The MFA and email security shortlist for Microsoft 365 and Google Workspace: What actually works in a mixed environment

A glowing envelope icon with a padlock symbolises Email Security, surrounded by digital circuit lines and binary code on a dark background, representing secure digital communication.

Running Microsoft 365 and Google Workspace side by side is common at UK agencies. What is less common is a security setup that actually covers both. Most businesses default to Microsoft’s native tools for M365 and Google’s built-in controls for Workspace, and end up with two separate, inconsistently configured security layers and a gap in the middle where neither has full visibility. This article names the tools that close that gap: the identity and MFA platforms that govern both environments from a single admin console, and the email security tools that protect both inboxes without requiring two separate configurations.

Why mixed environments create a security layer problem

The core issue is not that native tools are weak. It is that they are designed to protect their own ecosystem only. Microsoft Entra ID conditional access policies govern M365 sessions. They do not extend to Google Workspace. Google’s context-aware access controls Workspace activity. It does not extend to M365 app behaviour. For an IT team supporting both platforms, the result is two policy sets, two audit logs, and two places where a compromised account might go undetected.

This is the structural argument for an independent identity layer: a single platform that federates authentication across both environments, applies consistent MFA policies regardless of which app a user is signing into, and provides a unified view of who is accessing what. Without it, a user with compromised M365 credentials may still have unchallenged access to Google Workspace, and vice versa.

What Microsoft and Google’s built-in security actually covers

Both platforms include meaningful built-in security. Understanding where each stops is what determines whether additional tooling is necessary.

Microsoft Entra ID (included with M365 Business Premium) provides conditional access, MFA enforcement, Defender for Office 365 email protection, and device compliance policies via Intune. For a business running M365 only, Business Premium covers most of the Cyber Essentials technical controls without additional tools. The limitation in a mixed environment is scope: Entra ID is not designed to govern non-Microsoft application sign-ins, and its conditional access policies do not extend cleanly to Google Workspace sessions.

For the changes to Defender for Office 365 rolling out in 2026, see Securing Microsoft 365 and Google Workspace for Hybrid Teams for full details.

Google Workspace’s built-in security includes Gmail phishing and malware scanning, Safe Browsing integration, context-aware access (available from Business Standard upward), and Drive sharing controls. For a Google-only environment, these are a solid baseline. In a mixed environment, they create the same scoping problem in reverse: they protect Workspace activity but have no visibility into what a user is doing inside M365.

Where both fall short in a mixed environment: Under Cyber Essentials v3.3, in force from 28 April 2026, MFA on every in-scope cloud service is now a mandatory requirement, and failure to meet it is an automatic fail on the User Access Control section. Businesses relying on each platform’s native MFA independently, without a consistent cross-platform policy, may pass on paper but are exposed in practice. Separate admin consoles mean separate remediation work, separate audit evidence, and a higher risk of gaps.

Independent identity and MFA platforms that works across both

The tools below each address the core problem: governing authentication across both M365 and Google Workspace from a single admin plane. They vary in complexity, cost, and the level of IT resources required to manage them.

JumpCloud: the strongest fit for Mac-first businesses

JumpCloud is a cloud directory platform that federates identity across Microsoft 365, Google Workspace, and Mac devices from a single console. We recommend JumpCloud for Mac-first businesses running a mixed M365/Google environment because it handles the parts that neither Microsoft nor Google’s native tools address: unified identity across both platforms, DMS (formerly MDM) capabilities for Mac endpoints, and MFA enforcement regardless of which application a user is signing into.

In practice, JumpCloud means one place to onboard a new user, one place to offboard them, and one place to see whether MFA is active across every application they access. For businesses without a dedicated in-house security team, that reduction in admin surface is significant. JumpCloud also has established Google Workspace integration, recognised with the 2026 Google Cloud Partner of the Year award, and its HRIS integrations mean joiners and leavers can be provisioned and deprovisioned without manual admin work across two separate consoles.

JumpCloud’s Cyber Essentials alignment is strong: its access control, MFA enforcement, and device trust policies map directly to the User Access Control and Secure Configuration requirements under v3.3.

Suitable for: 20 to 250 users, Mac-first or hybrid device fleets, businesses without a dedicated in-house security function.

Okta: stronger at scale, higher admin overhead

Okta is the market leader in standalone identity and access management, and it handles multi-platform federation well. For a 70 to 150-person agency with a part-time IT manager or an MSP managing the environment, Okta is a credible option. It is more complex to configure than JumpCloud and typically requires more ongoing admin attention, but its application catalogue, policy engine, and reporting capabilities are more granular at higher seat counts.

The honest position: for a Mac-first business under 100 users without a dedicated IT resource, Okta adds configuration overhead that is not necessary. At 100 seats and above, or where the business needs fine-grained conditional access policies across a large application estate, Okta earns the additional complexity.

Suitable for: 100 or more users, businesses with a part-time IT manager or MSP relationship, and more complex application environments.

Microsoft Entra ID with external identities

Worth noting because many businesses already hold it. Entra ID External Identities (B2B) allows M365 tenants to extend access to guest users and external applications, and with additional configuration, it can be used to enforce MFA on Google Workspace access for M365-licensed users. This is not a clean-out-of-the-box solution for mixed-environment governance: it requires deliberate configuration and is best suited to businesses that are primarily M365-first with Google Workspace as a secondary platform.

If your M365 licensing already includes Entra ID P1 or P2, it is worth exploring what coverage you already have before investing in a standalone IdP. We recommend that Entra ID alone is sufficient for M365-only environments, but insufficient as the sole identity layer for a business running both platforms actively.

