๐ Lesson 8.2: Admin, Workspace Editions & Security Best Practices (Honest)
Two things separate a Drive you use from a Drive you trust: understanding who's really in charge of your files, and locking down your account so that the powerful sharing we've learned can't be turned against you. This lesson gives you the honest org picture โ personal vs Google Workspace, and what an admin controls โ then walks you through a real security hardening pass you'll run on your own account today.
๐ What You'll Learn
By the end of this lesson, you will be able to:
- Distinguish a personal Google account from a Google Workspace edition (Business/Enterprise/Education)
- Explain what an admin controls โ storage, sharing policies, shared drives, security, retention โ and what that means for your files
- Understand why files on a work/school account may be organization-owned, not yours
- Run a consolidated security best-practices pass: 2-step verification, strong unique passwords, app-access review
- Apply least-privilege sharing and periodically audit your shared items
- Recognize phishing and fake shares, handle sensitive data carefully, and set up account recovery
โฑ๏ธ Estimated Time: 45 minutes
๐ฏ Project: Complete a personal security hardening pass โ turn on or confirm 2-step verification, review third-party app access, and audit what you're sharing โ so your Drive is genuinely locked down.
In This Lesson
๐ข Personal Account vs Google Workspace
All course we've used "Drive works the same either way" as a friendly simplification. It's mostly true โ but now, honestly, here's the difference that actually matters. There are two worlds your Drive can live in, and knowing which you're in explains a lot of "why can't I do that?" moments.
- A personal Google account โ the free account behind a Gmail address. You are in charge. You own your files, set your own sharing, and control your own storage. Nobody can look over your shoulder or set rules for you. Everything in this course was taught on exactly this.
- A Google Workspace account โ a work, school, or organization account (often with a custom domain like you@yourcompany.com). It runs the same apps, but an admin at your organization sets the rules, and the organization โ not you โ may ultimately own the files you create there.
Google Workspace comes in several editions aimed at different needs โ commonly grouped as Business, Enterprise, and Education (each with tiers). Bigger editions add capabilities like larger or pooled storage, shared drives for teams, stronger security and compliance controls, and longer data retention. The exact feature-by-edition breakdown changes over time, so we won't memorize a matrix โ the point is simply that Workspace is the managed, organizational version of the same Drive you already know.
๐ Definition
Admin: a person (or team) at an organization with an Admin console for its Google Workspace. They provision accounts, set policies, and manage security for everyone in the organization. On a personal account, there is no admin โ that role is you.
๐ก๏ธ What an Admin Controls (and Owns)
If you use Drive at a job or school, it's genuinely useful โ and a little sobering โ to know what your admin can control. This isn't cause for paranoia; it's the reality of files that belong to an organization rather than to you personally. Depending on the edition and how they've configured it, an admin may control:
- Storage โ how much space you get, and organization-wide quotas.
- Sharing policies โ whether you can share outside the organization at all, whether "anyone with the link" is even allowed, and default access levels.
- Shared drives โ team-owned spaces where the organization owns the files, so they don't vanish when a person leaves.
- Security โ required 2-step verification, device rules, and which third-party apps are permitted.
- Data retention & recovery โ how long deleted files are kept, and the ability (as we saw in 8.1) to restore a user's files from retention.
- Access & audit โ in many setups, the ability to access or audit organization-owned files when there's a legitimate business reason.
โ ๏ธ The honest truth about work/school files
On a Google Workspace account, files you create for work are typically organization-owned, not personal property. If you leave the organization, you may lose access to them, and an admin can reassign or remove them. So keep a clean line: personal files belong in your personal account, work files in your work account. Don't store your tax documents, family photos, or job search in a company Drive โ it isn't truly yours there.
๐ก What this means for you day-to-day
If a sharing option is greyed out, a link won't work outside your company, or your storage behaves differently than this course describes โ it's usually your admin's policy, not a bug. The move is simple: ask your admin or IT desk. They set the rules, and they're also your deepest safety net for recovery. On your personal account, none of this applies โ you're the admin.
๐ณ Editions & Pricing โ the Honest Hedge
People always want the answer to "which edition, and how much?" Here's the honest position this course has held from Lesson 1.1: we don't quote prices, storage numbers, or exact feature lists, because they change. Quoting a figure today just means teaching you something that's wrong next quarter.
