How-to

How to make a user a super admin

Super admin is granted from the Admin console user page by assigning the Super Admin role, and the change can take up to 24 hours to apply across all services. A tenant should hold at least 2 super admins for recovery, and almost never more than 3.

Role facts
Click pathDirectory, Users, the user, Admin roles and privileges
PropagationUp to 24 hours across all services
Recommended count2 super admins minimum, 3 maximum for most tenants
Better defaultA delegated role scoped to the task
Hard requirementTwo-step verification on every admin account

Grant it, then constrain it

Open the user in Directory, choose admin roles and privileges, and assign Super Admin. Confirm two-step verification is already enforced on that account first, because an unprotected super admin is the single highest-value target in the tenant.

Allow up to 24 hours before assuming the grant failed. Console access usually appears within minutes, while some service-level privileges lag noticeably behind.

Why a delegated role is usually the correct answer

Most requests for super admin are actually requests to reset passwords, manage groups or read a report. Each of those exists as a delegated privilege that can be scoped to an organizational unit, and granting it leaves the blast radius small.

Keep one break-glass super admin that nobody uses daily, with its credentials held offline. Every real recovery we have performed depended on that account existing before the incident, not on adding admins afterwards.

  • Enforce two-step verification before granting any admin role.
  • Prefer a scoped delegated role over full super admin.
  • Keep a break-glass super admin out of daily use.

What we see that others don't say

In the security reviews we run, tenants with more than three super admins are the norm rather than the exception, and in almost every case each extra admin needed only one delegated privilege.

What this doesn't cover

  • Super admin covers Workspace administration, not Google Cloud IAM, which is granted separately.
  • We advise on role design; approving who holds administrative access remains the client's decision.

Questions we get asked

How many super admins should a tenant have?
At least two so a single lost account cannot lock you out, and rarely more than three. Beyond that, use delegated roles scoped to the specific task and organizational unit.
Why has the role not taken effect yet?
Role changes propagate for up to 24 hours across services. Console access typically appears in minutes, so a partial grant is normal rather than a sign of failure.

How this page is verified

Reviewed by Pearl Lemon Cloud security desk, Workspace security and compliance reviewers. Last checked .

  • Click path and propagation notice checked in the current Google Admin console at the review date.
  • Admin count guidance drawn from security reviews of tenants between 40 and 500 seats.

Sources you can check

Related pages

Too many admins and no break-glass account?

A security review returns a role design with delegated privileges, a protected recovery account and a list of the grants to remove.