"If one of your employees' laptops disappeared right this second, could you wipe its files remotely?" When asking IT staff at SMBs this question, many are left at a loss for words. While device counts are listed on general affairs inventory spreadsheets, tracking which PC is with whom, whether screen locks are active, or if drives are encrypted remains out of reach. This situation is far from uncommon.
When people think of securing devices, they often assume they need a separate MDM (Mobile Device Management) subscription. However, if you already use Google Workspace, most company-issued Windows PCs can be managed directly through its built-in Google Endpoint Management. Before adding new software, you should first check what your existing contract already supports. As a companion to our article on controlling iPhones and iPads in Google Endpoint Management's new iOS settings, this article focuses specifically on Windows PCs.
What Actually Happens When Devices Are Left Unmanaged
Unmanaged PCs pose little concern during routine operations; the danger emerges during incidents. The following three scenarios are common:
- Loss or theft: A laptop is stolen from a sales vehicle. With only a login password protecting it, data can be extracted directly if the drive is unencrypted.
- Orphaned devices at departure: A PC effectively used as a personal device by a departing employee is neither recovered nor wiped, leaving customer data intact.
- Neglected updates: Windows Update is left to individual discretion, leaving a mix of vulnerable devices across the company.
All of these risks remain hidden as long as everyone assumes "someone else has it handled," only coming to light after an incident occurs. Conversely, enforcing screen locks, remote wiping, encryption, and update management centrally from the administrative console prevents the vast majority of potential damage.
Basic Management Starting at Zero Extra Cost
The good news is that getting started requires no added cost. Google Endpoint Management offers two tiers—basic management and advanced management—and basic management is available across all Google Workspace plans at no additional charge.
When employees sign into Chrome using their corporate Google account or connect it as a Windows work account, the device appears automatically in the Admin console's inventory. Even with basic management, administrators can perform the following actions:
| Permissions | Benefit |
|---|---|
| Device inventory visibility | See who is using corporate accounts on which devices |
| Account-level wipe | Remove corporate accounts and associated data from a lost device or upon employee departure |
| Enforce screen locks | Block devices that do not have a password configured |
Simply enabling these controls resolves the baseline problem of not knowing how many devices are deployed. Configuration is handled directly via the Google Workspace Admin console.
Advanced Management for Comprehensive Windows Control
If you need deeper control over company-issued Windows PCs, you can use Windows device management (advanced management). This feature is available on Business Plus and higher plans, enabling administrators to deploy controls like the following to Windows 10/11 PCs via the Admin console:
- Enforce disk encryption with BitLocker (preventing data access even if the drive is physically extracted after theft)
- Control the timing and frequency of Windows Updates centrally to eliminate neglected patches
- Enforce password complexity and screen lock parameters as organizational security policies
A valuable enhancement arrived in 2026 for practitioners: historically, combining central company device management with local administrator privileges for users was difficult. Now, Endpoint Management offers flexible settings to maintain local administrator access for specific users while still applying organizational management policies. This makes it far easier to accommodate realistic workplace demands, such as retaining administrator rights for developers or specific operational roles while enforcing baseline company-wide security.
If you also want to secure the front door by binding Windows logins directly to corporate Google accounts, a separate mechanism called GCPW (Google Credential Provider for Windows) is available. For details, refer to our article on securing Windows logins with GCPW and security keys. Pairing device management with login integration significantly enhances overall security.
A Rollout Sequence to Avoid Implementation Pitfalls
Applying strict policies across all devices at once inevitably sparks backlash from employees complaining that their PCs have become difficult to use, stalling adoption. A practical rollout follows these stages:
- First, audit with basic management: Compile an inventory of all devices to establish visibility into who is using what. You can start this today at no extra cost.
- Enable screen locks and remote wipe first: Prioritize controls that mitigate damage during incidents. This strengthens defense with virtually no disruption to user experience.
- Pilot encryption and update controls in selected teams: Test BitLocker enforcement and update policies with a few IT-adjacent users to confirm there are no operational issues before wider rollout.
- Establish policies for exceptions: Identify users requiring local administrator rights and manage them individually using the flexible permission settings mentioned above.
Following this progression establishes a baseline defense within your existing subscription budget without rushing into new MDM contracts. Even if your plan is below Business Plus, the gains from basic management alone are substantial.
First, Open the Device List in the Admin Console
Managing company PCs does not start with buying expensive software; it begins with understanding what you can see and do within your existing subscription. Open your Admin console device list today and check whether the number of active devices matches your records. If there is a discrepancy, that is where your work should begin.
If you need help determining how much management your plan supports, designing operational protocols for lost devices or employee offboarding, or deciding whether a dedicated MDM is necessary, feel free to contact GleamHub via our free IT & Google Workspace consultation. We will help you build a setup starting from capabilities available at no extra cost, tailored to your subscription tier and device environment.
Sources
- Device requirements for Google endpoint management - Google Workspace Admin Help
- What Is Google Workspace Device Management? Capabilities, Plan Differences, and Setup Procedures for Endpoint Management | MuuMuu Domain Media
- Enhance Security with Google Workspace Device and Access Management! | G-gen Inc.
- Google Workspace Device Management for Windows Devices | Scalefusion









