Overview
By default, Google Workspace allows users and administrators to reset their own passwords without additional verification. Disabling this means accounts must go through a more secure recovery process if access is lost, reducing the risk of account takeover through self-service recovery.
Prerequisites
Super Admin access to the Google Admin console
Instructions
Sign in to the Google Admin console
Navigate to Security > Authentication > Account recovery
Under Super admin account recovery, toggle the setting to Off
Under User account recovery, toggle the setting to Off
Save your changes
โ
โ ๏ธ Once disabled, anyone locked out of their account will not be able to recover access on their own. Make sure your organization has a process in place for account recovery before making this change.
