The Google Admin console has hundreds of settings and about seven that will cost you real money if they are wrong. This is those seven, with what each one does, where it sits today, what to change it to, and what you give up by changing it.
The Google Admin console at admin.google.com is the single web interface where a Google Workspace administrator manages users, security policy, device access and every service setting for the organisation. Almost everything below is set per organisational unit, so you can apply a strict setting to finance and a looser one to the warehouse rather than choosing one answer for everybody.
1. 2-Step Verification enforcement decides whether a stolen password matters
Where: Security, then Authentication, then 2-Step Verification.
What it does: Requires a second factor at sign-in. Google’s console lets you allow users to turn it on, or enforce it, and lets you restrict which methods count: any method, any method except verification codes sent by text or phone call, or security key only.
The current position: Google is progressively enforcing 2SV on administrator accounts across editions. Super administrators are notified roughly 90 days ahead of their enforcement date and other admins roughly 60 days ahead. After the date passes, Google applies escalating restrictions: reminders in the Admin console after seven days, no access to Workspace apps on mobile devices after fifteen days, and no access to web apps after thirty days.
What to set: Enforce 2SV for every user, not only admins. Set the allowed methods to exclude codes sent by SMS or voice call, because those are the methods that fall to SIM swap and phishing relay. Security keys or passkeys for admins and anyone handling payments or client data.
The trade-off: Enforcement creates lockouts. A user who loses their phone before enrolling a second method cannot sign in, and someone has to be available to reset them. Set a new user enrolment period so people joining mid-week are not locked out on day one, make everyone generate backup codes, and enrol a second security key on admin accounts. If every admin is locked out at once you are into locked out of your Google Workspace admin account territory, which is far slower than a reset.
2. Admin role assignment is the one setting that is almost always too generous
Where: Account, then Admin roles. Assignments per user under Directory, then Users.
What it does: Grants administrative privileges. Super admin is total control: every setting, every user’s password, all business data. The prebuilt roles below it (Groups Admin, User Management Admin, Help Desk Admin, Services Admin, Storage Admin and so on) are narrower, and you can build custom roles scoped to a single organisational unit.
The default: Whoever signed the account up is a super admin. Everything else is whatever has accumulated since.
What to set: More than one super admin, held by separate people, because a single super admin is a single point of failure. Google’s own guidance goes further: give each super admin two accounts, one for super admin tasks and a separate ordinary account for daily email, and delegate routine work to limited roles. Never share a generic admin account between people, because the audit log then cannot tell you which human made a change. Review the role assignment list at least twice a year and after anyone leaves.
The trade-off: Least privilege generates help desk traffic. Someone who used to fix their own problem now has to ask. That is the point, and it is cheaper than the alternative. Do the work once by mapping roles to actual job functions rather than granting super admin because it is quicker on the day.
3. Third-party app access is where data leaves without anybody noticing
Where: Security, then Access and data control, then API controls.
What it does: Governs which third-party applications can reach your Gmail, Drive, Calendar and other data through OAuth. This is the mechanism behind every “sign in with Google” prompt and every add-on someone installed in 2021.
How it works in the console: Under Manage Google Services you mark each Google service as Unrestricted or Restricted. Restricted means an app cannot use that service’s high-risk OAuth scopes unless you have explicitly trusted the app. Google publishes the high-risk scope lists, and they are the ones that matter: for Gmail they include full mailbox access, read, modify, send and settings changes, and for Drive they include full Drive access and Drive readonly. Under Manage Third-Party App Access you set each app to Trusted, Limited or Blocked. Under the Settings card, Unconfigured third-party apps controls what happens to everything you have not classified, with options to allow any third-party app, to allow only apps that ask for Google sign-in information, or to block them all.
What to set: Start by reviewing the Accessed apps list before you change anything, because you will find integrations that the business genuinely depends on. Then restrict Gmail and Drive, allowlist the apps you actually use as Trusted, and move Unconfigured third-party apps to sign-in information only. Turn on Trust internal apps only if you build your own.
The trade-off: This one breaks things. Google states plainly that when you move a service to Restricted, previously installed apps you have not trusted stop working and their tokens are revoked. Do it out of hours, tell people first, and expect a week of allowlisting requests. Also note the reporting lag: app details typically appear 24 to 48 hours after authorisation, so the list you are looking at is not live.
4. Drive external sharing defaults decide how much of your IP is already public
Where: Apps, then Google Workspace, then Drive and Docs, then Sharing settings, then Sharing options.
What it does: Controls whether users can share files outside the organisation, whether they can create “anyone with the link” files, whether they are warned when sharing externally, and whether external files are visually flagged.
What to check first: Whether external sharing is On or Off, whether sharing is limited to allowlisted domains, what the default access is when a user creates a new item, and whether Highlight external files is enabled. That last one is on by default and shows a warning indicator on files owned by or shared with someone outside the organisation, and it is worth confirming nobody has turned it off.
What to set: For most Australian SMBs, external sharing On but with link sharing defaulting to restricted, warnings enabled when a user shares outside the domain, and the external file indicator on. If you work in a regulated space or handle client files under contract, allowlisted domains is a stronger position and is manageable if your external collaborators are stable.
The trade-off: Turning external sharing off entirely does not stop data leaving, it moves it to personal Dropbox accounts and email attachments where you have no visibility at all. Restricting to allowlisted domains creates friction every time a new client or supplier appears. Whatever you choose, changes can take up to 24 hours to apply and old and new settings can be enforced intermittently during that window, so do not test at 4pm on a Friday and conclude it failed.
5. Gmail routing and spoofing protections are where business email compromise gets in
Where: Apps, then Google Workspace, then Gmail. Safety settings under Safety, routing under Routing and Default routing.
What it does: Two separate risks live here.
The Spoofing and authentication section under Safety controls what Gmail does with mail that impersonates your domain, impersonates an employee name, or arrives unauthenticated from any domain. Alongside it, Advanced phishing and malware protection adds screening of attachments, links and external images, and enhanced pre-delivery message scanning improves detection of phishing that would otherwise get through.
Routing is the quieter risk. Attackers who reach an account frequently create a routing rule or a forwarding rule that silently copies mail to an external address, and it survives the password reset that everyone assumes fixed the problem. Routing rules do not appear in the user’s own settings, so nobody finds them by looking in the mailbox.
What to set: Turn on every option in Spoofing and authentication and in Advanced phishing and malware protection, applying the quarantine or spam action rather than the “keep in inbox with warning” action for the impersonation checks. Then audit the routing and default routing lists and confirm every rule is one you put there. Do that audit again after any account compromise.
The trade-off: Impersonation protections generate false positives, usually on legitimate mail from suppliers with badly configured authentication, on newsletters sent through third-party platforms, and on staff sending from personal addresses. Start with the warning action, watch for two weeks, then move to quarantine.
The part that is not in the console: SPF, DKIM and DMARC are DNS records, not Admin console settings. Google generates the DKIM key for you in the console, but SPF and DMARC are published at your domain host. A DMARC policy of p=none publishes reports and blocks nothing, so if you set one up years ago and never revisited it, it is very likely doing nothing.
6. Data regions are the setting Australian buyers ask about and Google answers narrowly
Where: Data, then Compliance, then Data regions. Availability depends on your edition.
What it does: Sets a geographic policy for where covered data is stored at rest, including backups, for a set of core Workspace services.
What the options actually are: United States, Europe, or No preference. There is no Australian data region option. If your obligation is that Australian personal information stays in Australia, Workspace data regions do not deliver that, and no amount of console configuration will change it.
What to set: If you have a contractual or client-driven requirement to keep data out of a particular jurisdiction, set the policy and record it. If your requirement is genuinely that data must reside in Australia, that is an architecture conversation, not a setting.
The trade-off: Data regions are edition-dependent, with the more granular controls sitting in the Enterprise tier and above, and they cover a defined list of core services rather than everything in your tenancy. Read Google’s covered-data list before you tell a client or an auditor that the box is ticked. If you are being asked this question in a client security review, say what the control does and does not cover rather than answering yes.
7. Audit logging is free, already on, and shorter than you think
Where: Reporting, then Audit and investigation.
What it does: Records log events across Admin actions, user logins, Drive, Gmail, OAuth tokens, devices, Groups, Chrome and more. Administrators cannot delete log event data or extend how long it is kept.
