Atlas project production

Google Workspace MFA Enforcement and Reporting

Enforces Google Workspace multi-factor authentication through staged group-based enforcement while sustaining ongoing 2SV reporting, notice delivery, and follow-up operations.

Internal-only entry. Do not publish externally without review.
Type
System
Lifecycle
Active
Last touched
2026-03-24
Visibility
Internal

Purpose

Enforce multi-factor authentication for staff accounts and reduce district risk from compromised credentials.

Current state

Production enforcement remains active beyond the original rollout. The live district workflow combines group-based enforcement, sheet-driven outreach, hardware-token handling, and the Google Group Expansion + 2SV Status Reporter as the primary reporting component for ongoing review and follow-up.

Next step

Document exception handling, hardware-token inventory, report retention, and the active trigger model for ongoing reporting runs.

Interfaces

Inputs
  • Google account roster
  • group membership
  • MFA enrollment state
  • pending and keyfob notice sheets
Outputs
  • Enforced MFA state
  • notice emails
  • support follow-up lists

Reality to Action trace

Reality Ingestion

Contributes in this stage.

Canonical Storage

Not in scope.

Automation Engines

Not in scope.

Human Interfaces

Contributes in this stage.

Operational Adoption

Contributes in this stage.

Core workflow

TBD. Document the 5-10 steps that define the core workflow.

Data integrity and contracts

Source of truth rules

  • Google Workspace is canonical for MFA state.
  • Group assignments and rollout trackers govern enforcement cohorts.

Safe handling

  • Restrict MFA tracking sheets to admins.
  • Protect security-state reports, tokens, and exception lists.

Operational notes

Reliability posture

Campaign-based workflow with manual exception handling; failures mostly create enforcement drift or support backlog rather than silent data loss.

Observability

  • Google Admin MFA visibility
  • mailer logs and sheet-based notice tracking
  • support follow-up lists

Security and privacy

Confidential staff identity and security-state data; keep trackers and notices internal.

Dependencies

Upstream
  • Google Workspace Admin access
  • group governance
  • sheet-driven notice data
Downstream
  • account security posture
  • exception handling and support

Ownership

Owners

Technology Services, Josh Barton

Users

Technology Services, district administration, Josh Barton (owner)

Google Workspace MFA Enforcement and Reporting

Operational Notes

  • Production path combines admin policy enforcement with notice workflows, assisted enrollment support, and ongoing 2SV reporting.
  • The registry points to mfa_notices.sh, HTML templates, and the Google Group Expansion + 2SV Status Reporter as the current district automation support layer.
  • Failure mostly creates incomplete enforcement or delayed support rather than corruption of source data.

Registry Alignment

  • Mapped registry scope: INT-006, with former INT-007 now treated as component context within the same integration.
  • Registry clarified: this is an active identity-security workflow with real sheet-driven outreach and reporting, not just a rollout-era policy setting.
  • Validation gaps: document the exception matrix, hardware-token inventory, rollback path for edge cases, and reporting-run ownership.