Skip to main content

Block Self-Service Account Recovery in Google Workspace

How to require additional verification for password resets for both admins and standard users in Google Workspace.

Written by Kavi Harshawat

Overview

By default, Google Workspace allows users and administrators to reset their own passwords without additional verification. Disabling this means accounts must go through a more secure recovery process if access is lost, reducing the risk of account takeover through self-service recovery.

Prerequisites

  • Super Admin access to the Google Admin console

Instructions

  1. Sign in to the Google Admin console

  2. Navigate to Security > Authentication > Account recovery

  3. Under Super admin account recovery, toggle the setting to Off

  4. Under User account recovery, toggle the setting to Off

  5. Save your changes
    โ€‹

โš ๏ธ Once disabled, anyone locked out of their account will not be able to recover access on their own. Make sure your organization has a process in place for account recovery before making this change.

Did this answer your question?