Skip to content
GeneralAdvanced

How to Recover a Google Workspace Super Admin Account: Password, 2-Step Verification, Lost Phone, DNS Verification, and Admin Recovery

A Google Workspace Super Administrator is one of the most important accounts in an organization. A Super Admin can manage users, security settings, authentic...

BI
Bison Technical Team Enterprise IT specialists
Updated 31 Jul 2026 18 min read 1 total views

A Google Workspace Super Administrator is one of the most important accounts in an organization. A Super Admin can manage users, security settings, authentication policies, domains, licenses, applications, and other administrators.

Losing access to this account can therefore become a serious administrative problem.

Advertisement

Fortunately, losing the password, phone, Google Authenticator access, security key, or another verification method does not necessarily mean that the Google Workspace organization is lost. Google provides several recovery mechanisms, ranging from normal account recovery to domain ownership verification through DNS.

This guide explains the major Google Workspace Super Admin recovery scenarios and the correct recovery path for each.


1. What Is a Google Workspace Super Admin?

Google Workspace administrator privileges are assigned through administrator roles. The Super Admin role has broad administrative authority over the Workspace organization.

Depending on configuration and licensing, Super Admins can perform critical tasks such as:

  • Create, modify, suspend, and delete users
  • Reset user passwords
  • Manage administrator roles
  • Configure security policies
  • Manage 2-Step Verification policies
  • Manage domains
  • Configure applications and services
  • Manage authentication settings
  • Review security information
  • Manage licenses and organizational settings

Because of these privileges, Super Admin accounts should receive stronger protection than normal user accounts.


2. Common Reasons a Super Admin Gets Locked Out

Super Admin recovery may be required because of several different problems.

Forgotten password

The administrator remembers the account address but cannot remember the password.

Lost or stolen phone

The password is known, but the phone used for Google Prompt, SMS verification, or an authenticator is unavailable.

Lost Google Authenticator access

The administrator changed, reset, damaged, or lost the phone containing the authenticator configuration.

Lost security key

A physical security key used for authentication is unavailable.

No access to recovery phone or email

The administrator no longer controls the recovery information associated with the account.

Former administrator left the organization

The only known Super Admin may have left the business without transferring administrative control.

Account compromised

An attacker may have changed the password or recovery information.

Username forgotten

The organization knows the domain but does not remember which account was configured as an administrator.

All administrators are inaccessible

This is one of the most serious cases because another Super Admin cannot simply reset the affected administrator's password.

The correct recovery method depends on which of these situations applies.


3. Recovery Method 1: Another Super Admin Resets the Account

This is generally the easiest recovery scenario.

If your organization has another accessible Super Admin account, use that administrator to restore access to the affected administrator.

The other Super Admin can access the Google Admin console, locate the affected account, and perform the appropriate administrative recovery action.

For example, another Super Admin can reset another administrator's password. Google states that resetting another administrator's password requires Super Admin privileges.

After recovery, review the affected account's authentication and security configuration before returning it to normal administrative use.

Why organizations should have multiple Super Admins

Having a second properly secured Super Admin account can prevent a lost phone, forgotten password, or unavailable employee from becoming an organization-wide recovery emergency.

However, this does not mean every IT administrator should receive Super Admin privileges. Super Admin access should remain tightly controlled.


4. Recovery Method 2: Use Google's Account Recovery Process

When another Super Admin is unavailable, start with Google's administrator recovery process.

Use Google's account recovery page:

Google Account Recovery:
https://accounts.google.com/signin/recovery

Enter the administrator account, for example:

admin@example.com

Then follow the available verification methods.

Google may offer different recovery options depending on how the account was configured and what information Google can use to verify the request.


5. Recover Using a Recovery Phone or Email

If a recovery phone number or recovery email address was configured on the administrator account, recovery may be relatively straightforward.

Google's current administrator recovery instructions recommend entering the administrator account in the recovery process and selecting Try another way where appropriate.

