Choose your language
Google Security Hardening Course
Over 400,000 professionals on the platform
Exclusive for businesses

Google Security Hardening Course

Lock down your Google Workspace environment with the same rigour security engineers use at scale. This course walks you through every critical control layer — identity, devices, data, email, and monitoring — so you can eliminate misconfigurations before attackers exploit them. Leave with a hardened, audit-ready Workspace and the skills to keep it that way.

Dedika for students

What your team will master:

  • Configure authentication policies, MFA enforcement, and least-privilege admin roles across Workspace.

  • Build DLP rules that detect and block sensitive data exfiltration through Gmail, Drive, and Chat.

  • Deploy SPF, DKIM, and DMARC controls to eliminate email spoofing and phishing attack vectors.

  • Implement context-aware access and endpoint compliance policies to block non-compliant devices.

  • Establish centralised audit log pipelines, alert policies, and SIEM integrations for real-time threat detection.

  • Execute structured incident response procedures, including account containment and forensic log collection.

How your team learns in practice Google Security Hardening Course

How your team practises Google Security Hardening Course

Professionals from these companies study at Dedika

ActemiumFR
Nunner LogisticsNL
GT Constructora GeotécnicaCR
Sydel StarBR
Metrô de São PauloBR
Aguas AndinasCL
DSMIN
MeridianbetRS
CDHCN

Course content

8 Chapters • 36 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Google Workspace Security Fundamentals

  • Lesson 1 • Shared Responsibility Security Model

    Defines what Google secures versus what the customer must configure. Clarifies accountability gaps that hardening tasks must close.

  • Lesson 2 • Default Security Posture Assessment

    Evaluates out-of-the-box settings against security best practices. Produces a gap list that drives the hardening roadmap built in later chapters.

  • Lesson 3 • Google Workspace Architecture Overview

    Covers tenant structure, data residency, and service boundaries within Google Workspace. Grounds all subsequent hardening decisions in platform topology.

  • Lesson 4 • Regulatory and Compliance Context

    Maps common data-protection and privacy requirements to Google Workspace controls. Ensures hardening work satisfies audit and compliance obligations.

Chapter 2See details

Identity and Access Management Hardening

  • Lesson 1 • Organisational Unit and Group Access Control

    Uses organisational units and groups to segment policy application and data access. Prevents lateral movement by isolating user populations.

  • Lesson 2 • Single Sign-On and Identity Federation

    Configures SAML-based SSO and external identity provider federation securely. Ensures federated identities inherit the same hardening controls as native accounts.

  • Lesson 3 • Authentication Policies and MFA Enforcement

    Configures password policies, multi-factor authentication methods, and session controls. Directly reduces credential-based attack surface established in Chapter 1.

  • Lesson 4 • Admin Role Design and Least Privilege

    Structures custom admin roles to limit blast radius of compromised accounts. Applies least-privilege principles to every administrative function.

  • Lesson 5 • Privileged Access Monitoring

    Establishes continuous monitoring of admin actions and privileged sessions. Feeds alert pipelines introduced in Chapter 6.

Chapter 3See details

Endpoint and Device Security Controls

  • Lesson 1 • Context-Aware Access Policies

    Uses device signals and user context to grant granular, conditional access to apps. Extends least-privilege principles from Chapter 2 to the device layer.

  • Lesson 2 • Mobile Device Management Hardening

    Applies MDM policies for corporate and bring-your-own-device scenarios. Balances security controls with user privacy requirements.

  • Lesson 3 • Google Endpoint Management Overview

    Introduces basic and advanced endpoint management tiers and their enrolment requirements. Establishes the device trust foundation for access decisions.

  • Lesson 4 • Device Compliance Policy Configuration

    Defines and enforces compliance rules such as screen lock, encryption, and OS version. Non-compliant devices are blocked from accessing Workspace data.

Chapter 4See details

Data Protection and Loss Prevention

  • Lesson 1 • DLP Rule Design for Drive and Chat

    Extends DLP coverage to file sharing and messaging channels. Prevents exfiltration paths not covered by email controls.

  • Lesson 2 • DLP Rule Design for Gmail

    Builds content-inspection rules that detect and act on sensitive data in outbound email. Covers predefined detectors, custom regex, and optical character recognition.

  • Lesson 3 • Data Classification and Labelling

    Establishes a classification taxonomy and applies Drive labels to enforce handling rules. Classification drives all downstream DLP policy logic.

  • Lesson 4 • DLP Monitoring and Tuning

    Analyses DLP incident reports to reduce false positives and close coverage gaps. Establishes a continuous improvement cycle for data protection rules.

