Instiq

Google Cloud Associate Google Workspace AdministratorStudy guide

The associate certification for daily administration of Google Workspace users, services, security, and compliance (Associate Google Workspace Administrator).

About Google Cloud Associate Google Workspace Administrator (GCP-AGWA)

Google Cloud Associate Google Workspace Administrator (GCP-AGWA) is a Associate-level certification from Google Cloud. This page organizes the exam scope into a 6-chapter, 12-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Managing user accounts, domains, and Directory~20%
  • Managing core Workspace services~22%
  • Managing data governance and compliance~15%
  • Managing security policies and access controls~20%
  • Managing browsers and endpoints~10%
  • Monitoring and troubleshooting common issues~13%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://cloud.google.com/learn/certification/associate-google-workspace-administrator

1Managing users, domains, and the directory

  • 1.1User provisioning and the directory

    Understand the methods to create Google Workspace user accounts (individual, bulk via CSV, Directory Sync (GCDS)/SSO federation, API/automation) and when to use each, domain and DNS verification (MX, SPF, DKIM, DMARC), and managing the organization directory (the scope of shared contacts and information).

  • 1.2Organizational units, groups, and admin roles

    Understand organizing users with the organizational unit (OU) hierarchy to differentiate policies/services, managing permissions/distribution/sharing in bulk via groups, and delegating admin roles (super admin and predefined/custom admin roles) with least privilege.

2Managing core services

  • 2.1Configuring core services (Gmail, Drive, Calendar, Meet)

    Understand configuring core services per OU/group: Gmail routing and compliance (routing rules, attachment limits), Drive sharing and storage, Calendar resources (rooms) and sharing, and Meet meeting policies (recording, participant controls).

  • 2.2Service on/off and managing additional apps

    Understand turning core/additional Google services on/off per OU or group, controlling access for Marketplace and third-party apps (API access, allow/block connected apps), and governing external sharing and integrations per organizational policy.

3Data governance and compliance

  • 3.1Data retention and eDiscovery (Vault)

    Understand Google Vault retention rules (retain data for a period / delete after it), holds (preserve specific users data), eDiscovery via search and export, and the precedence of retention vs deletion (a hold overrides deletion).

  • 3.2Data protection and compliance (DLP, data regions)

    Understand data loss prevention (DLP) rules to detect sensitive data (e.g., credit card numbers) and block sharing, data regions to control storage location geographically, trust rules to govern sharing with external organizations, and classification with labels.

4Security policy and access control

  • 4.1Strengthening authentication (2-step verification, SSO)

    Understand enforcing 2-step verification (2SV) and stronger methods (security keys/passkeys), SAML SSO federation with an external IdP, password policy (length, reuse, strength), and configuring secure account recovery.

  • 4.2Access control and security response

    Understand context-aware access to control access by device/location/IP, the security dashboard and alert center to understand and respond to threats, blocking less secure apps, and operations to protect accounts during compromise.

5Managing browsers and endpoints

  • 5.1Chrome browser management

    Understand centralized policy with Chrome Browser Cloud Management, allowing/blocking and force-installing extensions, browser security settings, and differentiating policy per OU.

  • 5.2Endpoint (device) management

    Understand the difference between basic and advanced endpoint management for mobile/PC, handling company-owned vs personal (BYOD) devices, on-device data protection (screen lock, encryption, remote wipe), app management, and lost-device response.

6Monitoring and troubleshooting

  • 6.1Reports and audit logs

    Understand using Admin console reports (usage, security) and audit logs (admin actions, login, Drive, Gmail activity), exporting logs to BigQuery for long-term analysis, and tracking "who did what, when."

  • 6.2Troubleshooting (mail delivery and investigation)

    Understand tracking delivery with Email Log Search, analyzing message headers, investigating incidents and taking bulk action with the investigation tool, and isolating typical access/sync/sharing problems.