Multi-party approval for sensitive actions  |  Security & data protection  |  Google Workspace Help Skip to main content Security & data protection Documentation Administrators Getting started Apps and integrations Set up and manage services Billing and subscriptions Data migration Data synchronization Device management Domain management Reports and monitoring Security and data protection User management Legal and compliance Support and troubleshooting Users Calendar Chat Cloud Search Gmail Groups Docs, Forms, Sheets, and Slides Drive Keep Meet Meet Hardware Sites Vids Developers Apps Script Marketplace Workspace APIs Training & business user guides Workspace Learning Center Google Skills Community Communities Workspace Admin Community Workspace Developers Community Support / English Deutsch Español – América Latina Français Indonesia Italiano Nederlands Polski Português – Brasil Svenska Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어 Sign in Administrators Security & data protection Admin console Contact us Overview Guides Security & data protection Overview Guides Documentation More Community More Support Get started Security checklists Security checklist for small businesses (1-100 users) Security checklist for medium and large businesses (100+ users) Threat types Account security About 2SV enforcement for admins Add employee ID as a login challenge Avoid account lockouts when 2-Step Verification is enforced by your organization Block access to consumer accounts Deploy 2-Step Verification How 2-Step Verification works with legacy apps How 2-Step Verification works with third-party IdPs Investigate and take action on suspicious session cookies Manage a user's security settings Prevent cookie theft with session binding Protect Google Workspace accounts with security challenges Protect your business with 2-Step Verification Recover an account protected by 2-Step Verification Set session length for Google Cloud services Set session length for Google services Temporarily turn off login challenges for a user Transfer a Drive file from an unknown owner Advanced Protection Program Advanced Protection Program FAQ Enable user enrollment in the Advanced Protection Program Manage Advanced Protection Program user enrollment Protect users with the Advanced Protection Program Alert center About the alert center Configure alert center email notifications Delete alerts Grant access to the alert center Provide feedback on alerts Recommended actions: Take action in response to alerts Start an investigation from the alert center Use rules to turn alerts on or off Use the alert center View alert details View and change alert assignees View and change alert severity View and change alert status View VirusTotal reports from the alert center Assured Controls & Access Transparency About Assured Controls and Assured Controls Plus Access Approvals: Require Google staff to request approval before viewing support data Access Management: Limit the Google staff who can take support actions related to your data Access Transparency log events Access Transparency: View logs on Google access to user content Assured Support for Access Management Policy compliance log events What data is covered by Access Management and Access Approvals? Chrome Enterprise Chrome browsers log events Chrome data protection summary report Chrome high risk domains report Chrome high risk users report Chrome threat protection summary report Domain types with most content transfer on Chrome report Domains with most content transfer on Chrome report Investigate and take action on suspicious files Monitoring for insider risk and data loss Protect Chrome users with Chrome Enterprise Premium Sensitive content transfers on Chrome report Set up timeout deadlines for DLP & malware scans Use Chrome Enterprise Premium to integrate DLP with Chrome Use custom URL lists for DLP in Chrome Use data masking to strengthen DLP in Chrome Users with most content transfer on Chrome report Client-side encryption About client-side encryption Add and manage key services for client-side encryption Assign client-side encryption to users Choose your key service for client-side encryption Client-side encryption FAQ Client-side encryption setup overview Client-side encryption user experience overview Connect to your identity provider for client-side encryption Convert exported and decrypted Google files to Microsoft Office files Decrypt exported client-side encrypted files and email Gmail only: Configure S/MIME for client-side encryption Set up and manage hardware keys for Gmail Migrate messages to Gmail as client-side encrypted email Protect your organization's data with CSE Provide external access to client-side encrypted content Set up your external key service for client-side encryption Turn client-side encryption on or off for users View logs and reports for client-side encryption Classification labels Apply Default classification labels to new files automatically Apply classification labels to Drive files automatically with DLP rules Create classification labels for your organization Edit and monitor classification labels for your organization Enable or disable a classification label Get started as a classification labels admin Label Google Drive files automatically using AI classification Context-Aware Access About Context-Aware Access Allow users to unblock apps with remediation messages in Context Aware Access Apply recommended access levels Assign Context-Aware access levels to apps Assign Context-Aware access levels to the Admin console Assign access levels to Google-owned apps Assign access levels to private web apps Assign access levels to third-party apps Apply a default Context-Aware Access policy for all SAML apps Combine DLP rules with Context-Aware Access conditions Context-Aware Access examples for Advanced mode Context-Aware Access examples for Basic mode Context-Aware Access FAQ Control access to actions in apps Create Context-Aware access levels Delete access levels (which are a shared resource) Deploy Context-Aware Access Protect your business with Context-Aware Access Use Context-Aware Access with configuration groups Use case: Device policy enforcement Use case: Managed Chrome browser enforcement Use case: Public IP address enforcement Use case: Require enterprise certificates Use cases: Exempt trusted third-party apps from being blocked Data loss prevention About DLP Create data protection rules DLP Data Protection Insights reports Examples of DLP rules with nested condition operators How to use predefined