Purpose
Enforce multi-factor authentication for staff accounts and reduce district risk from compromised credentials.
Current state
Production enforcement remains active beyond the original rollout. The live district workflow combines group-based enforcement, sheet-driven outreach, hardware-token handling, and the Google Group Expansion + 2SV Status Reporter as the primary reporting component for ongoing review and follow-up.
Next step
Document exception handling, hardware-token inventory, report retention, and the active trigger model for ongoing reporting runs.
Interfaces
Inputs- Google account roster
- group membership
- MFA enrollment state
- pending and keyfob notice sheets
Outputs- Enforced MFA state
- notice emails
- support follow-up lists
Reality to Action trace
Reality IngestionContributes in this stage.
Canonical StorageNot in scope.
Automation EnginesNot in scope.
Human InterfacesContributes in this stage.
Operational AdoptionContributes in this stage.
Core workflow
TBD. Document the 5-10 steps that define the core workflow.
Data integrity and contracts
Source of truth rules
- Google Workspace is canonical for MFA state.
- Group assignments and rollout trackers govern enforcement cohorts.
Safe handling
- Restrict MFA tracking sheets to admins.
- Protect security-state reports, tokens, and exception lists.
Operational notes
Reliability posture
Campaign-based workflow with manual exception handling; failures mostly create enforcement drift or support backlog rather than silent data loss.
Observability
- Google Admin MFA visibility
- mailer logs and sheet-based notice tracking
- support follow-up lists
Security and privacy
Confidential staff identity and security-state data; keep trackers and notices internal.
Dependencies
Upstream- Google Workspace Admin access
- group governance
- sheet-driven notice data
Downstream- account security posture
- exception handling and support
Ownership
OwnersTechnology Services, Josh Barton
UsersTechnology Services, district administration, Josh Barton (owner)
Google Workspace MFA Enforcement and Reporting
Operational Notes
- Production path combines admin policy enforcement with notice workflows, assisted enrollment support, and ongoing 2SV reporting.
- The registry points to
mfa_notices.sh, HTML templates, and the Google Group Expansion + 2SV Status Reporter as the current district automation support layer. - Failure mostly creates incomplete enforcement or delayed support rather than corruption of source data.
Registry Alignment
- Mapped registry scope:
INT-006, with former INT-007 now treated as component context within the same integration. - Registry clarified: this is an active identity-security workflow with real sheet-driven outreach and reporting, not just a rollout-era policy setting.
- Validation gaps: document the exception matrix, hardware-token inventory, rollback path for edge cases, and reporting-run ownership.