IT Admin Change Calendar Google Workspace
Multi-party approvals available for sensitive Admin console actions
Google Workspace can require a second admin to approve sensitive Admin console actions such as 2SV and account-recovery changes; off by default.
Product
Google Workspace (Admin console)
Announced
9 April 2024
Effective from
9 April 2024
Who is affected
Organizations on eligible editions that want to prevent a single admin from unilaterally changing sensitive security settings.
Admin roles to involve: Google Workspace super admin, Security admin
Why no action is required
Optional security hardening. On eligible editions, turn on multi-party approvals so a second super admin must approve sensitive changes — 2-Step Verification, account recovery, Advanced Protection, Google session control, login challenges, and passwordless settings. It is off by default and configured in the Admin console. Available on Enterprise Standard/Plus, Education Standard/Plus, and Cloud Identity Premium.
What happens if this is ignored
None required — without it, sensitive security changes can still be made by a single admin, so the extra safeguard simply goes unused.
Official source
Protect sensitive admin actions with multi-party approvals
Published by Google · Source dated 9 April 2024 · Checked 24 August 2026
Last verified 24 August 2026
Related changes
- Users can request admin access to blocked unconfigured third-party apps (14 August 2025)
- Gmail enforces authentication requirements for bulk senders (1 February 2024)
- Less secure apps and Google Sync password-only access turned off (15 June 2024)