GWS-K12-005: Delegated Admin Least Privilege
- Platform
- Google Workspace
- Category
- K12 Baseline
- Severity
- High
- Zero Trust pillar
- Identity (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- original
- Scope
- Tenant-wide: assessed across the whole tenant, no student OU input required.
Guerrilla K12 Baseline (candidate)
This check assesses control K12-IDENT-003 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.
What it checks
Districts routinely give counselors, secretaries, and building administrators delegated admin roles for legitimate tasks using roles far broader than the task. A delegated role that carries user-management or security privileges across the whole domain reaches every student account; scoping the same role to an organizational unit contains it. This check surfaces domain-wide delegated assignments for review; whether each holder needs that reach is the district's determination.
Recommended value
Delegated admin roles with user-management or security privileges are scoped to the organizational units the holder supports, not the whole domain
Remediation
Admin Console > Account > Admin roles. For each custom or prebuilt role assignment flagged in the evidence, either narrow the assignment to the relevant organizational unit (edit the assignment's scope) or replace the role with one carrying only the privileges the holder's duties need.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| not-assessed | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-6, AC-5
- MITRE ATT&CK
- T1078.004