What's durable is the shape of the choices:
- Free personal account โ does everything taught in this course. A great home base for individuals and families.
- Google One โ a personal upgrade primarily for more storage (plus some extras) while staying on your personal account.
- Google Workspace โ the paid business/education editions with admin controls, custom domains, shared drives on some plans, and larger/pooled storage.
- Gemini / AI features โ some advanced AI capabilities are paid add-ons.
For anything with a number attached โ current prices, exactly how much storage a tier includes, or which feature is in which edition โ go to Google's current Workspace pages (and Google One's page for personal upgrades). Deciding later from the real, current page beats deciding now from a stale figure.
โ Pro Tip
Most individuals never need to pay. Reach for Google One only when your free storage genuinely fills up (tidying and emptying the Trash from Lesson 8.1 often buys back plenty first). Reach for Workspace when an organization needs admin control, a custom domain, or team-owned shared drives โ not for personal use.
๐ Security Best Practices โ Your Account
Here's the sobering reality that makes this the most important lesson in the safety module: your Google account is the master key to your whole digital life โ Drive, Gmail, Photos, and every file and every login tied to them. If someone gets into it, the powerful sharing we've celebrated all course becomes a way to exfiltrate your files. The good news: a handful of habits make your account dramatically harder to break into, and you can set most of them up in one sitting.
1. Turn on 2-Step Verification (the single biggest win)
2-Step Verification (2SV / two-factor) means that even if someone learns your password, they still can't get in without a second factor โ a prompt on your phone, a code, or a security key. This one setting blocks the overwhelming majority of account takeovers. If you do nothing else on this list, do this. You'll find it in your Google Account security settings.
2. Use a strong, unique password
"Unique" matters as much as "strong": if you reuse a password and any one site is breached, attackers try that combination everywhere โ including your Google account. Use a long passphrase you don't use anywhere else, and let a password manager remember it so you never have to reuse or write it down.
3. Review third-party app access
Over the years you've probably clicked "Sign in with Google" or "Allow access to your Drive" for apps you no longer use. Each of those may still hold permission to your account or files. Periodically open your Google Account's security โ third-party access section and remove anything you don't recognize or no longer use. Least access, fewer risks.
4. Set up account recovery
Add and keep current a recovery phone and recovery email. If you're ever locked out โ or need to prove it's really you โ recovery options are how you get back in. This is also part of why 2SV is safe to enable: recovery gives you a path back if you lose a device.
๐ง Security is a habit, not a one-time chore
Think of these like locking your front door: you don't do it once and declare yourself safe forever. A quick security pass a couple of times a year โ confirm 2SV is on, glance at app access, audit what you're sharing โ keeps the powerful, connected home base you've built working for you instead of against you.
๐ฃ Sharing Safely & Spotting Fakes
Back in Module 4 we learned the mechanics of sharing. Security is where those mechanics meet judgment. Careless sharing is the single biggest everyday risk to a Drive โ not hackers, just an over-broad link that traveled further than you meant.
Least-privilege sharing
The golden rule: give the least access that gets the job done. Someone who only needs to read doesn't need Editor. A file meant for one colleague shouldn't be "anyone with the link." Prefer sharing with specific people over open links, and prefer Viewer or Commenter over Editor unless real editing is needed. "Share on purpose, not by reflex" has been our through-line โ this is where it protects you.
Audit your shared items periodically
Sharing accumulates silently. A file you opened to a team two years ago is probably still open. A couple of times a year, review what you've shared โ the Shared views and each important file's sharing settings โ and revoke access that's no longer needed. Removing a person or turning off a link takes seconds and closes doors you forgot were open.
Phishing and fake shares
Attackers abuse Drive's own sharing to look legitimate: you get a "shared with you" notification or an email that mimics a real Drive share, urging you to open a file or "sign in" on a page that steals your password. Warning signs: urgency, an unfamiliar sender, an odd file name, or a login page that isn't genuinely Google. Never enter your Google password on a page you reached by clicking a link โ go to drive.google.com or accounts.google.com directly. When in doubt, send it to the Spam view (Lesson 8.1) and don't click.