If recovery information is available, Google may send a verification code to the configured recovery email address or phone number.

After successful verification, follow Google's instructions to establish a new password.

Important

A recovery email should ideally be an account that remains accessible even when the organization's Google Workspace environment is unavailable.

For example, using:

recovery@example.com

for:

admin@example.com

may create a dependency if both accounts become inaccessible simultaneously.

An independently controlled recovery address can provide another recovery route.


6. Recover a Super Admin After Losing the 2FA Phone

Suppose you know:

  • Super Admin email address
  • Correct password

but Google asks for verification on a phone that has been lost or stolen.

Do not immediately assume that the account cannot be recovered.

Select Try another way during sign-in and check for another configured verification method.

Possible methods can include:

  • Another signed-in phone
  • Backup phone number
  • Backup code
  • Another security key
  • Passkey on another device
  • Previously trusted device
  • Other recovery options offered by Google

The options available depend on the account's previous configuration.


7. Recover Using Google Backup Codes

Backup codes are particularly useful for administrator accounts.

When 2-Step Verification is enabled, Google can provide a set of backup codes that can be stored securely for emergencies.

During sign-in:

  1. Enter the administrator email address.
  2. Enter the password.
  3. Select Try another way.
  4. Select the backup-code option when available.
  5. Enter an unused backup code.

Google's current documentation states that backup codes are single-use. A new set contains 10 codes, and generating a new set invalidates the previous set.

Backup codes should therefore be treated like passwords and stored securely.

Never keep the only copy on the phone whose loss the codes are intended to protect against.


8. Recover Using Another Trusted Device

A Super Admin may still have an authenticated session on another device.

Examples include:

  • Office desktop
  • Administrative laptop
  • Secondary smartphone
  • Tablet
  • Dedicated management workstation

Google also notes that a device previously configured as trusted may sometimes allow access without requiring the unavailable second verification step.

If an administrator is still signed in somewhere, do not sign out of that device until recovery is complete.

Use the existing authenticated session to review security settings, authentication methods, recovery information, and the account's devices.


9. Lost Security Key

A Super Admin may use a hardware security key for stronger authentication.

If the primary security key is lost but another second step was configured, use the alternate method to sign in and then remove the missing security key.

Possible alternatives include another security key, backup codes, verification methods, or a trusted device, depending on the account configuration.

Google recommends keeping a backup security key where appropriate.

If no alternative authentication method is available, account recovery may be required.

Google notes that some 2-Step Verification recovery cases can take 3–5 business days while account ownership is verified.


10. What If You Have No Recovery Phone or Recovery Email?

This is where Google Workspace administrator recovery differs significantly from an ordinary forgotten-password situation.

If normal recovery information is unavailable, Google can use domain ownership verification as part of the administrator recovery process.

The recovery wizard may instruct you to create a DNS record for the organization's domain.

This is important because control over the domain's authoritative DNS provides strong evidence that the person requesting recovery has administrative control over the organization's domain.


11. Super Admin Recovery Through DNS Verification

According to Google's current administrator recovery procedure, when recovery phone/email options are unavailable, the recovery wizard can ask the administrator to verify the domain by adding a CNAME record.

Suppose your Workspace domain is:

example.com

Google will provide the exact CNAME record that needs to be created.

Do not copy a CNAME value from another recovery attempt or an online tutorial. Use the record Google generates for your recovery request.

Log in to the DNS management service responsible for the domain.

This may be your:

  • Domain registrar
  • DNS hosting provider
  • Web hosting provider
  • Managed DNS platform

Add the CNAME exactly as instructed by Google.

Google specifically notes that when hosting and domain registration are separate, the record must be added where the domain's DNS is actually managed.


12. What Happens After Adding the CNAME?

After creating the requested CNAME record, wait a few minutes and return to Google's recovery wizard.

Google will check the DNS.

