How to exclude some users from Password Sync  |  User management  |  Google Workspace Help Skip to main content User management Documentation Administrators Getting started Apps and integrations Set up and manage services Billing and subscriptions Data migration Data synchronization Device management Domain management Reports and monitoring Security and data protection User management Legal and compliance Support and troubleshooting Users Calendar Chat Cloud Search Gmail Groups Docs, Forms, Sheets, and Slides Drive Keep Meet Meet Hardware Sites Vids Developers Apps Script Marketplace Workspace APIs Training & business user guides Workspace Learning Center Google Skills Community Communities Workspace Admin Community Workspace Developers Community Support / English Deutsch Español – América Latina Français Indonesia Italiano Nederlands Polski Português – Brasil Svenska Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어 Sign in Administrators User management Admin console Contact us Overview Guides User management Overview Guides Documentation More Community More Support Add & manage users Options for adding users Add an account for a new user Add or update multiple users from a CSV file Use a third-party tool for quick mass provisioning Name guidelines for users and groups Avoid sharing an account among users Request additional Education licenses Delete or remove a user from your organization Suspend a user temporarily Restore a suspended user Restore a recently deleted user Archive former employee accounts Archive a single-user subscription Maintain data security after an employee leaves Choose a language for new users Change the default time zone for new users Impact on Google apps when changing a user's email address Let users buy add-ons Manage individual Google Cloud accounts Investigate user problems with log events Advanced user management User profiles & Directory Overview: Set up and manage the Directory Turn Directory on or off Control who users can find in the Directory Customize a directory for a team or group Hide a user from the Directory Hide Groups or domain shared contacts Add information to a user's Directory profile Add or change a user's profile photo Change a user's profile name Allow Directory users to change their profile and photo Create custom attributes for user profiles Troubleshoot custom user attribute errors Add advanced contact information Add shared external contacts to the Directory Bulk update user profiles with LDAP directory or API Let third-party apps access Directory data Email addresses & aliases Overview: Add additional email addresses for users Add or delete an alternate email address (email alias) Delegate a user's email address Set which email addresses show in the Directory Overview: Changing a Directory user's name or email address Administrator roles & privileges About administrator roles Prebuilt administrator roles Administrator privilege definitions Assign specific admin roles Make a user an admin Create, edit, and delete custom admin roles Create an admin role for an organizational unit Remove Google Workspace administrator privileges Delete an administrator account View role assignments and privileges Security best practices for administrator accounts Set admin privileges to protect user privacy Designate users with analytics data access Designate users with temporary class access Passwords & account recovery Enforce and monitor password requirements for users Allow users to skip passwords at sign-in Prevent phishing attacks on your users Phishing prevention with Password Alert FAQ Set up password recovery for users Add recovery information for admins and users Allow super administrators to recover their password Allow users to add password recovery details Recovering administrator access to your account Account recovery information for Support Reset a user's password Restore a suspended Gmail account Unmanaged users Find and add unmanaged users Prevent creation of unmanaged user accounts Before using the transfer tool Use the transfer tool to migrate unmanaged users Use CSV to migrate unmanaged users Sync users with an external directory Sync data with your LDAP server Compare options for syncing directories Directory Sync Get started with Directory Sync System requirements Supported network connections Set up a VPC access connector Enable the Data Connectors API Add, edit, or remove an external directory Set up user sync Set up group sync Run a sync Replace the domain name for synced users Update user or group settings Check log events for Directory Sync Troubleshoot Directory Sync Directory Sync FAQ Google Cloud Directory Sync (GCDS) About Google Cloud Directory Sync GCDS best practices What is synced? System requirements 1. Download and install GCDS 2. Prepare your LDAP directory 3. Organize LDAP data 4. Authorize your Google Account 5. Allow access to URLs and ports What is Configuration Manager? Set up your sync with Configuration Manager Learn more about Configuration Manager options Work with configuration files Use LDAP search rules to synchronize data Omit data with exclusion rules and queries Use limits with GCDS Maintain different user attributes during a sync GCDS synchronization options Perform a manual synchronization Synchronize using the command line Schedule