Skip to content
Email & Google WorkspaceAdvanced

How to Reset a User Password in Google Workspace – Complete Admin Guide, Security Steps & Troubleshooting

Resetting a user's password is one of the most common account-management and security tasks performed by a Google Workspace administrator. A password reset m...

BI
Bison Technical Team Enterprise IT specialists
Updated 06 Mar 2026 17 min read 75 total views

Resetting a user's password is one of the most common account-management and security tasks performed by a Google Workspace administrator.

A password reset may be necessary when:

Advertisement
  • A user forgets their Google Workspace password.
  • An employee cannot sign in to Gmail.
  • A user has been locked out of their account.
  • An administrator suspects that an account has been compromised.
  • A password has accidentally been disclosed.
  • An employee changes department or device.
  • An administrator needs to regain control of an organizational account.
  • A security incident requires immediate credential rotation.
  • An organization is enforcing new password policies.
  • A former employee's credentials may still be known to someone else.

However, resetting the password is only one part of properly securing a Google Workspace account.

Administrators should also understand what happens to existing sessions, OAuth applications, mobile devices, App Passwords, sign-in cookies, 2-Step Verification (2SV), and account recovery.

This guide explains the complete process.


1. What Does Resetting a Google Workspace Password Mean?

Google Workspace accounts are managed organizational Google Accounts, such as:

employee@company.com

Instead of relying entirely on the user to recover the password, an authorized Google Workspace administrator can reset the password through the Google Admin console.

The administrator can either:

  1. Allow Google to automatically generate a password, or
  2. Create a password manually.

The administrator can also require the user to choose a new password the next time the user signs in.

Google's current administrator procedure is available in its official documentation.


2. Requirements Before Resetting a Password

You must have access to an administrator account with the appropriate Reset password privilege.

A regular Google Workspace user cannot open the Admin console and reset another user's password.

Google Workspace supports delegated user-management privileges, including privileges to:

  • Reset passwords
  • Force password changes
  • Suspend users
  • Rename users
  • Manage aliases
  • Perform other permitted user-management operations

Some higher-level administrative operations require Super Administrator privileges.


3. How to Reset a User Password in Google Workspace

Step 1 – Sign In to Google Admin Console

Open the Google Admin console:

admin.google.com

Sign in using an administrator account that has permission to reset passwords.


Step 2 – Open the Users Section

From the Admin console, navigate to:

Menu → Directory → Users

You will see the users belonging to your Google Workspace organization.


Step 3 – Find the User

Locate the account whose password needs to be reset.

For example:

accounts@company.com

or

john@company.com

If your organization has many accounts, use the search function to locate the user.


Step 4 – Select Reset Password

You can normally point to the user in the Users list and select:

Reset password

Alternatively, open the user's account page and select the password-reset option from there.


4. Choose the New Password

Google provides two general approaches.

Option A – Automatically Generate a Password

Google can generate a secure temporary password.

This is particularly useful when:

  • You suspect an account compromise.
  • You don't want administrators choosing predictable passwords.
  • You need a strong temporary credential immediately.

Copy the generated password and securely provide it to the user.


Option B – Create a Password Manually

An administrator can enter a new password manually.

For example, an IT administrator may need to provide a temporary password verbally to an employee.

Avoid predictable temporary passwords such as:

Password123

Company123

Welcome123

User@123

12345678

Temporary passwords should still be difficult for unauthorized persons to guess.


5. Enable “Ask the User to Change Their Password”

When manually creating a temporary password, administrators should normally enable:

Ask the user to change their password

The user will then authenticate with the temporary password and be required to create a new password.

This approach has an important security benefit:

The administrator does not need to know the user's permanent password.

Google also recommends this workflow when an administrator manually creates a temporary password.


6. Securely Give the Temporary Password to the User

Do not send sensitive credentials through an insecure or publicly accessible communication channel.

Possible approaches include:

  • Verified telephone call
  • Secure corporate messaging platform
  • Approved password-sharing mechanism
  • Personally providing the credential to the employee
  • Sending password information to a verified secondary address when appropriate

Before giving a temporary password, verify that you are communicating with the correct employee.

This is particularly important for:

  • Finance personnel
  • Senior management
  • HR users
  • IT administrators
  • Employees with access to confidential data

Attackers sometimes impersonate employees and request password resets from help desks.


7. Important Security Step: Reset Sign-In Cookies

A password reset should not always be considered the end of a security incident.

Google specifically provides administrators with the ability to reset a user's sign-in cookies.