If the record is detected successfully, Google may display the Create Password screen, allowing you to create a new administrator password and regain access.

If Google does not immediately find the CNAME, the recovery process can continue.

You may be asked to provide another email address where Google can contact you.

Do not use the locked administrator address as the contact email.

Google can send a verification code to the contact address and continue checking the domain verification record.

According to Google's current documentation, if the CNAME cannot be found within 48 hours, Google may report that the password recovery attempt was unsuccessful.


13. Why DNS Verification Works

Consider:

admin@example.com

The Google Workspace organization uses:

example.com

Control of the authoritative DNS zone for example.com demonstrates administrative control over an important part of the organization's domain infrastructure.

Google provides a unique record to add.

The requester creates that record.

Google queries DNS.

If Google's systems find the expected value, domain control has been demonstrated.

DNS verification is therefore useful when the normal recovery phone or recovery email cannot be used.

It should not be interpreted as an automatic bypass of Google's security. Google can require additional verification.


14. Support-Assisted Super Admin Recovery

Google's current process also provides a support-assisted recovery path in eligible situations when automated recovery cannot resolve the problem.

You should first attempt the automated recovery process.

If the recovery workflow provides Contact support, follow that option.

Google may direct you to its Apps Admin Toolbox recovery process.

You will need to provide a contact email address that you can access.

Again, do not provide the locked Workspace account as your only contact method.

Google generates a support reference number and provides instructions for proving domain ownership.


15. DNS Verification During Support-Assisted Recovery

For support-assisted recovery, Google may instruct you to add a:

CNAME record

or

TXT record

to your domain's DNS configuration.

Use exactly the hostname and value supplied by Google.

DNS propagation is not always immediate.

Google states that the record can take up to 24 hours to propagate.

After the DNS record is detected, return to the recovery workflow and complete the request.

For a locked administrator account, the appropriate request can be Request for Password Reset, depending on the recovery workflow presented by Google.

Google Support may request additional verification before administrative access is restored.


16. What If the Only Super Admin Has Left the Company?

Consider this situation:

A company uses:

companyexample.com

The former IT administrator controlled:

admin@companyexample.com

That employee leaves the organization, and nobody knows the password or has access to the administrator's 2-Step Verification method.

This is a critical but potentially recoverable situation.

First determine whether another Super Admin exists.

If another Super Admin is available, that administrator can reset the affected administrator account.

If no accessible administrator exists, use Google's administrator recovery process.

When normal recovery methods cannot be used, domain ownership verification may become the key recovery mechanism.


17. What If You Are a User and Cannot Contact Any Administrator?

Google provides another recovery scenario for organizations where an existing active user can sign in but cannot contact the Workspace administrator.

Google's current documentation says that an active user account can potentially be promoted to Super Admin after domain ownership is verified.

Google provides its recovery workflow through the Apps Admin Toolbox.

The user enters the organization's domain and chooses the recovery option indicating that they are a user who cannot contact the administrator.

Google generates a support reference and asks the requester to verify domain ownership using DNS.

After verification, the requester can submit a Request User Promotion where that option is available.

Google attempts to contact existing administrators. If the administrators are inactive and unresponsive, Google may promote the requesting active user account.

This is particularly useful for organizations where an old employee, consultant, or IT provider originally controlled Google Workspace administration.


18. What If Google Workspace Was Purchased Through a Reseller?

Some organizations purchase Google Workspace through an authorized reseller rather than directly from Google.

If normal administrator recovery is unsuccessful and the Workspace service was purchased from a reseller, Google recommends contacting the reseller.

The reseller relationship may therefore become relevant during administrative recovery.

Keep your organization's Google Workspace customer information, reseller details, domain registrar details, and authorized contacts documented internally.


19. What If the Super Admin Account Was Hacked?

Treat a compromised Super Admin account as a security incident, not merely a forgotten-password problem.

An attacker with Super Admin privileges could potentially modify users, authentication settings, administrator roles, security policies, or other organization-wide configuration.

