AUTH-015: 2SV Enrollment Grace Period

Platform
Google Workspace
Category
Authentication & Access Controls
Severity
Low
Zero Trust pillar
Identity (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

The grace period before newly added users must enroll in 2SV should be short. A long grace period leaves accounts unprotected by MFA for an extended window after creation

Recommended value

Grace period of 7 days (168 hours) or less

Remediation

Security > Authentication > 2-step verification > Set the new-user enrollment grace period to 7 days or less

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for AUTH-015
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

NIST SP 800-53
IA-2(1)
CIS Benchmark
1.2
CISA SCuBA
GWS.COMMONCONTROLS.1.4v1
MITRE ATT&CK
T1078.004