View user security settings and revoke access

This feature is not available in the legacy free edition of Google Apps.

You can view the security settings for a particular user in the Google Admin console. You can also revoke access to third-party services and security keys if needed. In particular, you can:

Security settings overview

To access a user's security settings:

  1. Sign in to the Google Admin console.
  2. Click Users.
  3. Click the user whose security settings you want to access.
  4. Click Security. You may need to click Show more to see the Security section.

2-Step Verification

Determine if the user has enabled 2-Step Verification at the top. You can disable 2-Step Verification by clicking Turn off 2-step verification.

If 2-Step Verification is enabled, the user's backup verification codes are also available and can be displayed by clicking Show backup verification codes. See Sign in using backup codes to help users with these codes.

Password strength

In this section, you can verify the user's password strength. See Set password strength and user password recovery for instructions on changing password requirements.

Security keys

View the security keys enrolled by the user. See Add a Security Key to your Google Account to help users with these keys.

Order a discounted security key by logging in using your Google Apps account.

If you unenroll a security key, the user will not be able to use it for 2-Factor Authentication. To unenroll a key, click Revoke and then click OK. The Admin console audit log adds an entry each time you revoke a security key.

Note: The security key feature is available only with Google Apps Unlimited or Google Apps for Education.

Application specific passwords

Here, you can see any application-specific passwords created by the user. See Sign in using App Passwords to help users set them up.

If you want to remove a password, click Revoke and then click OK.

Authorized access

In this section, you can see the third-party services that have access to the user's Google Apps account. See How authorized access works to understand how this authorization is enabled.

The column for Service identifies what applications your users have granted access to their Google Apps data. The Scope of access column specifies the user data that the service can access. A user can grant full access or access to specific Google Apps.

To remove access to a service, click Revoke > OK. You can only revoke service access after it's been granted. You can't preemptively block users from granting access to certain apps. See Remove App Passwords to help users remove their own passwords.

Temporarily disable a Login Challenge

If Google Apps detects that an unauthorized person is attempting to access a user's account, it presents them with a Login Challenge before granting access to the account. The user must verify their identity by entering a verification code that Google Apps sent to their phone or by answering some other challenge that only the authorized user can resolve.

Click Disable Login Challenge if the authorized user can't verify their identity. The Login Challenge will be disabled for a period of 10 minutes to allow the user to sign in.

Was this article helpful?