# Cis Gworkspace 4.1.2.1

> Ensure Super Admin account recovery is disabled

- Skill: `cyberstrikeus/cis-gworkspace-4-1-2-1` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-gworkspace-4-1-2-1`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-gworkspace-4-1-2-1/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-gworkspace-4-1-2-1

---


# 4.1.2.1 Ensure Super Admin account recovery is disabled

## Profile Applicability

- Enterprise Level 2

## Description

This option allows Super Admin users to recover access to their accounts if their password has been forgotten.

The option is not available if either _Single Sign On_ or _Password Sync_ is in use.

## Rationale

Allowing Super Admins to recover access to their accounts when they have forgotten their passwords reduces the number of support tickets generated by users, and reduces the amount of down time spent waiting on the account recovery process to initiate and complete.

## Impact

The potential impact to Super Admins being allowed to recover their accounts includes:

1. The Super Admins are now empowered to reset their passwords.
2. The Super Admins will no longer need to call a helpdesk or open a support ticket to regain access to their account.

An organization that allows users to recover their account will realize less time spent by administrative staff working on these tasks.

## Audit

To verify this setting via the Google Workspace Admin Console:

1. Log in to `https://admin.google.com` as an administrator.
2. Select `Security`.
3. Select `Authentication`.
4. Under `Account recovery` select `Super admin account recovery`.
5. Ensure `Allow super admins to recover their account` is `unchecked`.

## Remediation

To configure this setting via the Google Workspace Admin Console:

1. Log in to `https://admin.google.com` as an administrator.
2. Select `Security`.
3. Select `Authentication`.
4. Under `Account recovery` select `Super admin account recovery`.
5. Set `Allow super admins to recover their account` to `unchecked`.
6. Click `Save`.

## Default Value

`Allow super admins to recover their account` is `OFF`

