Running Microsoft 365 and Google Workspace side by side is common at UK agencies. What is less common is a security setup that actually covers both. Most businesses default to Microsoft’s native tools for M365 and Google’s built-in controls for Workspace, and end up with two separate, inconsistently configured security layers and a gap in the middle where neither has full visibility. This article names the tools that close that gap: the identity and MFA platforms that govern both environments from a single admin console, and the email security tools that protect both inboxes without requiring two separate configurations.
Why mixed environments create a security layer problem
The core issue is not that native tools are weak. It is that they are designed to protect their own ecosystem only. Microsoft Entra ID conditional access policies govern M365 sessions. They do not extend to Google Workspace. Google’s context-aware access controls Workspace activity. It does not extend to M365 app behaviour. For an IT team supporting both platforms, the result is two policy sets, two audit logs, and two places where a compromised account might go undetected.
This is the structural argument for an independent identity layer: a single platform that federates authentication across both environments, applies consistent MFA policies regardless of which app a user is signing into, and provides a unified view of who is accessing what. Without it, a user with compromised M365 credentials may still have unchallenged access to Google Workspace, and vice versa.
What Microsoft and Google’s built-in security actually covers
Both platforms include meaningful built-in security. Understanding where each stops is what determines whether additional tooling is necessary.
Microsoft Entra ID (included with M365 Business Premium) provides conditional access, MFA enforcement, Defender for Office 365 email protection, and device compliance policies via Intune. For a business running M365 only, Business Premium covers most of the Cyber Essentials technical controls without additional tools. The limitation in a mixed environment is scope: Entra ID is not designed to govern non-Microsoft application sign-ins, and its conditional access policies do not extend cleanly to Google Workspace sessions.
For the changes to Defender for Office 365 rolling out in 2026, see Securing Microsoft 365 and Google Workspace for Hybrid Teams for full details.
Google Workspace’s built-in security includes Gmail phishing and malware scanning, Safe Browsing integration, context-aware access (available from Business Standard upward), and Drive sharing controls. For a Google-only environment, these are a solid baseline. In a mixed environment, they create the same scoping problem in reverse: they protect Workspace activity but have no visibility into what a user is doing inside M365.
Where both fall short in a mixed environment: Under Cyber Essentials v3.3, in force from 28 April 2026, MFA on every in-scope cloud service is now a mandatory requirement, and failure to meet it is an automatic fail on the User Access Control section. Businesses relying on each platform’s native MFA independently, without a consistent cross-platform policy, may pass on paper but are exposed in practice. Separate admin consoles mean separate remediation work, separate audit evidence, and a higher risk of gaps.
Independent identity and MFA platforms that works across both
The tools below each address the core problem: governing authentication across both M365 and Google Workspace from a single admin plane. They vary in complexity, cost, and the level of IT resources required to manage them.
JumpCloud: the strongest fit for Mac-first businesses
JumpCloud is a cloud directory platform that federates identity across Microsoft 365, Google Workspace, and Mac devices from a single console. We recommend JumpCloud for Mac-first businesses running a mixed M365/Google environment because it handles the parts that neither Microsoft nor Google’s native tools address: unified identity across both platforms, DMS (formerly MDM) capabilities for Mac endpoints, and MFA enforcement regardless of which application a user is signing into.
In practice, JumpCloud means one place to onboard a new user, one place to offboard them, and one place to see whether MFA is active across every application they access. For businesses without a dedicated in-house security team, that reduction in admin surface is significant. JumpCloud also has established Google Workspace integration, recognised with the 2026 Google Cloud Partner of the Year award, and its HRIS integrations mean joiners and leavers can be provisioned and deprovisioned without manual admin work across two separate consoles.
JumpCloud’s Cyber Essentials alignment is strong: its access control, MFA enforcement, and device trust policies map directly to the User Access Control and Secure Configuration requirements under v3.3.
Suitable for: 20 to 250 users, Mac-first or hybrid device fleets, businesses without a dedicated in-house security function.
Okta: stronger at scale, higher admin overhead
Okta is the market leader in standalone identity and access management, and it handles multi-platform federation well. For a 70 to 150-person agency with a part-time IT manager or an MSP managing the environment, Okta is a credible option. It is more complex to configure than JumpCloud and typically requires more ongoing admin attention, but its application catalogue, policy engine, and reporting capabilities are more granular at higher seat counts.
The honest position: for a Mac-first business under 100 users without a dedicated IT resource, Okta adds configuration overhead that is not necessary. At 100 seats and above, or where the business needs fine-grained conditional access policies across a large application estate, Okta earns the additional complexity.
Suitable for: 100 or more users, businesses with a part-time IT manager or MSP relationship, and more complex application environments.
Microsoft Entra ID with external identities
Worth noting because many businesses already hold it. Entra ID External Identities (B2B) allows M365 tenants to extend access to guest users and external applications, and with additional configuration, it can be used to enforce MFA on Google Workspace access for M365-licensed users. This is not a clean-out-of-the-box solution for mixed-environment governance: it requires deliberate configuration and is best suited to businesses that are primarily M365-first with Google Workspace as a secondary platform.
If your M365 licensing already includes Entra ID P1 or P2, it is worth exploring what coverage you already have before investing in a standalone IdP. We recommend that Entra ID alone is sufficient for M365-only environments, but insufficient as the sole identity layer for a business running both platforms actively.