How long you actually have: Google publishes the retention periods and they are worth knowing before an incident rather than during one. Most log event types are retained for six months, including Admin log events, user login events, Drive, Gmail, OAuth token and Context-Aware Access events. Email log search is 30 days. Chrome apps, extension usage and version reports are 12 months. Customer and user usage data retrieved via the API is 15 months. Vault log events are retained indefinitely.
What to set: Nothing to enable, but two things to do. Turn on admin email alerts for the events that matter, including suspicious sign-in attempts, admin role changes and settings changed by another admin. Then decide whether six months is long enough for your obligations, and if it is not, export log events on a schedule to somewhere you control.
The trade-off: The security investigation tool, which is what makes these logs genuinely usable at speed, is not available on every edition. Google lists it for Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus and Cloud Identity Premium. On Business tier editions you have the audit and investigation page and the reports, which is enough to answer a question you already know how to ask, and slower for open-ended hunting.
What to do with this list
Work top down. Identity first, because a compromised admin account makes every other setting irrelevant. Then third-party app access, because it is the control most tenancies have never touched. Then sharing, then mail, then the compliance and logging settings that matter mostly when something has already gone wrong.
If you want the full sequence with licence tiers mapped out, that is in a sequenced hardening plan. If you have just inherited a tenancy from a previous provider, start with taking over a tenancy nobody documented instead, because you need to know what is configured before you change anything. If you are weighing the platform itself rather than the settings, how Microsoft 365 and Google Workspace compare covers that decision, and multi-factor authentication across the business covers the identity piece beyond Workspace. Logging and retention are also not backup, which is the point of what Google actually retains.
We administer Google Workspace tenancies for Melbourne businesses and are listed in Google Cloud’s partner directory. We audit those tenancies against this list and hand back a written report showing what is set, what it should be, and what breaks if you change it. Call 1300 028 324 to book one, or start at techassist.au/contact.
Google guarantees that Gmail and Drive stay available. It does not guarantee that a file one of your staff deleted in March is recoverable in June. Those are different promises, and the gap between them is where Australian businesses lose data they legally have to keep.
Backing up Google Workspace means holding an independent copy of your Gmail, Drive, Shared drives, Calendar, Contacts and Chat data, outside the tenancy and outside the control of the accounts that use it, that can be restored to a chosen point in time. Nothing included with a Workspace licence does that.
The shared responsibility line, stated plainly
Google is responsible for the infrastructure: keeping the service running, keeping the data centres up, protecting against hardware failure, and replicating your data so a disk or a site failure does not lose it.
You are responsible for what happens inside your tenancy: what your users delete, what an attacker who has your password deletes, what a departing employee takes or destroys, and how long you keep records you are legally obliged to keep.
Google’s replication is not a backup, because replication faithfully copies the deletion. If a file is gone from the live system, it is gone from every copy of the live system. The question is never whether Google still has your data somewhere. The question is whether Google will give it back to you, and for how long.
What Google actually retains, and for how long
These are Google’s published windows. They are shorter than most business owners assume, and they are not adjustable.
Drive trash: 30 days. By default, Drive permanently deletes files 30 days after a user moves them to their trash. The user can restore them during that window.
Admin recovery after the trash is emptied: 25 days. If a user empties their trash, an administrator can recover deleted Drive items for a further 25 days from the Admin console. After that, Google purges the items and states they cannot be recovered.
Deleted user accounts: 20 days. If you delete a user and do not transfer their files at the time, Google deletes those files 20 days later. Restoring the account inside that window is the only route back.
Deleted Gmail: a comparable window and no more. Admins can restore a user’s permanently deleted email for a limited period after deletion, and after that Google purges it.
Shared drives: deleting a shared drive removes its content, with a limited administrative restore window rather than an indefinite one.
Audit logs: mostly six months. Most log event types are retained for six months. Email log search is 30 days. Chrome reports are 12 months. Administrators cannot delete log event data or change how long it is kept.
Put those together and the practical position is this: you have roughly a month to notice an ordinary deletion, and slightly less if the deletion happened through an account that was then removed. If your only detection mechanism is somebody looking for a file, you will regularly miss the window.
Vault is not backup, and Google says so
This is the most expensive misunderstanding in the Google ecosystem, because Vault is genuinely good at its actual job.
Google Vault is an information governance and eDiscovery tool. It lets you retain, hold, search and export Gmail, Drive, Calendar, Chat, Meet recordings, Groups, Sites, Voice and Gemini data. It is included with Business Plus, Frontline Standard and Plus, Enterprise Standard and Plus, all Education editions, Enterprise Essentials and Enterprise Essentials Plus for domain-verified accounts, and G Suite Business, and it is available as an add-on licence for some other editions. Since 1 November 2025 administrators need a Vault licence themselves in order to use it.
Here is why it is not backup, in Google’s own terms.
Vault does nothing until you configure retention rules. Google states it directly: Vault does not retain data until you set up retention rules, and until you do, users can delete data and services can purge it on their normal schedule. A tenancy with Vault licensed and no rules configured has exactly the same recovery position as a tenancy without Vault.
Vault is not an archive. Google’s documentation says Vault retention rules are applied to the live data systems of the underlying services and that Vault is not a data archive. When a retention period ends and the data is not on hold, it is subject to normal deletion, and once purged it cannot be recovered by users or admins.
Vault deletes as well as retains. Retention rules cut both ways. A rule configured to purge data after a set period will purge it, permanently, on schedule. That is the intended behaviour for a governance tool and the opposite of what you want from a backup.
Vault exports, it does not restore. You can search retained data and export it. You cannot press a button and put a user’s Drive back the way it was on Tuesday. Recovering a mailbox from a Vault export is a manual reconstruction project, not a restore.
Vault dies with the licence. Google’s documentation warns that if you delete a user or a required licence, their data may be irreversibly purged and no longer available to Vault. A backup that disappears when you stop paying for the platform it protects is not an independent copy.
Vault is bounded by the tenancy. If you lose administrative control of the tenancy, you lose Vault along with everything else. That scenario is covered in losing admin access to the tenancy.
Vault is the right tool for legal hold, for eDiscovery, and for enforcing a retention policy. Use it for those. Do not put it in the recovery column of your business continuity plan.
The four scenarios that actually cause data loss
Ransomware and account compromise. The modern version does not encrypt a file server. An attacker takes a password, signs in, and works through Drive and Gmail from inside a trusted session. Files are deleted, shares are changed, mailbox rules are created. Google’s systems replicate every one of those actions correctly, because from the platform’s point of view an authenticated user is doing normal work. Your recovery position is the 30 day trash window and whatever the attacker did not bother to empty.
The malicious insider. Someone resigns badly and spends their notice period deleting or exfiltrating. Because they own the files, most of it is legitimate activity that no security control will block. Detection after the fact depends on Drive log events, which are retained for six months, and recovery depends on those same short windows.
Departing staff and the 20 day clock. This is the quiet one, and it is almost always self-inflicted. An employee leaves, someone deletes the account to stop paying for the licence, and nobody transfers the files. Twenty days later the data is gone, including files that were the only copy of a client project. Google’s own guidance is to transfer ownership of Drive files and Calendar events before deleting, or to suspend rather than delete, or to archive the account. A proper offboarding checklist prevents this entirely, and it is a five minute change to the process.
Ordinary human error found too late. A folder is deleted in the last week of the financial year and nobody notices until the accountant asks for it in October. There is no window left, no matter how good your excuse is.
The Australian angle you cannot configure your way out of
Record keeping. The ATO requires businesses to keep records that explain their transactions, generally for five years. Employment, contractual and industry-specific obligations frequently run longer. Google’s Drive and Gmail recovery windows are measured in weeks. Vault can hold data for five years if you configure a rule to do it, which is a governance answer rather than a recovery answer, and only on the editions that include it.
Privacy Act and the NDB scheme. Under the Notifiable Data Breaches scheme, loss of personal information counts alongside unauthorised access and disclosure. If personal information is destroyed and you cannot recover it, you may still have a notifiable breach on your hands and an assessment obligation the OAIC expects you to complete within 30 calendar days. Being able to say precisely what was lost, and to restore it, materially changes both the assessment and the notification.