โ ๏ธ Sensitive data caution
Be deliberate about what you put in Drive and, especially, what you share. Government IDs, passwords, financial account numbers, medical records, and anything that would seriously hurt if it leaked deserve extra care: share only with specific people, never via open links, and think twice before uploading them at all. And remember โ on a work or school Workspace account, sensitive personal information doesn't belong there, since it isn't truly your private space.
or Workspace?"} B -- "Personal" --> C["๐ค You are the admin
you own & control everything"] B -- "Workspace" --> D["๐ข Admin sets policy
org may own the files"] C --> E["๐ Security checklist"] D --> E E --> F["1 ยท 2-Step Verification ON"] F --> G["2 ยท Strong, unique password"] G --> H["3 ยท Review third-party app access"] H --> I["4 ยท Least-privilege sharing"] I --> J["5 ยท Audit shared items periodically"] J --> K["6 ยท Spot phishing & fake shares"] K --> L["7 ยท Account recovery set up"] L --> M["โ A Drive you can trust"]
โ Your Security Checklist at a Glance
Here's the whole hardening pass in one place โ the list to run now and revisit a couple of times a year:
| Habit | Why it matters | How often |
|---|---|---|
| 2-Step Verification on | Blocks most takeovers even if your password leaks | Set once, confirm yearly |
| Strong, unique password | Reuse turns one breach into many; a manager makes it painless | Set once, change if exposed |
| Review app access | Old "Sign in with Google" apps may still reach your files | Twice a year |
| Least-privilege sharing | Give the least access that works โ Viewer over Editor, people over open links | Every time you share |
| Audit shared items | Old shares stay open silently; close what's no longer needed | Twice a year |
| Phishing awareness | Fake shares steal passwords; never sign in via a link | Always |
| Account recovery set | Gets you back in if locked out, and makes 2SV safe to use | Set once, keep current |
๐ก These habits transfer everywhere
2-step verification, unique passwords, app-access reviews, and least-privilege sharing aren't Google-specific โ they protect your OneDrive, Dropbox, bank, and every other account too. Learning them here makes your entire digital life safer, not just your Drive.
๐ฏ Project: A Security Hardening Pass
Reading about security changes nothing; running the pass changes everything. In this project you'll actually harden your real account โ the same pass a thoughtful professional runs a couple of times a year. Because menus shift, we describe what to accomplish rather than pixel positions; start from your Google Account settings.
๐๏ธ Lock down your account
Objective: Confirm 2-step verification, review third-party app access, and audit what you're sharing โ leaving your account measurably safer than when you started.
Instructions (about 15 minutes):
- (5 min) Open your Google Account security settings. Turn on 2-Step Verification if it isn't already on (or confirm it is). Add or confirm a recovery phone and recovery email while you're there.
- (4 min) Find the third-party access section (apps connected to your account). Read the list, and remove anything you don't recognize or no longer use.
- (4 min) In Drive, review what you're sharing: check the Shared views and open the sharing settings of a few important files. Downgrade any "anyone with the link" you no longer need to specific people, and remove any people who no longer need access.
- (2 min) Confirm your Google account password is strong and not reused elsewhere. If it is reused, plan to change it (a password manager makes this easy).
๐ก Hint โ where to look, without pixel-hunting
Everything account-level (2SV, password, recovery, third-party apps) lives in your Google Account at myaccount.google.com, under a "Security" area. Sharing lives in Drive itself โ right-click any file โ Share, or use the Shared views in the left navigation. If a label has moved, the concept is your map: account safety is in Google Account; who-can-see-my-files is in Drive.
โ Project Completion Checklist
- 2-Step Verification is confirmed ON for your account
- A recovery phone and recovery email are set and current
- You reviewed third-party app access and removed anything unused
- You audited your shared items and closed access that's no longer needed
- Your Google password is strong and not reused elsewhere
๐ฏ Quick Quiz
Question 1: You create work documents on your company's Google Workspace account. Who typically owns them, and what should you do with personal files?
Question 2: What single security step blocks the largest share of account takeovers, even if your password leaks?
โ Best Practices for Security & Editions
โ Do's
- Turn on 2-Step Verification today. It's the highest-value five minutes you'll spend on your digital safety.
- Keep personal and work separate. Personal files in a personal account; work files in the work Workspace account.
- Share least-privilege, and audit twice a year. Viewer over Editor, specific people over open links, and close old shares.
- Check Google's current pages for any number. Prices, storage, and edition features change.
โ Don'ts
- Don't reuse passwords. One breached site becomes a key to everything you reused it on.
