Google Workspace Admin Console: A Beginner's Guide

Follow the steps below in order.

  1. Log Into the Admin Console

    Sign in at admin.google.com with an account that has administrator privileges to open the console where you manage your organization's users, devices, and security settings.

  2. Add a New User

    Under Directory > Users, click 'Add new user' and enter a name and email address to create an account for a new team member right away. If you need to add many people at once, you can use the bulk upload feature with a CSV file instead.

  3. Suspend or Delete a Departing Employee's Account

    Select a former employee's account from the list and choose 'Suspend' or 'Delete' to prevent further sign-ins. If you need to preserve their data, transfer file ownership to another team member before deleting the account.

  4. Create Groups to Manage Permissions

    Under Directory > Groups, creating a group for a department or project lets you manage email distribution and file-sharing permissions at the group level instead of configuring every user individually.

  5. Enforce Two-Factor Authentication

    Under Security > Authentication > 2-Step Verification, you can require two-factor authentication organization-wide or for a specific group. It's worth giving your team advance notice and time to set it up before enforcing the policy, since anyone without it configured will be locked out the moment it takes effect.

  6. Apply Different Settings by Organizational Unit

    Creating organizational units lets you apply different app access or security policies to different departments, so you can manage settings with more precision instead of forcing one set of rules on the entire company.

Why centralize account and security management

As a team grows, managing accounts one by one becomes unworkable fast. Handling accounts, permissions, and security policy by group and organizational unit inside the admin console keeps things consistent and makes onboarding and offboarding far less error-prone.

A few settings worth reviewing beyond the basics

Beyond the steps above, it's worth checking mobile device management policies for company data on personal phones, setting up an alert center to get notified of suspicious sign-in activity, and reviewing third-party app access permissions periodically so unused integrations don't linger with standing access to your organization's data.

Frequently Asked Questions

Can anyone access the admin console?

No -- only accounts granted administrator privileges can access it; the admin console menu doesn't even appear for a regular user account.

Does enforcing two-factor authentication lock people out immediately?

Yes -- the moment the policy takes effect, anyone who hasn't set up two-factor authentication will be unable to sign in, so it's safest to announce the change and give people a grace period before turning it on.