AUTH-019: Conflicting unmanaged accounts replaced (GWS.COMMONCONTROLS.7.1)
- Platform
- Google Workspace
- Category
- Authentication & Access Controls
- Severity
- Medium
- Zero Trust pillar
- Identity (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.COMMONCONTROLS.7.1: an unmanaged consumer account created against a corporate address holds organization data outside any admin control, cannot be audited or suspended, and survives an employee's departure. Configuring conflict management to replace those accounts brings them under management instead of leaving them alongside the managed identity. Reads provisioning.conflicting_accounts_management and warns where option is anything other than REPLACE_CONFLICTING_ACCOUNT.
Recommended value
Conflicting unmanaged accounts are replaced with managed accounts
Remediation
Admin console > Account > Account settings > Conflicting accounts management. Set the option to replace conflicting unmanaged accounts so they are converted to managed accounts rather than preserved.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.COMMONCONTROLS.7.1v1
- NIST SP 800-53
- AC-2, IA-2, AC-2(7)
- MITRE ATT&CK
- T1078