Where the copy lives. If you take a third-party backup, ask where the backup itself is stored, because that answer may be different from where Workspace stores your live data. Workspace data regions offer United States, Europe or no preference, with no Australian option, so an Australian-hosted backup can end up being the only Australian copy you have. That question is worked through in where your business data actually lives.
What a real backup covers, and what to look for
We are not going to name a product, because the right one depends on your edition, your data volume and where you need the copy to sit. These are the criteria that separate a real backup from a file sync with good marketing.
Independent credentials and an independent blast radius. The backup must not be accessible with the Workspace admin credentials it is protecting. If compromising your super admin account also lets someone delete the backups, you have one copy, not two.
Coverage of everything, not just Drive. Gmail with labels and folder structure intact, My Drive, Shared drives, Calendar, Contacts, Chat, and Sites if you use them. Shared drives are the common gap, because they are owned by the organisation rather than a user and some tools skip them.
Point-in-time restore, not just latest. You need to restore to the day before the deletion, not to the current state. Daily is the minimum, more often is better.
Granular restore back into the tenancy. Restoring a single message to a single mailbox, or a folder to its original Drive location with permissions intact, without the user having to reimport a zip file. Export-only tools are recovery projects, not restores.
Retention you set, decoupled from your Workspace licence. If you need seven years, the backup should hold seven years regardless of whether the user is still licensed, still employed, or still exists.
Immutability and deletion protection. Backups that cannot be altered or deleted for a defined period, including by an administrator, so that an attacker who gets in cannot destroy the recovery path.
Data location you can specify and evidence. Ask where the data is stored, in writing, and ask what happens on termination.
A tested restore. An untested backup is a hypothesis. Restore something real, on a schedule, and document that you did. Cyber insurers and client security reviews increasingly ask for evidence of the test, not the policy.
The general architecture behind all of this is covered in how business cloud backup should be structured.
What to do this week
Check your Workspace edition and whether Vault is licensed and whether any retention rules exist, because a licensed Vault with no rules is a common and misleading finding. Check your offboarding process for the account deletion step and add a file transfer before it. Confirm someone owns the alerting so a mass deletion gets noticed inside days rather than months. Then decide whether a third-party backup is warranted, and if it is, scope it against the criteria above rather than on price alone.
Tightening the tenancy itself is a separate and complementary job, covered in hardening the tenancy itself and the Admin console settings that matter. Backup reduces the consequence of a bad day. Hardening reduces how often you have one.
We can tell you in one session what your current recovery position actually is, including which retention windows you are relying on without realising it. Call 1300 028 324 or start at techassist.au/contact.
Most Google Workspace tenancies in Australian small business are running close to the settings they had on day one. The good news is that the highest-value hardening steps cost nothing and are available on every edition. The bad news is that several controls your cyber insurer or your client’s security questionnaire asks about are only sold in the Enterprise and Frontline tiers, and no amount of configuration substitutes for them.
Hardening Google Workspace means changing the Admin console settings that govern identity, application access, data sharing and monitoring so that a stolen password, a malicious add-on or a departing employee cannot quietly take your data with them. Do it in the order below, because each phase makes the next one worth doing.
Why this matters in Australia specifically
Under the Privacy Act, APP 11 requires you to take reasonable steps to protect personal information. If you hold personal information and you suffer unauthorised access, disclosure or loss that is likely to result in serious harm, the Notifiable Data Breaches scheme obliges you to assess it and, if it qualifies, notify the OAIC and the affected individuals. The OAIC’s position is that you must take all reasonable steps to complete that assessment within 30 calendar days of becoming aware of grounds to suspect an eligible breach.
Two practical consequences follow. First, you cannot assess a breach you cannot see, which is why logging and alerting sit high in this plan rather than at the end. Second, the reasonable steps standard is judged against what was available to you, and 2-Step Verification is free on every Workspace edition.
Cyber insurance questionnaires now ask the same handful of questions: is MFA enforced on all users and all administrators, is email filtering in place, are backups separate and tested, and can you detect and investigate an incident. Answering those honestly is easier if you have already done the work. Your obligations under the Notifiable Data Breaches scheme covers the reporting side in detail.
Phase 0: find out which edition you are actually on
Before you plan anything, check Billing, then Subscriptions, and write down the exact edition name. Business Starter, Business Standard, Business Plus, Enterprise Standard, Enterprise Plus, Frontline Starter, Frontline Standard, Frontline Plus and the Essentials editions all differ, and several of the controls people assume are standard are not.
Also check whether all your users are on the same edition. Mixed tenancies are common after growth or acquisition, and a policy that relies on an Enterprise feature will silently not apply to the Business Standard users sitting next to them.
Phase 1: identity, because everything else is downstream of it
This phase is free on every edition and delivers most of the risk reduction.
Enforce 2-Step Verification for everyone. Not just admins. Set it under Security, then Authentication, then 2-Step Verification, and set a new user enrolment period so joiners are not locked out on their first day.
Move admins to phishing-resistant methods. Google’s own admin security guidance names security keys as the most secure form of 2SV and the one that resists phishing, because a hardware key will not authenticate to a lookalike domain. Codes delivered by SMS or voice call do not resist phishing or SIM swap. Set the allowed methods to exclude text and call codes at least for administrators and anyone who can move money. Enrol a second key per admin and store it separately. The broader case is in phishing-resistant MFA.
Fix the admin account structure. More than one super admin, each held by a separate person. Separate super admin accounts from the daily accounts those people use for email. Delegate routine tasks to limited prebuilt roles rather than handing out super admin. No shared generic admin logins, because the audit log cannot attribute a change to a person if three people use the same account.
Create a break-glass account and prepare recovery. A super admin account that belongs to the business, not used daily, with printed backup codes and a spare security key stored physically. Google’s guidance to keep signup and billing details on hand exists because those are the questions support asks during account recovery. If you skip this, read recovering a locked admin account now rather than later.
Consider the Advanced Protection Program for super admins. Google positions it as applying many of the admin hardening recommendations at once for high-risk accounts. It requires security keys or passkeys and restricts third-party app access to the account, which is exactly what you want on an account that should be doing nothing except administration.
Note the enforcement clock. Google is progressively enforcing 2SV on administrator accounts, with super admins notified roughly 90 days ahead and other admins roughly 60 days ahead, and escalating access restrictions after the date. Getting ahead of that is free.
Phase 2: close the doors nobody remembers opening
Still free on every edition, and this is where most tenancies have never been touched.
Restrict OAuth and third-party app access. Security, then Access and data control, then API controls. Review the accessed apps list first, then move Gmail and Drive to Restricted so that apps you have not explicitly trusted cannot use the high-risk scopes, allowlist the apps the business genuinely uses, and change the Unconfigured third-party apps setting so that unclassified apps get sign-in information only or nothing. Expect breakage: Google states that restricting a service stops previously installed untrusted apps and revokes their tokens.
Block less secure app access. Anything still authenticating with a username and password rather than OAuth is a standing bypass of your 2SV enforcement. Find it, migrate it, then block it.
Set Drive external sharing deliberately. Apps, then Google Workspace, then Drive and Docs, then Sharing settings. Default new items to restricted rather than link sharing, warn users when they share outside the organisation, and leave the external file indicator on. Allowlisted domains is stronger if your external collaborators are stable.
Turn on the Gmail safety settings. Spoofing and authentication protections against domain and employee-name impersonation, advanced phishing and malware protection for attachments, links and external images, and enhanced pre-delivery message scanning. Then publish SPF, DKIM and DMARC in DNS, and check that your DMARC policy is not still sitting at p=none doing nothing.
Audit Gmail routing rules. Attacker-created routing and forwarding rules survive password resets and do not show up in the user’s own settings. Check the list now and check it again after any suspected compromise.
Restrict Calendar and Chat externally. Free or busy only for external calendar visibility, and external chat limited to the people who need it.
The detail on each of these, including the trade-offs, is in the Admin console settings that carry real risk.
Phase 3: be able to see what happened
Set up admin email alerts. Suspicious sign-in attempts, admin role changes, settings changed by another admin, compromised devices. This is available without an Enterprise licence and it is the difference between finding out in an hour and finding out in a quarter.
