Protect Google Workspace accounts with security challenges

Security challenges are additional security measures to verify a user's identity. There are two types of security challenges:

  • Login challenge—If we suspect that an unauthorized user is trying to sign in to a Google Workspace account, we present them with a login challenge. If the user can't enter the requested information, we won't let them sign in to the account.
  • Verify-it's-you challenge—If a user is attempting actions that are considered sensitive, we present them with a verify-it's-you challenge. If the user can't enter the requested information, we disallow the sensitive action (they can keep using their account as normal).

Before you can use security challenges

Make sure your Google Workspace accounts have the information we need:

  • Remind employees to add a recovery phone number and email address to their account. We will periodically ask them to add these details when they sign in to their accounts.
  • Add employee IDs to your user accounts. See Add employee ID as a login challenge.

Open all   |   Close all

Types of login challenges

User confirms their identity with their mobile device
 

User chooses how to verify their identity

""

Google uses an app installed on the user's phone to confirm their identity

""

Google sends a text message with a verification code 

""

 Google calls the user's phone and provides a verification code

""
User enters their employee ID
If you've added employee ID as a login challenge, users can use this ID to confirm their identity.
""
User enters their recovery email
A user can enter a recovery email address as a login challenge. 
""

Verify-it's-you challenges for sensitive actions

If a Google Workspace user attempts a sensitive action, that user is sometimes presented with a verify-it's-you challenge. If the user can't enter the requested information, Google will disallow the sensitive action.

'Sensitive action blocked'

For most users who are presented with a verify-it's-you challenge for a sensitive action, a window is displayed with the title, Sensitive action blocked. The user is instructed to try again from a device they normally use (like their phone or laptop) or from the location they usually sign in from.

'Can't complete this action right now'

Because some users have devices or security keys that were recently added to their account, they can't immediately verify their identity in response to a security challenge. For these users, a window is displayed with the title, Can't complete this action right now. These users can verify their identity after a device, phone number, or security key has been associated with their account for at least 7 days.

Examples of sensitive actions

Here are a few examples of sensitive actions:

  • Disabling 2-step verification
  • Allowing an app to access Google data
  • Changing the account recovery email address or phone number
  • Downloading account data
  • Changing the name on the account

Enable login challenges with SSO

If your organization uses third-party identity providers (IdPs) to authenticate single sign-on (SSO) users through SAML, you can present these SSO users with additional risk-based login challenges, depending on how you use third-party IdPs:

  • If you’ve configured an SSO profile for your organization, you can choose whether to apply additional authentication challenges or 2-Step Verification (2SV) to users that profile is applied to. After the IdP authenticates a user during sign-in, Google can present additional login challenges or apply 2SV to the user.

    Note: The default behavior for these users is to bypass additional challenges. To turn them on, follow the steps in Set up post SSO verification below.

  • If you’re using another third-party profile for OUs or groups in your organization, any risk-based authentication challenges and 2SV (when turned on), are automatically applied to these users.
Use cases for additional login challenges with SSO
  • You want to use security keys to protect access to sensitive Google-hosted resources for maximum assurance, and your current IdP doesn’t support security keys.
  • You want to save the cost of using a third-party identity provider because in most cases users access Google resources.
  • You don’t want Google authentication (Google as identity provider), but want to leverage all of Google’s risk-based login challenges.
  • You want Google to protect sensitive actions inside the Google ecosystem.
What happens when you apply additional login challenges
For a smooth implementation, tell your users about the new policy and when you plan to apply it. Here’s what happens when you apply additional login challenges at sign-in:
  • If you have existing 2SV policies, such as 2SV enforcement, those policies apply immediately.
  • Users affected by the new policy and who are enrolled in 2SV get a 2SV login challenge at sign-in.
  • Based on Google sign-in risk analysis, users might see risk-based login challenges at sign-in.
Set up post SSO verification
  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. In the Admin console, go to Menu ""and then"" Securityand thenAuthenticationand thenLogin challenges.
  3. On the left, select the organizational unit where you want to set the policy.
    For all users, select the top-level organizational unit. Initially, organizational units inherit the settings of its parent.
  4. Click Post-SSO verification.
  5. Select Logins using SSO are subject to additional verifications (if appropriate) and 2-Step Verification (if configured).
    Google creates an entry in the Admin audit log to indicate the policy change. With the new policy, Google can present risk-based authentication login challenges and 2-Step Verification if it’s configured. The default is to bypass additional verification.
  6. On the bottom right, click Save.

