AUTH-017: Super Admin Account Self-Recovery

Platform
Google Workspace
Category
Authentication & Access Controls
Severity
High
Zero Trust pillar
Identity (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Self-service account recovery for super admins is an account-takeover path via social engineering and should be turned off. Super admins should be recovered only by another administrator

Recommended value

Super admin self-recovery disabled in all organizational units

Remediation

Security > Authentication > Account recovery > Turn off 'Allow super admins to recover their account' for all organizational units

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for AUTH-017
ScenarioExpected verdict
cleanPASS
known-badFAIL
no-dataNot Assessed

Framework mappings

NIST SP 800-53
IA-4, AC-6(5)
CIS Benchmark
1.15
CISA SCuBA
GWS.COMMONCONTROLS.8.1v1
MITRE ATT&CK
T1078.004, T1098