GWS-K12-005: Delegated Admin Least Privilege

Platform
Google Workspace
Category
K12 Baseline
Severity
High
Zero Trust pillar
Identity (weight 2)
Golden fixtures
3
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
Tenant-wide: assessed across the whole tenant, no student OU input required.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-IDENT-003 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

Districts routinely give counselors, secretaries, and building administrators delegated admin roles for legitimate tasks using roles far broader than the task. A delegated role that carries user-management or security privileges across the whole domain reaches every student account; scoping the same role to an organizational unit contains it. This check surfaces domain-wide delegated assignments for review; whether each holder needs that reach is the district's determination.

Recommended value

Delegated admin roles with user-management or security privileges are scoped to the organizational units the holder supports, not the whole domain

Remediation

Admin Console > Account > Admin roles. For each custom or prebuilt role assignment flagged in the evidence, either narrow the assignment to the relevant organizational unit (edit the assignment's scope) or replace the role with one carrying only the privileges the holder's duties need.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-005
ScenarioExpected verdict
cleanPASS
known-badWARN
not-assessedNot Assessed

Framework mappings

NIST SP 800-53
AC-6, AC-5
MITRE ATT&CK
T1078.004