Why Cloud Productivity Security Matters
Microsoft 365 and Google Workspace have become the standard productivity platforms for NGOs, schools, professional firms, and businesses across The Gambia and West Africa. Email, documents, spreadsheets, file storage, and communications all flow through these platforms every day.
This concentration of sensitive data in a single platform creates a significant risk if the platform is not properly secured. A compromised Microsoft 365 or Google Workspace account gives an attacker access to emails, contacts, files stored in OneDrive or Google Drive, and potentially the accounts of other users in the same organisation through the admin portal.
The good news is that both platforms include powerful security features as part of their standard licensing. The problem is that most organisations never configure them — leaving their accounts running on insecure default settings that were designed for ease of setup, not for security.
This guide covers the essential security configurations every organisation should implement, regardless of their technical expertise level.
Multi-Factor Authentication
Multi-factor authentication (MFA) is the single most impactful security improvement most organisations can make. MFA requires users to verify their identity using two or more factors — typically a password plus a code from an authenticator app — before accessing their account.
Even if a staff member's password is stolen through phishing or a data breach, MFA prevents the attacker from accessing the account without the second factor.
For Microsoft 365
MFA can be enforced across all users through the Microsoft 365 admin centre. Microsoft Authenticator is the recommended app. Organisations on Business Premium or higher plans have access to Conditional Access policies, which allow more granular control — for example, requiring MFA for access from outside the office network, or blocking access from certain countries.
At minimum, MFA should be enabled for all users. Administrators require the strongest MFA settings.
For Google Workspace
Two-step verification can be enforced for all users through the Google Admin console. Google Authenticator or a hardware security key can be used. As with Microsoft 365, administrators should have the strongest verification requirements.
Practical step: Enable MFA for all accounts today. Start with administrators, then roll out to all staff. Communicate to staff before enabling it — explain what it is, why it is being implemented, and how to set up the authenticator app on their phone.
Secure Admin Accounts
Administrator accounts have the highest level of access in your organisation's platform. A compromised admin account allows an attacker to create new accounts, delete data, disable security settings, and access every user's files and email.
Best practices for admin account security include:
- Use dedicated admin accounts that are separate from the admin's day-to-day user account. Do not use the same account for both administrative tasks and regular email and document work.
- Limit the number of admin accounts to the minimum necessary. Fewer admin accounts means fewer attack surfaces.
- Apply the strongest MFA requirements to all admin accounts — preferably a hardware security key or number matching, not just SMS.
- Review the admin accounts in your organisation periodically. Remove admin access from anyone who no longer needs it.
- Monitor admin sign-in activity and alert on unusual sign-ins, particularly from unexpected locations or devices.
Email Phishing Protection
Email is the most common attack vector for organisations across West Africa. Phishing emails are designed to trick staff into clicking malicious links, opening dangerous attachments, or entering credentials into fake login pages.
Microsoft 365 — Defender for Office 365
Microsoft 365 includes anti-phishing, safe links, and safe attachments features through Microsoft Defender for Office 365 (available in Business Premium and above). These features:
- Scan links in emails in real time when clicked, not just on arrival
- Detonate email attachments in a sandbox environment before delivery to detect malicious content
- Apply machine-learning-based anti-phishing policies to detect impersonation and suspicious patterns
These features should be enabled and configured by an administrator — they are not active by default in all configurations.
Google Workspace
Google Workspace includes Gmail's spam and phishing protection, which is enabled by default, plus advanced protection settings available in the Admin console. Administrators should enable enhanced pre-delivery message scanning, suspicious link protection, and external recipient warnings.
Staff training on phishing recognition remains important regardless of technical controls — no filter catches everything.
Sign-In Monitoring and Access Controls
Both Microsoft 365 and Google Workspace provide sign-in logs that show when users have logged in, from where, and on which devices. Reviewing these logs periodically can reveal suspicious activity — such as logins from unexpected countries, logins at unusual hours, or logins from many different locations in a short period (which can indicate credential sharing or compromise).
Conditional Access (Microsoft 365)
Organisations on Business Premium or higher can use Conditional Access policies to control access based on factors such as location, device compliance, and sign-in risk. For example: require MFA for access from outside The Gambia, or block legacy authentication protocols that are commonly exploited.
Context-Aware Access (Google Workspace)
Google Workspace supports context-aware access controls that restrict access based on device status, network location, and user attributes. These features are available in higher-tier plans.
SharePoint, OneDrive, and Google Drive Sharing Permissions
File sharing is one of the most commonly misconfigured areas in both platforms. Default sharing settings in Microsoft 365 and Google Workspace can allow users to share files broadly — including creating publicly accessible links — without always being aware of the implications.
Key sharing controls to review and configure:
- Set the default sharing scope to internal only — staff should be required to deliberately choose to share externally, not have it as the easiest default option
- Restrict or disable anonymous link sharing if your organisation handles sensitive data — anyone with the link should not be able to access confidential files
- Review existing shared files and folders periodically — particularly in organisations where staff turnover is high
- Disable or restrict sharing to personal Gmail or consumer Microsoft accounts where your organisation only works with business accounts
- In Microsoft 365, review SharePoint site permissions and confirm that sensitive sites are not accessible to all staff by default
Backup Considerations for Microsoft 365 and Google Workspace
As covered in our Backup and Recovery Planning guide, neither Microsoft nor Google provides traditional point-in-time backup for their productivity platforms. Both have limited data recovery options built in — deleted items retention, version history — but these have time limits and do not protect against all data loss scenarios.
For organisations whose business-critical data lives in Microsoft 365 or Google Workspace, a dedicated third-party backup solution should be considered. These solutions take regular snapshots of email, files, and calendar data that can be restored at a granular level — individual emails, files, or entire mailboxes — independent of the platform's built-in limitations.
Practical Security Checklist
- Enable MFA for all users — start with administrators, then all staff
- Create dedicated admin accounts separate from regular user accounts
- Limit the number of global administrators to the minimum necessary
- Enable anti-phishing, safe links, and safe attachments (Microsoft 365 Business Premium or above)
- Configure Google Workspace advanced phishing and malware protection in the Admin console
- Review and restrict default external sharing settings in SharePoint/OneDrive or Google Drive
- Disable anonymous link sharing for sensitive data environments
- Review admin and user sign-in logs for unusual activity at least monthly
- Configure sign-in alerts for suspicious activity
- Disable legacy authentication protocols (Microsoft 365) that bypass MFA
- Review whether a third-party backup solution is needed for your Microsoft 365 or Google Workspace data
- Train all staff on phishing recognition — filters help, but awareness is essential
How MI Secure Tech Solutions Can Help
MI Secure Tech Solutions provides Microsoft 365 and Google Workspace security reviews and configuration support as part of our managed IT and cybersecurity services for organisations in The Gambia and West Africa.
We help organisations:
- Audit their current Microsoft 365 or Google Workspace security configuration against best practice
- Enable and configure MFA across all users
- Configure anti-phishing, safe links, and safe attachments policies
- Review and correct sharing permissions
- Set up sign-in monitoring and alerts
- Implement backup solutions for Microsoft 365 and Google Workspace data
- Train staff on phishing recognition and safe platform use
Request a free technology and security review to assess your current Microsoft 365 or Google Workspace security posture and discuss practical improvements.