How to Use Google Workspace Admin Console to Manage Shared Drive Permissions

The Challenge of Data Ownership in the Cloud

In the early days of Google Workspace (formerly G Suite), file sharing was heavily reliant on “My Drive.” If an employee created a critical project folder in their My Drive and shared it with the team, that employee remained the sole owner of the data. If the employee left the company and their account was deleted without proper data migration, the entire team lost access to the project files.

To resolve this massive enterprise liability, Google introduced Shared Drives (formerly Team Drives). Files stored in a Shared Drive belong to the organization, not to an individual user. If a team member leaves, the files stay exactly where they are.

However, properly managing permissions, access levels, and organizational boundaries for Shared Drives requires careful administration via the Google Workspace Admin Console.

Step 1: Accessing Shared Drive Settings

To manage Shared Drive configurations, you must be a Super Administrator or hold specific Drive privileges.

  1. Log in to the Google Workspace Admin Console (admin.google.com).
  2. Navigate to Apps > Google Workspace > Drive and Docs.
  3. Click on Manage Shared Drives.

From this dashboard, an administrator can see every Shared Drive created across the entire organization, including drives where the admin is not explicitly added as a member. This is critical for auditing and compliance.

Step 2: Restricting Shared Drive Creation

By default in many Workspace editions, any user can create a Shared Drive. In a large enterprise, this rapidly leads to “drive sprawl,” where hundreds of abandoned or duplicate drives clutter the interface.

Best practice dictates that IT should restrict the creation of Shared Drives to specific administrative groups.

  1. In the Drive and Docs settings, click on Sharing settings.
  2. Select the top-level Organizational Unit (OU) on the left.
  3. Scroll down to Shared Drive creation.
  4. Uncheck the box that says “Prevent users from creating new shared drives.” Wait, to restrict it, you must check the box. Specifically, check the box that prevents users from creating them.
  5. You can then select a specific OU (like “IT Administrators”) and uncheck the box for that specific unit, overriding the global restriction.

Step 3: Configuring External Sharing Policies

Data exfiltration is a primary concern with cloud storage. Shared Drives allow granular control over who can share files externally.

When selecting a specific Shared Drive from the “Manage Shared Drives” dashboard, click on Settings to adjust its specific policies:

  • Allow people outside your organization to access files: Disabling this ensures that no file within the drive can ever be shared with an external Gmail or Workspace account. This is mandatory for drives containing HR, financial, or proprietary code.
  • Allow people who aren’t shared drive members to access files: Disabling this forces users to become members of the drive to see the files, preventing drive members from generating shareable links for other internal employees.
  • Allow viewers and commenters to download, print, and copy files: Disabling this adds a layer of Information Rights Management (IRM) to the drive, preventing casual data theft by lower-tier members.

Step 4: Managing Member Roles

When provisioning a Shared Drive, assigning the correct roles is essential for maintaining order.

  • Manager: Can add/remove members, change settings, and permanently delete files. (Limit this to 1-2 people per team).
  • Content Manager: Can add, edit, move, and delete files, but cannot alter the membership. (This is the ideal default role for active team members).
  • Contributor: Can add and edit files, but cannot delete or move files out of the drive. (Excellent for temporary contractors or interns).
  • Commenter/Viewer: Read-only access.

Administrators can forcefully change a user’s role on any Shared Drive directly from the Admin Console by clicking on the drive, selecting “Manage Members”, and adjusting the dropdown, even if the admin is not a member of the drive.

Step 5: Recovering Deleted Data

If a Manager or Content Manager accidentally deletes a critical file from a Shared Drive, it goes to the Shared Drive’s trash for 30 days. After 30 days, it is permanently deleted by the system.

However, Google Workspace administrators have a 25-day grace period to restore permanently deleted files. From the Manage Shared Drives console, hover over the specific drive, click the Restore button, and select a date range. This will instantly recover the lost data back to its original location.

Conclusion

Shared Drives are the cornerstone of secure, collaborative file management in Google Workspace. By utilizing the Admin Console to tightly control who can create drives, who can share files externally, and strictly managing member roles, IT administrators can ensure organizational data remains secure, compliant, and immune to employee turnover.

RELATED POSTS

  • How to Use Google Drive Offline Mode for Editing Without Wi-Fi
  • How to Use the Propose a New Time Feature in Google Calendar
  • How to Empty the Trash in Google Drive
  • How to Recover Deleted Files in Google Drive
  • How to Create a Bootable USB Drive in Ubuntu
  • Get the best tech tips delivered straight to your inbox.

    Join thousands of readers mastering Apple, Google, Microsoft, and Linux.