- Don't sign in via links in messages. Go to accounts.google.com directly โ that's how you dodge phishing.
- Don't store sensitive personal data in a work Drive. It isn't truly yours there, and an admin can access it.
- Don't assume greyed-out options are bugs. On Workspace, that's usually your admin's policy โ ask IT.
๐ก Pro Tips
- A password manager makes strong-and-unique effortless โ set it up once and never reuse a password again.
- Put a recurring reminder on your calendar for a twice-a-year security pass. Future you will be grateful.
๐ Learning Journal
Keep a learning journal as you work through this course โ a separate document, a note, or a Google Doc right in the Drive you're organizing. After each lesson, take a few minutes to write down:
- Key concepts you learned
- Techniques that clicked for you
- Questions or confusion points to revisit
- Ideas you want to try in your own Drive
- Your progress and feelings about learning this โ including where your confidence grew
โ๏ธ This lesson's prompt: Which security step surprised you most โ and which one had you been quietly neglecting? Now that you've run a hardening pass, how does it feel to know your account (not just your files) is protected? If you're on a work or school account, what's one thing you now understand about who really controls your files?
๐ Lesson Summary
๐ Key Takeaways
- A personal Google account makes you the admin โ you own and control everything. A Google Workspace edition (Business/Enterprise/Education) is the managed, organizational version where an admin sets policy and the organization may own your files.
- Admins control storage, sharing policies, shared drives, security, and retention โ so keep personal files in a personal account and work files in the work account, and ask your admin when something is restricted.
- Editions and prices change, so we hedge and point to Google's current pages rather than quoting numbers; free personal, Google One, Workspace, and paid Gemini/AI are the shapes to know.
- The security pass that protects everything: 2-Step Verification, a strong unique password, app-access review, least-privilege sharing, periodic share audits, phishing awareness, and account recovery.
๐ What You've Accomplished
You now see the honest org picture โ who owns and controls your files in each world โ and, more importantly, you've hardened your own account. 2-step verification is on, your app access is cleaned up, and your sharing is audited. The powerful, connected home base you've spent this course building is now a Drive you can genuinely trust, protected from the accidents (Lesson 8.1) and from bad actors (this one).
โ Common Questions at This Stage
Do I need Google Workspace, or is my free account enough?
For personal use, the free account does everything this course teaches โ you almost certainly don't need Workspace. Workspace is for organizations that need admin control, custom email domains, team-owned shared drives, and stronger compliance. If you just want more personal storage, Google One is the lighter step. For any current price or storage figure, check Google's Workspace pages.
Can my work admin really see my files?
On a Google Workspace account, files you create for work are typically organization-owned, and admins generally can access or audit them when there's a legitimate business reason, plus set sharing and retention rules. It's not sinister โ it's how organizations protect and manage their own data. The takeaway: keep genuinely personal files in your personal account, where you're the only one in charge.
Is 2-Step Verification annoying? What if I lose my phone?
It adds a few seconds now and then, and it's overwhelmingly worth it โ it stops most account takeovers cold. Losing your phone is exactly why you set up recovery options (a recovery email, backup codes, or a second method). With those in place, you can always get back in, and your account is far safer in the meantime.
๐ญ Looking Ahead
In the final lesson โ Lesson 8.3: Capstone โ A Fully Organized Drive + a Shared Hub โ we bring everything together. You'll finish a Drive you genuinely trust: a clean scalable structure, nothing lost, safe sharing, synced and backed up, connected through the Workspace apps, and protected by the versioning and security you just learned. There's a capstone rubric to measure your finished Drive against โ and a celebration of completing not just this course, but the whole four-part Workspace series.
โ Before the Next Lesson
- Finish the hardening pass so 2-step verification is on and your sharing is audited
- If you're on a work/school account, note one thing you'd move to a personal account instead
- Write your Learning Journal entry for this lesson
๐ Additional Resources
- Google Workspace โ editions & current pricing (Google)
- Google Drive Help Center โ sharing & security (Google Support)
- Google Drive Help Community
๐ Encouragement for the Journey
You just did what most people never get around to: you looked honestly at who controls your files and then locked your account down properly. That's the difference between hoping you're safe and knowing you are. One lesson left โ the grand finale, where every skill you've built comes together into a Drive you truly trust. Let's finish strong. ๐