  • Lesson 5 • Information Rights Management

    Applies persistent encryption and access controls to documents via Google Workspace IRM features. Protects data even after it leaves the organisational boundary.

Chapter 5See details

Email Security and Anti-Phishing Controls

  • Lesson 1 • Email Authentication Protocol Configuration

    Deploys SPF, DKIM, and DMARC records to authenticate outbound mail and reject spoofed inbound mail. Eliminates domain impersonation as an attack vector.

  • Lesson 2 • Outbound Mail Control and Data Leakage

    Restricts outbound mail routing and enforces TLS for sensitive destinations. Complements DLP rules from Chapter 4 at the transport layer.

  • Lesson 3 • Advanced Phishing and Malware Protection

    Enables Gmail's advanced protection settings to sandbox attachments and flag suspicious links. Builds on authentication controls to catch threats that pass protocol checks.

  • Lesson 4 • Inbound Mail Routing and Filtering

    Configures routing rules, content compliance filters, and blocked sender lists. Reduces malicious mail volume before it reaches end-user inboxes.

Chapter 6See details

Security Monitoring and Alerting

  • Lesson 1 • Audit Log Architecture and Retention

    Maps all available audit log sources and configures retention aligned with compliance requirements. Provides the data foundation for all detection use cases.

  • Lesson 2 • Alert Policy Configuration

    Creates and tunes alert policies for high-priority events such as admin changes and data exfiltration. Ensures the right personnel are notified with actionable context.

  • Lesson 3 • Threat Detection Use Case Development

    Builds detection rules for common Workspace attack patterns such as OAuth abuse and mass download. Operationalises monitoring into a repeatable detection engineering practice.

  • Lesson 4 • Security Dashboard and Investigation Tool

    Uses the Security Dashboard charts and the Investigation Tool to surface anomalies. Translates raw log data into actionable security insights.

  • Lesson 5 • SIEM Integration and Log Forwarding

    Exports Workspace logs to external SIEM platforms via API and Pub/Sub pipelines. Enables correlation with non-Google telemetry for broader threat detection.

Chapter 7See details

Third-Party App and API Security

  • Lesson 1 • OAuth App Access Governance

    Reviews and restricts third-party OAuth app permissions granted by users. Prevents unauthorised data access through over-privileged integrations.

  • Lesson 2 • Google Workspace Marketplace App Control

    Manages which Marketplace apps users may install and what data they can access. Reduces shadow-IT risk from unsanctioned productivity tools.

  • Lesson 3 • Service Account and API Key Management

    Audits and restricts service accounts and API keys used by internal and external applications. Applies least-privilege principles from Chapter 2 to non-human identities.

  • Lesson 4 • API Usage Monitoring and Anomaly Detection

    Monitors API call patterns to detect abuse, data harvesting, and credential misuse. Feeds alert pipelines configured in Chapter 6.

Chapter 8See details

Incident Response and Hardening Validation

  • Lesson 1 • Incident Response Workflow for Workspace

    Defines detection, containment, eradication, and recovery steps specific to Workspace incidents. Integrates with monitoring capabilities built in Chapter 6.

  • Lesson 2 • Continuous Hardening and Governance Cadence

    Establishes recurring review cycles, change management gates, and ownership assignments for ongoing security maintenance. Transforms one-time hardening into a sustainable programme.

  • Lesson 3 • Data Breach Containment in Workspace

    Stops active data exfiltration using Drive sharing revocation, DLP rule escalation, and user suspension. Limits breach scope while preserving evidence.

  • Lesson 4 • Security Configuration Validation and Testing

    Validates hardening controls through configuration review, simulated attacks, and automated scanning. Confirms that all settings from Chapters 1–7 are correctly applied.

  • Lesson 5 • Account Compromise Response Procedures

    Executes step-by-step remediation for compromised user and admin accounts. Covers credential reset, OAuth revocation, and forensic log collection.

Certification

Your valid completion certificate

This course is for you:

  • IT Administrator: manages Workspace daily but lacks a formal security framework.

  • Security Analyst: wants hands-on Google-specific skills to complement broader training.

  • Compliance Officer: needs to map Workspace controls to audit and regulatory requirements.

  • Cloud Engineer: expanding responsibilities now include SaaS security and governance.

  • Career Changer: moving from general IT support into a dedicated security role.

  • MSP Technician: responsible for securing multiple client Workspace environments at once.

Related courses

FAQ

Who is Dedika?

Is the certificate valid in the United Kingdom?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course