AUTH-019: Conflicting unmanaged accounts replaced (GWS.COMMONCONTROLS.7.1)

Platform
Google Workspace
Category
Authentication & Access Controls
Severity
Medium
Zero Trust pillar
Identity (weight 2)
Golden fixtures
3
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
baseline

What it checks

SCuBA GWS.COMMONCONTROLS.7.1: an unmanaged consumer account created against a corporate address holds organization data outside any admin control, cannot be audited or suspended, and survives an employee's departure. Configuring conflict management to replace those accounts brings them under management instead of leaving them alongside the managed identity. Reads provisioning.conflicting_accounts_management and warns where option is anything other than REPLACE_CONFLICTING_ACCOUNT.

Recommended value

Conflicting unmanaged accounts are replaced with managed accounts

Remediation

Admin console > Account > Account settings > Conflicting accounts management. Set the option to replace conflicting unmanaged accounts so they are converted to managed accounts rather than preserved.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for AUTH-019
ScenarioExpected verdict
cleanPASS
known-badWARN
not-assessedNot Assessed

Framework mappings

CISA SCuBA
GWS.COMMONCONTROLS.7.1v1
NIST SP 800-53
AC-2, IA-2, AC-2(7)
MITRE ATT&CK
T1078