Use the alert centre. It aggregates Google-generated security alerts in the Admin console under Security. Assign someone to actually look at it weekly, because an alert nobody reads is not a control.
Know your log retention before you need it. Google retains most log event types for six months, Email log search for 30 days, Chrome reports for 12 months, and Vault log events indefinitely. Administrators cannot extend those periods. If your obligations or your insurer require longer, export on a schedule.
Licence reality: the alert centre and the audit and investigation page are broadly available. The security investigation tool, which is what makes hunting across those logs fast, is listed by Google for Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus and Cloud Identity Premium. On Business tier you can still answer a question you know how to ask. You cannot easily go looking.
Phase 4: control which devices get in
Turn on endpoint management. Basic mobile management is broadly available and gets you an inventory, a screen lock requirement and remote wipe of work data. Advanced mobile management and desktop endpoint verification give you more, including the device signals that Context-Aware Access depends on.
Endpoint verification installs on managed desktops and reports device attributes back to Workspace. On its own it gives you an inventory of the computers accessing company data, which is more than most SMBs have.
Licence reality: Context-Aware Access is not on Business Plus. This is the one that catches people out. Context-Aware Access, which lets you allow or block access to Gmail, Drive and other services based on device state, IP address, geography or operating system, is supported on Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus and Cloud Identity Premium. Business Plus does support App access protection, which is a narrower control, but it is not the same thing. If a client questionnaire asks whether you enforce conditional access on managed devices only, and you are on a Business edition, the honest answer is no.
A warning that matters. Applying Context-Aware Access levels to the Admin console itself can create a total admin lockout if the conditions become unmeetable. Google’s documented remedy is a support case through the Customer Care Portal to strip the policies off the Admin console. Test on a pilot organisational unit first, and never apply an untested access level to the top-level unit.
Phase 5: control the data itself
Licence reality: Drive DLP needs Enterprise or Frontline. Data loss prevention rules for Drive, which scan content for things like credit card numbers, tax file numbers and custom patterns and then block or warn on sharing, are supported on Frontline Standard and Plus, Enterprise Standard and Plus, Education Fundamentals, Standard and Plus, and Enterprise Essentials Plus. If you are on Business Standard or Business Plus, you do not have Drive DLP, and the substitute is tighter sharing defaults plus the external shares report, which is coarser but real.
Data regions are US or Europe only. There is no Australian data region option in Workspace. The choices are United States, Europe or No preference, availability varies by edition, and the policy covers a defined list of core services. If your requirement is genuinely that Australian personal information stays onshore, say so plainly to whoever is asking rather than pointing at this setting.
Vault is retention and eDiscovery, and it needs a licence. Vault is included with Business Plus, Frontline Standard and Plus, Enterprise Standard and Plus, all Education editions, Enterprise Essentials and Enterprise Essentials Plus for domain-verified accounts, and G Suite Business, and is available as an add-on for some other editions. Since 1 November 2025 admins have needed a Vault licence themselves to use it. Vault also does nothing until you configure retention rules. It is not backup, and treating it as backup is the single most common mistake in this space. That argument is set out in backup is a separate problem.
Client-side encryption exists for Gmail, Drive, Meet and Calendar in the higher tiers, and is worth considering only if you genuinely hold regulated or high-value intellectual property, because it changes how search and collaboration behave.
The licence tier summary, stated plainly
Free on every edition, and worth more than anything you can buy: 2-Step Verification enforcement, admin role separation, multiple super admins, OAuth and API controls, Drive sharing defaults, Gmail safety settings, SPF, DKIM and DMARC, admin email alerts, and the audit and investigation page with six month retention.
Needs Business Plus or above: Vault for retention and eDiscovery.
Needs Enterprise Standard or above, or the equivalent Frontline tiers: Context-Aware Access, Drive DLP, the security investigation tool, and the more granular data region controls.
If your risk profile genuinely requires the second and third groups, the licence cost is the cheapest part of getting there. If it does not, spend the money on the first group being done properly and on backup, and do not buy Enterprise to tick a box you will never configure.
How this maps to the Essential Eight
The ACSC and ASD Essential Eight is the framework Australian clients, insurers and government buyers actually reference. Several of its mitigation strategies map cleanly onto Workspace controls, particularly multi-factor authentication and restricting administrative privileges. Others, notably application control, patch applications, patch operating systems and macro settings, are endpoint controls that Workspace does not address at all and that you have to solve on the devices themselves. The full mapping, including where Workspace genuinely cannot help, is in meeting the Essential Eight on Google Workspace, and the framework itself is covered in the Essential Eight explained.
Settle who can raise a support case before you need one
This belongs in the plan rather than at the end of it. Contacting Google Workspace support requires the Support administrator privilege and access to the Admin console, so the people most likely to need support during an incident are exactly the people who may not be able to reach it. Standard Support is included with your licence, has 24/7 access and carries a four hour service level objective for P1 cases, and Google’s published hours of operation table lists Australia as 24/7 in English, so there is no overnight gap to design around.
If someone outside the business is going to open cases for you, Google documents two arrangements. A reseller who manages your subscription can access your Admin console and submit support cases for you unless you remove that access, controlled under Account, then Reseller management. Separately, you can assign a Support Partner in the Google Cloud Support Portal, after which Google states that partner can file cases on your behalf and see cases you filed yourself. Both switches need a working admin sign-in, which is the whole point of doing it now.
Do it in this order
Phase 1 in a week. Phase 2 over a fortnight with a change window for the OAuth restrictions. Phase 3 the same week, because it costs nothing. Phases 4 and 5 only after you have confirmed your edition supports them and someone owns the ongoing tuning.
The mistake to avoid is buying Enterprise licences first and configuring nothing. A Business Standard tenancy with enforced security keys, restricted OAuth scopes and tight sharing defaults is meaningfully safer than an Enterprise Plus tenancy running defaults.
We are listed in Google Cloud’s partner directory, and Workspace hardening is ordinary work for us rather than a side project. We do this as a fixed-scope uplift: an audit against the list above, a written plan with the licence implications spelled out, and the changes made in staged windows so nothing breaks unannounced. Call 1300 028 324 or start at techassist.au/contact.
A mixed fleet is a business running more than one desktop platform and more than one productivity suite at the same time, most commonly Windows with Microsoft 365 alongside Macs and Google Workspace. Almost every Melbourne business over about thirty staff is one, whether anyone planned it or not. The design team bought Macs, the accounts team runs Windows because the practice software demands it, and the founder set up Google Workspace in 2016 and never looked back.
Most providers respond to this by proposing a migration. That is usually a sales position rather than a technical one. A mixed fleet is entirely runnable, but only if you are honest about which layer must be unified and which layers should be left alone.
Identity is the only thing you genuinely must unify
Everything else in a mixed environment can be tolerated. Two identity stores cannot.
The moment a person exists as a separate account in Microsoft 365, in Google Workspace and again in Apple’s ecosystem, you have three joiner processes, three leaver processes and three places to enforce multi-factor authentication. When someone resigns on a Friday afternoon, the account you forget is the one that gets used. This is the single most common failure we see in businesses that grew into a mixed fleet rather than designing one.
Unified identity does not mean one vendor. It means one authoritative directory that every other system trusts, and one onboarding and offboarding checklist that closes every door at once.
Make Entra ID the anchor and Google the relying party
If you are running both suites, the direction of federation is not a matter of taste. It is determined by what the two vendors actually support.
Microsoft publishes a first-party integration for using Microsoft Entra ID as the identity provider for Google Workspace, listed in the Entra gallery as the Google Cloud / G Suite Connector by Microsoft, with SCIM provisioning alongside it. Google documents the other half from its side, confirming that Workspace supports single sign-on from third-party identity providers over both SAML and OIDC, and ships a pre-built Microsoft Entra OIDC profile.
The reverse is not a supported architecture. Microsoft’s Google federation feature is scoped to business-to-business guest users, and Microsoft states plainly that it no longer performs validation testing of independent identity providers for compatibility with Entra ID. Anyone proposing Google Workspace as the primary identity provider for a Microsoft 365 tenancy is proposing something neither vendor documents.
One caveat worth writing into your runbook: Google restricts single sign-on for super administrators, and super admins signing in to the admin console must use their Google password rather than federated credentials. Keep at least one break-glass Google super admin outside single sign-on, store the credential properly, and test it. If you skip this, read what happens when you are locked out of your Google Workspace admin account before you find out the hard way.
