Google has rolled out two significant security improvements to Google Workspace this month, alongside expanded controls for businesses managing iOS devices.
What has changed:
- Device Bound Session Credentials (DBSC) — now active by default: This feature, which rolled out on 3 June 2026, ties a user's Google login session to the specific device they authenticated from. In practical terms, if malware on a device steals a login cookie, the stolen cookie cannot be used to access the account from another device. This closes a well-known attack technique used to bypass multi-factor authentication after the initial login. No action is required — it is enabled automatically for all Workspace users on Chrome for Windows.
- Data Loss Prevention (DLP) for Google Calendar — now generally available: Workspace admins can now create rules that scan calendar event titles, descriptions, and locations for sensitive content such as credit card numbers or identification numbers. Admins can choose to warn users, audit events silently, or block an event from being saved if a policy is triggered. This is particularly relevant for businesses that handle sensitive client data.
- Expanded iOS device management settings: Google Endpoint Management now includes a broader set of native Apple MDM controls, giving administrators more granular management of iPhones and iPads used for work — covering app access, data sharing, backup settings, and iCloud sync.
What to do:
- DBSC is enabled automatically — no action required for most businesses.
- Workspace admins should review the new Calendar DLP options in the Admin console if your business handles sensitive client information.
- Businesses managing staff iOS devices through Google Endpoint Management should review the new MDM settings for anything relevant to your security policy.
Sources: Google Workspace Updates Blog.