Administrator privilege definitions

When you assign an admin role to a user in the Google Admin console, you grant them administrator privileges and access to the Admin console.

The role's privileges determine the admin's controls in the Admin console, information they can access, and tasks they can perform. Admins can also perform corresponding actions in the Admin API.

Assign roles now Create a custom role

Administrator privileges

* Note: Some privileges, such as Jamboard Management, are available only with certain editions of G Suite, hardware, or user licenses.

Admin settings privileges Services privileges  
 

Admin privileges definitions

OPEN ALL | CLOSE ALL

Organizational units

Admins with this privilege can manage your account's organizational structure from the Users page in their Admin console. Also grants the corresponding Admin API privileges (below).

Organizational units rights:

  • Read
  • Create
  • Update
  • Delete

The Create, Update, or Delete privileges automatically grants the Read privilege.

You can allow admins to perform actions on all users in your account or only on users in specific organizational units. Learn more about assigning administrator roles to a user.

Users

Admins with the Users privilege can perform actions on users. Only super admins can change another admin's settings. Also grants the corresponding Admin API privileges (below).

  • Create
  • Read
  • Update
    • Move users
    • Suspend users
    • Rename users
    • Reset password
    • Force password change
    • Add/remove aliases 
  • Delete

The Create privilege automatically grants Read and Update privileges. Update or Delete privileges automatically grant Read privilege.

You can let admins perform actions on all users in your account or only users in specific organizational units. For details, see Assign user management roles.

Tip: To let admins view a user's groups but not edit them, give them the API privilege by clicking Groupsand thenRead API privilege.

Security

User security management

Note: Only super admins can see another admin's security settings.

Admins can manage security settings for individual users. They can only manage users who don't have admin privileges. Also grants the corresponding Admin API privileges (below).

On a person's Users page, admins with the User security management privilege can:

  • Disable 2-Step Verification. Only super administrators can enforce 2-Step Verification for the entire organization.
  • Disable the sign in challenge for 10 minutes.
  • Review and revoke security keys.
  • Review and revoke app passwords.
  • Reset sign-in cookies (not for reseller admins).
  • Review and revoke any 3-legged OAuth tokens the user granted to third-party apps.

All of these actions can be limited to specific organizational units, except enforcing or disabling 2-Step Verification.

Security settings

  • Allow less secure apps to access accounts
  • Monitor user passwords
  • Set up single sign-on (SSO) and authentication

Allowing less secure apps to access accounts is the only action that can be limited to specific organizational units.

Groups

Admins with the Groups privilege have full control over groups created in your Admin console. Also grants the corresponding Admin API privileges (below).

Administrators with this privilege can:

  • View user profiles and your organizational structure.
  • Create, manage, and delete groups in the Admin console.
  • Manage group access settings.
  • Turn on services for access groups (also requires privileges for Organizational units and Services). For details, see Customize service settings with configuration groups.

These actions can't be limited to specific organizational units.

Tip: To let admins view the groups a user belongs to but not edit them, give them the Groupsand thenRead API privilege.

Domains settings
Admins with the Domains settings privilege can:
  • Change the organization name, language, logo, and time zone.
  • Delete your G Suite or Cloud Identity Account.
  • View billing for your G Suite or Cloud Identity Account.
  • Add and remove domains and domain aliases.
  • Map a custom URL to a site in Google Sites.
  • Update contact information for password recovery.
  • Manage your feature release process.
  • Choose the types of email you get from Google. For details, see Set communications preferences for G Suite.

These actions can’t be limited to specific organizational units.

Reports

Admins have access to usage reports and audit logs. For details, see Reporting tools overview.

Admins with the Reports privilege can:

  • View graphs showing service use.
  • Track user activities such as document edits.
  • Track changes made by other admins in the Admin console.

These actions can’t be limited to specific organizational units.

Support

Admins with the Support privilege can use phone, chat, and email options to contact G Suite support. 

The ability to contact G Suite support can't be limited to specific organizational units.

Admin API

Granting privileges to a user in the Admin console gives them corresponding rights in the API. For example, granting the right to create users in the Admin console also lets admins create users using the API. Likewise, updating Admin API rights updates corresponding rights in the Admin console.

To grant rights in the Admin console without allowing admins to perform actions in an API, turn off API access for your account. For details, go to Control which third-party & internal apps access G Suite data.

