Instiq
Chapter 1 · Managing users, domains, and the directory·v1.0.0·Updated 6/15/2026·~14 min

What's changed: Created Associate Google Workspace Administrator Chapter 1 (Domain 1 "Users/domains/directory": provisioning and directory = individual/bulk CSV/GCDS/SCIM-API, DNS verification, MX, SPF/DKIM/DMARC; OUs/groups/admin roles = OU hierarchy and policy inheritance, groups, delegation of super admin/predefined/custom roles with least privilege).

1.2Organizational units, groups, and admin roles

Key points

Understand organizing users with the organizational unit (OU) hierarchy to differentiate policies/services, managing permissions/distribution/sharing in bulk via groups, and delegating admin roles (super admin and predefined/custom admin roles) with least privilege.

Beyond creating users, how you organize them and who you delegate to is central to operations. The units of organization are OUs and groups; the unit of delegation is admin roles.

1.2.1Organizational units (OUs) and groups

An organizational unit (OU) organizes users in a hierarchy. You can differentiate policies and service on/off per OU, and settings inherit from parent OUs (e.g., disable a specific service only for the Sales OU). A group, by contrast, bundles a mailing list, sharing, and permission grants together, and is not used for hierarchical policy differentiation. Distinguish "differentiate policy/service by hierarchy = OU" from "bundle distribution/sharing/permissions = group."

1.2.2Admin roles and delegation

The super admin is the top role that can do everything—limit it to the fewest people. For daily operations, assign purpose-specific predefined admin roles (e.g., User Management Admin, Help Desk Admin, Groups Admin) or a custom admin role with only the needed privileges, delegating with least privilege. You can also scope a role to specific OUs. Map "all-powerful super admin = keep minimal" and "daily delegation = predefined/custom roles with least privilege."

Exam point

Common: requirement → means. E.g., "enable/disable a service per department" = OU; "grant a distribution list, sharing, or permissions in bulk" = group; "let the help desk only reset passwords" = predefined/custom admin role (least privilege); "keep all-powerful access minimal" = limiting super admins.

Warning

Watch the mix-ups: (1) OUs inherit policy by hierarchy while groups bundle permissions/distribution—different roles (do not differentiate services via groups). (2) Do not over-grant super admin. (3) Delegate via predefined/custom roles + OU scope for least privilege.

Diagram of OUs (hierarchical policy inheritance/service differentiation), groups (bundle distribution-sharing-permissions), and admin roles (minimal super admin; delegate predefined/custom with least privilege).
Organize and delegate

1.2.3Section summary

  • OUs organize users hierarchically and differentiate/inherit policies and services
  • Groups bundle distribution/sharing/permissions (not hierarchical differentiation)
  • Keep super admins minimal; delegate daily work via predefined/custom roles with least privilege

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To differentiate a service on/off per department and inherit settings hierarchically, which unit do you use?

Q2. To bundle a mailing list, sharing, and permission grants together, which unit best fits?

Q3. Which is appropriate operation of the top admin role that can do everything?

Q4. To let the help desk perform only limited actions like password resets, which is most appropriate?

Q5. Which correctly contrasts OUs and groups?

Q6. To scope a delegated admin role so it applies only to a specific department, what can you use?

Check your understandingPractice questions for Chapter 1: Managing users, domains, and the directory