Skip to main content

🛡️ Google Super Admin Email Address is tied to a single user🟢⚪

  • Contextual name: 🛡️ Super Admin Email Address is tied to a single user🟢⚪
  • ID: /ce/ca/google/iam/super-admin-email-not-tied-to-single-user
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY

Description

Open File

Description

Assign the Google Workspace or Cloud Identity Super Admin role to a dedicated administrative account, such as gcp-superadmin@company.com, rather than to an individual user's email address.

Rationale

Super Admin accounts have broad administrative authority over Google Workspace, Cloud Identity, and organization-level settings. Using a dedicated account reduces dependency on a single employee, separates privileged administration from day-to-day user activity, and supports stronger controls such as hardware security keys and restricted session policies.

Impact

Creating a dedicated Super Admin account requires coordination with Google Workspace or Cloud Identity administrators. Existing individual user accounts should be removed from the Super Admin role after the dedicated account is configured and validated.

Audit

From Google Admin Console
  1. Open the Google Admin Console at https://admin.google.com.
  2. Go to Account > Admin roles.
  3. Open the Super Admin role.
  4. Review the assigned users.

... see more

Remediation

Open File

Remediation

From Google Admin Console

  1. Open the Google Admin Console at https://admin.google.com.
  2. Go to Directory > Users.
  3. Create a dedicated Super Admin account.
  4. Configure strong authentication for the dedicated account, such as 2-Step Verification with a hardware security key.
  5. Go to Account > Admin roles.
  6. Open the Super Admin role and assign it to the dedicated account.
  7. Remove individual user accounts from the Super Admin role after confirming the dedicated account works as expected.

policy.yaml

Open File

Linked Framework Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS GCP v5.0.0 → 💼 1.1.1 Ensure Super Admin Email Address Is Not Tied To A Single User - Level 1 (Manual)1no data
💼 Cloudaware Framework → 💼 General Access Controls23no data