Memory hook: Route mail; scope sharing; preserve ownership.
Must remember
- MX records direct inbound mail. SPF authorizes sending sources; DKIM signs messages; DMARC checks alignment and tells receivers how to handle failures. Start enforcement with visibility into legitimate senders.
- Gmail routing, compliance rules, quarantine, attachment restrictions, forwarding and POP/IMAP settings solve different needs. Delegation grants mailbox access without sharing a password; migration tools move historical mail.
- My Drive content is typically individually owned; shared drives provide team ownership. Configure external sharing, target audiences, labels, storage limits, templates, offline access and Drive for desktop according to policy.
- Calendar sharing distinguishes free/busy visibility from event detail and management permissions. Review resource booking, delegation, unknown invitations and event ownership during personnel changes.
- Meet access, recording, transcripts, note taking and media settings depend on edition and policy. Chat history, external spaces, invitations, apps and moderation also affect governance.
- Test settings with a representative OU/group before applying them widely. A service enabled at organization level may still be unavailable because of licensing, user settings or more specific policy.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Mail reaches the wrong provider | Check MX and routing before changing a user password. |
| Files must remain with a department after staff changes | A shared drive with appropriate membership. |
Traps
- SPF passing alone does not prove DMARC alignment.
- Disabling external links does not retroactively erase every copy already exported.
Active recall
1. What does DKIM protect?
Message authenticity and integrity through a domain signature verified by the receiver.
2. How share only availability?
Calendar free/busy permission rather than detailed event access.
3. Why avoid a global spam allowlist?
It can weaken filtering for malicious mail; diagnose and scope exceptions.
4. Who owns shared-drive files?
The organization/team context rather than an individual user’s My Drive ownership.
5. Why review Chat history?
It affects retained conversation data and must align with policy and supported retention controls.