How to Configure Custom Administrative Roles in Google Workspace

The Danger of the Super Admin Role

When a company hires a new IT Helpdesk technician to manage password resets and create new user accounts, the easiest solution is to assign them the “Super Administrator” role in Google Workspace. However, this is a massive security risk. A Super Admin has the power to delete the entire company domain, read the CEO’s emails via Google Vault, and disable two-factor authentication.

To adhere to the principle of least privilege, you should never assign the Super Admin role unless absolutely necessary. Instead, Google Workspace allows you to create highly granular, custom administrative roles that grant technicians exactly the permissions they need—and nothing more.

Step 1: Access the Roles Menu

  1. Log into the Google Workspace Admin Console (admin.google.com) using your existing Super Administrator credentials.
  2. In the left-hand navigation pane, click on Account > Admin roles.
  3. You will see a list of pre-built system roles (like Groups Admin, Help Desk Admin, and Services Admin). While these are useful, creating a custom role provides much tighter security.

Step 2: Create a Custom Role

  1. At the top of the screen, click the Create new role button.
  2. Give the role a descriptive name, such as “Tier 1 Helpdesk (Password Resets Only)”.
  3. Provide a brief description of what the role is allowed to do, then click Continue.

Step 3: Select Granular Privileges

You will now see a massive tree of checkboxes representing every single administrative action possible in Google Workspace.

  1. Expand the Admin Console Privileges section.
  2. Expand the Users section.
  3. Because this role is only for password resets, leave “Create” and “Delete” unchecked. Check the box next to Reset Password.
  4. Check the box next to Force Password Change (this allows the technician to force the user to pick a new password on their next login).
  5. Click Continue, review the privileges, and click Create Role.

Step 4: Assign Users to the Role

Now that the role exists, you must assign your IT technicians to it.

  1. On the role’s overview page, click the Assign users button in the top right.
  2. Search for the technician’s email address (e.g., [email protected]).
  3. Crucial Step: Google Workspace allows you to limit a role’s scope to a specific Organizational Unit (OU). Instead of allowing John to reset passwords for the entire company (including the Executive OU), select only the standard employee OUs from the scope dropdown.
  4. Click Assign Role.

When John logs into the Admin Console, he will only see the “Users” icon. He will not even see the icons for Billing, Security, or Google Vault, perfectly securing your administrative environment.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.