Skip to main content
Google Workspace posture uses a six-check MSPortal calculation with 100 available points. It is separate from Microsoft Secure Score. Use it to review recorded coverage and discuss follow-up with your MSP; it is not a comprehensive security assessment. Audience: Company users with Microsoft 365 read access and MSP staff. This permission also governs Google posture readers.

Open the checks

  1. Open Cloud > Posture and confirm the company scope.
  2. In a multi-company overview, click the Google Workspace row. With one company selected, available Google checks appear directly on the page.
  3. Confirm Google Workspace, MSPortal, the Snapshot date, the percentage and the points total.
  4. Read each row’s Check, Status, Coverage and Points. On small screens, scroll the table horizontally; the description also includes the counts when the separate Coverage column is hidden.
  5. Record the check and date when requesting help. The rows do not open lists of affected users or edit provider settings.

Read the provider, MSPortal score source and recorded snapshot date before interpreting the checks. This is an example captured from the MSP view.

Understand the six checks

Active users here exclude suspended and archived accounts. Administrator checks include active administrators and delegated administrators. Enrollment and enforcement are different signals. A known license state measures visibility; it does not establish license compliance, available seats or that every person needs a paid license. Suspended or archived exclusions do not prove that offboarding is complete.

Read statuses and points

For a check that can be evaluated, points = passing items / total items × maximum points, rounded to two decimal places. For example, 18 of 20 enrolled active users earns 22.5 of 25 points. The overall percentage is displayed as a whole number, so use the points when small differences matter. Unknown items remain in the coverage denominator when some evidence is available. A partially missing dataset can therefore lower a score and show Needs attention instead of making the whole check Unknown. Confirm whether the issue is failed coverage or missing reporting before acting. Administrator protection and verified domains require complete coverage to Pass and have no Warning band. They still earn proportional points when evaluable: a Needs attention status does not necessarily mean zero points. Unknown checks remain in the 100-point maximum.

Check freshness

The Snapshot date is the date the portal stored the sync’s snapshot. Google usage reporting is requested for an earlier date, normally three days before the run, and an older available report may be used. Directory, domain and license inputs are collected separately. The visible date is not a promise that all inputs describe that same day. If usage reports are unavailable, the sync can defer creating a new posture snapshot while other datasets update. The previous snapshot can remain visible. A new sync is not a guarantee that an Unknown check will resolve. MSP staff should check the Google connection’s Daily security posture sync setting, reporting availability and company mapping when a snapshot is missing or stale. See the separate Google Workspace setup guide. There is no Run now control on the checks reader.

Request and track follow-up

Company users should open a ticket from the Home AI Assistant. Include the company, snapshot date, check title, status and coverage. The MSP can verify the underlying accounts or domains and decide on the appropriate changes. MSP staff can use Cloud Users and Cloud Domains as related inventories. Their current rows can differ from an older posture snapshot, and the checks panel does not expose its per-user evidence list. Confirm evidence in the connected provider before changing an account. Changes are reflected only after collection and a new posture calculation succeed.

FAQs

No. Google rows use the MSPortal calculation, identified by MSPortal in the detail. Microsoft rows use a different source and model.
Yes. The administrator check counts an active administrator as protected only when both flags are reported true. Delegated administrators are included.
They are excluded from these user-based checks. This scoring exclusion does not verify complete offboarding.
No. An explicit zero-assignment state counts as visible. The check measures known assignment state, not purchasing or compliance.
A zero-size scope is Unknown rather than an automatic Pass. It contributes zero points while the maximum remains 100.
No. If some evidence is known, missing items remain in the total and lower coverage. The status can be Warning or Needs attention.
No. Evaluable checks earn proportional points. Administrator and domain checks have no warning band but can still earn partial points.
When a usable last-sign-in date is unavailable, the calculation uses account creation time against the 90-day threshold. That is not proof of a successful sign-in.
Usage reports can be unavailable and postpone the new posture calculation while other data syncs. Ask your MSP to check the reports and sync result.
No. It shows check counts, status and points. Use the Home AI Assistant to request MSP help, or have MSP staff investigate the related inventory and provider evidence.