Web_Logo
Remote Support
Google Workspace: DBSC Enabled by Default, Calendar DLP Live
Home » Google Workspace Updates  »  Google Workspace: DBSC Enabled by Default, Calendar DLP Live

Google Workspace: DBSC Enabled by Default, Calendar DLP Live

Google has rolled out two security improvements to Google Workspace this week — one that is automatically active for all users, and one that admins can now choose to enable.

  • Device Bound Session Credentials (now on by default): When you log in to a Google account in Chrome, your login session is now tied to the specific device you used. If someone steals your login cookie (a method attackers use to bypass passwords and two-factor authentication), they cannot use it from another device. This is enabled automatically — no action required from staff or admins.
  • Who benefits: All Google Workspace users on Chrome for Windows. This is particularly valuable for businesses where staff access Google apps from shared or less-controlled devices.
  • Data Loss Prevention for Calendar (now available, off by default): Admins can now set rules that flag or block calendar invitations containing sensitive information — such as financial details or personal data — before they are sent to external recipients.
  • Who should consider enabling Calendar DLP: Businesses in professional services, finance, legal, or healthcare where confidential information may inadvertently appear in meeting invitations sent outside the organisation.
  • What to do: No action is needed for DBSC — it is already protecting your users. For Calendar DLP, Workspace admins can review and enable it in the Admin console under Data Protection settings.

If you would like help reviewing your Google Workspace security settings, contact your IT provider. Sources: Google Workspace Updates Blog