Use Google's recovery process if you cannot sign in.

After recovering access, investigate the environment before considering the incident closed.

Review areas such as:

  • Administrator roles
  • Super Admin accounts
  • Recovery information
  • 2-Step Verification methods
  • Registered passkeys
  • Security keys
  • Signed-in devices
  • Suspicious sessions
  • User accounts
  • OAuth application access
  • Gmail forwarding and routing
  • Security settings
  • Domain configuration
  • Third-party integrations

Change compromised credentials and revoke unauthorized access.


20. Password Reset Alone May Not Solve Every Lockout

A common mistake is assuming:

"I changed the password, so the administrator should now be able to log in."

That is not always true.

Google Workspace sign-in can involve several layers:

Username → Password → Login challenge → 2-Step Verification → Device/security checks

A password reset addresses the password.

It does not necessarily resolve a separate login challenge or unavailable 2-Step Verification method.

Google's troubleshooting documentation specifically distinguishes these scenarios.

Always identify what is actually blocking access before repeatedly changing passwords.


21. Recovery Decision Flow

A practical recovery sequence is:

Can another Super Admin sign in?

Yes → Use that Super Admin to recover the affected administrator.

No → Continue.

Do you have the password but cannot complete 2-Step Verification?

Try alternate verification methods, such as backup codes, another signed-in device, backup phone, passkey, security key, or other method Google offers.

No working method → Continue.

Do you have access to the recovery email or phone?

Yes → Use Google's account recovery workflow.

No → Continue.

Do you control the organization's DNS?

Yes → Follow Google's domain verification recovery instructions.

No → Determine who controls the registrar/DNS and restore authorized access to that infrastructure.

Did you purchase Workspace through a reseller?

Contact the reseller if Google's recovery workflow instructs you to do so or automated recovery remains unsuccessful.

Does the recovery workflow offer support-assisted recovery?

Follow Google's support process and complete the required domain/account ownership verification.


22. Do Not Delete DNS Records Randomly

During recovery, do not remove unrelated records such as:

  • MX records
  • SPF records
  • DKIM records
  • DMARC records
  • Existing TXT verification records
  • Website A/AAAA records
  • Application CNAME records

Google normally asks you to add a specific verification record.

Removing existing records unnecessarily can cause additional problems with Gmail, website hosting, email authentication, or other services.


23. DNS Propagation Can Delay Recovery

DNS changes do not necessarily become visible everywhere immediately.

A record may appear in your DNS management portal while external DNS resolvers still return the previous configuration.

For support-assisted recovery, Google notes that DNS propagation can take up to 24 hours.

Therefore, do not repeatedly delete and recreate the record simply because verification fails immediately.

First confirm that:

  • The hostname is correct
  • The value is correct
  • The record type is correct
  • The record is in the authoritative DNS zone
  • No unwanted characters were added
  • The DNS provider saved the change

Then allow sufficient propagation time.


24. Security Steps Immediately After Recovery

Regaining access is only the first part of the job.

After successfully recovering a Super Admin account, secure it immediately.

Change the password

Use a unique password that has not been used elsewhere.

Review recovery information

Verify the recovery email and phone number.

Remove information belonging to former employees or unknown parties.

Review 2-Step Verification

Confirm that all registered methods are legitimate.

Remove lost or unauthorized devices and keys.

Generate new backup codes

If old backup codes may have been exposed, generate a new set. Google's system invalidates the previous set when a new set is generated.

Review Super Admin accounts

Check which accounts currently have Super Admin privileges.

Remove unnecessary administrative access.

Review recent security activity

Investigate unexpected authentication or administrative events.

Review third-party access

Remove suspicious or unnecessary integrations.

Secure domain registrar and DNS accounts

Your Workspace recovery strategy can depend on domain control, so the registrar and DNS accounts themselves require strong authentication and recovery planning.


