Skip to main content

Description

Setup multi-factor authentication for Google Cloud Platform accounts.

Rationaleโ€‹

Multi-factor authentication requires more than one mechanism to authenticate a user. This secures user logins from attackers exploiting stolen or weak credentials.

Auditโ€‹

From Google Cloud Consoleโ€‹

For each Google Cloud Platform project, folder, or organization:

  1. Identify non-service accounts.
  2. Manually verify that multi-factor authentication for each account is set.

Default Valueโ€‹

By default, multi-factor authentication is not set.

Referencesโ€‹

  1. https://cloud.google.com/solutions/securing-gcp-account-u2f
  2. https://support.google.com/accounts/answer/185839