automatic synchronizations Manage and assign licenses Archive or unarchive users Sync groups and users to a Cloud Search identity source Manage conflicting accounts with GCDS Troubleshoot certificate-related problems GCDS error messages Troubleshoot common GCDS issues GCDS FAQ What GCDS information do I need before contacting support? Update GCDS GCDS reports and notifications Google Cloud Directory Sync release notes Inbound SCIM Get started with Inbound SCIM Manage connections Troubleshoot Inbound SCIM Sync user passwords with Microsoft Active Directory About Password Sync How does Password Sync work? 1. Get ready to use Password Sync 2. Choose your authentication method 3. Create a service account 4. Download and install 5. Configure Password Sync 6. Set up user authentication 7. Have users change their AD passwords Install and configure Password Sync from the command line Change a Password Sync configuration from the command line How to exclude some users from Password Sync Troubleshoot Password Sync Use logs to troubleshoot Authentication errors in Password Sync logs Password Sync error codes and messages Some user passwords aren't syncing Upgrade Password Sync Password Sync release notes Administrators Getting started Apps and integrations Set up and manage services Billing and subscriptions Data migration Data synchronization Device management Domain management Reports and monitoring Security and data protection User management Legal and compliance Support and troubleshooting Users Calendar Chat Cloud Search Gmail Groups Docs, Forms, Sheets, and Slides Drive Keep Meet Meet Hardware Sites Vids Developers Apps Script Marketplace Workspace APIs Training & business user guides Workspace Learning Center Google Skills Communities Workspace Admin Community Workspace Developers Community Google Workspace Help Administrators User management Guides Send feedback How to exclude some users from Password Sync Stay organized with collections Save and categorize content based on your preferences. You might want to prevent certain users' Google Workspace and Cloud Identity passwords from being synchronized to your Google domain. This article explains how to exclude users from Password Sync. Password Sync is available to Google Workspace and Cloud Identity administrators. Important In most cases, there's no need to exclude users from Password Sync. Doing so requires advanced expertise in setting up Active Directory permissions. Google Cloud support might not be able to assist with this setup. If you encounter any password sync issues, revert to a standard configuration to make sure the issue isn't with your Active Directory permissions. Exclude users from a sync This method is based on the way Password Sync retrieves users' email addresses to update the Google domain. If Password Sync can't retrieve the email address, it can't update the password in Google. To exclude users from the sync, create a service user for Password Sync that won't have access to the excluded users' email addresses. Open Active Directory Users and Computers (ADUC). Navigate to any organizational unit you use for administrative users, and create an Active Directory user for Password Sync to use. We'll refer to it as the Password Sync user. Make sure that Advanced Features is turned on under the View menu. Select any users or organizational units you wish to exclude, and right-click them. Click Properties. Click the Security tab. Click the Add button. Enter the name of the Password Sync user you created in step 2 and click OK. A new entry is added for the Password Sync user. Check the Deny / Read box. Click OK. From the Start menu, run Password Sync. In the Active Directory step of the Password Sync configuration, enter the username and password of the Password Sync user. Complete the configuration as usual. Once Password Sync is running with this configuration, it will not sync the passwords for any users it doesn't have access to. The Password Sync service logs show errors when trying to find these users' email addresses. This indicates the exclusion is working as expected. Undo the exclusion To undo the exclusion, simply remove any Deny entries you've created for the Password Sync user. To make sure you've removed every entry, you can create another Password Sync user in Active Directory. Then, set Password Sync to use it in the Active Directory step of the Password Sync configuration. Related topic Configure Password Sync Google, Google Workspace, and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated. Send feedback Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates. Last updated 2026-07-17 UTC. Need to tell us more? [[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-17 UTC."],[],[]] Try Google Workspace Boost your productivity with AI at no cost Admin Community Get answers from industry peers and experts Customer Care Learn about support options and services Documentation & training Help Centers Developer guides Learning Center Google Skills Tools Admin console Apps Script Dashboard Google Cloud console Support Admin Community Developers Community Customer Care Terms Privacy Manage cookies English Deutsch Español – América Latina Français Indonesia Italiano Nederlands Polski Português – Brasil Svenska Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어