Apple will federate with one identity provider, not two
Apple Business, the portal formerly known as Apple Business Manager, can federate with Google Workspace, with Microsoft Entra ID, or with a generic provider over OIDC or SCIM. Apple’s documentation is explicit that you can link to one of these at a time, not several.
That single sentence settles a lot of architectural arguments. If your Macs and iPhones are going to draw their Managed Apple Accounts from a directory, you must choose which directory, and in a Microsoft-anchored environment that is Entra ID.
There is a second trap here that catches people badly. Before Apple will federate a domain it must be verified and captured, and turning on Domain Capture gives every staff member with a personal Apple Account on your company domain a fixed thirty days to move their personal data off it. Apple states the date cannot be extended and that turning on Domain Capture cannot be undone. Staff with a decade of personal photos and App Store purchases attached to a work email address will not take this well if it lands unannounced. Communicate before you press the button, not after. The full sequence is covered in the guide to Apple Business, the portal formerly called Apple Business Manager.
Device management does not consolidate, and that is fine
Identity converges. Device management does not, and chasing a single pane of glass here usually costs more than it saves.
Windows provisioning through Autopilot, macOS enrolment through Apple’s Automated Device Enrolment, and Chrome or Android enrolment through the Google admin console are three genuinely different pipelines with three different trust models. One console can hold all three records, but the underlying work is still platform-specific. What matters is that every device is enrolled in something, that the something reports compliance back to your identity provider, and that nothing is unmanaged.
If you already pay for Microsoft 365 Business Premium or E3, you already own Intune, and Intune will manage Macs. Whether it manages them well enough is a real question with a real answer, covered in what Intune can and cannot do on a Mac and in the head-to-head on Jamf and Intune compared honestly. The practical mechanics of enrolling and managing a Mac fleet are a separate discipline again, and it is the one most generalist providers quietly skip. We have written separately about why most Melbourne MSPs cannot support Macs properly, because the gap is structural rather than a matter of effort.
On the Google side, the equivalent baseline work is in the Google Workspace admin console settings that matter, and the day-to-day device story sits alongside your broader approach to mobile device management.
Running both suites costs more than two subscriptions
The licence line is the visible cost. It is rarely the largest one.
Only one system can own your mail. Your domain has one set of MX records. Google documents split delivery and dual delivery as the two ways to run a second mail platform alongside Gmail, and in both cases the second system receives forwarded copies rather than authoritative delivery. You pay for two mail platforms and get one authoritative mailbox store, plus permanent complexity in SPF, DKIM and DMARC alignment on forwarded messages.
Storage entitlements do not travel. Google’s pooled storage is pooled within Google. Microsoft’s mailbox and OneDrive quotas are entitlements within Microsoft. Buying more of one never offsets the other, and staff will keep the same files in both, so you pay twice to store the same bytes. Neither vendor is backing that data up for you either, which is the subject of Google is not backing up your Workspace data.
Policy parity requires an edition uplift on both sides. Conditional Access on the Microsoft side requires Entra ID P1, which is included in Microsoft 365 Business Premium and E3. The nearest Google equivalent, Context-Aware Access, is restricted to the Enterprise, Education and Frontline editions or to Cloud Identity Premium, and Google states that users without a supported edition are simply not subject to Context-Aware Access policies at all. That Google-side uplift is the cost most businesses miss, because it is not a security add-on you buy for a handful of people. It is an edition change across every user.
We are not going to publish a dollar figure here, because the honest answer depends on your exact mix of editions. What we will say is that the second suite is almost never as cheap as the second subscription line suggests.
Your security baseline does not translate across platforms
This is where mixed fleets quietly fail audits and cyber insurance questionnaires.
The Essential Eight is the framework Australian businesses are measured against, and read closely it is shaped around Microsoft products. The current maturity model, last updated in November 2023, contains no mention of macOS, Apple, iOS, Chrome or Google anywhere in the document. One of the eight strategies is restrict Microsoft Office macros, and at Maturity Level Two and above it requires blocking macros from making Win32 API calls, which is Windows-only by definition. Application control at Maturity Level Two and above requires implementing Microsoft’s recommended application blocklist. User application hardening names Internet Explorer 11 and PowerShell logging.
ASD’s own hardening library reflects the same shape. It publishes hardening guides for Windows 10, Windows 11 and Linux workstations. There is no enterprise macOS hardening publication at all, and the only Apple configuration guide covers iOS 14. Its Blueprint for Secure Cloud is described by ASD as having a current focus on Microsoft 365, with no Google Workspace equivalent.
None of that means a Mac fleet cannot be secured to an equivalent standard. It means the equivalence has to be argued and documented rather than assumed, using the model’s own allowance for vendor hardening guidance and its exceptions process. Do that work before an assessor asks, not during. The detail sits in mapping the Essential Eight onto macOS and whether you can meet the Essential Eight on Google Workspace, and the underlying platform hardening in hardening Google Workspace.
One more thing worth knowing if you are planning a multi-year uplift: ASD ran a consultation on the evolution of the Essential Eight that closed on 12 July 2026, proposing a new Essentials series with the current guidance becoming a chapter called Essentials for enterprise IT. ASD says existing adopters can expect strong alignment with their current controls. Build your roadmap anyway, but build it knowing the framework is being rewritten.
When consolidating actually is the right call
Sometimes the migration everyone keeps proposing is correct. The honest triggers are these.
Consolidate when the duplication is at the identity layer and cannot be federated away. Consolidate when a compliance obligation or a client security review requires a single enforceable policy set and you cannot demonstrate equivalence on the second platform. Consolidate when the second suite is used by fewer people than it costs to administer properly. Consolidate when the business is being sold or is acquiring, because two suites double the integration work later.
Do not consolidate because one platform is unfamiliar to your provider. That is their problem to fix, not yours to pay for.
If you do decide to move, move deliberately. The comparison itself is covered where we have already compared the two suites feature by feature, and the actual migration mechanics, including what breaks in shared drives and calendar delegation, are in the mechanics of moving off Google Workspace. If you have inherited an environment and cannot even establish who owns what, start with inheriting a Workspace tenancy nobody documented.
What a properly run mixed fleet looks like
One authoritative directory. Every other platform federated to it, including Apple. Every device enrolled in a management service appropriate to its platform, reporting compliance back to that directory. One documented joiner and leaver process that touches every system. A written, defensible mapping of your security baseline onto each platform, including the parts where the framework does not fit and you have documented an equivalent control instead. And a hardware lifecycle that does not depend on who happened to buy the laptop, which is the subject of buying, redeploying and disposing of Apple hardware.
That is achievable at 30 staff and at 200. What it requires is a provider who is competent on all three platforms rather than one who tolerates two of them: someone who works with Apple’s business deployment programmes for enrolment and device management, runs Entra ID and Intune as daily work rather than as an escalation, and can open the Google Admin console and tell you what is wrong with it.
TechAssist has run Windows, Mac and Google environments side by side for Melbourne businesses for over 20 years, with 13 certified specialists across the team. We are a Microsoft partner and a Jamf partner, and on the Apple side we are a member of the Apple Consultants Network, Apple’s programme of independent technology partners specialising in Apple solutions for small and medium-sized businesses. That combination is the point rather than the decoration. A provider holding partnerships on both sides of an argument has no commercial reason to steer the answer, and the only honest test of neutrality is whether they ever recommend the option that earns them less. We do that regularly, and you will find us doing it in the posts linked above. If you want a straight assessment of whether your mixed fleet should be unified or simply run properly, call 1300 028 324 or get in touch at https://techassist.au/contact/. We will tell you which of the two it is, including when the answer is that you do not need to change anything.
For most Australian SMEs the honest answer to Microsoft 365 vs Google Workspace comes down to how your team actually works. Google suits lean, cloud-native businesses that live in a browser. Microsoft suits desktop-heavy, Windows-fleet, compliance-driven operations. Both are mature, secure platforms — the wrong fit just costs you in friction.
We’re a Microsoft-centric MSP, so I’ll declare that bias up front. But there are plenty of Melbourne businesses where I’d point a client to Google without hesitation. This is a fair comparison, not a sales pitch, and below there’s a table to cut through the marketing on both sides.
