re extending these protections to sensitive actions taken in Gmail, specifically actions related to:
- Filters: creating a new filter, editing an existing filter, or importing filters.
- Forwarding: Adding a new forwarding address from the Forwarding and POP/IMAP settings.
- IMAP access: Enabling the IMAP access status from the settings. (Workspace admins control whether this setting is visible to end users or not)
When these actions are taken, Google will evaluate the session attempting the action, and if it’s deemed risky, it will be challenged with a “Verify it’s you” prompt. Through a second and trusted factor, such as a 2-step verification code, users can confirm the validity of the action. If a verification challenge is failed or not completed, users are sent a “Critical security alert” notification on trusted devices.
If a risky action is taken, you'll be prompted with a "Verify it's you" challenge.
Additional details
Note that this feature only supports users that use Google as their identity provider and actions taken within Google products. SAML users are not supported at this time. See below for more information.
Getting started
- Admins: Visit the Help Center to learn more about protecting Google Workspace accounts with security challenges, verifying a users identity, and temporarily turning off the login challenges.
- End users: There is no end user setting for this feature, you'll see "Verify it’s you" challenges if an account action is deemed risky. We recommend that you enable 2-step verification if you haven’t already.
Rollout pace
- Rapid Release domains: Gradual rollout (up to 15 days for feature visibility) starting on August 23, 2023
- Scheduled Release domains: Full rollout (1-3 days for feature visibility) starting on September 6, 2023
Availability
- Available to all Google Workspace customers and users with personal Google Accounts
Resources
- Google Workspace Admin Help: SAML-based SSO: technical overview
- Google Workspace Admin Help: Protect Google Workspace accounts with security challenges
- Google Workspace Admin Help: Manage a user's security settings
- Google Help: Verify it’s you when you complete a sensitive action
- Google Help: Turn on 2-step verification