Google Mandates Multi-Factor Authentication for Cloud Services by 2025, Pushes Gmail Passkey Adoption

Panoramic view of the iconic red brick towers and domes of St. Basil’s Cathedral and the Kremlin in Moscow, Russia, framed by bare tree branches in the foreground during winter sunset.

Google is implementing comprehensive changes to its authentication requirements, with a particular focus on enhancing security across its Google Cloud and Gmail services through multi-factor authentication (MFA) and passkey adoption. The initiative continues the company’s ongoing efforts to replace traditional passwords with more secure authentication methods.

The technology giant has announced that MFA will become mandatory for all Google Cloud accounts by the end of 2025. The implementation will occur in three phases to ensure a smooth transition for users and enterprises. According to data cited by Google from the Cybersecurity and Infrastructure Security Agency (CISA), MFA makes users 99 percent less likely to experience unauthorized account access. The requirement matches similar security measures from other tech companies, as Microsoft has also set a 2025 deadline for mandatory MFA across its services.

To support this transition, Google is offering various MFA options, including passkeys that use biometric data. Users can enable these enhanced security features through their account settings, though enterprise users may need to comply with specific administrative policies. The shift toward passkeys comes as password-based attacks continue to surge, with Google reporting that 61 percent of security breaches involve compromised credentials.

The company is simultaneously encouraging its 2.5 billion Gmail users to adopt passkeys and app-based two-factor authentication (2FA) in place of traditional passwords. The change supports Google’s plan to phase out less secure authentication methods, such as SMS-based verification, which federal agencies have warned against due to security vulnerabilities.

Passkeys represent a more secure authentication approach, using cryptographic methods and biometric verification instead of conventional passwords or SMS codes, which can be intercepted. While MFA significantly reduces security risks, experts note that weak passwords can still present vulnerabilities if not combined with robust authentication methods. The FIDO Alliance has recently published guidance for enterprise implementation of passkeys, supporting organizations in their transition to passwordless authentication.

Google has also implemented additional technical measures to enhance both security and privacy. The measures include anonymous, hardware-backed attestation and unique cryptographic certificates designed to prevent the traceability of user actions. These features build upon Google’s existing security infrastructure while addressing emerging threats in the digital authentication landscape.

The company advises users to remain vigilant against fraudulent 2FA prompts, which malicious actors may use to obtain authentication codes or gain unauthorized access. The warning comes as sophisticated phishing attacks targeting Gmail users through AI-enhanced security alert scams have increased. Users are recommended to reject unexpected 2FA requests and update their passwords if they detect suspicious activity.

Sources: Bitdefender, Mobile ID World, Bleeping Computer, Google Online Security Blog, Android Police