The quick comparison
| Area | Microsoft 365 | Google Workspace |
|---|
| Productivity apps | Full desktop Word, Excel, PowerPoint, Outlook (plus web versions) | Web-first Docs, Sheets, Slides — fast, but lighter than desktop Office |
| Email | Exchange Online + Outlook — rich rules, shared mailboxes, calendaring | Gmail — excellent search and spam filtering, simpler admin |
| Storage | OneDrive (per user) + SharePoint (team sites), 1 TB+ per user | Google Drive + Shared Drives, pooled storage by tier |
| Meetings & chat | Teams — meetings, chat, calls, channels, deep app integration | Google Meet + Google Chat/Spaces — clean, lightweight |
| Identity | Microsoft Entra ID — granular conditional access, hybrid AD | Google identity / Cloud Identity — strong, but less enterprise-deep |
| Admin & security | Defender, Purview, very granular controls — steep but powerful | Admin console — simpler, faster to learn, fewer knobs |
| Data residency (AU) | Australian data centres available for core data at rest | Regional storage options; some data still processed globally |
| Entry pricing (AUD, ex GST) | Business Basic ~$8.20/user/mo; Standard ~$17.20; Premium ~$30.20 | Business Starter ~$10/user/mo; Standard ~$20; Plus ~$32 |
| Best fit | Desktop-heavy, Windows fleets, regulated industries | Cloud-native startups, lean teams, browser-first work |
Pricing changes regularly and varies by term and reseller, so treat those figures as a guide rather than a quote. The real cost difference between the two is usually rounding error compared with the cost of choosing the platform that fights your workflow.
Apps: desktop power vs web speed
This is the clearest fork in the road. Microsoft gives you the full desktop Office suite — the real Excel, with the pivot tables, Power Query, macros and add-ins that finance teams and engineers depend on. If your business runs complex spreadsheets, branded Word templates, or PowerPoint decks that have to look identical every time, desktop Office still has no equal.
Google Workspace is web-first and proud of it. Docs, Sheets and Slides load instantly, autosave constantly, and make real-time co-editing feel effortless. For a marketing agency or a startup where two people are in the same document at once all day, that collaboration model is genuinely better. The trade-off is depth: heavy Excel users hit Sheets’ ceiling quickly, and complex formatting can drift.
Where Google clearly wins: if your team already does everything in a browser and nobody opens a desktop app from one week to the next, paying for desktop Office you’ll never install is waste.
Email: Outlook vs Gmail
Exchange Online with Outlook is the workhorse of Australian business email. Shared mailboxes, delegate access, distribution groups, calendar scheduling across a team — it’s all mature and granular. For a law firm in Hawthorn juggling shared client inboxes and rigid retention rules, Exchange and Microsoft Purview make that straightforward.
Gmail’s strength is search and filtering. Its spam and phishing detection is excellent, the interface is clean, and conversation threading is hard to beat. Smaller teams often find Gmail simply gets out of the way. Either way, email is your single biggest attack surface — we cover that in our guide to business email security and BEC, and the controls matter more than the brand.
Storage: OneDrive/SharePoint vs Drive
Microsoft splits storage into OneDrive (your personal files) and SharePoint (team document libraries). Done well, SharePoint is a proper intranet and document-management system with versioning, metadata and permissions. Done badly, it’s a sprawl of sites nobody can navigate. It rewards structure.
Google Drive with Shared Drives is more intuitive out of the box. Files live where you’d expect, sharing is a couple of clicks, and there’s less to misconfigure. For a business that just wants files in folders without a SharePoint information-architecture project, Drive is the gentler path.
Meetings: Teams vs Meet and Chat
Teams is the centre of gravity in the Microsoft world — meetings, calls, persistent chat, channels and an app platform all in one. For organisations already on Microsoft, that integration is a real advantage; for ones that aren’t, Teams can feel like a lot. Plenty of people find it heavy.
Google Meet and Google Chat are deliberately lighter. Meet is reliable, browser-based and quick to join with no client to install. If your meetings are mostly external and you value “click the link and you’re in”, Meet’s simplicity is a genuine plus. Microsoft’s edge shows up in internal collaboration depth, calling features and telephony integration.
Identity, admin and security
This is where Microsoft pulls ahead for businesses that need it. Microsoft Entra ID (the identity platform formerly known as Azure AD) offers some of the most granular access controls available — you can require multi-factor authentication only from unmanaged devices, block sign-ins from outside Australia, or enforce compliant-device checks. We walk through this in our piece on conditional access policies in Microsoft 365. Defender and Purview add threat protection and data-loss prevention that map neatly onto frameworks like the Essential Eight.
Google’s admin console is more approachable. Fewer settings means less to get wrong, which for a small team without dedicated IT is a real benefit. Google’s identity and security are strong — context-aware access and solid MFA — but Microsoft’s controls go deeper for complex, regulated or hybrid environments where on-premises Active Directory is still in the mix.
Compliance and data residency
For Australian businesses bound by the Privacy Act and the OAIC’s Notifiable Data Breaches scheme, data residency and auditability matter. Microsoft offers Australian data centres for core data at rest and gives detailed control over retention, legal hold and audit logging through Purview — useful for sectors under AHPRA, ASIC or similar oversight.
Google Workspace provides regional storage options and strong compliance certifications, though some processing still happens across its global infrastructure. For most SMEs that’s perfectly acceptable. For a healthcare practice or a firm with strict data-handling obligations, Microsoft’s granular controls usually make the compliance conversation easier — see our notes on healthcare IT and OAIC obligations.
Migration effort
Moving platforms is rarely trivial. Email migrates reasonably well in both directions, but the friction lives in the details: shared mailboxes, calendar permissions, distribution lists, and re-training people on a new interface. Document migration is messier — Google formats don’t always survive a clean trip into Office, and complex Excel or SharePoint structures don’t always land neatly in Sheets and Drive.
The practical rule is to migrate once, deliberately, and stay put. Bouncing between platforms because of a price tweak costs far more in lost time than it saves. Whichever way you go, plan the cutover properly and run the two systems in parallel briefly so nothing falls through the cracks.
A Melbourne example
A construction firm in Box Hill we work with came to us split down the middle — the site teams lived in Gmail on their phones, while the office ran Excel-heavy estimating and project schedules that Sheets simply couldn’t handle. They’d been arguing about it for a year. We standardised them on Microsoft 365 because the desktop Office dependency was non-negotiable for their estimators, then used Teams to pull the field and office staff onto one platform. Had their work been browser-only, we’d have recommended Google and meant it.
That’s the point. TechAssist is a Melbourne-based MSP founded in 2014 with 13 Australian-employed engineers, and most of our client base runs Microsoft because that’s where desktop-heavy, compliance-driven Australian businesses tend to land. But the right answer is the one that fits how your people actually work, not the one your MSP is most comfortable supporting.
Frequently asked questions
Is Microsoft 365 more secure than Google Workspace?
Neither is inherently more secure — both are mature, well-defended platforms. The difference is control depth. Microsoft Entra ID and Defender offer more granular configuration, which helps in regulated or complex environments. Google’s simpler model means fewer settings to misconfigure, which suits smaller teams. Security comes from how you configure either platform, not the logo.
Can I run both Microsoft 365 and Google Workspace?
You can, and some businesses do — for example, Microsoft for email and Office, Google for a specific cloud tool. But running both means two sets of licences, two admin consoles and two security surfaces to manage. For most SMEs the overhead outweighs the benefit. Pick one as your primary platform.
Which is cheaper for a small Australian business?
Entry tiers are close — Microsoft 365 Business Basic and Google Business Starter sit within a few dollars of each other per user per month. The bigger cost is fit: paying for desktop Office you never use, or wrestling with Sheets when you need real Excel, costs far more than the licence-price gap.
How hard is it to migrate from Google to Microsoft?
Email migrates fairly cleanly; documents and shared-drive structures are where the work lives. Expect format conversion, permission rebuilding and user re-training. With a planned cutover and a short parallel-run period it’s very manageable — the mistake is doing it ad hoc without a migration plan.
