Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

Google Drive Ransomware Detection Reaches GA: Key Settings and Operational Guidelines for Admins

On March 30, 2026, Google announced the General Availability (GA) of ransomware detection and file recovery in Google Drive. Approximately six months after the September 2025 beta launch, significant enhancements to the underlying AI model now enable it to detect over 14 times more ransomware than in beta.

For administrators of organizations relying on Google Workspace as their operational foundation, determining how to configure this feature and incorporate it into operations is an immediate priority. This article breaks down everything from the feature overview to configuration steps in the Admin Console and operational best practices.


What changed: Feature overview

When ransomware compromises an endpoint, it encrypts local files and can spread that damage to the cloud through drive synchronization. Previously, Google Drive lacked a mechanism to stop this propagation, requiring administrators to manually locate and restore impacted files after an incident.

With this GA release, the system responds automatically through the following workflow:

  1. Drive for Desktop uses AI to scan synchronized files in real time
  2. Upon detecting ransomware encryption, it halts syncing immediately to prevent damage from spreading
  3. A notification appears on the user's desktop while an alert is simultaneously sent to the administrator Alert Center
  4. Users can perform a bulk rollback to pre-infection states without requiring administrator intervention

In particular, step 4's bulk recovery dramatically cuts down the time and expense IT departments previously spent handling incidents manually. The greatest benefit is enabling businesses to resume operations quickly without paying ransoms.


Supported plans and prerequisites

The ransomware detection feature is available on the following plans (free Gmail and Business Starter are excluded).

CategoriesSupported plans
BusinessBusiness Standard / Business Plus
EnterpriseEnterprise Starter / Enterprise Standard / Enterprise Plus
EducationEducation Standard / Education Plus
FrontlineFrontline Standard / Frontline Plus

Furthermore, to take full advantage of this feature, endpoints must have Drive for Desktop v.114 or later installed. If an older version is used, synchronization will still halt, but detection alerts will not reach administrators. We recommend configuring mandatory updates via device management policies.


Configuration steps in the Admin Console

While the feature is enabled by default, it is essential for administrators to verify and manage the current settings.

Enabling / disabling ransomware detection

管理コンソール(admin.google.com)
  > アプリ
  > Google Workspace
  > ドライブとドキュメントの設定
  > マルウェアとランサムウェア
  > ランサムウェア検出

Because it can be managed by Organizational Unit (OU), you can target specific departments or roles. For example, you might prioritize enabling it for sales teams that frequently share files externally, or keep it disabled only in test environment OUs for validation.

File recovery settings

管理コンソール
  > アプリ
  > Google Workspace
  > ドライブとドキュメントの設定
  > ドライブファイルの復元

This can also be controlled at the OU level. Establishing and communicating recovery instructions within your company beforehand ensures swift execution if an actual incident occurs.


Alert intake and response workflow

When ransomware is detected, administrators receive alerts through two channels:

  • Email notifications: Sent automatically to administrator email addresses
  • Alert Center: Accessible via Admin Console > Security > Alert Center

Upon receiving an alert, we recommend executing the following response steps in order:

  1. Check the Alert Center to determine the scope of affected users and files
  2. Isolate the affected user's device (leveraging MDM / endpoint management integrations)
  3. Bulk-restore files on Drive to their pre-incident versions
  4. Identify the infection vector and implement preventative measures

Because Google Workspace unifies the Admin Console, Alert Center, and Vault (eDiscovery), combining them provides an integrated process from incident investigation through evidence preservation.


3 things administrators should verify today

The greatest risk in security is assuming a feature is enabled. Verify these three points today:

1. Is ransomware detection enabled across all target OUs?

While enabled by default, settings may have been modified in the past. Verify this explicitly in the Admin Console.

2. Is Drive for Desktop on v.114 or later?

Installed application versions can be verified in Admin Console > Devices > Endpoints. If older versions remain on devices, consider enforcing an update.

3. Are administrator alert recipient lists up to date?

It is remarkably common for alerts to fail to deliver due to personnel transfers or departures. Take a moment to review the Alert Center notification email addresses.


Approaching Google Workspace security through defense-in-depth

While this ransomware detection capability strengthens drive-layer defense, robust security cannot rely on a single countermeasure. Google Workspace provides a comprehensive array of security features:

  • Advanced Gmail protections (automated detection of phishing and malicious attachments)
  • Zero-trust access control (integration with BeyondCorp Enterprise)
  • Data Loss Prevention (DLP) (preventing leaks of sensitive organizational information)
  • Data retention and auditing via Vault

Combining these tools into a defense-in-depth architecture is the most direct way to fundamentally lower organizational risk. For more details on the benefits of Google Workspace and how it compares with other platforms, read Benefits and Real-World Use Cases of Google Workspace.

In addition, default storage locations for meeting recordings are another setting administrators frequently overlook. Please also see Google Meet Recording Downloads Become Default: Crucial Admin Settings to Review.


Conclusion

Google Drive ransomware detection and file recovery has reached General Availability. Here is a summary of the key takeaways:

  • AI models deliver 14x greater detection accuracy compared to beta, reaching GA on March 30, 2026
  • Requires Drive for Desktop v.114 or later; enabled by default but configurable per OU in the Admin Console
  • Alerts are delivered through two channels: email and the Alert Center
  • Incident response workflow: check Alert Center → isolate device → restore Drive files → investigate cause

Security capabilities have little value if left unmanaged. True operational security entails ongoing audits of configuration states alongside documented incident response plans.


If you need expert guidance on Google Workspace security configurations or administrator support, reach out to GleamHub. We can propose configurations tailored to your organization's scale and licensing tier.

Contact us here

Share this articleXFacebook
Rui Teruya

Former corporate league baseball player and founder of an IT venture. Founded the company with the drive to ride the fast-moving waves of the world and deliver truly valuable services to society.

Turn this article's theme into your company's next step

The right way forward with Workspace for your company.

We organize data to migrate, sharing rules, and governance structures to map out the journey from implementation to daily operations.

  • Migration and initial setup
  • Sharing and permission organization
  • Governance structure
Consult on Workspace implementation and operations

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles by email