Google Workspace Lets Admins Set Role Expiration Dates

Google Workspace now lets admins time-limit role assignments for users, security groups, and service accounts. See how expiration works and its key limits.

Written By
Michelle Lojo
Michelle Lojo
Sep 29, 2026
Google Workspace Lets Admins Set Role Expiration Dates

Google Workspace now lets super administrators set expiration dates for admin roles assigned to users, groups, and service accounts. Image generated by ChatGPT

A temporary project can leave behind permanent administrator access if no one remembers to remove it. Google Workspace now lets super administrators put an expiration date on an admin role assignment, so the access granted by that role is revoked when the time runs out.

Google announced the feature on September 23. It applies to users, eligible security groups, and service accounts and is available to all Google Workspace customers. Google suggests using it for short projects, coverage during an employee’s absence, and external audits.

How expiring admin roles work

A super administrator can choose a preset duration, such as 30 days, or enter a custom expiration date and time. Google’s admin instructions set a maximum of one year. In the Admin console, a super administrator goes to Account > Admin roles, selects the member or service account, and uses Change expiration when assigning the role. An expiration can also be set on an existing assignment.

The expiration applies to the access granted by that role assignment. IT teams should check what other roles and permissions an account holds before treating an expiration date as the end of all its administrative access. The Google Workspace Admin console is where administrators can review the roles and settings available to their organization.

Google says an organization’s primary administrator cannot receive a temporary role because that account requires permanent super administrator privileges. Its help page also says a service account cannot be assigned the Super Admin role. Google says the feature is available to Rapid Release and Scheduled Release domains, though its help page cautions that some enterprise users may not see the expiration controls until the release is complete.

Why this matters for IT teams

An expiration date removes a manual cleanup task that is easy to miss when an audit ends or an employee returns from leave. It is especially useful for service accounts, which can hold privileges for automated work without a person routinely signing in. Google’s documentation gives the example of a service account using an admin role to manage groups through an API.

The practical first step is to review existing administrator access, choose the narrowest role needed, and set an end date when the work has a known finish. Service accounts deserve the same scrutiny. Earlier reporting on Workspace domain-wide delegation examined a separate risk involving service account keys and OAuth scopes.

Advertisement

Read more: Google Drive’s expanded ransomware detection and file recovery gives Workspace administrators another security change to assess.

Michelle Lojo

Michelle Lojo is the News Editor for TechRepublic, with eight years of experience in journalism. She oversees timely, accurate, and accessible coverage that helps readers understand the technologies, companies, and developments shaping the industry. Michelle is committed to turning complex topics into clear, relevant stories for technology professionals and business leaders.