Getting the decision right
If your business is lean, cloud-native and browser-first, Google Workspace is a strong, often better choice — and we’ll tell you so. If you’re desktop-heavy, running a Windows fleet, or carrying real compliance obligations, Microsoft 365 usually wins, and it’s where our Microsoft 365 support is built to add the most value with security and identity configured properly rather than left on defaults.
Not sure which way to jump? Get in touch and we’ll look at how your team actually works before recommending anything. No pressure to switch, and an honest answer either way.
Most Microsoft 365 vs Google Workspace comparisons are written by Microsoft Partners and read like a sales pitch. Here is the straight version. Google wins for sub-15-person startups, design agencies, and web-native teams. Microsoft wins for anything compliance-driven, anything with Windows endpoints, and anything that touches Excel-heavy finance or operations tooling.
That is the headline. The rest of this article shows the working. We will cover the licensing reality in 2026, the Copilot versus Gemini story without the marketing gloss, the security and admin gap that has quietly widened, Australian data residency and Privacy Act considerations, and the genuine cost of switching either direction. Spoiler: it is almost always three to five months of dual-running, and the migration is rarely the expensive part.
TechAssist has been running these conversations with Melbourne SMEs since we were founded in 2014. Our managed IT services Melbourne team has migrated firms in both directions, so the bias here is genuinely thin. If anything, our preference leans Microsoft for clients in regulated sectors and Google for clients whose entire workflow lives in a browser, but the answer depends on what you actually do for a living.
The Honest Summary Up Front
If you want the verdict before the detail, here it is. Pick Google Workspace if you are under 15 staff, your team lives in Chrome, you do not run any line-of-business application that requires Windows, and you do not have meaningful compliance obligations beyond the Australian Privacy Act baseline. Pick Microsoft 365 if you have Windows endpoints, finance staff who live in Excel, ISO 27001, Essential Eight or sector-specific compliance ambitions, or any line-of-business application that integrates with Outlook calendars, SharePoint document libraries, or Power BI.
The grey zone is the 15-to-50-staff Melbourne SME with mixed Mac and Windows endpoints, a handful of legacy Office documents, and a desire to use Gmail because the founder likes it. That is the zone where the decision actually matters, and where most of our consulting time goes.
Licensing and Pricing in 2026
The headline SKUs have not changed dramatically, but the value gap inside each plan has. Microsoft has loaded more security and compliance into the mid-tier Business Premium plan, while Google has shifted more of its AI value into the Gemini Business and Enterprise add-ons. The result is that the apples-to-apples comparison is genuinely harder in 2026 than it was two years ago.
Here is the realistic comparison for a 30-person Melbourne SME at current AUD list pricing, rounded for clarity. Your actual prices via a partner will be slightly lower, but the ratios hold.
| Plan tier | Microsoft 365 | Google Workspace | What you actually get |
|---|
| Entry | Business Basic – approx $11/user/month | Business Starter – approx $12/user/month | Email, web apps, 30GB storage. Limited admin and security. |
| Mid | Business Standard – approx $22/user/month | Business Standard – approx $24/user/month | Desktop apps (M365 only), 1-2TB storage, basic meetings. |
| Security-grade | Business Premium – approx $36/user/month | Business Plus – approx $34/user/month | Intune/MDM, Defender, conditional access (M365). Vault, advanced endpoint (Google). |
| AI add-on | Copilot – approx $46/user/month extra | Gemini Business – approx $34/user/month extra | In-app AI across the suite. |
The numbers look close. They are not. The security-grade tier comparison is the one most decision-makers get wrong. Business Premium on Microsoft includes Intune device management, Defender for Business endpoint protection, conditional access, Azure AD Premium P1 (now Entra ID P1), and Purview data loss prevention. Google Business Plus includes Vault retention, advanced endpoint management, and Drive labels, but it does not include the equivalent of conditional access without stepping up to Enterprise Standard or Plus, which approximately doubles the per-user cost.
For a 30-person firm in Cremorne with Windows laptops, Business Premium replaces three or four separate tools that you would otherwise buy: a mobile device management product, an endpoint security product, a multi-factor enforcement layer, and a data loss prevention tool. That is the bundle value that has widened. It is not visible in the headline SKU price.
Where Google Wins, Honestly
Google Workspace genuinely wins in three scenarios, and we recommend it for all three.
The first is the sub-15-person startup. If you are five to twelve people, you live in a browser, you collaborate constantly in shared documents, and your security threat model is mostly phishing and credential theft, Google Workspace is faster to deploy, easier to administer without an IT team, and the collaboration UX is better. Docs and Sheets real-time editing remains a notch ahead of Word and Excel on the web, and the unified search across Drive, Gmail, and Calendar is excellent.
The second is the design or creative agency. If your team is on Macs, you use Figma, Adobe Creative Cloud, and Slack, and your finance person is the only one who touches a spreadsheet seriously, the Microsoft stack is overkill. Google Workspace plus a third-party MDM like Kandji or Jamf will serve you well. We have a 22-person creative agency client in Fitzroy that runs exactly this stack and has zero appetite to switch.
The third is genuinely web-first businesses. SaaS companies, marketing agencies, online publishers, e-commerce operators. Teams whose entire workflow is browser tabs and where Microsoft’s deep desktop integration provides no value. Google is leaner here, and Gemini’s integration with Search and YouTube is genuinely useful for these workflows in ways that Copilot’s Office integration is not.
Where Microsoft Wins, Also Honestly
Microsoft 365 wins in more scenarios than Google fans like to admit, and the gap has widened in 2024 and 2025.
The first and biggest is compliance. If you are pursuing ISO 27001, aligning with the Essential Eight, or operating in a sector with specific data handling requirements (legal, health, financial services, government supply chain), Microsoft Purview, Defender, and Entra ID together give you the audit trail, the controls, and the certifications evidence that auditors expect. Google can technically achieve much of this, but the auditor-readiness gap is real, and we have seen it cost clients during certification.
The second is Windows endpoint reality. Most Australian SMEs run Windows. Intune is now genuinely good. Autopilot deployment for a new laptop is a fifteen-minute experience for the user, and the device arrives at the desk pre-enrolled and pre-configured. Google’s endpoint management story for Windows is workable, but it is not in the same league. If your fleet is Windows, this matters every single week.
The third is finance and operations integration. Power Query, Power Pivot, Power BI, and the broader Power Platform tie into Excel and Outlook in ways that have no Google equivalent. If your finance manager is building cashflow models, your operations team is reconciling job costing across two systems, or your sales lead lives in pipeline spreadsheets, the Microsoft ecosystem is genuinely more productive.
The fourth is line-of-business application integration. Practice management systems in Melbourne law firms, patient management in healthcare practices, ERP and MRP systems in manufacturing, and most Australian accounting and payroll platforms integrate more deeply with Microsoft than Google. The Outlook calendar plug-in, the SharePoint document repository, the Teams meeting integration. These are table stakes for serious vertical software.
Copilot vs Gemini: The Honest Take
Both AI assistants are useful. Both are overhyped by their vendors. Both will be markedly better in twelve months than they are today. Here is what we are seeing in actual SME use in 2026.
Copilot in Microsoft 365 is genuinely useful when it can see across your tenant. Drafting emails from meeting notes, summarising long Teams threads, generating first-draft PowerPoint from a Word brief, and pulling figures from Excel into commentary. The killer use case for SMEs is Teams meeting summaries with action items. Once finance and operations staff have used this for a month, taking it away is painful. The weak spot is reliability on numerical reasoning in complex spreadsheets, and the occasional confident hallucination when pulling data from SharePoint sites it should not be searching.
Gemini in Workspace is strong on text generation in Docs, summarising Gmail threads, and the integration with Google Search for research is genuinely useful. The meeting note-taking in Meet is good. The weak spot is that Gemini in Sheets is not yet at Copilot in Excel parity for serious analytical work, and the Drive search story is less mature than SharePoint plus Copilot for document-heavy organisations.
The honest answer on cost-benefit: at $46 per user per month for Copilot, you need each user to save roughly 45 minutes a week to break even on a $100k salary. We are seeing that achieved in about 60 percent of seats in client deployments, with marketing, sales, and executive assistants getting the highest return, and field-based staff getting the lowest. Gemini at $34 per user per month has a slightly easier payback maths but a slightly narrower set of killer workflows. If you are deciding whether to buy AI for your suite at all, the answer in 2026 is yes for office-based staff and no for field, retail, or shop-floor staff.
