Choose your language
Google Workspace: Advanced Administration and Security Course
More than 20 lakh learners worldwide

Google Workspace: Advanced Administration and Security Course

Take full command of Google Workspace security and administration at the enterprise level. This course covers everything from OU design and identity federation to DLP, threat investigation, and compliance readiness — giving IT administrators the hands-on expertise to protect their organisation and pass any audit with confidence.

Dedika for businesses

What you will learn:

  • Configure organisational units, admin roles, and delegated access using least-privilege principles throughout the domain.

  • Build and enforce MFA, SAML-based SSO, and Context-Aware Access policies to protect every user account.

  • Design Gmail security controls including SPF, DKIM, DMARC, content compliance rules, and outbound DLP policies.

  • Implement Drive and Chat data loss prevention, classification labels, and Google Vault retention and hold policies.

  • Automate user provisioning and lifecycle management using SCIM, the Directory API, and Admin SDK scripts.

  • Conduct forensic investigations with the Security Center, Alert Center, and Investigation Tool to contain and remediate threats.

How you study in a practical way Google Workspace: Advanced Administration and Security Course

How you practise Google Workspace: Advanced Administration and Security Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Google Workspace Architecture and Admin Foundations

  • Lesson 1 • Admin Roles and Delegated Administration

    Covers built-in admin roles, custom role creation, and privilege scoping. Establishes least-privilege principles applied throughout the course.

  • Lesson 2 • Google Workspace Service Architecture Overview

    Maps the relationship between core services, data centres, and tenant isolation. Provides the mental model needed for every subsequent configuration decision.

  • Lesson 3 • Admin Console Navigation and Layout

    Introduces every major Admin Console section and its primary controls. Builds the spatial familiarity required for efficient day-to-day administration.

  • Lesson 4 • Organisational Units and Policy Inheritance

    Explains the OU tree, policy inheritance rules, and override mechanics. Correct OU design is the prerequisite for all policy-based configurations in later chapters.

  • Lesson 5 • Licensing Tiers and Feature Entitlements

    Compares Business Starter through Enterprise Plus feature sets and add-on licences. Enables accurate licence planning before provisioning users.

Chapter 2See details

User and Group Lifecycle Management

  • Lesson 1 • User Profile Attributes and Directory Schema

    Explains standard and custom directory attributes, schema extensions, and their use in access policies. Custom attributes feed into group membership rules covered next.

  • Lesson 2 • User Account Provisioning Methods

    Covers manual creation, CSV bulk import, and API-driven provisioning. Connects provisioning method choice to organisational scale and HR system integration.

  • Lesson 3 • Offboarding and Account Suspension Workflows

    Defines secure offboarding steps: suspension, data transfer, and deletion timelines. Proper offboarding prevents data loss and unauthorised access after departure.

  • Lesson 4 • Google Groups Types and Configuration

    Differentiates email lists, security groups, dynamic groups, and collaborative inboxes. Group type selection directly affects mail routing and access control in later chapters.

  • Lesson 5 • Automated Provisioning with SCIM and LDAP

    Configures SCIM-based sync from identity providers and LDAP directory sync. Automation reduces manual error and is foundational for SSO integration in Chapter 3.

Chapter 3See details

Identity, Authentication, and Single Sign-On

  • Lesson 1 • SAML-Based Single Sign-On Configuration

    Walks through SP-initiated and IdP-initiated SAML flows and metadata exchange. SSO configuration builds on the OU and group structures established in Chapter 2.

  • Lesson 2 • Context-Aware Access Policies

    Creates access levels based on device state, IP range, and user attributes. Context-Aware Access enforces zero-trust principles at the application layer.

  • Lesson 3 • Multi-Factor Authentication Deployment

    Covers MFA method types, enforcement modes, and grace period configuration. MFA is the single highest-impact control for account compromise prevention.

  • Lesson 4 • Password Policies and Strength Enforcement

    Sets minimum length, complexity, reuse, and expiration rules per OU. Strong password policy is the baseline before layering MFA and SSO controls.

  • Lesson 5 • OAuth 2.0 and OpenID Connect Integration

    Explains OAuth scopes, consent screens, and OIDC token flows for third-party apps. Scope management directly controls what data third-party apps can access.

Chapter 4See details

Device Management and Endpoint Security

  • Lesson 1 • Mobile Device Policies and Compliance Rules

    Configures screen lock, encryption, app restrictions, and compliance actions. Compliance rules automate responses to policy violations without manual intervention.

  • Lesson 2 • Mobile Device Management Fundamentals

    Compares basic and advanced MDM modes and enrollment methods for iOS and Android. MDM mode selection determines which policies and wipe capabilities are available.

  • Lesson 3 • Chrome Browser and ChromeOS Device Management

    Enrols Chrome devices, applies browser policies, and manages extensions centrally. Chrome management extends endpoint control to browser-based work environments.

  • Lesson 4 • Remote Wipe and Data Loss Prevention on Devices

    Executes selective and full remote wipe and configures work profile data separation. Data separation limits corporate data exposure on personally owned devices.

