Google is taking the next step towards secure cloud security by making multi-factor authentication (MFA) mandatory for all Google Cloud users by the end of 2025.
With an increase in global cyberattacks in the last two years, the second quarter of 2024 saw a 30% increase compared to Q2 2023.
This has led to an ongoing effort from many companies, including Google, to strengthen data protection against cyberattacks.
Why is Google making MFA mandatory?
Passwords simply are not enough for your accounts anymore. Cyber threats are becoming tougher to handle, especially with the rapid increase and advancement in AI technology.
One password that may be compromised can have dire consequences, possibly leading to a major data breach.
This is where MFA comes in.
MFA is a security feature that asks you to prove who you are in more than one way before you can access your Google Cloud account. For instance, you might enter your password and then get a text confirmation of a code sent to your phone.
We have a full blog on the explanation of multi-factor authentication and why it’s important here
Although it may seem a little more time-consuming, this simple, extra step makes it much harder for anyone else to get into your account.
What this means for Google Cloud users
If you’re using Google Cloud and you don’t already have MFA set up, you’ll need to apply it to all accounts. For teams and organisations, here’s what you should do:
Activate MFA for all users
Essentially, just make sure that every user in your organisation has MFA enabled on their Google Cloud account.
Educate them on why Google Cloud security and MFA are important
People must understand why MFA is essential to stop cyber attacks, data breaches, etc.
Review your security policies
Update your cloud security policies to reflect the MFA requirement.
The benefits of MFA for Google Cloud security
We touched on the benefits earlier, but it’s important that you and your team understand the benefits that MFA provides to truly gather why this mandatory update is needed.
Stronger data protection
Even if a password is compromised (i.e. it has been exposed or stolen due to a data breach, phishing attack, etc.) MFA adds an extra step to keep your data safe.
Of course, you should update your password, but you have that extra defence with MFA if you did not notice that it had been compromised at that point.
Improved compliance
Many organisations and businesses require MFA for data security compliance. If your passwords are compromised, data on clients or your business can be exposed.
Adding MFA helps you stay secure and compliant.
Reduce the risks of cybersecurity breaches
This comes under both categories, but is important to point out. MFA simply makes it much harder for cybercriminals to attack your accounts.
Even if a cybercriminal can get past one point of authentication (e.g. your password), steps like confirming your identity with an email, phone number, passkey, etc., make it much harder.
Why MFA is critical for cloud security solutions
This mandatory MFA update is not just about Google Cloud—it’s a sign of a broader industry shift towards stronger security practices.
As more businesses rely on cloud services for storing and managing data, robust security measures like MFA become essential.
Final thoughts
Google’s decision to enforce mandatory multi-factor authentication for Google Cloud users by the end of 2025 is a positive step for cloud security and data protection.
If you haven’t set up MFA for your accounts yet, now is the perfect time.
Stay secure, stay compliant, and keep your data protected.If you want more information on a similar topic, you can take a look at our breakdown of Google Cloud and the fundamentals of the cloud-based service here.




