How to Fix
Enforce multifactor authentication on all your organization's Google accounts.
Log in to the Google admin console.
Click Security | Authentication | 2-step-verification to enforce 2-step verification.
Select Turn on enforcement from date.
Enter a date by which all of your users are required to use multifactor authentication to access their Google accounts. We recommend selecting a date two to four weeks in the future, as employees without multi-factor authentication will be unable to sign in to their accounts once enforcement is in effect. (More information from Google Workspace)
This setting enforces 2-step verification across your organization. However, individual users must log in and complete setup before MFA is active for their account.
Confirm that 2-Step verification is enabled for the user
Even if 2-step verification is enforced at the organizational level, it is not considered active for a specific user until they log in and complete setup.
To confirm whether MFA is enabled for a user:
Go to the Users page in the Google Admin console.
Locate the user.
Check the 2-step verification column.
If 2-step verification is enabled for the user, it will show as On (or similar status).
Global enforcement alone does not mean the user has completed setup.
Common reasons for failure
Enforcing MFA works by requiring individual users to complete the setup the next time they log in. If a user has not logged out or their SSO Session has remained active, the setup may not have been completed.
If a user is failing this test, it is recommend they try logging out of their current Google instance. They should be prompted to use MFA when logging back in.
Further information on managing Google Workspace security settings can be found on the Google Workspace Admin Help pageVanta is only able to identify MFA settings enforced directly in Google Workspace, and is unable to recognize if accounts are accessing Google through a different SAML provider (AKA Okta).