  • Lesson 5 • Endpoint Verification and Device Trust

    Deploys Endpoint Verification to collect device posture signals for Context-Aware Access. Device trust data feeds directly into the access level conditions from Chapter 3.

Chapter 5See details

Gmail Security and Mail Flow Control

  • Lesson 1 • Compliance Footers, Content Compliance, and DLP

    Applies content compliance rules, objectionable content filters, and DLP policies to outbound mail. DLP rules prevent sensitive data from leaving the organisation via email.

  • Lesson 2 • Email authentication protocols

    Configures SPF, DKIM, and DMARC records and interprets alignment reports. Authentication is the prerequisite for all anti-spoofing and deliverability improvements.

  • Lesson 3 • Email encryption and confidential mode

    Configures S/MIME hosted encryption and Gmail confidential mode restrictions. Encryption controls protect message content in transit and at rest.

  • Lesson 4 • Mail routing rules and gateways

    Creates routing rules, split delivery, and dual delivery configurations for hybrid environments. Routing rules enable coexistence with on-premises mail systems.

  • Lesson 5 • Spam, phishing, and malware filters

    Tunes Gmail's built-in filters, safe lists, blocked senders, and enhanced pre-delivery scanning. Filter tuning reduces both false positives and missed threats.

Chapter 6See details

Data loss prevention and information governance

  • Lesson 1 • Data classification and labels

    Creates Drive labels, applies classification badges, and ties labels to DLP and sharing rules. Labels provide the metadata layer that makes automated policy enforcement precise.

  • Lesson 2 • Drive sharing controls and external access

    Restricts external sharing, link sharing defaults, and trusted domain allowlists. Sharing controls are the first line of defence for Drive-based data exfiltration.

  • Lesson 3 • Chat and spaces governance

    Applies Chat history settings, DLP rules, and external Chat restrictions. Chat governance closes the data leakage gap that email-only policies leave open.

  • Lesson 4 • Google Vault retention and hold policies

    Configures Vault retention rules, litigation holds, and matter-based searches. Vault ensures data is preserved and discoverable for legal and compliance purposes.

  • Lesson 5 • Drive DLP policy configuration

    Creates Drive DLP rules using predefined and custom detectors to block or warn on sensitive content. Drive DLP extends the email DLP concepts from Chapter 5 to file storage.

Chapter 7See details

Security centre, alerts, and threat investigation

  • Lesson 1 • Security centre dashboard and health page

    Interprets security health recommendations and dashboard charts for the domain. The health page surfaces misconfiguration risks that earlier chapters' settings may have introduced.

  • Lesson 2 • Automated response rules

    Creates automated rules that trigger actions such as message deletion or user suspension on alert conditions. Automation reduces mean time to respond to confirmed threats.

  • Lesson 3 • Reporting and compliance dashboards

    Builds custom reports in the Reports section and schedules exports for compliance stakeholders. Regular reporting demonstrates control effectiveness to auditors and leadership.

  • Lesson 4 • Alert centre configuration and triage

    Reviews built-in alert types, configures notification recipients, and establishes triage workflows. Structured triage prevents alert fatigue and ensures critical events are escalated.

  • Lesson 5 • Investigation tool queries and filters

    Runs Investigation tool queries across Gmail, Drive, and device data sources. The Investigation tool enables forensic analysis of events identified in the Alert centre.

Chapter 8See details

Advanced configuration, automation, and strategic governance

  • Lesson 1 • Google AppSheet and Apps Script for admin tasks

    Builds lightweight admin tools using Apps Script triggers and AppSheet interfaces. Low-code automation extends admin capabilities without requiring full engineering resources.

  • Lesson 2 • Change management and admin change controls

    Applies change control processes to Workspace configuration changes using audit logs and rollback strategies. Controlled change management reduces the risk of service disruption.

  • Lesson 3 • Multi-domain and reseller administration

    Manages primary, secondary, and alias domains and configures reseller console delegation. Multi-domain environments require careful OU and policy mapping to avoid conflicts.

  • Lesson 4 • Admin SDK and Directory API automation

    Uses the Admin SDK to automate user, group, and OU management via scripts and pipelines. API automation eliminates manual toil for repetitive administrative tasks at scale.

  • Lesson 5 • Governance frameworks and risk alignment

    Maps Workspace controls to common security frameworks and data protection principles. Framework alignment enables administrators to communicate risk posture to executive stakeholders.

Certification

Your valid completion certificate

This course is for you:

  • IT Administrator: managing Workspace on a daily basis but lacking deep security configuration skills.

  • Systems Engineer: supporting cloud migrations and requiring stronger identity governance knowledge.

  • Security Analyst: expanding scope to include SaaS platforms beyond traditional network perimeters.

  • Help Desk Lead: stepping into a junior admin role and building enterprise-level technical depth.

  • Compliance Officer: needing hands-on Workspace knowledge to evaluate and close regulatory gaps.

  • Career Changer: transitioning from on-premises IT into cloud administration and security roles.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content that I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way of presentation and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot in learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQs

Who is Dedika?

Is the certificate valid in India?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course