The Admin API privilege allows the G Suite Admin API to perform actions on:

  • Organizational units
  • Users
  • Groups
  • User-security management
  • Data transfer—Super admins or services admins can transfer ownership of users' Drive files using the Admin console. Admins also need the Drive Services privilege to access the Transfer ownership setting in the console. None of these actions can be limited to specific organizational units.
    Note: Only super admins can transfer file ownership when deleting a user.
  • Schema management—Super admins or services admins can create schemas to define custom fields for their domain, such as user projects, locations, or hire dates.
  • License management—Super admins can assign and manage G Suite licenses for the organization, an organizational unit, a group of users, or an individual user. Note: This privilege works only in the Admin console and authorizes only super admins to use the License Manager API.
  • Billing management
  • Domain management—Admins can add or remove domains and set up domain aliases.

If you create a custom role, you can check the box next to the privilege to allow using the API to perform all actions on that object. Or, click individual actions (such as Create or Read) to permit only selected actions.

Services privileges

Open all | Close all

Service Settings

Admins with the Service Settings privilege can:

  • Turn services on or off and change service settings and permissions—applies for certain products you've added to your account (G Suite services, such as Calendar, and Drive), Marketplace apps, and free Google services, such as YouTube and Blogger.
  • Create custom web addresses for services
  • Manage Chrome and mobile devices already in the Admin console.

Note: Selecting the Service Settings privileges does not automatically grant privileges to: 

  • Chrome management
  • Data security
  • Google Cloud Print
  • Google Vault
  • Managed Google Play
  • Secure LDAP
  • Security center
  • Shared device settings
  • Work Insights
  • Some settings for Gmail and Currents (Google+), Data Loss Prevention (DLP), and AppMaker
Alert Center

For description of privileges and recommendations for creating roles, go to admin privileges for the alert center.

App Maker

Admins can view reports about all App Maker apps in your organization.

This privilege is automatically selected with the Service Settings privilege.

Calendar

Admins with the Calendar privilege can create, edit, and delete resources. They can't modify the sharing settings of Google Calendar resources.

Calendar management rights:

  • All Settings—Admins can access and manage sharing settings, resources, the Room Insights Dashboard, and general settings.
  • Buildings and Resources—Admins can create, edit, and delete calendar resources and access the Room Insights Dashboard.
  • Room Insights—Admins can view, set filters, and adjust the date range on the Room Insights Dashboard.

This privilege is automatically selected with the Service Settings privilege.

Chrome Management

These privileges are available only if you have users with G Suite Enterprise or Enterprise for Education licenses.

Admins can manage your organization’s Chrome devices and policies, including:

  • User settings
  • Device settings
  • Chrome and Managed Google Play apps and extensions on Chrome devices

For more information, go to Delegate administrator roles in Chrome.

Cloud Search

Admins with the Cloud Search privilege can:

  • Grant user access to Google Cloud Search.
  • Turn the service on or off.
  • View reports on how the organization uses Cloud Search, including the number of search queries from different types of devices and the number of active users.
  • Manage settings for third-party repositories, such as settings for data sources, identity sources, and search applications. Admins also have read or write access for indexing.

Granting access to Settings automatically grants privileges to Cloud Search Indexing and Cloud Search Indexing Read Only.

This privilege is not automatically selected with the Service Settings privilege.

Google+ (Currents)

Admins privileges for Google+ (Currents):

  • Settings—Manage settings for Google+.
  • Batch-add user groups to communities—Admins can add users directly Google+ communities.

Only the Settings privilege is automatically selected with the Service Settings privilege.

Data Security

Admins with this privilege can manage the organization's context-aware access policies. Admins can control the apps a user can access based on their context, such as their location or whether their device complies with your organization's policies.

Data Security management rights:

  • Access level management—Admins can create access levels.
  • Rule management—Admins can turn on or off context-aware access and to assign access levels to apps.

This privilege is not automatically selected with the Service Settings privilege.

Data Studio

Admins with this privilege can manage Google Data Studio settings, including viewing, sharing, and customizing dashboards and reports. Learn more about Data Studio.

This privilege is automatically selected with the Service Settings privilege.

Directory Settings

Admins can manage settings and control Directory profile changes to let users make changes to their profile, including their name, photo, gender, and birthday.

This privilege is automatically selected with the Service Settings privilege.

Drive & Docs

Google Drive and Docs management rights:

  • Settings—Admins can manage all settings for your organization's Drive and Docs services. You need this privilege and the Data Transfer privilege to transfer ownership of Drive files. For details, see Transfer Drive files to a new owner.
  • Docs templates—Admins can remove and categorize templates in the Docs, Sheets, Slides, and Forms template galleries and in the Drive and Docs section of the Admin console. When template submission is set to Moderated in the Admin Console, admins can accept or reject template submissions. When submission is set to Restricted, admins can add templates to the gallery. For details, see Create custom Drive templates.
  • Move any file or folder into shared drives—Admins can move files and folders into shared drives in your organization.
  • Manage Metadata Categories—Admins can create custom metadata categories for Drive files and folders. Drive metadata is currently in Beta, and the Help is not yet available in all languages. For details, see Manage Drive metadata (beta).
  • View details of New Google Sites—Admins can identify the owner of a site, see the date the site was last published, and request edit access to the site.