25. Recommended Super Admin Architecture

A business should avoid depending on one person, one phone, and one administrator account.

A stronger structure is:

Primary Super Admin

Used for controlled administrative work.

Secondary/Emergency Super Admin

Protected separately and reserved for recovery or emergency administration.

Both should use strong authentication.

Avoid sharing one Super Admin password among multiple IT staff members.

Individual administrator identities improve accountability and reduce credential-sharing risk.


26. Create a Super Admin Emergency Recovery Kit

Organizations should maintain an internal recovery procedure containing information such as:

  • Primary Workspace domain
  • Super Admin account names
  • Secondary Super Admin information
  • Domain registrar
  • DNS provider
  • Workspace reseller, when applicable
  • Recovery contact procedure
  • Location of backup security keys
  • Location of securely stored backup codes
  • Internal authorization procedure for emergency recovery

Do not store passwords or backup codes in an unsecured document.

The purpose of the recovery kit is to ensure that authorized personnel know where and how recovery can be performed.


27. Secure the Domain Registrar Too

DNS verification can help recover Workspace administration, but that creates an important dependency:

Who controls the domain?

Protect the domain registrar and DNS provider accounts using strong authentication.

Otherwise, you could face a situation where:

  • Workspace Super Admin is inaccessible
  • DNS account is inaccessible
  • Registrar recovery email belongs to a former employee

That can turn a manageable Workspace recovery into a much more complicated domain ownership problem.


28. Common Mistakes to Avoid

Avoid these common recovery mistakes:

  • Having only one Super Admin
  • Using only one 2FA method
  • Keeping backup codes only on the administrator's phone
  • Using outdated recovery email addresses
  • Using former employees' phone numbers
  • Sharing Super Admin credentials
  • Losing access to the domain registrar
  • Losing access to the DNS provider
  • Randomly changing DNS records
  • Assuming a password reset automatically bypasses 2FA
  • Disabling security controls permanently just to simplify administration
  • Trusting third parties claiming they can bypass Google's recovery process

Never provide your password, backup codes, authentication codes, security keys, or DNS credentials to an unknown "account recovery" service.


29. Recommended Recovery Priority

For most organizations, use this order:

1. Existing authenticated session

Use a device where the administrator is already signed in.

2. Alternate 2-Step Verification method

Use backup codes, another device, backup phone, passkey, security key, or another method Google presents.

3. Another Super Admin

Have another Super Admin restore access.

4. Recovery email or phone

Use Google's automated account recovery.

5. Domain verification

Use the DNS CNAME verification workflow when offered.

6. Support-assisted recovery

Complete Google's ownership verification process.

7. Reseller assistance

For reseller-managed subscriptions, contact the reseller where appropriate.

The exact options Google presents can vary depending on the account's security configuration and recovery history.


Frequently Asked Questions

1. Can a Google Workspace Super Admin account be recovered?

Yes. Recovery options can include another Super Admin, recovery phone/email, alternative 2-Step Verification methods, DNS domain verification, and support-assisted recovery.

2. What happens if I forget the Super Admin password?

Start Google's account recovery process. If another Super Admin exists, that administrator can also reset the affected administrator's password.

3. Can another Super Admin reset my password?

Yes. Google states that a Super Admin can reset another administrator's password.

4. I lost my phone. Is the Super Admin account lost?

Not necessarily. Try another verification method such as backup codes, another signed-in device, backup phone, security key, passkey, or another method offered by Google.

5. Can I recover the account using DNS?

Google's administrator recovery process can use domain verification when normal recovery options are unavailable. The automated workflow may request a CNAME record, while support-assisted recovery may use a CNAME or TXT record.

6. Do I need access to the domain registrar?

You need access to the service controlling the authoritative DNS records. This might be the registrar, hosting provider, or a separate DNS provider.

7. Can I use a TXT record instead of a CNAME?

Use exactly the record type Google requests. Automated recovery can request a CNAME. Support-assisted recovery can request a CNAME or TXT record.