Cisco Duo: cross-platform MFA without full IdP complexity
Cisco Duo is a platform-agnostic MFA layer that integrates with both M365 and Google Workspace without requiring a full identity platform deployment. For businesses that are not ready to implement a cloud directory but need consistent MFA across both platforms now, Duo is a practical interim or long-term option. It is simpler to deploy than JumpCloud or Okta, supports Mac-native authentication, including Touch ID, and provides per-application MFA enforcement and device trust policies.
The trade-off is scope: Duo provides MFA and device trust, but not the unified directory, user lifecycle management, or HRIS integration that JumpCloud provides. For businesses where the priority is closing the MFA gap quickly across both platforms, Duo is the right tool. For businesses that also need to solve provisioning, offboarding, and Mac management from a single console, JumpCloud is the better starting point.
Suitable for: Businesses of any size that need cross-platform MFA without full IdP complexity; also works as an additional layer alongside a cloud directory.
Email security tools that cover both platforms
Email security for mixed environments falls into two categories: native tools provided by each platform, and third-party platforms that sit above both.
What Microsoft and Google provide natively
Microsoft Defender for Office 365 provides anti-phishing, anti-malware, Safe Links, and Safe Attachments for M365. For the 2026 licensing changes to Defender for Office 365 Plan 1, see the Securing Microsoft 365 and Google Workspace for Hybrid Teams article.
Google Workspace includes Gmail phishing and malware scanning, Safe Browsing integration, and DMARC enforcement. For a Google-only environment, these are adequate for most businesses. In a mixed environment, each tool protects its own inbox, and neither has visibility into the other. An attacker who compromises a Google Workspace account and uses it to send internally to M365 users is working in a space that neither platform’s native tooling monitors well.
Proofpoint Essentials: third-party coverage across both platforms
Proofpoint Essentials is the SMB-accessible tier of Proofpoint’s enterprise email security platform. It deploys as a gateway (via MX record routing) in front of both Microsoft 365 and Google Workspace, providing a single point of control for inbound email filtering, phishing detection, malware scanning, and email archiving regardless of which platform hosts the mailbox.
For a business running both platforms, Proofpoint Essentials means one policy set, one admin console, and one audit trail for email security across the entire organisation. The MX record deployment model is well-documented for both platforms and does not require API-level integration, which keeps the configuration relatively straightforward for a small IT team.
Proofpoint Essentials is well-suited to businesses under 500 seats that need consistent email security coverage across a mixed environment without enterprise-level complexity or cost.
Mimecast: worth knowing, better suited to larger environments
Mimecast provides similar gateway-model coverage for both platforms and adds email continuity features. It is more complex and more expensive than Proofpoint Essentials and is better suited to organisations above 200 seats, or where email continuity during outages is a specific requirement. For most UK agencies in the 70 to 150-seat range, Proofpoint Essentials covers the same ground at a lower administrative overhead.
How these tools map to Cyber Essentials V3.3
| CE Control | Requirement | Relevant Tools |
|---|---|---|
| User Access Control | MFA mandatory for all in-scope cloud services; auto-fail if missing | JumpCloud, Okta, Duo, Entra ID |
| Secure Configuration | Default settings must be hardened; MFA is not optional, even as a paid add-on | All IdP platforms above |
| Access Control | Unique credentials, least-privilege access, timely offboarding | JumpCloud (lifecycle management), Okta |
| Malware Protection | Email-borne malware must be filtered | Proofpoint Essentials, Defender for Office 365, Gmail native |
| Patch Management | Software and firmware kept up to date; device trust as evidence | JumpCloud (device management), Entra ID with Intune |
JumpCloud and Microsoft Entra ID both produce audit evidence that maps directly to CE+ assessment requirements. For businesses pursuing CE+ (the independently audited tier), having a platform that generates exportable access logs and MFA enforcement evidence is material to passing the technical verification.
The right configuration depends on which licensing tiers you already hold for M365 and Google Workspace, how your devices are managed, and what your Cyber Essentials status is or needs to be.
Book a Cyber Health Check with Dr Logic to establish your current posture and identify the shortest path to a configuration that covers both platforms consistently.
FAQs
Do I need a separate MFA tool if I already have Microsoft 365?
If you only use Microsoft 365, the MFA included in your licence is sufficient for most Cyber Essentials requirements. If your business also uses Google Workspace, Microsoft’s native MFA does not extend to Google sessions. A cross-platform tool such as JumpCloud or Cisco Duo is needed to apply consistent MFA policy across both environments from a single admin console.
Is JumpCloud suitable for a Mac-first business under 100 users?
Yes. JumpCloud is one of Dr Logic’s recommended platforms for Mac-first businesses running a mixed M365 and Google Workspace environment. It provides cross-platform identity federation, Mac device management, MFA enforcement, and user lifecycle management from a single console, without the configuration complexity of enterprise IdP platforms. It is well-suited to businesses from around 20 users upward that do not have a dedicated in-house IT security team.
What is the difference between Defender for Office 365 and a third-party email security gateway?
Defender for Office 365 protects Microsoft 365 mailboxes only. It has no visibility into Google Workspace inboxes. A third-party gateway such as Proofpoint Essentials sits in front of both platforms via MX record routing, applying the same filtering, phishing detection, and archiving policies to all mailboxes regardless of which platform hosts them. For businesses running both M365 and Google Workspace, a third-party gateway provides consistent coverage that neither platform’s native tooling can match.



















































