Set up password recovery for users
As your organization's administrator, you can choose how to let users who aren't administrators and non-super administrators get back in to their account if they forget their password:
Option 1: Let users reset passwords themselves
This feature isn’t available if you’re running single sign-on (SSO) or G Suite Password Sync. It also doesn’t work for users under the age of 18. See details below
You can let users who aren't super admins reset their own passwords without having to contact an administrator. Each user has to add a recovery phone number or email address to their account where they can receive recovery instructions via voice, text message, or email. They can then reset their password by entering their Google Account address and following automated instructions.Turn on non-admin password recovery
By default, only super admins can reset a forgotten password using the automated system. Here's how to let other users and non-super admins do this, too:
From the Admin console Home page, go to SecurityBasic settings.
To see Security on the Home page, you might have to click More controls at the bottom.
- Under Password recovery, click Enable/disable non-admin user password recovery.
This link isn't available if your organization is running SSO or G Suite Password Sync.
- Under Password recovery, check Enable non-admin user password recovery.
- At the bottom, click Save.
- Tell users to set up a recovery phone number or email address where they can receive password recovery instructions (via voice, text message, or email).
G Suite for Education users under the age of 18 can't add contact information to their account. They therefore can't recover their password this way. Instead, they have to contact an administrator.Immediately remove a user's recovery information when they leave your organization or if their account might be hijacked. See details below.
Now, if any user in your organization clicks Forgot password? on the sign-in page, they see instructions on recovering their own password. If they've added a recovery phone number or email address to their account and answer questions correctly, they can reset their own password.
2-step verification: Users with 2-step verification can also follow these steps to reset their own password. However, they can only reset their password using their recovery email. If they haven't added recovery information or don't answer questions correctly, they're told to contact an administrator.
If you turn on non-admin password recovery, immediately remove a user's recovery information if...
- The user is terminated or leaves your organization. That way they can’t recover their password to access their old account.
- You suspect the account has been hijacked and the user’s recovery information is no longer legitimate.
To remove a user’s recovery information or check if it’s been hacked, sign in to the account as the user. Then follow steps at Set up a recovery phone number or email address.
- G Suite for Education users under the age of 18—Younger G Suite for Education users aren’t permitted to add a recovery phone number or email to their account. They can't reset a forgotten password on their own.
Note: Users of any age with primary or secondary education accounts can't supply a recovery phone number or email. The option to add a phone number or email is disabled for these types of accounts.
Only users with Higher Education accounts, administrators, and teachers using G Suite for Education can supply a recovery phone number or email.
- Organizations using SSO or GSPS—If your organization is running single sign-on (SSO), you won’t see the enable non-admin user password recovery option in your Admin console. If your organization is running G Suite Password Sync for Active Directory (GSPS) and you've prevented users from changing their G Suite passwords, users are redirected to Active Directory to reset their passwords. This keeps their Active Directory passwords in sync with G Suite.
Option 2: Ask users to contact an administrator
If a user clicks Forgot password? on the sign-in page, and you haven't turned on non-admin password recovery, they see a message to contact their administrator. Make sure you've provided a way for users to contact an administrator if they can't sign in to their account.
See also Reset a user's password.