Cisco Duo: cross-platform MFA without full IdP complexity

Cisco Duo is a platform-agnostic MFA layer that integrates with both M365 and Google Workspace without requiring a full identity platform deployment. For businesses that are not ready to implement a cloud directory but need consistent MFA across both platforms now, Duo is a practical interim or long-term option. It is simpler to deploy than JumpCloud or Okta, supports Mac-native authentication, including Touch ID, and provides per-application MFA enforcement and device trust policies.

The trade-off is scope: Duo provides MFA and device trust, but not the unified directory, user lifecycle management, or HRIS integration that JumpCloud provides. For businesses where the priority is closing the MFA gap quickly across both platforms, Duo is the right tool. For businesses that also need to solve provisioning, offboarding, and Mac management from a single console, JumpCloud is the better starting point.

Suitable for: Businesses of any size that need cross-platform MFA without full IdP complexity; also works as an additional layer alongside a cloud directory.

Email security tools that cover both platforms

Email security for mixed environments falls into two categories: native tools provided by each platform, and third-party platforms that sit above both.

What Microsoft and Google provide natively

Microsoft Defender for Office 365 provides anti-phishing, anti-malware, Safe Links, and Safe Attachments for M365. For the 2026 licensing changes to Defender for Office 365 Plan 1, see the Securing Microsoft 365 and Google Workspace for Hybrid Teams article.

Google Workspace includes Gmail phishing and malware scanning, Safe Browsing integration, and DMARC enforcement. For a Google-only environment, these are adequate for most businesses. In a mixed environment, each tool protects its own inbox, and neither has visibility into the other. An attacker who compromises a Google Workspace account and uses it to send internally to M365 users is working in a space that neither platform’s native tooling monitors well.

Proofpoint Essentials: third-party coverage across both platforms

Proofpoint Essentials is the SMB-accessible tier of Proofpoint’s enterprise email security platform. It deploys as a gateway (via MX record routing) in front of both Microsoft 365 and Google Workspace, providing a single point of control for inbound email filtering, phishing detection, malware scanning, and email archiving regardless of which platform hosts the mailbox.

For a business running both platforms, Proofpoint Essentials means one policy set, one admin console, and one audit trail for email security across the entire organisation. The MX record deployment model is well-documented for both platforms and does not require API-level integration, which keeps the configuration relatively straightforward for a small IT team.

Proofpoint Essentials is well-suited to businesses under 500 seats that need consistent email security coverage across a mixed environment without enterprise-level complexity or cost.

Mimecast: worth knowing, better suited to larger environments

Mimecast provides similar gateway-model coverage for both platforms and adds email continuity features. It is more complex and more expensive than Proofpoint Essentials and is better suited to organisations above 200 seats, or where email continuity during outages is a specific requirement. For most UK agencies in the 70 to 150-seat range, Proofpoint Essentials covers the same ground at a lower administrative overhead.

How these tools map to Cyber Essentials V3.3

CE ControlRequirementRelevant Tools
User Access ControlMFA mandatory for all in-scope cloud services; auto-fail if missingJumpCloud, Okta, Duo, Entra ID
Secure ConfigurationDefault settings must be hardened; MFA is not optional, even as a paid add-onAll IdP platforms above
Access ControlUnique credentials, least-privilege access, timely offboardingJumpCloud (lifecycle management), Okta
Malware ProtectionEmail-borne malware must be filteredProofpoint Essentials, Defender for Office 365, Gmail native
Patch ManagementSoftware and firmware kept up to date; device trust as evidenceJumpCloud (device management), Entra ID with Intune

JumpCloud and Microsoft Entra ID both produce audit evidence that maps directly to CE+ assessment requirements. For businesses pursuing CE+ (the independently audited tier), having a platform that generates exportable access logs and MFA enforcement evidence is material to passing the technical verification.

The right configuration depends on which licensing tiers you already hold for M365 and Google Workspace, how your devices are managed, and what your Cyber Essentials status is or needs to be.

Book a Cyber Health Check with Dr Logic to establish your current posture and identify the shortest path to a configuration that covers both platforms consistently.

FAQs

Do I need a separate MFA tool if I already have Microsoft 365?

If you only use Microsoft 365, the MFA included in your licence is sufficient for most Cyber Essentials requirements. If your business also uses Google Workspace, Microsoft’s native MFA does not extend to Google sessions. A cross-platform tool such as JumpCloud or Cisco Duo is needed to apply consistent MFA policy across both environments from a single admin console.

Is JumpCloud suitable for a Mac-first business under 100 users?

Yes. JumpCloud is one of Dr Logic’s recommended platforms for Mac-first businesses running a mixed M365 and Google Workspace environment. It provides cross-platform identity federation, Mac device management, MFA enforcement, and user lifecycle management from a single console, without the configuration complexity of enterprise IdP platforms. It is well-suited to businesses from around 20 users upward that do not have a dedicated in-house IT security team.

What is the difference between Defender for Office 365 and a third-party email security gateway?

Defender for Office 365 protects Microsoft 365 mailboxes only. It has no visibility into Google Workspace inboxes. A third-party gateway such as Proofpoint Essentials sits in front of both platforms via MX record routing, applying the same filtering, phishing detection, and archiving policies to all mailboxes regardless of which platform hosts them. For businesses running both M365 and Google Workspace, a third-party gateway provides consistent coverage that neither platform’s native tooling can match.

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.