Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

One IT Member with Full Admin Rights: Narrowing Privileges by Department

Table of contents · 5 items

"In our Admin console, only two accounts have full super admin rights: myself and a former executive. Nobody uses the executive's account anymore, but we left it alone because we were afraid to delete it." We received this consultation from the IT lead at a company with around 60 employees. While key responsibilities become siloed due to having too few administrators, unused privileged accounts are left unmonitored, and external vendors retain broad privileges granted for maintenance tasks. This setup may look managed on the surface, but it is actually the most prone to security incidents. If a single privileged account is breached, the damage spreads across the entire company.

Google Workspace provides a framework to assign administrator privileges strictly where needed and within necessary boundaries. In July 2026, this capability was expanded to allow mobile device management (MDM) privileges to be delegated by organizational unit (OU), which was previously difficult. In this article, we explain why all-inclusive admin accounts are dangerous and how to partition roles effectively, from the perspective of an organization planning its setup.

Three risks of all-inclusive super admin accounts

Consolidating all access under a single super admin creates several simultaneous vulnerabilities:

  • Blast radius during account takeover: If that account is breached, the attacker gains the power to do anything, from viewing every user's email to exfiltrating data and deleting accounts.
  • Insider fraud and operational errors: Beyond intentional data exfiltration, accidents like accidentally modifying unintended settings become more frequent the broader the assigned privileges are.
  • Audit findings: Security assessments from clients and ISMS audits almost always check whether least privilege is enforced and whether privileged accounts are regularly reviewed.

The first point in particular, alongside offboarding processes for departing employees, is among the first items inspected during security assessments. An abandoned executive privileged account, as mentioned earlier, represents an ideal entry point for attackers.

July 2026 changes: delegating privileges by organizational unit

In addition to default roles (such as User Management Admin and Help Desk Admin), Google Workspace administrator roles allow you to create custom roles bundling only the required permissions. Crucially, you can assign that role scoped to a specific organizational unit (OU) rather than the entire organization. You can create a restricted administrator who can only reset passwords for users belonging to the Osaka branch OU.

With the July 2026 update, mobile device management privileges—which were previously manageable only domain-wide—can now also be delegated per OU. For example, management of smartphones and tablets distributed to individual retail stores can now be delegated to the store manager for their store's devices alone. You can transition from a structure where the IT team shoulders all company devices to one where scoped authority is delegated to personnel closer to the frontline. This approach works hand-in-hand with BYOD and endpoint management design.

Deciding who gets what access

While role division varies by company, typical delegation patterns in small and medium-sized businesses can be structured as follows:

RecipientScope of Granted Privileges
Help desk staff / General affairsDay-to-day operations only, such as password resets and group additions. Configuration changes and data viewing are prohibited.
Branch and store leadersManagement of users and devices within their own OU only. Other departments are invisible.
External operations vendorsRequired privileges granted for a limited time during tasks, then revoked immediately upon completion.
IT team (super administrators)Restricted to the absolute minimum number of people. Mandatory 2-step verification and regular auditing for all.

The crucial principle is to avoid granting broad privileges simply for convenience. Staff whose daily duties only require password resets do not need access to read company-wide data. The narrower the privileges, the smaller the blast radius if an account is breached and the lower the risk of accidental mistakes.

Operations to keep delegation running securely

Delegating privileges is not the end of the job. You need mechanisms to continuously monitor whether delegated privileges are used appropriately. Configure audit logs and alerts in the Admin console to track who performed which admin actions and when, allowing you to catch unexpected privilege use. In addition, review active permissions quarterly to verify whether individuals still require their assigned access, revoking roles made obsolete by resignations or transfers. Removing unused privileged accounts like the abandoned account mentioned earlier directly shrinks your attack surface.

Designing administrator privileges is a defensive foundation that delivers lasting protection once established. If you are concerned about super admin rights concentrated in one person, external vendors holding onto strong permissions, or old administrator accounts left undeleted, please reach out to GleamHub's Google Workspace operational support and IT consulting. We will work with you to design least-privilege roles and establish review routines tailored to your organizational structure.

Sources

Share this articleXFacebook
Kakeru Suzuki

Fascinated by the possibilities of technology, has had a deep interest in programming and digital art since student days

Turn this article's theme into your company's next step

The right way forward with Workspace for your company.

We organize data to migrate, sharing rules, and governance structures to map out the journey from implementation to daily operations.

  • Migration and initial setup
  • Sharing and permission organization
  • Governance structure
Consult on Workspace implementation and operations

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles by email