8. How long does DNS verification take?

It may work within minutes, but DNS propagation can take longer. Google states that support-assisted DNS verification can take up to 24 hours to propagate.

9. What happens if the recovery CNAME isn't detected?

Check that the record was added to the correct DNS zone and wait for propagation. Google's automated recovery documentation says that if the CNAME is not found within 48 hours, the recovery attempt may be reported unsuccessful.

10. Can Google Support simply give me the Super Admin password?

No. Recovery requires verification. Google may require proof of account and domain ownership before restoring administrative access.

11. Can I recover an account without my old phone?

Yes, provided another recovery or verification path is available.

12. Can backup codes recover access after losing my phone?

Yes, when backup codes were previously generated and are valid for the account.

13. Can I reuse a Google backup code?

No. Backup codes are single-use.

14. How many Google backup codes are generated?

Google currently generates a set of 10 backup codes. Generating a new set invalidates the previous set.

15. Can I recover an administrator if Google Authenticator was deleted?

Potentially. Try another configured second step or use the account recovery process.

16. What if my security key is lost?

Use another configured authentication method. Once signed in, remove the lost key and register a replacement.

17. Can 2-Step Verification recovery take several days?

Yes. Google states that certain recovery cases involving 2-Step Verification can take 3–5 business days while ownership is verified.

18. What if the company's only Super Admin left?

Try administrator recovery. An active Workspace user who cannot contact the administrator may also be able to request promotion after domain ownership verification through Google's recovery process.

19. Can an ordinary user become Super Admin through recovery?

In Google's specific "cannot contact administrator" recovery scenario, an active user can request promotion after proving domain ownership. Google may contact existing administrators before approving the request.

20. What if Workspace was purchased through a reseller?

Contact the Google Workspace reseller when automated recovery is unsuccessful or Google's recovery instructions direct you to the reseller.

21. Should I disable 2FA after recovering the account?

Generally, no. Administrator accounts should use strong authentication. Replace the unavailable method and establish appropriate backup authentication instead.

22. Should an organization have two Super Admin accounts?

Having more than one appropriately secured Super Admin helps prevent a single administrator lockout from becoming an organization-wide emergency.

23. Should administrators share a Super Admin account?

No. Separate administrator identities provide better security and accountability.

24. Does changing the password remove 2-Step Verification?

Do not assume so. Password authentication and 2-Step Verification are separate parts of the sign-in process.

25. What should I do immediately after recovery?

Change compromised credentials, verify recovery information and 2FA methods, replace backup codes where necessary, review administrator roles and devices, investigate suspicious activity, and secure domain/DNS access.

 

#GoogleWorkspace #GoogleWorkspaceAdmin #GoogleAdmin #SuperAdmin #GoogleAdminConsole #WorkspaceAdmin #AccountRecovery #AdminRecovery #GoogleAccountRecovery #PasswordRecovery #PasswordReset #TwoStepVerification #2StepVerification #2FA #2FARecovery #GoogleAuthenticator #AuthenticatorRecovery #BackupCodes #SecurityKey #Passkeys #LostPhone #AccountSecurity #GoogleSecurity #WorkspaceSecurity #CyberSecurity #ITSecurity #CloudSecurity #AdminSecurity #GoogleWorkspaceSecurity #DNS #DNSVerification #CNAME #TXTRecord #DomainVerification #DomainSecurity #DomainOwnership #GoogleDNS #GoogleSupport #GoogleWorkspaceSupport #WorkspaceRecovery #AdminAccess #LoginRecovery #AccountProtection #SecurityBestPractices #ITAdministrator #SystemAdministrator #GoogleCloud #BusinessEmail #GmailSecurity #TechnicalSupport

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “How to Recover a Google Workspace Super Admin Account: Password, 2-Step Verification, Lost Phone, DNS Verification, and Admin Recovery”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.