Admin console updates from March 2018
-
2018-03-27Admin & Security
Admins can now manage the frequency of 2-step verification (2SV) challenges.
Admins across all G Suite editions can now control whether users are allowed to trust their devices during 2-step verification. Admins can choose to display the 'Remember this computer' checkbox, allowing users to skip the second factor on trusted devices, or disable it to force a 2SV challenge every time a user signs in.
Release: Both • Rapid: 2018-03-27 • Scheduled: 2018-03-27 -
Admins can now control the session length for Google services on the web.
G Suite Business, Enterprise, and Education admins now have the ability to specify the duration of web sessions for Google services (e.g., four hours, seven days, or infinite). Users will be automatically signed out at the end of the specified duration and prompted to re-enter their login credentials, unless they log out manually beforehand. This applies to desktop web sessions and some mobile browser sessions, but not native mobile apps or domains using SAML federation.
Release: Both • Rapid: 2018-03-27 • Scheduled: 2018-03-27 -
All G Suite editions can now manage security keys for two-step verification.
Google has expanded security key management capabilities to all G Suite editions. Admins can now restrict users' two-step verification methods to security keys only, add or revoke security keys for users, and view reports on security key usage within the Admin console to enhance organizational security against phishing attacks.
Release: Both • Rapid: 2018-03-23 • Scheduled: 2018-03-23 -
Basic mobile management will be enabled by default for G Suite domains by the end of 2018.
Google is automatically enabling basic mobile management for G Suite domains that have not previously enabled it by the end of 2018. This change requires users on Android and iOS devices to set up a passcode or screen lock before accessing G Suite apps. Admins can control the timing of this rollout by manually enabling basic mobile management (with or without passcode enforcement) or by enabling and then disabling it to prevent the automatic activation.
Release: Both