Note: In rare cases, log event data might not be present for all events. We are working to resolve this issue.

FAQ

Extra security questions and login challenges  |  Phone verification  |  Disabling a login or security challenge  |  Administrators

Extra security questions and login challenges

When does a user see a security challenge?

A user is presented with the login challenge when a suspicious login is detected, such as the user not following the sign-in patterns that they've shown in the past. A user is presented with a verify-it's-you challenge if they have a risky session when attempting a sensitive action.

Important: Google decides which type of security challenge is appropriate to present to a user based on multiple security and usability factors. For example, the employee ID login challenge might not always be presented to a specific user, even if you turned it on.

As an administrator, can I choose which type of login challenge to show my users?

2-Step Verification (2SV) is a type of login challenge. As an administrator, you can enforce the 2SV login challenge for your users. By doing so, they won't receive another type of risk-based login challenge.

If you don't enforce 2SV for your users, or if a user doesn't have it on, Google decides which type of login challenge is appropriate to present to that user. The type of login challenge that's appropriate is based on multiple security and usability factors. For example, the employee ID login challenge might not always be presented to a specific user, even if you turned it on.

Can users update their recovery information? We use 2-Step Verification. Why do we need login challenges?

2-Step Verification (2SV) is a type of login challenge. When your users have it on, they won't get another login challenge. For the same reason, Admin Reports display each 2-Step Verification as a login challenge​.​

How do login challenges work when I have SSO enabled?

It depends on how you've configured SSO in your organization:

  • If you’ve configured an SSO profile for your organization - By default, login challenges aren’t enabled. However, you can set up post SSO verification to allow additional risk-based authentication challenges and 2-Step Verification (2SV) if configured.
  • If you’re using another SSO profile, any additional login challenges (including 2SV, if configured) are automatically applied.
Is this feature available in Education editions?

Yes, all Google Workspace editions include extra security questions and login challenges.

When does Google consider a sign-in attempt suspicious?

We determine whether a sign-in is suspicious when our risk-analysis system identifies an attempt that’s outside the normal pattern of user behavior. For example, a user might try to sign in from an unusual location or in a manner associated with abuse.

Phone verification

If my users don’t have a corporate phone, is there another way to verify their accounts?

Yes, there are different types of login challenges. Depending on the information that’s available for a user’s account, users are presented with a different type of login challenge, such as entering their employee ID or recovery email address. If a user doesn’t have access to their phone, they can use backup codes to sign in. For details, see Sign in using backup codes.

How can a user update the recovery phone number or email associated with their account?

The user can update the recovery information through the account settings.

Can a user opt to verify criteria other than their recovery phone number?

If the user doesn’t enter a recovery phone number, other types of login challenges apply, such as entering their recovery email address or using their employee ID.

Disabling a login challenge or verify-it's-you challenge

If the user can't verify their identity, can I disable the login or verify-it's-you challenge?

Yes, an administrator can turn off a login or verify-it's-you challenge for 10 minutes. 

In some situations, an authorized user can’t verify their identity. For example, they might not have a phone signal and can’t get the verification code. Or, they can’t remember or find their employee ID. If this happens, as a super administrator you can turn off the login or verify-it's-you challenge for 10 minutes to allow them to sign in or complete the sensitive action. Exercise caution when turning off login or verify-it's-you challenges, as the account is less secure from account hijackers during the 10-minute window.

Can I turn the login or verify-it's-you challenges off for my organization?

No, you can’t turn off this feature for your entire organization. You can only turn it off temporarily on a per-user basis.

Can the user turn this off themselves from their account settings?

No, only an administrator can turn off the login or security challenges temporarily.

Administrator login challenges

How can an administrator who can’t verify their identity re-enter their account?

As an administrator, you can regain access to your account by following the prompts on the login page to reset your password.

If you're a Google Workspace administrator who's having trouble signing in to your admin account, go to Recovering administrator access to your account for instructions.

What if a super administrator can't verify their identity?

If a super administrator user can't verify their identity, then another super administrator (if available) can temporarily turn off the login challenge for them, as described in the steps above.

Alternatively, the super administrator can bypass the login challenge by resetting their password.

Note: The automated password reset option isn't available to all super administrators. For more information about admin account recovery, see Add recovery options to your administrator account.

Was this helpful?
How can we improve it?

Need more help?

Sign in for additional support options to quickly solve your issue

Search
Clear search
Close search
Google apps
Main menu
Search Help Center
true
true
true
73010
false
false