IT Admin Change Calendar Google Workspace

Multi-party approvals available for sensitive Admin console actions

Google Workspace can require a second admin to approve sensitive Admin console actions such as 2SV and account-recovery changes; off by default.

MediumAdmin control changeAwareness onlyIn effectVerified

Product

Google Workspace (Admin console)

Announced

9 April 2024

Effective from

9 April 2024

Who is affected

Organizations on eligible editions that want to prevent a single admin from unilaterally changing sensitive security settings.

Admin roles to involve: Google Workspace super admin, Security admin

Why no action is required

Optional security hardening. On eligible editions, turn on multi-party approvals so a second super admin must approve sensitive changes — 2-Step Verification, account recovery, Advanced Protection, Google session control, login challenges, and passwordless settings. It is off by default and configured in the Admin console. Available on Enterprise Standard/Plus, Education Standard/Plus, and Cloud Identity Premium.

What happens if this is ignored

None required — without it, sensitive security changes can still be made by a single admin, so the extra safeguard simply goes unused.

Why this is rated medium: severity comes from a fixed rubric — this entry is a admin control change that requires no administrator action. Time-to-deadline is shown separately and never changes the rating.

Official source

Protect sensitive admin actions with multi-party approvals

Published by Google · Source dated 9 April 2024 · Checked 24 August 2026

Last verified 24 August 2026