Passwords
The only rule is length: at least eight characters, and no more than two hundred. There is no requirement for a capital or a symbol, because rules like that reliably produce one predictable password rather than a good one. Pick something long.
There is no change-your-password screen inside the portal. Changing yours means going through the emailed reset, which is the same path as forgetting it. That is a deliberate simplification rather than an omission, but it does surprise people looking for it under their profile.
Resetting one
A reset link lasts an hour and works once. Asking for a reset gives the same reply whether or not there is an account on that address, so the page cannot be used to find out who has one.
Completing a reset signs you out on every device you were signed in on, and disconnects Google sign-in if you had connected it — you reconnect it afterwards. If you have an authenticator app set up, a reset still asks for that code before letting you in.
Two-factor
The second factor is an authenticator app: a six-digit code that changes every thirty seconds. Setting it up gives you ten recovery codes, shown once and never again, each usable a single time. Write them down somewhere that is not the laptop you sign in on.
It is optional to begin with. An Owner — and only an Owner — can make it required for everyone in the workspace, and that requirement is applied at sign-in: somebody without a second factor is sent to set one up rather than being let in and nagged later.
Three things this screen does not do
There is no list of your signed-in devices. Sessions are not tracked individually, and rather than invent a device table that looked authoritative and was not, the product offers sign out everywhere — which genuinely does end every other session.
There is no way to switch your own two-factor off once it is on. There is also no way to generate a fresh set of recovery codes after the ten you were given. If you are out of codes or need to start again, that is a support request.
Google sign-in is not single sign-on
Connecting Google links one Google account to one person's login here. It is not a company-wide directory sign-in: it does not admit anybody who happens to have an email address at your domain, and there is no automatic matching between a Google account and a person in your workspace.
What the audit log covers
The audit log records actions that were written to record themselves — settings changes, team changes, money actions. It is not a complete transcript of the workspace: ordinary reads, sign-ins and most day-to-day staff activity are not in it.
That is worth knowing before you rely on it to answer a question. It is a good record of who changed what, and not a record of who looked at what.