Navigate approximately to:

Directory → Users → Select User → Security → Sign in cookies → Reset

Resetting sign-in cookies helps terminate existing authenticated sessions. Google recommends performing this step after resetting a user's password.

This is particularly important if:

  • The account may have been hacked.
  • An unknown person may already be signed in.
  • A laptop was stolen.
  • A former employee had access.
  • Credentials were exposed.
  • Suspicious login activity was detected.

8. What Happens After Resetting the Password?

A common misconception is that changing a Google Workspace password only changes the Gmail password.

The Google Workspace account can be connected to many services and devices.

After resetting the password and sign-in cookies, users may need to authenticate again in various applications.


Gmail and Google Drive in a Web Browser

The user may be required to sign in again using the new password.

This can affect services such as:

  • Gmail
  • Google Drive
  • Google Calendar
  • Google Docs
  • Google Sheets
  • Google Meet
  • Google Chat
  • Other Google Workspace services

9. What Happens on Android Devices?

On Android devices, Google may notify the user that identity verification is required.

Previously synchronized information may remain visible locally, but synchronization can stop until the account is authenticated again with the new credentials.

Therefore, if a user reports:

“My Gmail stopped receiving new messages after IT changed my password.”

the first thing to check is whether the Google account needs to be authenticated again on the device.


10. What Happens on iPhone or iPad?

Google notes that following the relevant reset process, the Google Account may need to be added again on Apple iOS devices.

The user should authenticate using the new password when requested.

Administrators should therefore warn mobile users before performing planned password resets.


11. What Happens to Outlook, Thunderbird and Other Email Applications?

Modern email applications should generally authenticate to Google Workspace using OAuth 2.0 rather than storing the ordinary Google password.

A password reset can invalidate relevant OAuth access and require the user to authenticate again.

Applications affected can include:

  • Microsoft Outlook
  • Mozilla Thunderbird
  • Apple Mail
  • Mobile mail clients
  • CRM applications
  • Email archiving software
  • Backup applications
  • Other Google-integrated applications

Google states that certain third-party applications using OAuth mail access can stop synchronizing after a password reset until a new OAuth token is granted.

The user may therefore need to select:

Sign in with Google

again and authorize the application.


12. What Happens to Google App Passwords?

This is extremely important for organizations using older applications.

When the Google Account password is changed, Google revokes existing App Passwords.

An App Password may have been used for:

  • Older Outlook configurations
  • Older email clients
  • Scanners
  • Multifunction printers
  • ERP software
  • Accounting applications
  • Legacy SMTP applications
  • Email notification systems
  • Other devices or applications that cannot use modern OAuth authentication

If such an application stops working after the password reset, investigate whether it was using an App Password.

A new App Password may need to be generated where the feature remains applicable.


13. Important Change: Don't Rely on “Less Secure Apps”

Organizations should not design new configurations around applications that authenticate only with the user's normal Google username and password.

Google states that, starting in 2025, less-secure sign-in methods relying only on username/password are no longer supported for Google Workspace accounts, with organizations expected to use more secure authentication such as OAuth.

Therefore, if an old application stops authenticating, simply changing the Google Workspace password repeatedly may not solve the problem.

Check whether the application supports:

OAuth 2.0 / Sign in with Google


14. Password Reset vs Password Change

These terms are related but not identical.

Password Change

The user knows the existing password and intentionally changes it.

Password Reset

An administrator or recovery mechanism replaces the existing password because:

  • The old password is forgotten.
  • The account is compromised.
  • Administrative intervention is required.

For normal users who know their credentials, allowing them to manage their own password is preferable.


15. Password Reset vs Account Recovery

Password reset and account recovery should also not be confused.

Google Workspace administrators can configure whether eligible non-admin users are allowed to recover their own accounts.

When self-service recovery is enabled, users can potentially use recovery information rather than contacting IT every time they forget a password.


16. Enable Self-Service Password Recovery

A Super Administrator can configure account recovery approximately under:

Admin Console → Security → Authentication → Account recovery

The option can allow users and non-super administrators to recover their accounts.

Recovery generally depends on appropriately configured recovery information.

However, self-service recovery is not available in every configuration.

For example, different behavior applies when organizations use:

  • Third-party Single Sign-On (SSO)
  • Password Sync
  • Certain Google Workspace for Education configurations

Administrators should therefore review the organization's authentication architecture before enabling or relying on self-service recovery.


17. Special Case: Organization Uses Active Directory or Third-Party SSO

Do not blindly reset passwords from Google Admin console when your organization authenticates users through another identity provider.

