Delegate administrator roles in Chrome

If your organization needs multiple Chrome administrators, you can create administrator roles in your Google Admin console. Administrator roles let you grant administrators access to settings they need while blocking access to settings they don't need.

Delegated administrator icon

With delegated administration for Chrome devices, you can grant users permissions specific to their roles. For example, you can let teachers create new users and set passwords for students, without giving them management access to all the devices in your school district. You can also give a manager administrative access to configure the email settings of their direct reports, without giving Super Admin permissions over your entire domain.

About administrator roles and privileges

These settings give you more control of what other administrators in your organization can do. These settings can limit administrator access to specific Chrome Management tabs in the Admin console.

To change Chrome privileges for an administrator role:

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in

  2. From the Admin console Home page, go to Admin roles.

    To see Admin roles, you might have to click More controls at the bottom. 

  3. On the left, click the role you want to change.
  4. On the Privileges tab, check boxes to select each privilege you want users with this role to have.
    1. For Chrome OS, go to Admin Console Privileges and then Services and then Chrome OS.
    2. For Chrome browser, go to Admin Console Privileges and then Google Chrome Management.
  5. Click Save changes.
Setting What permissions it gives to delegated administrators Applies to Can be delegated by OU
Manage Devices READ and WRITE access to Devices. Chrome OS Yes
Manage User Settings READ and WRITE access to User Settings for the organizational units for which the administrator has privileges. Chrome OS and Chrome browser Yes
Manage Application Settings READ and WRITE access to the Apps and Extensions section of User Settings for the organizational units for which the delegated admin has privileges. This is a subcategory of User Settings, so all admins who can manage User Settings can also manage Application Settings.* Chrome OS and Chrome browser Yes
Manage Device Settings READ and WRITE access to Device Settings for the organizational units for which the delegated admin has privileges. Chrome OS Yes

*Use Manage Application Settings if you want to give a teacher the ability to preinstall and manage applications for his students without giving him access to all of the permissions under User Settings.

For more about delegated administration roles, see Administrator privilege details.


  1. If you haven’t already, create organizational units in G Suite. These can be groupings such as schools and classrooms, or business subsidiaries and offices.
  2. Follow these instructions to grant administrator privileges to users in your organization.

Once you’ve assigned privileges, do the following to see which roles your user has been assigned.

  1. In your Admin console, click Users and click on the name of a user.
  2. Scroll down and click Show more at the bottom.
  3. Click Admin roles and privileges to see the privileges that user has.
If you choose a setting that isn't manageable by suborganization (such as Shipments), when you assign roles, you won't be able to choose a suborganization. For example, if an admin role only manages User Settings, you can assign it to a teacher for an organizational unit called "Classroom A". But if that role also manages Shipments, you won't be able to assign it to only your "Classroom A" organizational unit because the Shipments page currently doesn't support privileges by organizational units.

Related topics

Was this article helpful?
How can we improve it?