The Security and Admin Gap
This is the section where we annoy Google fans. The security and administration gap between Microsoft 365 Business Premium and Google Workspace Business Plus has widened, and pretending otherwise is not helpful to clients.
Conditional access is the clearest example. On Microsoft, you can write a policy that says “users in the finance group can only access the payroll system from a managed device, on a trusted network, with a fresh MFA challenge, between business hours, from Australia.” That policy is enforced at the identity layer for any application using Entra ID for sign-in. On Google, the equivalent context-aware access requires Enterprise tier, and the policy expressiveness is meaningfully thinner.
Endpoint management is the second example. Intune with Defender for Business gives you device compliance evaluation, attack surface reduction rules, controlled folder access, web content filtering, and integration with conditional access in one stack. Google’s endpoint management is fine for Chromebooks, workable for Mac, and basic for Windows.
The third is data loss prevention. Purview DLP can scan content in SharePoint, OneDrive, Exchange, Teams, and increasingly third-party SaaS via Defender for Cloud Apps. Google DLP works well within Drive and Gmail but does not extend as broadly.
None of this means Google is insecure. It is not. It means that if your cybersecurity services Melbourne requirements include detailed conditional access policies, device-based access controls, or aligning to Essential Eight Maturity Level Two, Microsoft gets you there with less bolting-on. Read our zero trust security model explained guide for the framework view.
Australian Data Residency and the Privacy Act
Both Microsoft and Google host Australian customer data in Australian data centres for the core services. Microsoft uses the Australia East and Australia Southeast regions for Exchange Online, SharePoint Online, OneDrive, and Teams. Google uses Australian data centres for Workspace core data at rest. So far, so similar.
The differences appear at the edges. Microsoft publishes detailed data location commitments for each workload, and the Advanced Data Residency add-on lets you pin certain services more strictly. Google’s data residency commitments are good but less granular below the core service level. For most SMEs, this does not matter. For clients we work with in government supply chain or in regulated sectors where data sovereignty questionnaires come up, it matters significantly.
Both vendors comply with the Australian Privacy Act and the Notifiable Data Breaches scheme as data processors. Your obligations as a data controller do not go away by choosing either. If you handle personal information at scale, read our Australian Privacy Act for SMBs guide for the practical checklist.
The Real Cost of Switching
This is where most articles lie to you. They quote the migration tooling cost, which is small, and ignore the dual-running cost, the retraining cost, and the lost-productivity tail, which are large.
Here is the realistic switching cost for a 50-person Melbourne SME moving from Google Workspace to Microsoft 365 or vice versa. We will use a worked example: a 50-person property services firm in Hawthorn we migrated in early 2025 from Google to Microsoft because they had taken on a client who required vendor security questionnaires they could not answer cleanly.
| Cost line | Amount (AUD) | Notes |
|---|
| Migration project (planning, tooling, execution) | $18,000 | Mail, Drive, calendars, contacts. Fixed fee. |
| Dual-licensing during cutover (4 months) | $13,200 | Both suites paid simultaneously to ensure no data loss. |
| Endpoint reconfiguration | $6,500 | 50 devices re-enrolled, profiles redeployed. |
| Training and change management | $4,800 | Two group sessions plus drop-in clinics. |
| Productivity dip (first 6 weeks) | $28,000 estimated | 10% productivity reduction across the team while learning new tools. |
| Total realistic cost | $70,500 | Roughly $1,400 per user. |
That is the real cost. The migration project line is the only one most quotes show you. The dual-licensing, the productivity dip, and the change management are usually invisible until you are deep in the project. We had this client back to full productivity by week eight, and the ROI is positive within the second year because they retained the client whose questionnaire triggered the move. But if you switch suites without that kind of trigger, the payback is much harder to justify.
The honest test we run with clients: if you cannot articulate a specific business reason for the switch that is worth at least 1,500 dollars per user, do not switch. Stick with what you have and make it better.
Melbourne Examples: When We Recommend Each
A 12-person digital marketing agency in Collingwood. All Macs, Slack, Figma, web analytics tools, two finance staff using Xero. We recommended Google Workspace Business Plus plus Kandji for Mac MDM. Total stack cost roughly $850 per month. They are happy, audit-clean for their compliance needs, and the founder loves the Gmail UX.
A 35-person mechanical engineering consultancy in Box Hill. Windows fleet, AutoCAD and Revit, project management in a Microsoft-integrated platform, finance team building project costing models in Excel. We recommended Microsoft 365 Business Premium, Intune-managed Windows 11 devices delivered via Autopilot, Defender for Business, and Copilot for the senior engineers and finance team only. Total stack cost roughly $2,800 per month for the M365 layer. They cleared an ISO 27001 surveillance audit cleanly last quarter.
A 28-person allied health practice in Camberwell. Mixed Mac and Windows, patient management system that integrates deeply with Outlook calendars, NDIS and Medicare claiming. We recommended Microsoft 365 Business Premium for the integration reasons, Intune for device management, Defender for endpoint protection, and a structured Purview information protection deployment because patient information requires strict handling. Total cost slightly higher than Google would have been, but the integration requirements ruled Google out at the discovery stage.
For our broader take on choosing partners and platforms, see how to choose an MSP Melbourne and our top managed service providers Melbourne overview.
How TechAssist Approaches the Decision
We are platform-agnostic for genuine reasons. We were founded in 2014, we have 13 Australian engineers between our Tecoma office and our 575 Bourke St CBD office, and we operate a 24/7 NOC out of Tecoma. We migrate clients in both directions every quarter. Our per-user fixed monthly pricing does not change based on which suite you choose, so we have no commercial incentive to push either.
For new clients in our MSP Melbourne programme, we run a one-day platform assessment. We look at your endpoint fleet, your line-of-business applications, your compliance trajectory, your team’s working style, and your current pain points. We recommend Microsoft or Google based on the answer, not based on the margin. We respond to P1 incidents in under 15 minutes, and we run same-business-day on-site visits across Melbourne metro when something needs hands on hardware. The platform under the hood matters less than the discipline around it.
Our cloud services Melbourne team can scope a migration in either direction with a realistic dual-running budget and a change management plan, not just a tooling quote. Our co-managed IT support model also works if you have an internal IT lead who wants to keep the strategic decisions in-house and outsource the operational lift.
Frequently Asked Questions
Can a small business get away with just the entry-level plan?
For a five-to-ten-person business with low compliance requirements, the entry-level plan plus a third-party MFA enforcement layer and a basic backup tool will work. For anything more, the security and management gap between the entry tier and the security-grade tier is large enough that the entry tier is a false economy. We see clients spend more remediating after a security incident than they saved over three years of running on the entry tier.
What about Outlook on Mac with Google Workspace?
It works, but it is not great. If your team is on Mac and your founder wants Gmail, lean into the Google ecosystem fully rather than trying to bridge Outlook to Gmail. The hybrid setup creates calendar invitation issues, contacts sync issues, and frustrating support tickets. Pick one ecosystem.
Is Copilot worth it for a 20-person business?
For ten of those twenty people, yes. For the other ten, probably not. Buy Copilot for the seats where it will see daily use: executive assistants, sales, marketing, finance leads, and anyone whose job involves drafting documents, summarising meetings, or building reports. Do not buy it for field staff, warehouse staff, or part-time admin staff. The per-seat economics only work when actually used.
How long does a Microsoft to Google or Google to Microsoft migration actually take?
The migration tooling runs over a weekend. The dual-running window is three to five months. The team is at full productivity on the new platform by week eight to twelve. The cleanup of the old tenant takes another month or two. Anyone who tells you it is a one-month project is selling you a migration, not a successful outcome.
What about hybrid: some users on Microsoft and some on Google?
Avoid it unless you have a genuinely good reason, like a recent acquisition you are integrating. Hybrid creates shared calendar friction, email signature inconsistency, document collaboration confusion, and double the admin workload. We have a few clients running hybrid for legitimate transitional reasons. None of them are happy about it.
How do I get an honest scoping conversation?
Talk to us. We will tell you which platform fits your business and which one does not, and we will do that regardless of what you end up choosing. Reach our team via the contact page or call the office. The conversation is free and the recommendation will be straight.