Examples may include:

  • Microsoft Active Directory
  • Microsoft Entra ID
  • Okta
  • Third-party identity providers
  • SAML-based authentication platforms

If authentication is controlled by an external identity provider, the authoritative password may need to be changed there.

Google specifically distinguishes environments using third-party SSO or Password Sync from ordinary Google-managed password recovery.


18. What Should You Do If the Account May Be Hacked?

If you suspect compromise, simply giving the user another password may not be sufficient.

A more complete incident-response procedure should be followed.

Recommended Security Checklist

  1. Reset the user's password.
  2. Reset the user's sign-in cookies.
  3. Review recent security activity.
  4. Review unfamiliar devices.
  5. Review recovery phone and recovery email.
  6. Review third-party application access.
  7. Review OAuth access.
  8. Review App Passwords.
  9. Check Gmail forwarding settings.
  10. Check Gmail filters.
  11. Check delegation settings.
  12. Check suspicious sent emails.
  13. Review account login activity.
  14. Verify 2-Step Verification.
  15. Investigate how the original credentials were compromised.

Google's guidance for compromised Workspace accounts similarly recommends password reset, OAuth-token review/revocation, App Password review, and stronger 2-Step Verification controls.


19. Check Gmail Forwarding After an Account Compromise

Attackers who obtain access to Gmail sometimes configure forwarding rules so that email continues being copied to an external address even after the password has been changed.

Therefore check:

Gmail → Settings → See all settings → Forwarding and POP/IMAP

Look for unknown forwarding addresses.


20. Check Suspicious Gmail Filters

An attacker may create filters designed to:

  • Delete security alerts.
  • Archive incoming messages.
  • Forward selected emails.
  • Hide password-reset messages.
  • Hide banking or financial emails.

Check:

Gmail → Settings → Filters and Blocked Addresses

Remove anything the user or administrator cannot explain.


21. Check Recovery Information

Review the user's:

  • Recovery email
  • Recovery phone
  • Alternate email
  • Security information

If the account was compromised, an attacker may have attempted to alter recovery information.

Google recommends reviewing unfamiliar changes to critical account security information when investigating suspicious activity.


22. Enable 2-Step Verification

Passwords alone should not be the organization's only defense.

Enable 2-Step Verification (2SV) according to your organization's Google Workspace security policy.

Possible verification mechanisms can include:

  • Google Prompt
  • Authenticator applications
  • Passkeys
  • Security keys
  • Other methods supported by your Workspace configuration

For privileged administrators, stronger phishing-resistant authentication should be considered wherever practical.


23. Do Not Share Permanent Passwords With IT Staff

A good organizational procedure is:

Administrator creates temporary password → User signs in → User creates private permanent password

IT staff should generally have no reason to know an employee's permanent password.

This provides better:

  • Security
  • Accountability
  • Auditability
  • Privacy
  • Administrative control

24. Resetting Another Administrator's Password

Resetting the password of another administrator has additional privilege requirements.

Google states that resetting another administrator's password requires Super Admin privileges.

Be particularly careful when resetting privileged accounts.

Administrator accounts should have stronger security controls than ordinary users.


25. What If the Super Administrator Forgot the Password?

If you cannot sign in to the Google Admin console because the administrator itself has lost access, the ordinary user-reset procedure cannot be used from that locked account.

You will need to use Google's administrator account recovery process.

Organizations should ideally maintain:

  • More than one appropriately secured Super Administrator account.
  • Correct administrator recovery information.
  • Emergency administrative procedures.
  • Strong 2-Step Verification.
  • Secure recovery methods.

This reduces the possibility of being completely locked out of the Google Workspace organization.


26. Why Is “Reset Password” Missing or Disabled?

Possible reasons include:

1. You Are Not Signed In as an Administrator

A normal user cannot manage other Workspace users.

2. Your Admin Role Lacks Permission

Your delegated administrator role may not include the Reset password privilege.

3. The User Is an Administrator

Additional permissions may be required, particularly for another administrator.

4. Authentication Is Controlled Externally

Your organization may use SSO or another identity-management platform.

5. You Are Managing the Wrong Workspace Organization

Verify the administrator account and domain.


27. User Says “Contact Your Administrator”

This is common when self-service account recovery is not enabled or available.

The user may click:

Forgot password?

and receive instructions to contact the organization's administrator.

This does not necessarily mean the account is damaged.

It may simply mean that the organization requires administrator-controlled password recovery.

