Show administrators how to require 2‑Step Verification (2SV) whenever users access the Cloud Secure Edge (CSE) application. If this is not configured, it will follow the Google session control settings.
Product: Cloud Secure Edge by SonicWall
Identity Provider: Google Workspace (Cloud Identity)
License requirement: Google Workspace Business or Enterprise edition, or Cloud Identity Premium
Cloud Secure Edge is already configured as a SAML application in Google Workspace and assigned to users.
Target users have enrolled in 2‑Step Verification (security key, Google Authenticator, or Google Prompt).
You have Super Admin (or Security Admin + Groups Admin) privileges to manage security settings.
Maintain at least one break‑glass admin account stored securely for emergency lockout scenarios.
Sign in to the Google Admin console with a super‑admin account.
Navigate to Security → Authentication → 2‑step verification.
Select the Organizational Unit or Group that contains the users who need CSE access.
Under Enforcement, choose On and enable Enforce 2‑Step Verification.
Set a Grace period (optional) to give users time to enroll.
Click Save.
In the Admin console, go to Apps → Web and mobile apps.
Search for Cloud Secure Edge and open its settings.
Click User access.
Select ON for some and choose only the group/OU that has 2SV enforcement.
Click Save.
Navigate to Security → Access and data control → Context‑Aware Access.
Click Access levels → Create access level.
Name it Requires 2SV.
Under Add condition, enable Require user to have verified 2‑step verification and set any additional device/location rules you need.
Save the access level.
Go back to Apps → Web and mobile apps → Cloud Secure Edge → Context‑Aware Access.
Set the service status to ON, then apply the Requires 2SV access level.
Click Save.
Sign in with a test account in the targeted group/OU and launch Cloud Secure Edge. Verify that a 2SV prompt appears.
Remove 2SV enrollment from the test account or move it to an unenforced OU. Confirm that access to CSE is blocked with a message such as “This service requires 2‑Step Verification.”
Google Workspace enforces 2SV at login. To scope it only to Cloud Secure Edge, use group assignment or Context‑Aware Access.
Provide user training and clear communications before enforcing 2SV to avoid support tickets.
Keep backup codes or secondary admin accounts available to avoid lockouts.
Google: Context‑Aware Access overview
SonicWall: Cloud Secure Edge SSO Integration Guide