Automate Basics
Automation · Google

Google adds simpler setup for Workspace client-side encryption

By Automate Basics, written with AI from Google's original

· 2 min read

Hands hold a tablet beside closed folders on a conference table
Image: AI-generated illustration.

Google has added a simpler Admin console setup for Workspace client-side encryption. Eligible administrators can use Google Identity and Cloud HSM Keys to reduce the work involved in protecting sensitive Workspace content.

What changed in Workspace encryption setup?

Google says administrators can now set up Workspace client-side encryption through a simpler path in the Admin console. The option combines Google Identity with Cloud HSM Keys to automate work that previously involved configuring an identity provider and a separate key service. Google says admins can complete the initial setup in minutes.

Client-side encryption uses customer-controlled keys to encrypt data before it reaches Google servers. Google says organizations use it for sensitive email, files, meetings and calendar events, including work subject to compliance requirements. The change concerns how administrators set up that protection, not a new action for employees. Organizations that need a third-party key service can still use the existing, more customizable setup process.

Who can use the simpler setup, and what does it cost?

Google says the simpler setup is available now for both Rapid Release and Scheduled Release domains. An organization needs Google Workspace Enterprise Plus together with either the Assured Controls add-on or the Assured Controls Plus add-on. Administrators handle the setup; Google says end users do not need to take action.

The announcement does not state a price for the simplified setup or either add-on. It also does not say that other Workspace plans can use this option. If your organization is considering it, check which Workspace plan and add-on it has before planning a rollout. The availability Google describes applies to eligible organizations, not to every person who uses Workspace.

How do I try it at work?

An eligible Workspace administrator could start with a type of sensitive content the organization already manages, such as a file or meeting, and use Google's simplified setup guidance to plan its protection. Google says the new path uses Cloud HSM Keys and Google Identity, while the standard process remains available for organizations that require a third-party key service.

Before a wider rollout, check that the chosen content is covered by the intended encryption arrangement and that the people who need it can still do their work. Keep the initial check focused on the organization's actual requirements rather than assuming every Workspace item is protected. Google provides setup guidance for administrators and says employees do not need to change anything to get started.

Frequently asked questions

Does the new setup change what employees need to do?

Google says no end-user action is needed for the simpler Workspace client-side encryption setup. Administrators configure the protection. The announcement describes a change to initial setup, not a new employee workflow for email, files, meetings or calendar events.

Can administrators still use a third-party encryption key service?

Yes. Google says the existing client-side encryption setup process remains available for administrators who need a more customized configuration with a third-party key service. The new, simpler path instead combines Cloud HSM Keys with Google Identity to reduce initial setup work.

Written with AI from Google's original and published after automatic checks: every figure here appears in the original, and no sentence is copied from it. The picture is AI-generated. The original is the authority.

Source: Simple setup option for Workspace Client-side encryption, Google, 1 Oct 2026.