content detectors Prevent data leaks with Data protection recommended rules View content that triggers DLP rules View DLP content and rule size limits Calendar DLP About DLP for Calendar Chat DLP About DLP for Chat Drive DLP Create DLP for Drive rules and custom content detectors View DLP for Drive dashboard incidents, alerts, and audit events Prevent users from downloading, printing, or copying files DLP for Drive FAQ Gmail DLP About DLP for Gmail Add classification notes to outgoing messages Apply classification labels automatically Email authentication About authentication methods Authentication report Help prevent Drive spam and phishing Set up BIMI Set up DKIM Set up DMARC Set up SPF Gemini & agents How Google helps protect Gemini users from malicious content & prompt injections Indirect prompt injections & Google's layered defense strategy for Gemini Control access to Gemini Enterprise agents Manage Gemini Enterprise agents for Workspace users Rules Admin access to reporting rules & activity rules Create and manage activity rules Create and manage trust rules for Drive sharing Create & manage rules from the Rules page Automated account suspension for specific IP logins Security center About the security center About the security investigation tool Admin auditing for the security center Admin log event changes Admin privileges for the security center Admin privileges for the security investigation tool Assignments log events Change the time zone in the security investigation tool Configure settings for your investigations Create a custom chart based on an investigation Customize searches with nested queries Data sources for the security investigation tool Devices Get started with the security health page Gmail messages Group results by attribute when searching Investigate chat messages to moderate content and protect your data Investigate file sharing Investigate reports of malicious emails Investigate users across data sources Meet hardware log events Monitor the health of your Calendar settings Monitor the health of your device management settings Monitor the health of your Drive settings Monitor the health of your Gmail settings Monitor the health of your Groups settings Monitor the health of your Marketplace apps settings Monitor the health of your security settings Monitor the health of your Sites settings Require reviewers for bulk actions Save, share, delete, and duplicate investigations Search and investigate user log events Take action based on search results Use the security dashboard Use the investigation tool to end meetings Use the investigation tool to view sensitive content Users View the security dashboard, investigation tool, and security health page View VirusTotal reports from the investigation tool Other Firewall and proxy settings Guidelines for setting up a third-party CASB with Google Workspace Manage Google Workspace smart features for your users Moderate Chat and Gmail messages Multi-party approval for sensitive actions Obtain Google IP address ranges Security advisor for app access protection Security advisor for data protection Security advisor: Turn on recommended settings Administrators Getting started Apps and integrations Set up and manage services Billing and subscriptions Data migration Data synchronization Device management Domain management Reports and monitoring Security and data protection User management Legal and compliance Support and troubleshooting Users Calendar Chat Cloud Search Gmail Groups Docs, Forms, Sheets, and Slides Drive Keep Meet Meet Hardware Sites Vids Developers Apps Script Marketplace Workspace APIs Training & business user guides Workspace Learning Center Google Skills Communities Workspace Admin Community Workspace Developers Community Google Workspace Help Administrators Security & data protection Guides Send feedback Multi-party approval for sensitive actions Stay organized with collections Save and categorize content based on your preferences. Supported editions for this feature: Enterprise Standard and Enterprise Plus; Education Standard and Education Plus; Enterprise Essentials Plus. Compare your edition As a Google Workspace administrator, you can protect against malicious actions in the Google Admin console by using multi-party approval. When multi-party approval is on, a second administrator must approve changes to sensitive settings. You can use multi-party approval for certain security, Google Groups, Domains, Google Calendar, and Google Vault settings. To review all Admin console settings that multi-party approval can protect, go to Multi-party approval settings (later on this page). Note: Apps and services can also access certain Admin console settings through APIs. Separate multi-party approvals protect sensitive actions performed through public API calls. Before you begin To review requests for sensitive Admin console actions, any admin who isn't a super administrator must have either the Can review Multi-Party Approvals for all sensitive actions privilege or the privilege required to perform the sensitive action. If you turn off multi-party approval for your organization, pending requests remain active until they are approved, denied, canceled, or expire. If multi-party approval is turned on in a resold customer’s domain, and a reseller admin tries to update a sensitive setting, the approval request is sent only to the resold admins. Only these admins can approve, deny, or view the request. Step 1: Turn multi-party approval on or off You must be signed in as a super administrator for this task. In the Google Admin console, go to Menu Security Authentication Multi-party approval settings. Go to Multi-party approval settings Click Multi-party approval settings. Check or uncheck the Require multi-party approval for sensitive actions box. Click Save. Click a settings category and a setting. Learn about the settings (later on this page). To require multi-party approval for a setting, check the box. Click Save. Step 2: Give admins multi-party approval privileges You must be signed in as a super administrator for this task. Create one or more custom admin roles, each of which includes the multi-party approval privileges you want admins to have. Tip: Some Admin console actions require being a super admin, such as turning 2-Step Verification (2SV) on or off. If multi-party approval is turned on for one of these actions, a second super admin must review any associated multi-party approval requests. For details, go to Make a user a super admin. Assign the custom admin role that you created in