Skip to content
All insights
ProtectCross-platformBuying GuideJuly 24, 2026

Security and device management in a Google Workspace shop, without adding Microsoft

Companies standardized on Google Workspace Enterprise tend to arrive at the same three requirements: protection on every laptop, central device management with something close to zero-touch setup for new hires, and evidence to hand an auditor. The first architecture most people are shown adds a Microsoft identity and security layer alongside Google. That works, and we have written about how the side-by-side design fits together.

It is a fair question to ask what the same requirements look like without a second administrative ecosystem. This is the version of that answer we would give before knowing anything about your fleet.

Start from the requirements, not the platform

The comparison gets muddy when it starts as Google versus Microsoft. It gets clear when you write down what has to be true and then ask each design to satisfy it. For most companies handling regulated data, the list is close to this:

  • Every laptop runs current, monitored endpoint protection, and someone is accountable for the alerts.
  • Disks are encrypted, and you can prove it for a specific machine on a specific date.
  • A lost or stolen device can be locked or wiped from a console.
  • Operating systems, browsers, and third-party applications patch on a schedule you set.
  • Access to company data depends on who the person is and what device they are on.
  • Sensitive data is prevented from leaving the places it belongs, and retained for as long as your policy says.
  • A new laptop reaches a working, compliant state without a technician spending half a day on it.
  • Joiners, movers, and leavers are handled in one place, and closing an account closes everything.

Both architectures can be measured against that list. Neither satisfies all of it out of the box, including the Microsoft one.

What Google Workspace Enterprise already gives you

More than most teams have switched on. Worth an inventory before buying anything:

If your team has not walked through those settings, that alone is a project, and it is one that pays for itself whichever direction you go afterward.

What the third-party layer looks like

Here is the part that usually stays vague. In the Microsoft design, three products do the heavy lifting: Entra ID for identity and Conditional Access, Intune with Windows Autopilot for device management and provisioning, and Defender for Business for endpoint protection. Buy them separately or take Microsoft 365 Business Premium, which bundles all three with the Office apps.

A Google-native design covers the same ground with Google plus a small number of independent products. Named plainly, so you can price it and compare:

What it does Microsoft design Google-native design
Directory and SSO Entra ID Google Workspace, extended to Windows sign-in with Google Credential Provider for Windows, or JumpCloud where a fuller directory is needed
Conditional access Entra ID Conditional Access Context-Aware Access, with Chrome Enterprise Premium where browser-level control is required
Windows and macOS management Intune JumpCloud, NinjaOne, or Hexnode; Kandji or Jamf where the Mac fleet is the priority
Zero-touch provisioning Windows Autopilot Dell or Lenovo factory provisioning driven by the management product, and Apple Business Manager for Macs
Endpoint protection Defender for Business CrowdStrike, SentinelOne, Huntress, or Sophos Intercept X
Patching, including third-party apps Intune update rings Automox, Action1, or the patch engine inside the management product
Data loss prevention Purview Google DLP, extended by Chrome Enterprise Premium
Retention and eDiscovery Purview Google Vault
Backup of the productivity data Third party either way Afi, Spanning, or Datto SaaS Protection
Log retention and alerting Defender and Sentinel Google's security tooling, with Blumira or Huntress where a security information and event management (SIEM) product is required

Three things stand out when it is laid out this way.

The first is that the Google-native column is a real, buildable architecture. Every line has a mature product behind it, most of them cloud-managed, and none of them require a Microsoft tenant.

The second is that it is more products, not fewer. The Microsoft design consolidates identity, management, and endpoint protection into one license and one console at the cost of introducing a second ecosystem. The Google-native design keeps one ecosystem for productivity at the cost of assembling three or four security and management products around it. Whichever way you go, "one pane of glass" is a slogan rather than a deliverable.

The third is cost, and it runs the opposite way from what most people assume. The Microsoft layer lands at roughly $17 to $22 per user per month: Entra ID, Intune, and Defender for Business bought a la carte at the low end, Microsoft 365 Business Premium at the high end with the Office apps included. The Google-native column is priced product by product, each one per user or per endpoint, and any combination that covers the same ground comes out well above that band. Both layers sit on top of what you already pay Google, so the comparison worth running is layer against layer, and the Google-native one is very unlikely to be the cheaper of the two.

Where co-managed and Phase 0 engagements can help

Companies hesitate at that table less because of the products themselves and more because of what sits behind them: selecting them, negotiating them, deploying them, and then owning the operational load of four consoles with a small internal team.

That work is what a co-managed arrangement is for. We bring the third-party stack already selected, licensed, deployed, and monitored, tuned across the environments we run it in rather than assembled from scratch for yours. Your team keeps the Google Admin console and the relationship with your users. We run the endpoint protection, the patch pipeline, the device enrollment, and the alert queue, and we are the ones who take the call when a machine is lost on a Sunday.

That model applies to either architecture. If the Microsoft layer turns out to be the right answer for you, co-managed looks the same, just with Intune and Defender in place of the products above. The point of it is that the number of consoles becomes our problem instead of yours.

If you are not ready to hand anything over, there is a smaller first step. A Phase 0 assessment inventories what you already own, who administers it, what it costs to run, and where the gaps sit, and it ends in a roadmap rather than a deployment. It is a scoped engagement with a defined output, and you can take that roadmap and execute it yourself. Companies weighing two architectures with an incomplete picture of their own environment usually get more out of that than out of another round of comparison.

The consoles do not disappear either way

"One ecosystem" is the strongest argument for staying Google-native, and the count is worth doing on both sides. A Google-native design with a separate endpoint protection product and a separate management product is also more than one console, more than one support contract, and more than one place a problem could be. You end up with second and third tools on both paths. What separates them is which ones, who administers them, and how well they are connected.

The questions that decide it

We would not pick a direction for you from a blog post. These are the inputs that move the answer, and they are specific to your environment:

  1. What is the fleet? Make, model, Windows edition, and whether there is a Trusted Platform Module (TPM) chip. Machines bought through consumer channels often run Windows Home, which cannot join either management story without an upgrade.
  2. Who is running this in a year? Both designs need an owner, whether that is your team, ours, or a split. The right answer often follows the skills already in place rather than the feature matrix.
  3. What has to be provable, and to whom? Auditors ask for evidence, not architecture. Whichever design produces the report you will be asked for, with the least manual assembly, has a real advantage.
  4. What happens to the on-premises pieces? An existing Active Directory, a virtual private network, or a file server changes the shape of both options.
  5. What are you likely to add next? A design that is right at 40 people can be awkward at 400, and the reverse is also true.

Where this lands

A Google-native path is a legitimate answer, not a compromise, and for some companies it is the better one. It is also not free of second tools, and the Microsoft path is not the only route to zero-touch provisioning and managed endpoint protection. What separates the two, for your company, is a handful of facts about your fleet, your team, and your obligations.

If you are weighing this, bring us the hardware inventory and the requirements list. We will map both designs against it and tell you what each one costs you in operational load, not only in licenses.

See where you stand. Then move forward.

Book a free intro call. We'll talk through where you are today and map a plan for growth, protection, automation, and alignment.

30 minutesNo obligationGet an initial estimate within one week