Google documents both administrator-controlled reset and optional self-service recovery for eligible Workspace users.


28. User Still Cannot Sign In After Password Reset

Check the following.

Confirm the Email Address

Make sure the user is entering the correct Workspace account:

username@company.com

rather than a personal Gmail account.

Check the Password Carefully

Look for:

  • Caps Lock
  • Keyboard-layout differences
  • Accidental spaces
  • Incorrect copied characters

Try an Incognito/Private Window

This can help rule out cached sessions or incorrect account selection.

Check Account Status

Verify that the user has not been:

  • Suspended
  • Deleted
  • Renamed
  • Archived
  • Otherwise restricted

Check 2-Step Verification

The password may be correct while the user is failing at the second authentication stage.

Check SSO

If your organization uses SSO, authentication may be failing at the external identity provider rather than Google itself.


29. Should Administrators Periodically Force Password Changes?

Frequent password changes are not automatically the best security strategy.

Organizations should focus on:

  • Strong passwords
  • Unique passwords
  • Multi-factor authentication
  • Passkeys/security keys where appropriate
  • Compromised-password response
  • Login monitoring
  • Phishing prevention
  • Endpoint security

Passwords should definitely be changed when there is evidence or reasonable suspicion that credentials have been compromised.


30. Recommended Google Workspace Password Reset SOP

Organizations can use the following operational procedure:

Step 1: Verify the identity of the employee requesting the reset.

Step 2: Confirm the correct Google Workspace account.

Step 3: Determine whether the reset is routine or security-related.

Step 4: Generate a strong temporary password.

Step 5: Require the user to change it at next login where appropriate.

Step 6: Provide the temporary password through an approved secure channel.

Step 7: For a security incident, reset sign-in cookies.

Step 8: Review OAuth applications and App Passwords if compromise is suspected.

Step 9: Verify 2-Step Verification.

Step 10: Review recovery information.

Step 11: Check Gmail forwarding and filters if compromise is suspected.

Step 12: Confirm the user can successfully sign in.

Step 13: Verify Gmail/mobile/Outlook synchronization.

Step 14: Document the support action according to organizational policy.


31. Quick Troubleshooting Table

Problem What to Check
User forgot password Admin Console → Directory → Users → Reset password
User still cannot sign in Username, new password, 2SV, account status
Outlook stopped syncing OAuth authentication may need renewal
Thunderbird stopped syncing Reauthenticate Google account
Printer/scanner stopped sending email Check OAuth/App Password configuration
App Password stopped working Password change may have revoked it
User keeps getting old session Reset sign-in cookies
Suspected hacked account Password + cookies + OAuth + security review
“Contact administrator” displayed Check self-service recovery policy
Reset option unavailable Check administrator privileges
SSO user cannot sign in Check identity provider/SSO
Mobile Gmail stopped syncing Reauthenticate account
Another admin needs reset Super Admin permissions required

32. Frequently Asked Questions (FAQ)

Q1. Can a Google Workspace administrator reset a user's password?

Yes. An administrator with the appropriate password-reset privilege can reset a managed user's password through the Google Admin console.


Q2. Where is the password reset option?

Generally navigate to:

Admin Console → Directory → Users → Select User → Reset password


Q3. Can I create the password myself?

Yes. Administrators can create a password manually or allow Google to automatically generate one.


Q4. Should I automatically generate the temporary password?

For security-sensitive situations, an automatically generated password is generally preferable to an easily guessed temporary password.


Q5. Can I force the user to change the temporary password?

Yes. Use the option requiring the user to change the password when they next sign in.


Q6. Does resetting a Gmail password also reset the Google Workspace password?

For a Workspace user, Gmail is part of the managed Google Account. The password is associated with the Google Account rather than being a separate Gmail-only password.


Q7. Will the user's emails be deleted?

No. Resetting a password does not normally delete the user's Gmail messages, Drive files, Calendar data, or other Workspace data.


Q8. Will the user be logged out?

Password resets and resetting sign-in cookies can require the user to authenticate again across Google services and connected devices.


Q9. Should I reset sign-in cookies?

It is particularly important for compromised or potentially compromised accounts. Google includes resetting sign-in cookies as part of its documented password-reset procedure.


Q10. Will Outlook stop working after the password reset?

It can. Applications using OAuth may need the user to authenticate again.


Q11. Will Thunderbird stop working?

Potentially. If its OAuth authorization is invalidated, the user must authenticate again and grant a new token.


Q12. What happens to App Passwords?