step 1 to one or more admins. For details, go to Assign specific admin roles. Save the role configuration that you assigned in step 2. Step 3: Review multi-party approval requests You can review multi-party approval requests that you created, as well as requests from others that you're authorized to review. In the Google Admin console, go to Menu Security Authentication Multi-party approval requests. Go to Multi-party approval requests You must be signed in as a super administrator for this task. To approve or deny a request, click the request name Approve request or Deny request. To cancel a request that you submitted, click Requests submitted request name Cancel request. Multi-party approval settings Multi-party approval for security settings 2-Step Verification Check the box to require multi-party approval for changes to your organization's 2SV settings. A super admin must approve the request. For details, go to Protect your business with 2-Step Verification. Account recovery Requires multi-party approval to change your organization's account recovery settings. A super admin must approve the request. For details, go to Set up password recovery for users. Google session control Requires multi-party approval to change your organization's Google session control settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review security actions Security Control security settings read and write For details, go to Set session length for Google services. Advanced Protection Program Requires multi-party approval to change your organization's Advanced Protection Program settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review security actions Security Control security settings read and write For details, go to Protect users with the Advanced Protection Program. Login challenges Requires multi-party approval to change your organization's login challenges settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review security actions Security Control security settings read and write For details, go to Protect Google Workspace accounts with security challenges. Passwordless Requires multi-party approval to change your organization's passwordless settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review security actions Security Control security settings read and write For details, go to Allow users to skip passwords at sign-in. Domain-wide delegation Requires multi-party approval to change your organization's domain-wide delegation settings. A super admin must approve the request. For details, go to Control API access with domain-wide delegation. SSO with third-party identity provider (IdP) Requires multi-party approval to change your organization's single sign-on (SSO) with third-party IdP settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review security actions Security Control security settings read and write Security Control inbound SSO settings read and write For details, go to Setting up SSO. Context-Aware Access Requires multi-party approval to change your organization's Context-Aware Access settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review security actions Security Data Security Access Level Management For details, go to Turn on and turn off Context-Aware Access. Multi-party approval for API access to security settings SSO with third-party IdP Requires multi-party approval to change your organization’s SSO with third-party IdP settings through an API. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review security actions Security Control security settings read and write Security Control inbound sso settings read and write Multi-party approval for domains admin settings Domains API Requires multi-party approval for these sensitive domain settings: Add a user alias domain or secondary domain Change your primary domain for Google Workspace Remove a domain from your managed Google Account A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review domain actions Admin API privileges Domain Management Multi-party approval for calendar settings Calendar sharing Requires multi-party approval to change your organization's Calendar sharing settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review calendar actions Calendar All Settings Manage settings For details, go to Set Google Calendar sharing options. General Calendar settings Requires multi-party approval to change your organization's Calendar general settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review calendar actions Calendar All Settings Manage settings For details, go to Manage Calendar for your users. Calendar third-party archiving settings Requires multi-party approval to change your organization's Calendar third-party archiving settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review calendar actions Third Party Archiving Manage Third Party Archiving Settings For details, go to Integrate Calendar with a third-party archiving solution. Multi-party approval for groups settings Groups sharing Requires multi-party approval to change your organization's Groups for Business sharing settings. A super admin, or an admin with one of the following privileges, must approve the request: Multi Party Approval Can review multi-party approvals for all sensitive actions Multi Party Approval Review Groups actions Groups for Business Groups service settings For details, go to Set organization-wide policies for using groups. Multi-party approval for Vault settings Create export Requires multi-party approval to change your organization's Google Vault export settings. A super admin, or an admin with the Multi Party Approval Can review multi-party approvals for all sensitive actions Review Vault actions privilege must approve the request. For details, go to Set up Multi-party approval for Vault exports. Send feedback Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates. Last updated 2026-07-17 UTC. Need to tell us more? [[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-17 UTC."],[],[]] Try Google Workspace Boost your productivity with AI at no cost Admin Community Get answers from industry peers and experts Customer Care Learn about support options and services Documentation & training Help Centers Developer guides Learning Center Google Skills Tools Admin console Apps Script Dashboard Google Cloud console Support Admin Community Developers Community Customer Care Terms Privacy Manage cookies English Deutsch Español – América Latina Français Indonesia Italiano Nederlands Polski Português – Brasil Svenska Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어