Skip to main content

Setting Up a Google Workspace Account for Your CUI Enclave

S
Written by Secureframe Engineering

Secureframe's CMMC setup for Google Workspace works best with a dedicated Workspace account on a subdomain of your existing domain (for example secure.yourcompany.com). This keeps your CUI environment separate from day-to-day email and means only the users who actually handle CUI need paid Enterprise licenses.

Before you begin

Have these ready so you can complete the setup in one sitting:

  • The subdomain you want to use (e.g. secure.yourcompany.com). You don't need to register anything new — you'll verify it with DNS records on your existing domain.

  • Access to your domain's DNS settings (Cloudflare, GoDaddy, etc.), or someone who has it available while you go through setup.

  • A payment card and billing address for the Google Workspace subscription.

  • A phone number that can receive a text, for one-time identity verification. The number is not saved to the account. If your number is rejected, try a different one -- numbers recently used to verify other Google accounts may be refused.

Create the account

  1. Enter the name and contact info of the person who will be the first super admin.

  2. If Google says an existing account was found, click Create a new Google Workspace account.

  3. Choose Set up using your existing domain.

  4. When asked for the domain name, enter your chosen subdomain (e.g. secure.yourcompany.com).

  5. Create the username for the first super admin.

  6. Complete phone verification if prompted.

  7. Start a trial on the Standard tier. You'll change the tier later.

  8. Provide contact info and payment method, then check out.

  9. When asked to add users, click Skip for now. You'll add them later.

Verify the domain and set up Gmail

  1. Follow Google's instructions to verify you own the domain. This is where you need DNS access.

    1. In Cloudflare: go to DNS > Records, click Add record, and copy in the record Google provides.

    2. Back on the Google screen, tick the confirmation checkbox and click Confirm.

  2. Repeat the same process for the Gmail (MX) records when prompted.

  3. Skip the remaining optional steps and go to https://admin.google.com

Set up licensing

  1. Under Billing > Subscriptions > Buy or Upgrade, find Cloud Identity Free and click Explore. Follow the steps and checkout.

  2. Review the license settings and switch Automatic licensing to OFF. This lets you assign paid licenses only to the users who need them.

    1. The setting may not show as OFF right away — refresh the page to see the updated value.

  3. Under Billing > Subscriptions > Buy or Upgrade, click Upgrade under Enterprise Standard (or Enterprise Plus). Follow the steps and click Place Order.

Add users

  1. Under Directory > Users, click Add new user. Create at least three users:

    1. A CUI user (a user who will work with CUI)

    2. A Workspace admin

    3. A second super admin, in addition to the one created during signup. You don't need to assign the super admin role in Google — Secureframe assigns it during setup.

  2. Assign an Enterprise license to the CUI user and the Workspace admin:

    1. Under Directory > Users, select both users using the checkboxes.

    2. Click Assign licenses at the top and choose your Enterprise subscription. (This option only appears from the multi-select toolbar, so it's easy to miss.)

Next steps

That's everything on the Google side. Sign in to Secureframe and continue the guided setup, which connects to this account using the super admin and completes the remaining configuration for you.

Did this answer your question?