Google states that App Passwords are revoked when the Google Account password is changed. New App Passwords may therefore be required for applicable legacy applications.


Q13. Does 2-Step Verification get disabled when I reset the password?

Do not assume that a password reset removes the organization's 2SV requirements. Password authentication and second-factor authentication are separate security controls.


Q14. Can users reset their own passwords?

Eligible organizations can enable self-service account recovery, provided the necessary recovery information and authentication configuration are in place.


Q15. Why does the user see “Contact your administrator”?

The organization may not have enabled self-service recovery, the feature may not apply to that account, or the authentication configuration may require administrator intervention.


Q16. Can a delegated administrator reset passwords?

Yes, if the delegated role includes the necessary user-management/password-reset privilege.


Q17. Can I reset another administrator's password?

Google requires Super Admin privileges to reset another administrator's password.


Q18. What if my organization uses SSO?

The password may be controlled by your identity provider rather than directly by Google. Follow your organization's SSO/identity-provider procedure.


Q19. Should I change a password immediately if an account is hacked?

Yes. Google recommends immediately changing the password when unauthorized access is suspected, followed by further investigation and security review.


Q20. Is changing the password enough after hacking?

Not necessarily. Review sign-in cookies, OAuth access, App Passwords, recovery information, Gmail forwarding, filters, devices, and 2-Step Verification.


Q21. Can resetting the password delete Google Drive files?

No. A password reset changes authentication credentials; it does not normally delete Drive data.


Q22. Can an administrator see the user's old password?

No. Administrators reset the password rather than retrieving the existing password.


Q23. Should IT know the user's permanent password?

Normally no. IT should provide a temporary credential and require the user to create a private permanent password.


Q24. Why did my scanner stop sending Gmail after a password reset?

The scanner or application may have been using an App Password or another authentication mechanism that was invalidated. Review its Google authentication configuration.


Q25. Can an old application continue using only my normal Google password?

Organizations should migrate away from username/password-only legacy authentication. Google Workspace has discontinued support for less-secure username/password-only application access and recommends more secure authentication such as OAuth.


Security Best Practices

For business Google Workspace environments:

  • Require strong, unique passwords.
  • Enable 2-Step Verification.
  • Consider phishing-resistant authentication for privileged users.
  • Never reuse Workspace passwords on unrelated websites.
  • Never send permanent passwords through ordinary email.
  • Verify employee identity before performing a reset.
  • Use temporary passwords for administrative resets.
  • Require users to replace temporary passwords.
  • Reset sign-in cookies during security incidents.
  • Review OAuth applications after suspected compromise.
  • Review App Passwords.
  • Review recovery information.
  • Check Gmail forwarding and filters.
  • Maintain more than one properly secured Super Administrator account.
  • Train employees to recognize phishing and fake Google login pages.

Conclusion

Resetting a Google Workspace password is easy, but secure account recovery involves much more than clicking “Reset password.”

For an ordinary forgotten password, the administrator can generate a temporary password, require the employee to change it, and verify successful sign-in.

For a suspected account compromise, administrators should treat the situation as a security incident. Reset the password, terminate authenticated sessions by resetting sign-in cookies, review OAuth and App Password access, inspect recovery information and Gmail settings, verify 2-Step Verification, and investigate the source of the compromise.

A properly managed password-reset procedure helps protect not only Gmail but also the organization's Google Drive files, business communications, cloud applications, mobile devices, and connected third-party systems.

 

#GoogleWorkspace #GoogleWorkspaceAdmin #GoogleAdmin #AdminConsole #PasswordReset #GooglePassword #GmailPassword #GmailAdmin #WorkspaceAdmin #GoogleSecurity #EmailSecurity #AccountSecurity #PasswordSecurity #PasswordRecovery #AccountRecovery #GoogleWorkspaceSecurity #GmailSecurity #TwoStepVerification #2StepVerification #2FA #MFA #GoogleAuthenticator #GoogleOAuth #OAuth2 #AppPassword #GoogleAppPassword #WorkspaceSecurity #WorkspaceSupport #GoogleSupport #ITSupport #ITAdministrator #SystemAdministrator #SysAdmin #EmailAdministrator #UserManagement #IdentityManagement #AccessManagement #CyberSecurity #BusinessEmail #CorporateEmail #GmailBusiness #GoogleWorkspaceHelp #GoogleWorkspaceGuide #PasswordManagement #SecurityBestPractices #AccountProtection #CompromisedAccount #GmailTroubleshooting #WorkspaceTroubleshooting #BISONKB

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.