How to Create an Unlicensed Admin Account in Google Workspace (Without Locking Yourself Out)
- Google Workspace
- Cloud Identity
- Admin
- Security
- Cost Optimization
Every Workspace tenant should have a dedicated administrator account that isn’t tied to a real person and isn’t burning a paid license. Google supports this, and it costs nothing.
But there’s a step most guides bury or skip entirely, and skipping it is how people lock themselves out of their own tenant. Read the Cloud Identity section before you touch anything.
Why bother
Break-glass access. If your day-to-day admin is locked out, compromised, or the person leaves, you need a way back in.
Separation of duties. Your personal account handles email. Your admin account handles admin work. Compromising one doesn’t hand over the other.
Cost. An unlicensed admin costs nothing. There’s no reason to pay for a seat that never sends an email.
Read this first: Cloud Identity is not optional
Here’s what most guides get wrong. “Remove the license” isn’t a complete instruction, because it depends entirely on whether there’s an identity license underneath to catch the account.
Cloud Identity Free is that identity layer. It’s what makes an account exist as a manageable, sign-in-capable identity separate from any Workspace apps. With it in place, removing someone’s Workspace license leaves them with a working Cloud Identity account: no Gmail, no Drive, but a valid identity that can still authenticate and use admin roles.
Without it, you’re removing the thing that makes the account work and putting nothing underneath.
The free edition uses site-based licensing. You don’t assign it per user. Once the subscription exists on your tenant, every user gets one automatically, and you can’t remove it even if you wanted to. That’s the point: it’s a floor.
The lockout scenario: someone reads a guide like this, decides to save money, and strips the license off the super admin account they’re currently signed in as, without Cloud Identity in place. If that was the only super admin in the tenant, there is now no account with the privilege to undo it. You’re on Google’s recovery process, which for a business tenant is not a fast phone call.
Set it up
- Sign in to admin.google.com as a super admin. (Billing management privilege is required, so this genuinely does need a super admin.)
- Go to Billing → Buy or upgrade.
- Under Categories, click Cloud Identity.
- Next to Cloud Identity (the free edition, not Premium), click Find Out More and follow the setup.
During signup, if you have Workspace auto-licensing turned on at the top level, Google will prompt you to turn it off. Take the prompt seriously. It’s asking whether new users should automatically consume a paid seat.
Verify before proceeding. Go to Billing → Subscriptions and confirm Cloud Identity appears in the list. Don’t take the next step on faith.
The user cap, and what it actually means
Signing up for Cloud Identity Free increases your user cap by 50. Read that carefully: it’s an increase, not a flat ceiling. Buying paid Workspace licenses raises it further, so a tenant with a few hundred Workspace seats has considerably more headroom than 50. Google doesn’t publish the exact formula, so check yours rather than guessing.
You can see your remaining headroom under Billing → Subscriptions → Cloud Identity. If you hit the cap, you get an error when adding users, and you can ask Google to raise it via a support form, though Google reviews each request rather than granting it automatically.
For the purpose of this article, none of this is likely to bite you. You’re creating one or two admin accounts, not fifty.
A common myth worth killing: scoping to an OU does not stretch the Cloud Identity cap. Free Cloud Identity is site-wide and unremovable, so every user in the tenant has one regardless of OU. OU scoping controls Workspace auto-licensing, which is where the actual money is. Same advice, different reason.
Unrelated but worth knowing: Business Starter, Standard, and Plus cap out at 300 users regardless of any of this. If you’re a growing SMB, that ceiling is more likely to be the one you hit.
Turn off automatic Workspace licensing
If auto-licensing is on, your new admin will pick up a paid seat the moment you create it.
Go to Billing → Subscriptions → [your Workspace subscription] → Licensing settings. Turn automatic licensing off, or scope it to specific OUs.
The cleaner pattern:
/
├── Staff ← auto-licensing ON
├── Contractors ← auto-licensing ON
└── Service Accounts ← auto-licensing OFF
└── unlicensed admins live here
Create the OU first, set licensing on it, then create the user inside it. Order matters. Create the user first and you may have already provisioned a seat you now have to unwind.
Create the account
- Directory → Users → Add new user.
- Set the OU to Service Accounts (or whatever you named it).
- Use a boring, obviously non-human name:
Break Glass Admin,workspace-admin. Clear beats witty. The person recovering your tenant may not be you. - Set a strong password manually rather than auto-generating. Store it where your team can reach it in an emergency: shared password manager vault, or a sealed physical copy in a safe.
- Uncheck Ask for a password change at the next sign-in for a true break-glass account. You don’t want a forced reset between you and a locked tenant at 2am.
- Add new user.
Then verify: open the user, check Licenses. You want to see Cloud Identity present and no Workspace SKU. If a Workspace license slipped through, toggle it off and save.
Assign the admin role
- Open the user → Admin roles and privileges.
- Assign Super Admin for break-glass, or a scoped role like User Management Admin or Help Desk Admin for day-to-day.
- Save.
Least privilege applies. If the account exists to reset passwords, give it Help Desk Admin and nothing more. Not every admin needs the keys to billing.
Secure it properly
Enable 2SV. Hardware security key, not SMS. If the account lives in a safe, the key goes in the safe with it.
Alert on any sign-in. Set up an alert under Reporting → Alerts. This account should never sign in. If it does, you want to know in minutes.
Watch your notification path. Google sends billing alerts, security warnings, and admin notifications to admin addresses. An unlicensed account has no mailbox, so mail to it bounces. Keep at least one licensed admin, or set the account’s secondary/recovery email to an address someone actually reads.
Test it quarterly. An emergency account you’ve never tested is a rumour, not a plan. Sign in, confirm console access, sign out.
While you’re in there: who else doesn’t need a license?
Once Cloud Identity Free is on your tenant, the break-glass admin is the smallest thing you can do with it. The same mechanism applies to anyone who needs an identity but not a mailbox.
Worth auditing:
- Frontline and deskless staff. Warehouse, retail, hospitality. They sign into a shared Android device or an internal app and never open Gmail. A Workspace license for them is money on fire.
- Contractors and external collaborators. An identity in your directory, access to what they need, no mailbox in your domain.
- Service and integration accounts. Anything non-human that needs to authenticate.
- Google Cloud users with no Workspace need. If your workloads are on GCP but your email is elsewhere, Cloud Identity is the correct product, not a workaround. GCP needs identities to attach IAM roles to; it doesn’t need those identities to have inboxes.
The maths is simple. Ten unused seats on Business Standard is real money over a year, and the fix is a licensing settings toggle and an OU. The audit takes twenty minutes: sort your user list, look for accounts with no Gmail activity, and ask what each one is actually for.
Do it carefully, though. Everything in the order-of-operations section below still applies. Removing a license from a real person who does use Gmail means they lose access to their mail, so confirm before you toggle.
The order of operations
If you take one thing away:
- Cloud Identity Free subscription first
- Verify it appears under Subscriptions
- Create the OU, set licensing on the OU
- Create the user inside that OU
- Verify licenses on the user
- Assign the role
- Secure and test
Never remove a license from the account you’re currently signed in as. Never remove a license from your only super admin. Build the new account, verify it works, and only then reconsider what your existing accounts need.
Need a break-glass admin set up properly, or want someone to audit where you’re paying for licenses you don’t need? That’s exactly the kind of work GRB Digital does as part of our cloud and cybersecurity services. And while you’re hardening your tenant, it’s worth confirming your email authentication is actually solid, not just present.