Only the Settings privilege is automatically selected with the Service Settings privilege.

Data loss prevention (DLP)

Data loss prevention (DLP) privileges:

  • View DLP rule—Admins can view but not modify or create DLP rules.
  • Manage DLP rule—Admins can view, modify, and create DLP rules.

You must enable both of these privileges to have complete access for creating and editing rules. We recommend you create a custom role that has both privileges.

These privileges are not automatically selected with the Service Settings privilege.

Gmail

Gmail management rights:

  • Settings—Manage all Gmail settings for your organization.
  • Email Log Search—Search the log, troubleshoot delivery, and investigate security issues associated with emails.
  • Access Admin Quarantine—Access and manage emails in all quarantines, including the default quarantine.
  • Access restricted quarantines—Access and manage emails only in quarantines associated with groups the admin belongs to.

Only the Settings privilege is automatically selected with the Service Settings privilege.

Google Cloud Print

Admins with this privilege can set up and manage Google Cloud Print services for their organization, including printing from:

  • Chrome devices and Chrome Browser on Windows®, Mac®, and Linux® computers
  • The mobile version of G Suite services, such as Gmail
  • Third-party native mobile apps

For details, see Google Cloud Print services.

This privilege is not automatically selected by the Service Settings privilege.

Google Meet

Admins with this privilege can:

This privilege is automatically selected with the Service Settings privilege.

 Hangouts Meet and Google Hangouts

Admins with this privilege can: 

This privilege is automatically selected with the Service Settings privilege.

Google meeting room hardware

This privilege is not available unless your account has at least one Google meeting room hardware license or enrolled device.

Admins can create user roles and assign privileges to specific Google meeting room hardware devices with or without Calendar privileges.

Users with the Chrome devices for meetings with Calendar privilege have full access to users' calendars. They can:

  • Read or write events.
  • Manage permissions of all calendars (primary, secondary, and resource) in the organization.
  • Delete any calendars in the organization.

After you assign this privilege to a user, it can take up to 24 hours for the Calendar privileges to be available.

Google Vault

Admins can view all matters and manage matters, holds, searches, exports, retention policies, and audits. For details, see Understand and grant Vault privileges.

This privilege is not automatically selected with the Service Settings privilege.

Google Chat

Admins can read and modify settings for Google Chat, such as saving conversations and allowing conversations with people outside or your organization.

This privilege is automatically selected with the Service Settings privilege.

Jamboard Management
Admins with this privilege can perform tasks such as view and edit Jamboard settings and set up devices.

This privilege is automatically selected with the Service Settings privilege.

Managed Google Play

This privilege is also listed as "Google Managed Play". Admins with this privilege can:

  • Distribute Android apps internally to users.
  • Upload private apps to the Google Play store.
  • Use Android app packages (APKs) hosted outside of Google Play.
Mobile device management

Admins with this privilege have full control over mobile devices listed in your Admin console, and can:

  • Manage mobile settings.
  • Manage device policies.
  • Perform all management operations, such as activate, block, delete, and wipe.

This privilege is automatically selected with the Service Settings privilege.

Security center

The security center is available with G Suite Enterprise, G Suite Enterprise for Education, G Suite Essentials, and Cloud Identity Premium editions.

Admins with this privilege have access to advanced security information and analytics and added visibility and control into security issues affecting their organization.

Super Admins have automatic access to all security center features, including the security dashboard, the security health page, and the investigation tool. You can give admins access to a specific security center feature (for example, just the security dashboard) by granting them the administrative privileges needed to access that feature. 

For instructions on setting up these privileges, see Admin privileges for the security center

Shared device settings

Admins with this privilege can manage all common device configurations. They can set up Virtual Private Network (VPN), Wi-Fi, and Ethernet networks for mobile, Chrome, and Chromebox for meetings devices.

This privilege is not automatically selected by the Service Settings privilege.

Work Insights

These privileges are available only if you have users with G Suite Enterprise or Enterprise for Education licenses.

Admins can access data on the Work Insights dashboard. Data is available only for teams that have Work Insights turned on. For details, see Control which data is available in Work Insights.

You can let users view data for all available teams or just specific teams, including organizational units, authorized groups, or teams in a manager's reporting line. For the list of privileges, see Grant access to Work Insights.

This privilege is not automatically selected by the Service Settings privilege.

Was this helpful?
How can we improve it?